Skip to content
Content type · 427 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 427 sort newestlargest fineoldest
Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to The DPA received a complaint from a data subject, after the Icelandic Farmers’ Association operating a database, disclosed her personal data without consent to the company… 2025010358 ·Iceland ·Art. 5, 14 Legitimate Interest Personal Data Fairness & Transparency Sep 23, 2026
€10,000 AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Spain ·Art. 4, 5, 7 +1 Personal Data IP Address Consent Sep 16, 2026
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Consent Right to Object Personal Data Sep 15, 2026
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Personal Data Recipient Legitimate Interest Sep 8, 2026
IP Slovenia: Controller breached Art. 15(1)(d) and 15(3) GDPR by denying storage info and The data subject made an access request asking for (i) a copy of their personal data processed by the controller and (ii) information on the envisaged storage period of this data.… 0602-68/2025/18 ·IP-RS ·Art. 12, 15 Right of Access Controllers Personal Data Sep 8, 2026
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Integrity and Confidentiality Principle Data Breaches Notification Obligation Sep 2, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Personal Data Right of Access Right to be Forgotten Aug 26, 2026
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Data Breaches Notification Obligation Integrity and Confidentiality Principle Aug 19, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
€9.5M Garante · 556/2026 Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited… Italy ·Art. 5, 6, 7 +5 Personal Data Integrity and Confidentiality Principle Controllers Jul 23, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Personal Data Lawful Basis Jul 22, 2026
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Personal Data IP Address Legitimate Interest Jul 14, 2026
€5M IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) fined IQVIA OPERATIONS FRANCE €5,000,000 on 2026-05-26 for: Non-compliance with general data processing principles. CNIL ·Art. 14, 25 ·Non-compliance with general data processing principles Supervisory Authorities IP Address Healthcare May 26, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Personal Data Consent Processing May 20, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Transparency Personal Data May 12, 2026
€240 Posada del León de Oro: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined Posada del León de Oro €240 on 2026-04-28 for: Non-compliance with general data processing principles. Spain ·AEPD ·Art. 5, 13 Supervisory Authorities Processing IP Address Apr 28, 2026
€4,000 SIPHONE 2020, S.L.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined SIPHONE 2020, S.L. €4,000 on 2026-04-28 for: Insufficient legal basis for data processing. Spain ·AEPD ·Art. 6, 13 Supervisory Authorities IP Address Employees Apr 28, 2026
€6.6M Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
€5,000 Framos Italia s.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Framos Italia s.r.l. €5,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Processing Supervisory Authorities Employees Apr 17, 2026
€5.9M Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
€6,600 Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Utility Company €6,600 on 2026-04-15 for: Insufficient legal basis for data processing. Slovenia ·IP-RS ·Art. 5 Processing Supervision IP Address Apr 15, 2026
€13,491 Legal Person: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Legal Person €13,491 on 2026-03-27 for: Insufficient technical and organisational measures to ensure information… Slovenia ·IP-RS ·Art. 32 Security Supervision IP Address Mar 27, 2026
€3,000 Municipality: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Municipality €3,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 Processing Public Authority Employees Mar 26, 2026
€5,000 Municipality: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Municipality €5,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 Processing Public Authority Employees Mar 26, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria ·DSB Legitimate Interest Personal Data Controllers Mar 20, 2026
€40,000 La7 S.p.A.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined La7 S.p.A. €40,000 on 2026-03-12 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5 Processing IP Address Telecommunications Mar 12, 2026
€900 ORNITOLÓGICA DE ANDALUCÍA FOA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined ORNITOLÓGICA DE ANDALUCÍA FOA €900 on 2026-03-02 for: Non-compliance with general data processing principles. Spain ·AEPD ·Art. 5 Processing IP Address Supervisory Authorities Mar 2, 2026
€1,000 Spain DPA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined an unnamed party €1,000 on 2026-03-01 for: Non-compliance with general data processing principles. AEPD ·Art. 5 ·Non-compliance with general data processing principles Processing Supervisory Authorities IP Address Mar 1, 2026
€15,000 Flamel S.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Flamel S.r.l. €15,000 on 2026-02-26 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 8, 11, 25 +3 Processing Supervisory Authorities IP Address Feb 26, 2026
€17M Reddit, Inc.: Non-compliance with general data processing principles Information Commissioner (ICO) fined Reddit, Inc. €16,610,000 on 2026-02-23 for: Non-compliance with general data processing principles. United Kingdom ·ICO ·Art. 5, 6, 8 +1 Processing IP Address Telecommunications Feb 23, 2026
€5,500 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €5,500 on 2026-02-16 for: Insufficient technical and organisational measures to ensure… IP-RS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Supervision Feb 16, 2026
€2,000 Comune di Velletri: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Comune di Velletri €2,000 on 2026-02-12 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +2 Processing Supervisory Authorities Education Feb 12, 2026
€6,000 Comune di Coccaglio: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Comune di Coccaglio €6,000 on 2026-02-12 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Processing Supervisory Authorities Cookies Feb 12, 2026
€5,220 Fundację Lumus: Non-compliance with general data processing principles Polish National Personal Data Protection Office (UODO) fined Fundację Lumus €5,220 on 2026-02-10 for: Non-compliance with general data processing principles. Poland ·UODO ·Art. 33, 34, 37 +1 Personal Data IP Address Processing Feb 10, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Types of Special Categories of Personal Data Jan 30, 2026
€12,000 Ministero della Cultura: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Ministero della Cultura €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Supervisory Authorities Processing Employees Jan 29, 2026
€12,000 Istituto San Giuseppe La Salle di Milano: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Istituto San Giuseppe La Salle di Milano €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Supervisory Authorities Processing Education Jan 29, 2026
€4,850 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €4,850 on 2026-01-20 for: Insufficient technical and organisational measures to ensure… IP-RS ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Supervision Jan 20, 2026
€1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… SPAIN ·AEPD ·Art. 5 Controllers Processing Security Jan 19, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Personal Data IP Address Fairness & Transparency Jan 16, 2026