Skip to content
Content type · 107 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 107 sort newestlargest fineoldest
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Processors Controllers Processing Agreement Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
RON 108,570 Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Sep 16, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy ·Garante ·Art. 5, 12, 24 +3 Public Authority Supervisory Authorities Integrity and Confidentiality Principle
RON 26,237 Fine against GEROCOSSEN S.R.L. Gerocossen SRL (the controller) suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Sep 8, 2026
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Integrity and Confidentiality Principle Data Breaches Notification Obligation Sep 2, 2026
RON 15,728 Fine against Poliserv JG (PJG) SRL A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges.… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Data Breaches Notification Obligation Integrity and Confidentiality Principle Aug 19, 2026
RON 523,900 Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Privacy by Design Jul 29, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
Finnish DPA: requesting address, ID number and strong authentication for access request A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Finland ·Tietosuojavaltuutettu Identification Personal Data Supervisory Authorities Jul 22, 2026
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France ·CNIL ·Art. 32, 34 Data Breaches Notification Obligation Healthcare Jul 21, 2026
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain ·AEPD Integrity and Confidentiality Principle Data Breaches Notification Obligation Jul 16, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Security Data Breaches Integrity and Confidentiality Principle Jun 19, 2026
€10,000 Altex Romania S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €10,000 for failing to implement sufficient technical and… ANSPDCP ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Notification Obligation Data Breaches Supervision Jun 18, 2026
€2,075 Edizioni Grandangolo di Giuseppe Castaldo: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Edizioni Grandangolo di Giuseppe Castaldo €2,075 for failing to comply with general data processing principles under Articles… Italy ·Garante ·Art. 5, 12, 13 +4 Notification Obligation Data Breaches Controllers Jun 18, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Data Breaches Integrity and Confidentiality Principle Notification Obligation Jun 13, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Controllers Processors Security Jun 11, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland ·UODO ·Art. 24, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers May 25, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland ·UODO ·Art. 5, 24, 25 +3 Data Breaches Integrity and Confidentiality Principle Notification Obligation May 19, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Data Breaches Notification Obligation May 8, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland ·DPC ·Art. 5, 32, 33 Notification Obligation Data Breaches Supervision Apr 30, 2026
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Supervisory Authorities Apr 30, 2026
€2,415 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Poland ·Art. 5, 24, 25 +2 Processors Integrity and Confidentiality Principle Controllers Apr 13, 2026
€2,350 Housing Associaction: Insufficient fulfilment of data breach notification obligations Polish National Personal Data Protection Office (UODO) fined Housing Associaction €2,350 on 2026-04-07 for: Insufficient fulfilment of data breach notification obligations. Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 7, 2026
Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access A controller, not named in the original decision but presumed to be a public institution, notified the Slovenian DPA after experiencing a data breach in relation to its website.… 0612-91/2025/40 ·Slovenia ·IP-RS Data Breaches Controllers Supervisory Authorities Mar 4, 2026
€15M UNACCEPTABLE: Insufficient technical and organizational measures to ensure information security. ⇄ The French data protection authority (CNIL) has imposed a fine of €15,000,000 on FREE. The company suffered a data breach as a result of insufficient technical and organizational… FRANCE ·CNIL ·Art. 32, 34 Security Data Breaches Notification Obligation Jan 8, 2026
€9,450 Gynecological Center: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 9,450 on a Gynecological Center. The controller sufferd a data breach and failed to report this to the DPO. POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 27, 2025
€5,000 Judicial enforcement officer: Insufficient compliance with obligations regarding the notification of personal data breaches. ⇄ Een boete van 5.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 33, 34 Controllers Data Breaches Education Oct 23, 2025
€5,000 Court Bailiff: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 5,000 on a court bailiff. The controller forwarded a letter containing personal data to the wrong person, failing to inform either the… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 23, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€870 Company: Insufficient compliance with obligations regarding the notification of data breaches. ⇄ 870 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·DSB ·Art. 33 Data Breaches Supervisory Authorities Controllers Sep 4, 2025
€870 Company: Insufficient fulfilment of data breach notification obligations The Austrian DPA has imposed a fine of EUR 870 on a company. After being informed of a data breach, the controller took adequate measures to close it but failed to inform the DPA. AUSTRIA ·DSB ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Sep 4, 2025
€9,000 Hestia Publishers & Booksellers, I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €9.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 25, 32 +2 Security Pseudonymization Controllers Jul 21, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Failure to comply with the obligations regarding the notification of personal data breaches. ⇄ 1.100 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28, 33 Controllers Processing Processors Jul 18, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine of EUR 1,100 on ADMINISTRACIONES BENIPON, S.L. The processor failed to notify the controller of a data breach and also used a sub-processor… SPAIN ·AEPD ·Art. 28, 33 Notification Obligation Data Breaches Processors Jul 18, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €20.725 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Accountability Supervisory Authorities Jun 24, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organizational measures to ensure information security. ⇄ 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·DPC ·Art. 5, 32, 33 +1 Security Personal Data Controllers Jun 23, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organizational measures to ensure information security. ⇄ Boete van €70.300 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Accountability Notification Obligation Apr 14, 2025
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… DPC Notification Obligation Data Breaches Controllers Dec 17, 2024
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Nov 26, 2024
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Notification Obligation Data Breaches Personal Data Aug 20, 2024
€210 Association: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an association EUR 210 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 30, 2024
€10,000 Azienda sanitaria locale Roma 3: Insufficient fulfilment of data breach notification obligations The Italian DPA has fined Azienda sanitaria locale Roma 3 EUR 10,000 for failing to report a data breach to the DPA in a timely manner and to properly document the data breach. ITALY ·Garante ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 21, 2024
€326,000 Santander Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 326,000 for failing to report a data breach to the DPA and data subjects in a timely manner. POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€18,000 Toyota Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Toyota Bank Polska S.A. EUR 18,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€800,000 NTT Data Italia S.P.A: Insufficient fulfilment of data breach notification obligations The Italian DPA has imposed a fine of EUR 800,000 on NTT Data Italia S.P.A. The fine is related to the fine imposed on UniCredit (ETid-2227). UniCredit had contracted NTT to carry… ITALY ·Garante ·Art. 28, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 8, 2024
€36,000 HISPAPOST, S.A.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine on HISPAPOST, S.A.. The police had found over a thousand abandoned letters containing the Hispapost logo. Hispapost had been contracted by… SPAIN ·AEPD ·Art. 28 Processors Notification Obligation Data Breaches Feb 1, 2024
€2,300 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a data controller EUR 2,300 for failing to report a data breach to the DPA and data subjects in a timely manner. UODO ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Supervisory Authorities Jan 18, 2024