Skip to content
Content type · 30 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–30 of 30 sort newestlargest fineoldest
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy ·Garante ·Art. 5, 12, 24 +3 Public Authority Supervisory Authorities Integrity and Confidentiality Principle
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Privacy by Design Personal Data Sep 16, 2026
€20,000 AEPD fines El Español for publishing video of minor assailant without anonymization El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Anonymization Privacy by Design & Default Privacy by Default Sep 16, 2026
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy ·Garante ·Art. 5, 9, 25 +1 Integrity and Confidentiality Principle Data Breaches Right of Access Sep 3, 2026
€9.5M Garante · 556/2026 Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited… Italy ·Art. 5, 6, 7 +5 Personal Data Integrity and Confidentiality Principle Controllers Jul 23, 2026
€100,000 Orange Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Orange Romania SA €100,000 for failing to implement sufficient technical and… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Privacy by Design Security Privacy by Design & Default Jul 17, 2026
€50,000 Garante · 10128005 The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Art. 5, 6, 13 +3 Personal Data Monitoring DPIA
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Personal Data IP Address Legitimate Interest Jul 14, 2026
€6,000 A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller) The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the… 382/2026 ·Italy ·Garante Privacy by Design Privacy by Design & Default DPIA May 28, 2026
€55,000 The data controller for the case is a government body called the Agency for Digital Italy (AgID) AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the… 419/2026 ·Garante ·Art. 5, 12, 14 +1 Personal Data Controllers Processing May 28, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·AEPD ·Art. 5, 25 Privacy by Design & Default Privacy by Default Privacy by Design Apr 15, 2026
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 25 Security Privacy by Design Privacy by Default Dec 22, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Personal Data Processing Supervisory Authorities Nov 26, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€4,750 The District Sanitary Inspector in Police: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€865,000 Aktia Bank Plc: Insufficient technical and organizational measures to ensure information security. ⇄ 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Privacy by Default Oct 23, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Sep 11, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organizational measures to ensure information security. ⇄ 1.800.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Accountability Sep 8, 2025
€80,000 Careggi University Hospital: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Aug 4, 2025
€9,000 Hestia Publishers & Booksellers, I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €9.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 25, 32 +2 Security Pseudonymization Controllers Jul 21, 2025
€25,000 Party "Alliance for the Union of Romanians": Non-compliance with the general principles of data processing. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Processing Personal Data Security Jun 26, 2025
€50,000 Lombardy Region: Insufficient legal basis for data processing. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +3 Controllers Processing Processors Apr 29, 2025
€20,000 Company: Non-compliance with general principles for data processing. ⇄ Een boete van 20.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD/GBA ·Art. 5, 6, 12 +4 Processing Marketing Personal Data Apr 22, 2025
€4,000 Hospital: Non-compliance with general principles of data processing. ⇄ 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 13, 14, 25 +1 Personal Data Processing Processors Mar 24, 2025
€3.5M CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a… SPAIN ·AEPD ·Art. 5, 25 Privacy by Design & Default Privacy by Default Privacy by Design Dec 12, 2024
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·AEPD ·Art. 5, 25, 32 Privacy by Design & Default Privacy by Default Privacy by Design Oct 26, 2023
€50,000 Athens Urban Transport Organization: Non-compliance with general data processing principles The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with… GREECE ·HDPA ·Art. 5, 25, 35 Privacy by Design & Default Privacy by Default Privacy by Design Sep 25, 2023
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE ·CNIL ·Art. 5, 13, 25 +2 Privacy by Default Storage Limitation Retention Period Nov 10, 2022
€150M Google LLC is a subsidiary owned wholly by Alphabet Inc Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out… SAN-2021-023 ·France ·CNIL Supervision Supervisory Authorities Material scope (GDPR) Dec 31, 2021
Deutsche Wohnen SE: Non-compliance with general data processing principles In addition to sanctioning violations of privacy by design principles (Art. 5 GDPR, Art. 25 GDPR - see separate entry), the Berlin data protection commissioner imposed further… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Privacy by Design Privacy by Design & Default Privacy by Default Oct 30, 2019