Skip to content
Content type · 227 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 227 sort newestlargest fineoldest
Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to The DPA received a complaint from a data subject, after the Icelandic Farmers’ Association operating a database, disclosed her personal data without consent to the company… 2025010358 ·Iceland ·Art. 5, 14 Legitimate Interest Personal Data Fairness & Transparency Sep 23, 2026
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Processors Controllers Processing Agreement Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Privacy by Design Personal Data Sep 16, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy ·Garante ·Art. 5, 12, 24 +3 Public Authority Supervisory Authorities Integrity and Confidentiality Principle
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Consent Personal Data Right to Object Sep 15, 2026
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Personal Data Healthcare Right of Access Sep 15, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Privacy by Design & Default Personal Data Privacy by Design Sep 10, 2026
IP Slovenia: Controller breached Art. 15(1)(d) and 15(3) GDPR by denying storage info and The data subject made an access request asking for (i) a copy of their personal data processed by the controller and (ii) information on the envisaged storage period of this data.… 0602-68/2025/18 ·IP-RS ·Art. 12, 15 Right of Access Controllers Personal Data Sep 8, 2026
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Personal Data Recipient Legitimate Interest Sep 8, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Controllers Personal Data Sep 4, 2026
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Integrity and Confidentiality Principle Data Breaches Notification Obligation Sep 2, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Personal Data Right of Access Right to be Forgotten Aug 26, 2026
€280,000 Garante · 10269624 The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the… Italy ·Art. 6, 7, 12 +2 Right to Object Personal Data Direct Marketing
€15,300 10266250 The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone… Italy ·Garante ·Art. 5, 6, 7 +6 Processors Controllers Personal Data Aug 19, 2026
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Data Breaches Notification Obligation Integrity and Confidentiality Principle Aug 19, 2026
€1,000 Austrian DSB: Employee who shared customer's phone number acted as GDPR controller An employee (controller) of a company shared the telephone number of a costumer (data subject) with a third person. The third person who was a personal acquaintance of the… Austria ·Art. 4, 5, 6 +1 Controllers Legitimate Interest Personal Data Aug 18, 2026
€1,282 IP-RS · 0609-41/2026/7 A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal… Slovenia ·Art. 28 Processors Controllers Representatives
ICO (UK) - ACRO Criminal Records Office ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates,… ACRO Criminal Records Office ·United Kingdom ·Art. 32 Controllers Processors Accountability Aug 7, 2026
Finnish DPA finds 12-year retention of rental applicant data violates minimisation The DPA began investigating the storage periods of the personal data of housing applicants (the data subjects) contained in rental housing applications during a previous… TSV/1319/2025 ·Finland ·Tietosuojavaltuutettu Retention Period Storage Limitation Privacy by Design Aug 7, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
€2,000 33/2020 The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant… Greece ·HDPA ·Art. 4, 5, 12 +8 Right to be Forgotten Personal Data Right of Access
€9.5M Garante · 556/2026 Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited… Italy ·Art. 5, 6, 7 +5 Personal Data Integrity and Confidentiality Principle Controllers Jul 23, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Personal Data Lawful Basis Jul 22, 2026
€90,000 AEPD · PS-00159-2025 On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15 Right to Restriction Right of Access Controllers
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Right to be Forgotten Personal Data Right to Restriction Jul 21, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Integrity and Confidentiality Principle Personal Data Identification Jul 17, 2026
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain ·AEPD Integrity and Confidentiality Principle Data Breaches Notification Obligation Jul 16, 2026
€1.4M Garante · 484/2026 EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Art. 5, 13, 14 +2 Retention Period Controllers Right of Access Jul 3, 2026
€5.8M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Hera Comm S.p.A. €5,800,000 for violations of the general data processing principles under Article 5 of the GDPR, alongside… Italy ·Garante ·Art. 5, 12, 13 +3 Processors Controllers Supervision Jul 3, 2026
€1.4M EstEnergy S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined EstEnergy S.p.A. €1,400,000 for violations of general data processing principles under Article 5(1) of the GDPR, alongside… Italy ·Garante ·Art. 5, 12, 13 +3 Controllers Processors Retention Period Jul 3, 2026
€5.8M 483/2026 Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy ·Garante ·Art. 5, 12, 13 +3 Controllers Processors Personal Data Jul 3, 2026
Persónuvernd (Island) - 2025010358 The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Art. 5, 32 Integrity and Confidentiality Principle Monitoring Personal Data Jul 1, 2026
2025010364 The DPA received a complaint from a data subject regarding the processing of their personal data by Borgarholtsskóli (a school and the controller) in connection with an anonymous… 2025010364 ·Iceland ·Persónuvernd Personal Data Fairness & Transparency Right to be Forgotten Jun 24, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Security Data Breaches Integrity and Confidentiality Principle Jun 19, 2026
€90,000 Acquirente Unico S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Acquirente Unio S.p.A. €90,000 for insufficient fulfilment of data subjects' rights under GDPR Articles 12, 16, and 28. The… Italy ·Garante ·Art. 12, 16, 28 Processors Supervision Controllers Jun 18, 2026
€5,000 Garante · 457/2026 The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Art. 5, 6, 12 +2 DPIA Personal Data Fairness & Transparency Jun 18, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
€15,300 Green Partner S.r.l.s.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Green Partner S.r.l.s. €15,300 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 15–22, and 28,… Italy ·Garante ·Art. 5, 6, 7 +3 Controllers Processors Supervision Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Controllers Processors Security Jun 11, 2026
€100,000 ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.): Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.) €100,000 for insufficient fulfillment of data subjects' rights,… Greece ·HDPA ·Art. 5, 12, 15 +1 Processors Supervisory Authorities Controllers Jun 5, 2026
€80,000 PRELUDE GROUP E.E.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined PRELUDE GROUP E.E. €80,000 for failing to implement sufficient technical and organizational measures to ensure information… Greece ·HDPA ·Art. 28, 29, 32 Security Processors Controllers Jun 2, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Controllers Personal Data Supervisory Authorities Jun 1, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 Personal Data Retention Period Integrity and Confidentiality Principle May 28, 2026
€2,951 Land-surveying office: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a land-surveying office €2,951 for failing to implement sufficient technical and organizational measures to ensure… Poland ·UODO ·Art. 28, 32 Security Controllers Processors May 25, 2026
€4,958 District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined the District Governor of Lubartów €4,958 for failing to implement adequate technical and organizational measures to ensure information security, citing… Poland ·UODO ·Art. 5, 25, 28 +1 Privacy by Design Processors Controllers May 25, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland ·UODO ·Art. 24, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers May 25, 2026
€100,000 Energia Sostenibile S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Energia Sostenibile S.r.l. €100,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 13, 15, 24,… Italy ·Garante ·Art. 5, 6, 7 +5 Controllers Processors Supervision May 14, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Personal Data Transparency May 12, 2026