Skip to content
Content type · 39 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–39 of 39 sort newestlargest fineoldest
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
Finnish DPA: requesting address, ID number and strong authentication for access request A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Finland ·Tietosuojavaltuutettu Identification Personal Data Supervisory Authorities Jul 22, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Integrity and Confidentiality Principle Personal Data Identification Jul 17, 2026
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Personal Data Healthcare
€700 Italian Red Cross: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Italian Red Cross €700 for violating general data processing principles under GDPR Articles 5(1)(c), 5(1)(f), and 9. The… Italy ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Retention Period Professional Secrecy May 28, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 Right of Access Criminal Data Personal Data May 13, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Personal Data Transparency May 12, 2026
DSB: complaint against Austrian media company dismissed, but cookie banner instruction issued ⇄ An Austrian media company (the controller) that published local news operated a website that collected personal data from visitors using cookies and a cookie consent banner. The… 2025-0.276.820 ·Oostenrijk Cookies Personal Data Right to be Forgotten Jan 7, 2026
€6,820 Austrian media company fined €6,820 for failing to comply with order to fix cookie banner An Austrian media company has been fined €6,820 by the Data Protection Authority because it failed to implement a binding instruction to modify the cookie banner on its website.… Austria ·DSB ·Art. 58 Right to be Forgotten Supervisory Authorities Cookies Jan 7, 2026
€60,000 ENDESA (energy supplier): Insufficient legal basis for data processing. ⇄ Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing Accountability Dec 30, 2025
€60,000 ENDESA (energy supplyer): Insufficient legal basis for data processing The complainant's bank account was charged by ENDESA, the beneficiary of which was a third party, who had been convicted under criminal law and imposed with a two-year restraining… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing IP Address
€2,670 POLAND, Data Protection Authority: Failure to appoint a data protection officer. ⇄ Een boete van 2.670 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). UODO ·Art. 38 ·Lack of appointment of data protection officer Supervisory Authorities Health Data Healthcare Sep 12, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Processing May 19, 2025
€1,000 Homeowners' Association: Failure to Comply with the Principle of Confidentiality ⇄ Boete van €1.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability Professional Secrecy May 19, 2025
€500,000 Chamber of Commerce, Industry, Services and Transport of Spain: Insufficient legal basis for the processing of data. ⇄ Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Processing Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… AEPD ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Retention Period Apr 15, 2025
€600 FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA. The controller was unable to ensure the confidentiality of personal data, which resulted in a… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Controllers Apr 9, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing Personal Data Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Accountability Personal Data Mar 28, 2025
€40,000 Company: Insufficient legal basis for the processing of data. ⇄ Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +3 Processing Professional Secrecy Personal Data Mar 24, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA ·AZOP ·Art. 13, 32, 33 +1 Security Supervisory Authorities Integrity and Confidentiality Principle Mar 24, 2025
€120,000 BEEDIGITAL AI, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine against BEEDIGITAL AI, S.A.. A individual had lodged a complaint with the DPA against the controller because they had received advertising from… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Processing Feb 11, 2025
€2,000 Property owner administrative board: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on a Property Owners Association. Two property owners had filed a complaint with the DPA. The individuals had submitted a request… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Processing Dec 20, 2022
€35,000 OES GLOBAL ENERGY S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 35,000 on OES GLOBAL ENERGY S.L.. A customer of the controller had filed a complaint with the DPA after receiving an e-mail from the… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Controllers Security Oct 17, 2022
€64,000 EVERIS SPAIN S.L: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of… AEPD ·Art. 5, 32 ·Non-compliance with general data processing principles Integrity and Confidentiality Principle Security Personal Data Oct 9, 2022
€800 EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. EUR 800. A trade union had filed a complaint with the DPA because the company had unauthorizedly shared… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Security Processing Jul 26, 2022
€56,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 56,000 on BANKINTER, S.A.. The controller had inadvertently sent a report on the data subject's investment portfolio to a third party.… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Jul 18, 2022
€26,000 Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Italy ·Garante ·Art. 5, 12, 13 +3 Public Authority Supervisory Authorities Storage Limitation Jun 9, 2022
€500 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500 on a homeowners' association. The executive board of the owners' association had publicly posted a list of defaulting owners. The DPA… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing IP Address Apr 12, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Integrity and Confidentiality Principle Data Breaches Personal Data Apr 4, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Mar 8, 2022
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·IMY ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Encryption Personal Data Jun 7, 2021
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Garante ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Healthcare Nov 26, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Oct 21, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Mar 9, 2020
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Processors Territorial scope (GDPR) Sep 3, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Anonymization Apr 12, 2019
Norwegian DPA: Legelisten.no may process healthcare reviews without prior consent Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Norway ·Datatilsynet (NO) Consent Supervisory Authorities Legitimate Interest Nov 8, 2017