Skip to content
Content type · 70 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 70 sort newestlargest fineoldest
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Right of Access Controllers Personal Data Jul 22, 2026
APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Catalonia Anonymization Professional Secrecy Integrity and Confidentiality Principle Jul 17, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Healthcare Health Data Jul 16, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Processing Criminal Data May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Transparency Personal Data Controllers May 12, 2026
€60,000 ENDESA (energieleverancier): Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Processing NL Dec 30, 2025
€60,000 ENDESA (energy supplyer): Insufficient legal basis for data processing The complainant's bank account was charged by ENDESA, the beneficiary of which was a third party, who had been convicted under criminal law and imposed with a two-year restraining… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Dec 30, 2025
€2,670 POLEN, Autoriteit voor gegevensbescherming: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 2.670 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 38 Health Data Supervisory Authorities Professional Secrecy NL Sep 12, 2025
€1,000 Vereniging van Eigenaren: Niet-naleving van de algemene principes voor gegevensverwerking. Boete van €1.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Processing IP Address NL May 19, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Personal Data May 19, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… aepd ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Controllers Fairness & Transparency Processors Apr 15, 2025
€500,000 Handelskamer, Industrie, Dienstverlening en Transport van Spanje: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 14 Processors Processing Controllers NL Apr 15, 2025
€600 FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA. The controller was unable to ensure the confidentiality of personal data, which resulted in a… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Apr 9, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Employees Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Processing Integrity and Confidentiality Principle NL Mar 28, 2025
€40,000 Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +3 Notified Body Responsibilities and Operational Obligations Processing Professional Secrecy NL Mar 24, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA ·azop ·Art. 13, 32, 33 +1 Healthcare Health Data Integrity and Confidentiality Principle Mar 24, 2025
€120,000 BEEDIGITAL AI, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine against BEEDIGITAL AI, S.A.. A individual had lodged a complaint with the DPA against the controller because they had received advertising from… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle IP Address Controllers Feb 11, 2025
€100,000 VIEC Limited: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… IRELAND ·Art. 5, 32 ·Non-compliance with general data processing principles Data Breaches Integrity and Confidentiality Principle Security Dec 22, 2022
€2,000 Property owner administrative board: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on a Property Owners Association. Two property owners had filed a complaint with the DPA. The individuals had submitted a request… SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Personal Data Dec 20, 2022
€3,000 INDECEMI, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,000 on INDECEMI, S.L.. A person had filed a complaint with the DPA against the controller after receiving an email from the controller… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Dec 3, 2022
€70,000 UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC (UPS). A person had filed a complaint with the DPA because UPS had delivered a… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Security IP Address Nov 3, 2022
€56,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA for having unsuccessfully requested a copy of their phone contract from… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Telecommunications IP Address Oct 31, 2022
€5,000 RESTEXPERIENCE, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined RESTEXPERIENCE, S.L. EUR 5,000. The controller had accidentally sent an email containing tax information of 36 individuals to 11 unauthorized… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Professional Secrecy Security Oct 19, 2022
€35,000 OES GLOBAL ENERGY S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 35,000 on OES GLOBAL ENERGY S.L.. A customer of the controller had filed a complaint with the DPA after receiving an e-mail from the… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Professional Secrecy Personal Data Oct 17, 2022
€64,000 EVERIS SPAIN S.L: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of… aepd ·Art. 5, 32 ·Non-compliance with general data processing principles Integrity and Confidentiality Principle Data Breaches Insurance Oct 9, 2022
€1,200 URBANO DIVERTIA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on URBANO DIVERTIA S.L.. A customer had filed a complaint with the DPA, for having received a document from the controller with data relating to… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Controllers Sep 23, 2022
€2,000 Bitfactor SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Bitfactor SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to a malfunction of an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Sep 22, 2022
€800 EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. EUR 800. A trade union had filed a complaint with the DPA because the company had unauthorizedly shared… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Jul 26, 2022
€56,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 56,000 on BANKINTER, S.A.. The controller had inadvertently sent a report on the data subject's investment portfolio to a third party.… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Controllers Jul 18, 2022
€3,000 S.C. Wine Point S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on S.C. Wine Point S.R.L.. A data subject had filed a complaint with the DPA for having received an advertising e-mail from the… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Security Professional Secrecy Jun 15, 2022
€26,000 Garante per la protezione dei dati personali (Italy) - 9794895 The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Art. 5, 12, 13 +3 Video Surveillance Storage Limitation Monitoring Jun 9, 2022
€1,000 LORIS FUEL SHOP SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on the gas station operator LORIS FUEL SHOP SRL. A person had filed a complaint with the DPA because pictures of him were… ROMANIA ·ANSPDCP ·Art. 29, 32 Video Surveillance Integrity and Confidentiality Principle Security May 12, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Data Breaches Healthcare Apr 28, 2022
€500 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500 on a homeowners' association. The executive board of the owners' association had publicly posted a list of defaulting owners. The DPA… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Apr 12, 2022
€10,000 Findomestic Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on Findomestic Banca spa. A customer had filed a complaint with the DPA regarding a breach of confidentiality related to the… ITALY ·Garante ·Art. 5 Integrity and Confidentiality Principle Controllers Insurance Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Video Surveillance Integrity and Confidentiality Principle IP Address Apr 7, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Data Breaches Integrity and Confidentiality Principle Accuracy Apr 4, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·azop ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 8, 2022
€40,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A woman filed a complaint against the controller based on the fact that the controller had sent telephone bills… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle IP Address Telecommunications Oct 13, 2021
€18,000 CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of… SPAIN ·aepd ·Art. 5 Insurance Health Data Healthcare Sep 20, 2021
€3,000 UST GLOBAL ESPAÑA, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on UST GLOBAL ESPAÑA, S.A.. An employee filed a complaint against the controller with the DPA. UST GLOBAL ESPAÑA, S.A. was… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Data Breaches IP Address Jul 27, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·azop ·Art. 32 Processors Controllers Security Jul 5, 2021
€40,000 Aeroporto Guglielmo Marconi di Bologna S.p.a.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 5, 25, 32 Encryption Security Professional Secrecy Jun 10, 2021
€40,000 aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 28, 32 Security Encryption Integrity and Confidentiality Principle Jun 10, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·Art. 5, 6, 9 +2 ·Non-compliance with general data processing principles Integrity and Confidentiality Principle Data Breaches Healthcare Jun 7, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Personal Data Apr 15, 2021
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY ·NAIH ·Art. 32, 33, 34 Encryption Integrity and Confidentiality Principle Healthcare Mar 24, 2021
€15,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 15,000 on a homeowners' association. The controller had publicly displayed the record of a homeowners' meeting in the elevator of the… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Mar 9, 2021