Skip to content
Content type · 42 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–42 of 42 sort newestlargest fineoldest
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Processors Controllers Processing Agreement Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Controllers Retention Period Sep 4, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Personal Data Right of Access Right to be Forgotten Aug 26, 2026
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Privacy Shield Processing Agreement International Transfer Aug 25, 2026
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Data Breaches Notification Obligation Integrity and Confidentiality Principle Aug 19, 2026
€1,000 Austrian DSB: Employee who shared customer's phone number acted as GDPR controller An employee (controller) of a company shared the telephone number of a costumer (data subject) with a third person. The third person who was a personal acquaintance of the… Austria ·Art. 4, 5, 6 +1 Controllers Legitimate Interest Personal Data Aug 18, 2026
Finnish DPA finds 12-year retention of rental applicant data violates minimisation The DPA began investigating the storage periods of the personal data of housing applicants (the data subjects) contained in rental housing applications during a previous… TSV/1319/2025 ·Finland ·Tietosuojavaltuutettu Retention Period Storage Limitation Privacy by Design Aug 7, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Integrity and Confidentiality Principle Personal Data Identification Jul 17, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria ·DSB Legitimate Interest Personal Data Controllers Mar 20, 2026
DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful The data subject was involved in a legal dispute before a civil court in which the findings of an expert opinion led to the dismissal of the case. The expert opinion concerned the… DSB-D124.0850/25 ·Art. 9 Health Data Healthcare Types of Special Categories of Personal Data Jan 28, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Personal Data IP Address Fairness & Transparency Jan 16, 2026
€200 A medical student (the controller) worked as a ward attendant at a hospital Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with… 2026-0.016.479 ·Austria ·DSB Legitimate Interest Personal Data Integrity and Confidentiality Principle Jan 12, 2026
The controller, an Austrian registered association, operates a therapy centre for psychosomatic illnesses The data subject was a patient of the controller. On 28 July 2025, the data subject sent an access request by email under Article 15 GDPR, asking for full information on all… DSB-D124.2437/25 ·Austria ·DSB Right of Access Personal Data Controllers Jan 9, 2026
DSB · 2025-0.968.031 A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Pseudonymization Anonymization Health Data Dec 3, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€9,000 Hestia Publishers & Booksellers, I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €9.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 25, 32 +2 Security Pseudonymization Controllers Jul 21, 2025
€9,000 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by… GREECE ·HDPA ·Art. 5, 25, 32 +2 Pseudonymization Security Personal Data Jul 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Storage Limitation Accountability May 21, 2025
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE ·CNIL ·Art. 5, 66 Identification Supervisory Authorities Processing Sep 12, 2024
€14M Avast Software s.r.o.: €13,900,000 fine The Czech DPA has fined Avast Software s.r.o. EUR 13.9 million. The company had disclosed the personal data of around 100 million users of its antivirus software to the US company… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Unknown Personal Data Anonymization Pseudonymization Apr 15, 2024
DSB-D124.5337 In August 2021, an unprotected Excel file containing the names and PCR test results of several thousand individuals was sent from the compromised email account of the first data… 2023-0.273.912 ·Austria ·Art. 5, 6, 12 +3 Right to be Forgotten Right of Access Personal Data Oct 6, 2023
DSB (Austria): DSB lacks competence over court processing under Art. 55(3) GDPR On 03 May 2021, the data subject sent a request to the controller for the erasure of their financial asset information. The controller did not respond to their erasure request. On… 2021-0.909.100 ·Art. 55, 77 Right to be Forgotten Supervisory Authorities Controllers Jun 12, 2023
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN ·AEPD ·Art. 6 Lawful Basis Personal Data Legitimate Interest Sep 16, 2022
DSB · 2021-0.643.804 The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·Art. 6, 55 Legitimate Interest Controllers Personal Data Jun 9, 2022
€50 Belgian DPA: Roularta Media Group violated cookie consent rules On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Belgium ·APD/GBA ·Art. 4, 5, 6 +3 Consent Supervisory Authorities Personal Data May 25, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches Anonymization Security Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +3 Anonymization Pseudonymization Marketing Jan 27, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +5 Anonymization Pseudonymization Marketing Jan 27, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Security Encryption Pseudonymization Jan 19, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Security Encryption Jan 19, 2022
DSB Austria: Publishing companies-register data on free ad-funded platform unlawful The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered… 2021-0.698.184 ·Art. 6, 51, 57 +1 Legitimate Interest Personal Data Lawful Basis Oct 8, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·DSB ·Art. 9 Personal Data Processors Legitimate Interest Aug 5, 2021
€29,000 Mermaids: Insufficient technical and organisational measures to ensure information security The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR.… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Encryption Pseudonymization Jul 5, 2021
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Healthcare Nov 19, 2020
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Controllers Pseudonymization Healthcare Nov 5, 2020
DSB: online article about former politician is journalistic processing under Art. 85 GDPR In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that website contained wrong statements about her.… 2020-0.303.727 ·Austria ·Art. 17, 85 Right to be Forgotten Processors Personal Data Sep 1, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA ·ANSPDCP ·Art. 32 Security Pseudonymization Anonymization Jul 30, 2020
The complainant belongs to a political party and is a member of the city council of an Austrian municipality In November, the municipality held a meeting on the "parking space concept", to which a certain group of addressees, including the complainant, was invited. The complainant did… DSB-D123.768/0004-DSB/201 ·Austria ·DSB Public Authority Pseudonymization Anonymization Dec 18, 2019