Skip to content
Content type · 52 documents in this view · 3,697 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 52 sort newestlargest fineoldest
€5,320 Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller) The personal data in these documents included the first name, last name, insurance number, date of birth, residential address, and gender of the data subjects. The discarded paper… 0609-113/2025/9 ·Slovenia ·IP Integrity and Confidentiality Principle Right of Access Security Sep 1, 2026
In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests 30 September 2025 the DPA reprimanded the controller for the processing time of access requests requested between 2019-2024, and ordered the controller to submit a statement… 2024-432-0039 ·Denmark ·Datatilsynet (DK) Right of Access Procedures Right of Access Data Subject Rights Exercise Modalities and Procedures
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Privacy Shield International Transfer Processing Agreement Aug 25, 2026
€1,000 An employee (controller) of a company shared the telephone number of a costumer (data subject) with a third person The third person who was a personal acquaintance of the controller, asked the controller to share the telephone number of the data subject, who was the third person’s ex-partner,… DSB-D550.1284 ·Austria ·DSB Legitimate Interest Personal Data Controllers Aug 18, 2026
€1,282 A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual… 0609-41/2026/7 ·Slovenia ·IP Controllers Processors Processing Agreement
€5,000 PS/00421/2020 The client of a financial institution lodged a complaint before the Spanish DPA (AEPD) due to the delivery of a mail for commercial purposes, even though he had expressly rejected… Spain ·AEPD ·Art. 21 Recipient Right to Object Child Consent
€1M The controller is a limited liability company whose business is the supply and production of electricity and gas in France Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them,… SAN-2022-011 ·CNIL ·Art. 12, 14, 15 +2 Personal Data Right to Object Accuracy
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Controllers Social Media Personal Data Jul 14, 2026
€1,198 A company (the controller) operates an online store An employee of the controller used a pirated and unlicensed software when creating the website. This software contained malicious code, which allowed a third person to access the… 0609-36/2026/7 ·Slovenia ·IP Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data The first complaint concerned processing that had taken place in January 2025, while the events giving rise to the second complaint had occurred in May 2025. During the… DKE.561.1.2026 ·Poland ·UODO Supervisory Authorities Supervision Personal Data Jun 1, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Recipient Direct Marketing Telecommunications May 20, 2026
€2,802 A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support This included ensuring that the controller had installed the latest security patch installed. It is unclear whether the DPA initiated an ex-officio investigation on the processor,… 0609-42/2026/7 ·Slovenia ·IP Security Controllers Encryption May 1, 2026
HUF 10M The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025 The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for… NAIH-4462-5-2026 ·Hungary ·NAIH Personal Data Accountability Controllers Apr 30, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia ·AKI Controllers Processors Data Controller Apr 16, 2026
€3,000 DHL PARCEL IBERIA, S.L.: Violation of the general principles of data processing. Een boete van 3.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 32 Recipient Processing Controllers Sep 22, 2025
€3,000 DHL PARCEL IBERIA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,000 on DHL PARCEL IBERIA, S.L. The conroller printed the private phone number of the recipient on a parcel, making it visible to third… SPAIN ·aepd ·Art. 32 Recipient Controllers IP Address Sep 22, 2025
€42,000 IBERCAJA BANCO, S.A.: Violation of the general principles of data processing. Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Recipient Data Controller Processing Jun 20, 2025
€42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… SPAIN ·aepd ·Art. 5 Recipient Controllers Processing Agreement Jun 20, 2025
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Aug 20, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Security Healthcare Recipient Feb 8, 2024
€496,000 Company: Non-compliance with general data processing principles The DPA of Hessen has imposed a fine of EUR 496,000 on a company. The DPA identified several GDPR violations, including transmitting customer data to the incorrect recipient and… GERMANY ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Recipient Direct Marketing IP Address Jan 1, 2024
€70,000 THE BEE LOGISTICS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on THE BEE LOGISTICS, S.L. for delivering a parcel to a person other than the recipient, thereby unlawfully disclosing the… SPAIN ·aepd ·Art. 5, 32 Recipient IP Address Processing Agreement Nov 7, 2023
€10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… ITALY ·Garante ·Art. 5, 9, 12 +5 Recipient Data Subject Rights Exercise Modalities and Procedures Healthcare Aug 31, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Recipient IP Address Aug 28, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 9, 32 Security Recipient Healthcare Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Security Recipient Healthcare Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Recipient Security Healthcare Mar 16, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 32, 75 Security Healthcare Recipient Jan 26, 2023
€75,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg imposed a fine of EUR 75,000 on a company. An employee had lodged a complaint with the DPA due to the fact that they had to report their sickness-related… GERMANY ·Art. 9, 32 ·Insufficient technical and organisational measures to ensure information security Employees Recipient Security Jan 1, 2023
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Recipient Nov 24, 2022
€1,000 Alpha Bank Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Alpha Bank Romania SA. The bank had accidentally sent a document to the wrong recipient via WhatsApp. The document contained… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Security Recipient Personal Data Aug 29, 2022
€4,000 Bookstore employee: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Agency has imposed a fine of EUR 4,000 on an employee of a bookstore. An individual had filed a complaint with the DPA because he had received an… SPAIN ·aepd ·Art. 5, 32 Recipient Personal Data Security Jul 19, 2022
€132,000 DKV Seguros y Reaseguros, S.A.E.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DKV Seguros y Reaseguros, S.A.E.. An individual had filed a complaint with the DPA after receiving multiple e-mails from the controller… SPAIN ·aepd ·Art. 5, 32, 33 Data Breaches Recipient Security Jul 13, 2022
€4,000 E Software Concept SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on E Software Concept SRL. The company had uploaded certain documents on its website that were publicly accessible. Among other… ROMANIA ·ANSPDCP ·Art. 32, 58 Recipient Security IP Address Jul 7, 2022
The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe The data subject requested access from the controller to all of his data under Article 15 GDPR. He also requested to have his data transmitted in a portable format under Article… 24-191 II#4781 ·Germany ·BfDI Recipient Telecommunications Social Media Jan 27, 2022
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Garante ·Art. 5 Fairness & Transparency Recipient Controllers Dec 16, 2021
€600 Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014 In September 2014, the municipality concluded that Person A's sickness had been caused by another individual (Person B) who was then asked for damages. In another proceeding… 2021-0.518.795 ·Austria ·DSB Personal Data Consent Health Data Aug 5, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·dsb ·Art. 9 Personal Data Genetic Data Controllers Aug 5, 2021
€35,300 Sopockie Towarzystwo Ubezpieczeń ERGO Hestia S.A.: Insufficient fulfilment of data breach notification obligations The controller had sent an email to that contained personal data of a customer to the wrong recipient. The leaked data included data such as the name, postal address of the data… POLAND ·UODO ·Art. 33, 34 Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 21, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Security Recipient Apr 22, 2021
€12,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U. EUR 20,000. An identity thief had obtained the data of a third party without authorization and applied for a microcredit… SPAIN ·aepd ·Art. 6 Controllers Recipient IP Address Mar 12, 2021
€6,000 Azienda Ospedaliera Universitaria Careggi: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Azienda Ospedaliera Universitaria Careggi for a breach of Art. 5 GDPR and Art. 9 GDPR. Azienda Ospedaliera… ITALY ·Garante ·Art. 5, 9 Data Breaches Healthcare Recipient Feb 25, 2021
€30,000 Enea S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information… POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 11, 2021
€4M Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… AUSTRIA ·dsb ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Encryption Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine in the six-digit range on a Hamburg-based company operating in the healthcare sector. The company had failed to take appropriate technical… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Recipient Healthcare Jan 1, 2021
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·aepd ·Art. 6, 13, 14 Recipient Personal Data IP Address Nov 25, 2020
The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent On 17.02.2020, the data subject lodged a complaint with the Austrian DPA (DSB) regarding the unlawful disclosure of their date of birth under Article 9 GDPR, which posed a risk of… 2020-0.714.215 ·Austria ·DSB Insurance Health Data Integrity and Confidentiality Principle Nov 5, 2020
€44,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The company had sent a contract with personal data, including the applicant's name, address and telephone number, to the wrong recipient. SPAIN ·aepd ·Art. 5 Recipient Personal Data IP Address Jan 7, 2020
The complainant belongs to a political party and is a member of the city council of an Austrian municipality In November, the municipality held a meeting on the "parking space concept", to which a certain group of addressees, including the complainant, was invited. The complainant did… DSB-D123.768/0004-DSB/201 ·Austria ·DSB Social Media Legitimate Interest Personal Data Dec 18, 2019
€5,000 Shop Macoyn, S.L.: Insufficient technical and organisational measures to ensure information security The company has sent advertising e-mails to several recipients where the e-mail addresses of all other recipients were visible to all recipients, because the recipient addresses… SPAIN ·aepd ·Art. 32 Recipient Direct Marketing IP Address Dec 10, 2019