Skip to content
Content type · 44 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Spain · €140 AEPD (Spain) - EXP202310345 Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Telecommunications Accountability Personal Data Jul 13, 2026
Slovenia · €1,198 IP (Slovenia) - 0609-36/2026/7 Facts — A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software… Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
Lithuania · €450,000 VDAI (Lithuania) - 3R-1143 Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and… Security Data Breaches Access Controls Jun 19, 2026
Poland · €26,711 UODO (Poland) - DKE.561.4.2026 Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance… Monitoring Fairness & Transparency Accountability May 22, 2026
UK · €300 ICO (UK) - KRA Consultancy Ltd Facts — The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related… Direct Marketing Telecommunications Marketing May 20, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Accountability Notified Body Reporting and Notification Obligations Notification Obligation May 8, 2026
Slovenia · €2,802 IP (Slovenia) - 0609-42/2026/7 Facts — A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had… Security Controllers Encryption May 1, 2026
Estonia · €1,000 AKI (Estonia) - No. 2.1-1/24/397-890-38 Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had… Controllers Processors Data Controller Apr 16, 2026
Spain · €150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party… Personal Data Controllers Integrity and Confidentiality Principle Feb 11, 2026
aepd · €3,000 DHL PARCEL IBERIA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,000 on DHL PARCEL IBERIA, S.L. The conroller printed the private phone number of the recipient on a parcel, making it visible to third… IP Address Processing Agreement Controllers Sep 22, 2025
aepd · €3,000 DHL PARCEL IBERIA, S.L.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 3.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). Processing Controllers Data Controller NL Sep 22, 2025
aepd · €42,000 IBERCAJA BANCO, S.A.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). Processing Data Controller Controllers NL Jun 20, 2025
aepd · €42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… Processing Agreement Controllers IP Address Jun 20, 2025
UODO · €940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… Data Breaches Notification Obligation Notified Body Reporting and Notification Obligations Aug 20, 2024
Garante · €18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… Health Data Security Healthcare Feb 8, 2024
€496,000 Company: Non-compliance with general data processing principles The DPA of Hessen has imposed a fine of EUR 496,000 on a company. The DPA identified several GDPR violations, including transmitting customer data to the incorrect recipient and… Processing Agreement Insurance IP Address Jan 1, 2024
aepd · €70,000 THE BEE LOGISTICS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on THE BEE LOGISTICS, S.L. for delivering a parcel to a person other than the recipient, thereby unlawfully disclosing the… Processing Agreement IP Address Processing Nov 7, 2023
Garante · €10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… Data Subject Rights Exercise Modalities and Procedures Healthcare Controllers Aug 31, 2023
€3,000,000 Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… Security Processing Agreement Access Controls Aug 28, 2023
Garante · €4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… Health Data Healthcare Security Mar 23, 2023
ANSPDCP · €1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… Health Data Security Healthcare Mar 16, 2023
ANSPDCP · €3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… Health Data Healthcare Healthcare Mar 16, 2023
Garante · €7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… Health Data Healthcare Security Jan 26, 2023
€75,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg imposed a fine of EUR 75,000 on a company. An employee had lodged a complaint with the DPA due to the fact that they had to report their sickness-related… Processing Agreement Employees IP Address Jan 1, 2023
ANSPDCP · €1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… Data Breaches Health Data Security Nov 24, 2022
ANSPDCP · €1,000 Alpha Bank Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Alpha Bank Romania SA. The bank had accidentally sent a document to the wrong recipient via WhatsApp. The document contained… Security Processing Agreement Personal Data Aug 29, 2022
aepd · €4,000 Bookstore employee: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Agency has imposed a fine of EUR 4,000 on an employee of a bookstore. An individual had filed a complaint with the DPA because he had received an… Processing Agreement Security Personal Data Jul 19, 2022
aepd · €132,000 DKV Seguros y Reaseguros, S.A.E.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DKV Seguros y Reaseguros, S.A.E.. An individual had filed a complaint with the DPA after receiving multiple e-mails from the controller… Data Breaches Security Insurance Jul 13, 2022
ANSPDCP · €4,000 E Software Concept SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on E Software Concept SRL. The company had uploaded certain documents on its website that were publicly accessible. Among other… Security Processing Agreement Personal Data Jul 7, 2022
Germany BfDI (Germany) - 24-191 II Facts — The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data… Telecommunications Data Portability Personal Data Jan 27, 2022
Garante · €100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… Fairness & Transparency Processing Agreement Insurance Dec 16, 2021
UODO · €35,300 Sopockie Towarzystwo Ubezpieczeń ERGO Hestia S.A.: Insufficient fulfilment of data breach notification obligations The controller had sent an email to that contained personal data of a customer to the wrong recipient. The leaked data included data such as the name, postal address of the data… Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 21, 2021
UODO · €245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… Data Breaches Security Telecommunications Apr 22, 2021
aepd · €12,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U. EUR 20,000. An identity thief had obtained the data of a third party without authorization and applied for a microcredit… Controllers IP Address Processing Agreement Mar 12, 2021
Garante · €6,000 Azienda Ospedaliera Universitaria Careggi: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Azienda Ospedaliera Universitaria Careggi for a breach of Art. 5 GDPR and Art. 9 GDPR. Azienda Ospedaliera… Data Breaches Health Data Healthcare Feb 25, 2021
UODO · €30,000 Enea S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information… Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 11, 2021
dsb · €4,000,000 Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… Data Breaches Encryption Integrity and Confidentiality Principle Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine in the six-digit range on a Hamburg-based company operating in the healthcare sector. The company had failed to take appropriate technical… Data Protection Authority of Hamburg Security Health Data Healthcare Jan 1, 2021
France · €35,000,000 CNIL (France) - SAN-2020-013 Facts — Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group… Transparency Certification Recipient Dec 7, 2020
aepd · €40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… IP Address Telecommunications Personal Data Nov 25, 2020
aepd · €44,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The company had sent a contract with personal data, including the applicant's name, address and telephone number, to the wrong recipient. Personal Data IP Address Telecommunications Jan 7, 2020
aepd · €5,000 Shop Macoyn, S.L.: Insufficient technical and organisational measures to ensure information security The company has sent advertising e-mails to several recipients where the e-mail addresses of all other recipients were visible to all recipients, because the recipient addresses… Direct Marketing Security IP Address Dec 10, 2019
NAIH · €286 Directorate of Social and Child Welfare Institutions of the Ferencvaros District of Budapest: Insufficient fulfilment of data breach notification obligations The employee of the Directorate sent by mistake 9 letters to the wrong recipient, which contained personal data of 18 data subjects (including data of children, criminal data and… Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations May 21, 2019
€2,500 Private person: Insufficient legal basis for data processing The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from… Criminal Data IP Address Processing Feb 5, 2019