Skip to content
Content type · 57 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 57 sort newestlargest fineoldest
€1,282 Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal… Slovenia ·IP ·Art. 28 Controllers Processors Processing Agreement Aug 11, 2026
€90,000 AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15 Right of Access Procedures Right to Restriction Retention Period Jul 21, 2026
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Right to be Forgotten Jul 18, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Personal Data Right of Access Right to Object Jul 17, 2026
APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Catalonia Anonymization Professional Secrecy Anonymization Jul 17, 2026
€16,000 Italian Garante: OPI of Pisa must remove residential addresses from public register The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Italy ·Garante per la protezione dei dati personali ·Art. 1, 5, 6 +3 Personal Data Controllers Retention Period Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Processing Personal Data Controllers Jul 14, 2026
€1,198 Slovenian DPA fines controller €1,198 for Art. 32 GDPR breach via pirated software A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software contained… Slovenia ·IP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives DPIA Jul 3, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Integrity and Confidentiality Principle May 28, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Recipient Direct Marketing Telecommunications May 20, 2026
€2,802 Slovenian DPA fines processor €2,802 for failing to patch known vulnerability (Art. 32) A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·IP ·Art. 32 Security Encryption Controllers May 1, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
Austrian DSB rules 360-degree feedback unlawful without specific works agreement The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department,… 2025-0.960.016 ·Austria ·Art. 6, 88 Legitimate Interest Personal Data Human Resources Mar 20, 2026
€72,000 AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Cookies Direct Marketing Nov 14, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on the club BALONCESTO TELDE. The controller published an image of a minor without the consent of the minors representative. SPAIN ·aepd ·Art. 6 Controllers Representatives Processing Agreement Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Onvoldoende juridische basis voor de verwerking van gegevens. 1.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Consent Data Controller NL Jul 18, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 13 Education Personal Data Processing NL Jun 20, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Processing Integrity and Confidentiality Principle NL Mar 28, 2025
Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·APD/GBA Cookies Direct Marketing Legitimate Interest Oct 11, 2024
€25,000 APD/GBA (Belgium) - 113/2024 A data subject visited four website operated by MediaHuis, namely: Gazet van Antwerpen; De Standaard; Het Nieuwsblad; Het Belang van Limburg. On each website there was a cookie… Art. 5, 6, 7 Cookies Legitimate Interest Direct Marketing Sep 6, 2024
€600 President of a workers' council: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the president of the workers' council of a company following a complaint by a former employee. During their employment, the company carried… SPAIN ·aepd ·Art. 5 Personal Data Employees IP Address May 23, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… Autoriteit Persoonsgegevens Social Media Fairness & Transparency Inspection Access Rights and Cooperation Obligations May 16, 2024
Belgian DPA settles with Mediafin: De Tijd cookie banner must add equal "refuse all" On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The… 159/2023 ·Belgium ·APD/GBA Cookies Direct Marketing Consent Nov 24, 2023
€20,000 Ew Business Machines S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 on Ew Business Machines S.p.A.. The controller had installed a video surveillance system that not only recorded images in real… ITALY ·Garante ·Art. 5, 9, 13 +1 Monitoring Video Surveillance Audit Logs Jun 1, 2023
€13,300 Company: Insufficient fulfilment of information obligations The Hungarian DPA has imposed a fine of EUR 13,300 on a company. A customer had filed a complaint with the DPA because a conversation, which they had with a sales representative… HUNGARY ·NAIH ·Art. 12, 13 Representatives Controllers Processing Agreement Apr 4, 2023
€8,000 Cypriot Ministry of the Interior: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on the Cypriot Ministry of the Interior. The Ministry of Interior had unlawfully transmitted personal data of employees to the… CYPRUS ·Art. 5 ·Non-compliance with general data processing principles Personal Data IP Address Public Authority Jan 1, 2023
€3M CNIL fines VOODOO for cookie and tracker consent failures in mobile games VOODOO ('provider') was a mobile game developer. The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of… France ·Art. 4, 5, 82 Cookies Telecommunications Direct Marketing Dec 29, 2022
Datatilsynet (Denmark) - 2020-422-0026 The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Art. 5 Controllers Processors Processing Sep 28, 2022
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Controllers Personal Data Right of Access Sep 22, 2022
€15 HDPA (Greece) - 50/2022 A former teacher (the data subject) at a private primary school (the controller) submitted a complaint to the Greek DPA regarding a video surveillance system in the classrooms,… Art. 5, 6, 12 +2 Legitimate Interest Video Surveillance Personal Data Sep 9, 2022
€2,000 Sindicato Intersectorial Trabajadores/as Provincia de Alicante: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on the Sindicato Intersectorial Trabajadores/as Provincia de Alicante union. The union published the protocols of a works council… SPAIN ·aepd ·Art. 5 IP Address Representatives Processing Agreement Aug 30, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Audit Logs Health Data Data Breaches Jul 7, 2022
Persónuvernd (Iceland) - 2020061979 The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Art. 38, 39 Supervisory Authorities Notified Body Responsibilities and Operational Obligations Scientific Panel Independence Jun 29, 2022
Austrian DPA: Court's publication of full divorce settlement in land register violates The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·DSB Material scope (GDPR) Controllers Integrity and Confidentiality Principle Jun 9, 2022
€85,000 Otavamedia Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 85,000 on Otavamedia Oy. The DPA had received eleven complaints regarding Otavamedia between 2018 and 2021. Namely, the complaints… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 15 +2 Personal Data Data Subject Rights Exercise Modalities and Procedures Representatives May 9, 2022
AEPD (Spain) - EXP202203606 Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against… R/00665/2022 ·Art. 17, 55 Right to Restriction Right of Access Procedures Data Portability Apr 22, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Legitimate Interest Personal Data Jan 5, 2022
€3,400 Company: Insufficient legal basis for data processing The Czech DPA imposed a fine of EUR 3,400 on a company. The data subject had concluded an energy supply contract with the controller in the past, but then duly terminated it.… CZECH REPUBLIC ·UOOU ·Insufficient legal basis for data processing Controllers Processing Agreement Processors Jan 1, 2022
DSB (Austria) - 2021-0.698.184 The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered… 2021-0.698.184 ·Art. 6, 51, 57 +1 Legitimate Interest Personal Data Lawful Basis Oct 8, 2021
€1.5M EDP Comercializadora, S.A.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing… SPAIN ·aepd ·Art. 13, 25 Controllers Personal Data Representatives May 4, 2021
€1.5M EDP Energía, S.A.U: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Energía, S.A.U.. The decision follows, in particular, several complaints received for processing personal data… SPAIN ·aepd ·Art. 13, 25 Controllers Personal Data Representatives May 4, 2021
€200,000 I-DE Redes Eléctricas Inteligentes, S.A.U: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on I-DE Redes Eléctricas Inteligentes, S.A.U. The DPA received complaints from Waitum, S.L. and Servicios Aby 2018, S.L.… SPAIN ·aepd ·Art. 5, 6 Integrity and Confidentiality Principle Controllers IP Address Mar 2, 2021
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives IP Address Telecommunications Dec 20, 2020
€1,500 Political Party: Insufficient legal basis for data processing Sending of an e-mail to a former party member who had since resigned, with the request to act as an election representative without sufficient legal basis to process the personal… SPAIN ·aepd ·Art. 5, 6 Personal Data Education Representatives Sep 11, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Telecommunications Cookies Supervision Sep 7, 2020
GBP 130,000 ICO - CPS Advisory Limited CPS Advisory Limited (CPSAL) conducted direct marketing calls in relation to personal pensions. The data CPSAL used to conduct the calls had been purchased from third party data… United Kingdom ·UK ·Art. 55A Direct Marketing Consent Marketing Sep 4, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN ·aepd ·Art. 6 Personal Data Representatives Telecommunications Jun 9, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Insurance May 26, 2020