Content type · 69 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Sep 15, 2026
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Sep 15, 2026
Garante warns ReLife Recycling for failing to timely respond to GDPR access request The data subject sent a complaint to the DPA regarding correspondence between him and the company ReLife Recycling s.r.l. (the controller), which was sent without his consent to… 515/2026 ·Italy ·Art. 12
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy · ·Art. 5, 12, 21 +1 Sep 3, 2026
€5,320 Slovenian DPA fines controller €5,320 for leaving employee personal data documents Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents… Slovenia · ·Art. 5, 32 Sep 1, 2026
€23,750 Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car On 4 January 2024, the newspaper “Il Fatto Quotidiano” (‘the controller’) published an article pertaining to the cable car accident of the data subject. The data subject sent a… Italy · ·Art. 5, 83 Aug 26, 2026
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Aug 25, 2026
€1,282 IP-RS · 0609-41/2026/7 A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal… Slovenia ·Art. 28
Finnish DPA finds 12-year retention of rental applicant data violates minimisation The DPA began investigating the storage periods of the personal data of housing applicants (the data subjects) contained in rental housing applications during a previous… TSV/1319/2025 ·Finland · Aug 7, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece · ·Art. 5, 28, 32 Jul 28, 2026
€90,000 AEPD · PS-00159-2025 On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15
€20,000 Garante · 471/2026 The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Art. 5, 6, 10 +1 Jul 18, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Jul 17, 2026
€1M CNIL · SAN-2022-011 The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2
€16,000 10192784 The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Italy · ·Art. 1, 5, 6 +3
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Jul 14, 2026
€1,198 A company (the controller) operates an online store An employee of the controller used a pirated and unlicensed software when creating the website. This software contained malicious code, which allowed a third person to access the… 0609-36/2026/7 ·Slovenia · Jul 8, 2026
€158,000 Character Technologies Inc.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Character Technologies Inc. €158,000 for violations of multiple GDPR provisions, including Article 5(2) on general data… Italy · ·Art. 5, 12, 13 +5 Jul 3, 2026
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Jul 3, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 May 28, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom May 20, 2026
€1,500 Francesco Gagliardi: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) found Francesco Gagliardi, operating as a sole proprietorship, in violation of Articles 5(1)(a) and 14 of the GDPR and Article 130… Italy · ·Art. 5, 14 May 14, 2026
€2,802 IP-RS · 0609-42/2026/7 A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·Art. 32 May 1, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia · Apr 16, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria · Mar 20, 2026
The controller, an Austrian registered association, operates a therapy centre for psychosomatic illnesses The data subject was a patient of the controller. On 28 July 2025, the data subject sent an access request by email under Article 15 GDPR, asking for full information on all… DSB-D124.2437/25 ·Austria · Jan 9, 2026
€72,000 AEPD · PS-00480-2025 Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Nov 14, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Oct 10, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on the club BALONCESTO TELDE. The controller published an image of a minor without the consent of the minors representative. SPAIN · ·Art. 6 Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for the processing of data. ⇄ 1.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 6 Jul 18, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5, 6, 13 Jun 20, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 5 Mar 28, 2025
APD/GBA · 131/2024 On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·Art. 4, 5, 6 Oct 11, 2024
€25,000 Belgian DPA finds MediaHuis violated GDPR fairness over cookie banner design A data subject visited four website operated by MediaHuis, namely: Gazet van Antwerpen; De Standaard; Het Nieuwsblad; Het Belang van Limburg. On each website there was a cookie… Belgium · ·Art. 5, 6, 7 Sep 6, 2024
€600 President of a workers' council: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the president of the workers' council of a company following a complaint by a former employee. During their employment, the company carried… SPAIN · ·Art. 5 May 23, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… May 16, 2024
APD/GBA · 159/2023 On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The… 159/2023 ·Belgium ·Art. 4, 6, 7 Nov 24, 2023
€20,000 Ew Business Machines S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 on Ew Business Machines S.p.A.. The controller had installed a video surveillance system that not only recorded images in real… ITALY · ·Art. 5, 9, 13 +1 Jun 1, 2023
€13,300 Company: Insufficient fulfilment of information obligations The Hungarian DPA has imposed a fine of EUR 13,300 on a company. A customer had filed a complaint with the DPA because a conversation, which they had with a sales representative… HUNGARY · ·Art. 12, 13 Apr 4, 2023
€8,000 Cypriot Ministry of the Interior: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on the Cypriot Ministry of the Interior. The Ministry of Interior had unlawfully transmitted personal data of employees to the… CYPRUS · ·Art. 5 Jan 1, 2023
€3M VOODOO ('provider') was a mobile game developer The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of the provider's mobile applications on iOS, in… SAN-2022-026 ·France · Dec 29, 2022
Danish DPA reprimands Region Syddanmark for inadequate processor audit procedures The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Denmark ·
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Sep 22, 2022
€15 Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient A former teacher (the data subject) at a private primary school (the controller) submitted a complaint to the Greek DPA regarding a video surveillance system in the classrooms,… Greece ·Art. 5, 6, 12 +2 Sep 9, 2022
€2,000 Sindicato Intersectorial Trabajadores/as Provincia de Alicante: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on the Sindicato Intersectorial Trabajadores/as Provincia de Alicante union. The union published the protocols of a works council… SPAIN · ·Art. 5 Aug 30, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY · ·Art. 5, 6, 7 +4 Jul 7, 2022
Icelandic DPA: genetic research company violated DPO independence under Art. 38(3) GDPR The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Iceland · Jun 29, 2022
DSB · 2021-0.643.804 The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·Art. 6, 55 Jun 9, 2022
€85,000 Otavamedia Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 85,000 on Otavamedia Oy. The DPA had received eleven complaints regarding Otavamedia between 2018 and 2021. Namely, the complaints… FINLAND · ·Art. 5, 12, 15 +2 May 9, 2022
AEPD admits claim against Securitas Direct for failure to handle access and erasure Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against… R/00665/2022 ·Spain ·Art. 17, 55 Apr 22, 2022