Skip to content
Content type · 82 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 82 sort newestlargest fineoldest
HUF 2M NAIH fines online store HUF 2M for unclear and incomplete privacy notice The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Processing Cookies Jul 22, 2026
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Personal Data Right of Access Controllers Jul 22, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Personal Data Right of Access Accuracy Jul 17, 2026
€5.8M Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 13 +3 Controllers Processors Fairness & Transparency Jul 3, 2026
€1.4M Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Garante per la protezione dei dati personali ·Art. 5, 13, 14 +2 Controllers Retention Period Right of Access Procedures Jul 3, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Representatives Controllers DPIA Jul 3, 2026
€5,000 Italian DPA: Vasto municipality breached transparency duties over traffic cameras The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 DPIA Privacy Impact Assessment Personal Data Jun 18, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 Personal Data Retention Period Storage Limitation Jun 18, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Controllers Processing May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Transparency Information Provision Modalities and Communication Methods May 12, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Fairness & Transparency Jan 19, 2026
€400,000 Verisure Italy s.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Archiving Data Controller Processing NL Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles IP Address Direct Marketing Controllers Nov 27, 2025
€200,900 ILVA A/S: Overtreding van algemene principes voor gegevensverwerking. Een boete van 200.900 euro - De Deense Autoriteit voor Gegevensbescherming (Datatilsynet). DENMARK ·Datatilsynet ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers NL Sep 2, 2025
€200,900 ILVA A/S: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 200,900 on ILVA A/S. The controller failed to implement data deletion deadlines. This led to an infringement of the principle of storage… DENMARK ·Datatilsynet ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Sep 2, 2025
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Processing NL Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Healthcare Health Data Retention Period Jul 10, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Health Data Retention Period Healthcare May 21, 2025
€200,000 ASNEF-EQUifax, een bedrijf dat informatie verstrekt over kredietwaardigheid, heeft onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 200.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 17 Processing Data Controller Personal Data NL May 19, 2025
€5,000 Bestuur voor steun aan burgers en de landbouw: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Storage Limitation Processing Education NL Apr 10, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 21.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 7, 28 Education Processing Data Controller NL Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed fine on SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. The controller offers fitness courses which are recorded and published. The consent obtained for the… SPAIN ·aepd ·Art. 5, 7, 28 Storage Limitation Retention Period Controllers Mar 28, 2025
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·azop ·Art. 5, 6, 12 +4 Data Breaches Healthcare Healthcare Sep 13, 2024
€80,000 Selectra S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access… ITALY ·Garante ·Art. 5, 13, 88 +1 Storage Limitation Retention Period Controllers Jul 17, 2024
€1M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1 million on Fastweb S.p.A. due to unauthorized telemarketing, the unlawful storage of customer data after contract termination, and… ITALY ·Garante ·Art. 5, 6, 7 +13 IP Address Right to Object Storage Limitation Jun 20, 2024
€4,000 Medical association: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,000 on the medical association 'Ordine dei Medici Chirurghi e degli Odontoiatri'. A patient had filed a complaint with the DPA. During… ITALY ·Garante ·Art. 12, 13, 15 Storage Limitation Personal Data Healthcare Jun 20, 2024
€180 Website operator: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the operator of a website for storing data of a data subject for an excessively long period of time and contrary to the principle of storage… SPAIN ·aepd ·Art. 5 Storage Limitation Retention Period IP Address Jun 5, 2024
€856,000 Verkkokauppa.com: Non-compliance with general data processing principles The Finnish DPA has imposed a fine of EUR 856,000 on Verkkokauppa.com Plc for not specifying the retention period of customer account data of e-commerce customers. The DPA also… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25 Storage Limitation Retention Period IP Address Mar 6, 2024
€174,640 Black Tiger Belgium: Insufficient fulfilment of information obligations The Belgian DPA has imposed a fine of EUR 174,640 on Black Tiger Belgium. An individual had filed a complaint with the DPA due to the controller's failure to properly comply with… APD ·Art. 5, 6, 12 +5 ·Insufficient fulfilment of information obligations Storage Limitation Right of Access Right of Access Procedures Jan 16, 2024
€16,600 Reykjanesbær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Reykjanesbær. The municipality had used the Google Education system without sufficiently complying with… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Education Public Authority Processing Agreement Dec 6, 2023
€18,600 City of Hafnarfjörður: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processing Agreement Processors Education Dec 6, 2023
€20,000 City of Kópavogur: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 20,000 on the city of Kópavogur. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Education Processing Agreement Processors Dec 6, 2023
€16,600 Garðabær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær. The municipality had used the Google Education system without sufficiently complying with data… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Education Processing Agreement Processors Dec 6, 2023
€600,000 GROUPE CANAL +: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on GROUPE CANAL+ for multiple violations of the GDPR. The DPA determined that the data controller failed to demonstrate that it… FRANCE ·CNIL ·Art. 7, 12, 13 +5 Data Breaches Controllers IP Address Oct 12, 2023
€50,000 Athens Urban Transport Organization: Non-compliance with general data processing principles The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with… GREECE ·HDPA ·Art. 5, 25, 35 Privacy by Default Privacy by Design DPIA Sep 25, 2023
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·azop ·Art. 6, 7, 13 Cookies Controllers Retention Period Sep 14, 2023
€30,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 30,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·azop ·Art. 6, 7, 13 Cookies Personal Data Retention Period Sep 14, 2023
€6,000 ELECTRAWORKS - CEUTA, S.A.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on ELECTRAWORKS - CEUTA, S.A.. The controller had failed to provide sufficient information about the retention periods of personal data. The… SPAIN ·aepd ·Art. 13 Storage Limitation Personal Data Controllers Aug 8, 2023
€100,000 Tiscali Italia SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Tiscali Italia SpA. The controller had sent advertising messages to more than 160,000 customers within four months, even… ITALY ·Garante ·Art. 5, 12, 13 +2 Retention Period Storage Limitation IP Address Jul 18, 2023
€300,000 Rinascente S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing… ITALY ·Garante ·Art. 5, 12, 32 +1 DPIA Social Media Privacy Impact Assessment Jun 8, 2023
€380,000 Sports betting operator: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 380,000 on a sports betting operator. AZOP had received a complaint from a data subject, stating that the controller had obtained… CROATIA ·azop ·Art. 6, 13, 25 +1 Controllers Personal Data Storage Limitation May 18, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Data Breaches Security Storage Limitation Apr 20, 2023
€8,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has fined a company EUR 8, 000. The controller failed ot properly fulfil the data subject's right to access their personal data processed by the company. The… LITHUANIA ·VDAI ·Art. 5, 15 Personal Data Storage Limitation Data Subject Rights Exercise Modalities and Procedures Jan 24, 2023
€3,600 Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM: Insufficient legal basis for data processing The Spanish DPA has fined the Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM. The controller processed medical data from Covid-19… SPAIN ·aepd ·Art. 9, 13 Healthcare Health Data Storage Limitation Dec 2, 2022
€600,000 ÉLECTRICITÉ DE FRANCE: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on ÉLECTRICITÉ DE FRANCE (EDF), France's largest electricity supplier. The DPA had received several complaints that individuals… CNIL ·Art. 7, 12, 13 +3 ·Insufficient fulfilment of data subjects rights Right to Object Personal Data Data Subject Rights Exercise Modalities and Procedures Nov 24, 2022
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE ·CNIL ·Art. 5, 13, 25 +2 DPIA Storage Limitation Privacy by Default Nov 10, 2022
€180,000 Setúbal municipality: Non-compliance with general data processing principles The Portuguese DPA has imposed a fine of EUR 170,000 on Setúbal municipality. The DPA found data protection violations regarding the collection of personal data from Ukrainian… PORTUGAL ·CNPD ·Art. 5, 13, 37 IP Address Personal Data Public Authority Nov 2, 2022
€525,000 TECHPUMP SOLUTIONS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Techpump Solutions S.L. EUR 525,000. Techpump operates several websites with adult content. The DPA found several violations of data protection law… SPAIN ·aepd ·Art. 5, 6, 8 +5 Retention Period Data Subject Rights Exercise Modalities and Procedures IP Address Oct 31, 2022
€2M Alpha Exploration: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2 million on Alpha Exploration. Alpha Exploration operates the social network Clubhouse. In the course of its investigation, the DPA… ITALY ·Garante ·Art. 5, 6, 7 +7 DPIA Privacy Impact Assessment IP Address Oct 6, 2022