Content type · 486 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€10,000 AEPD (Spain) - PS/00249/2025 MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Art. 4, 5, 7 +1 Aug 12, 2026
RON 108,570 ANSPDCP (Romania) - Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Art. 32 Aug 11, 2026
€20,000 AEPD fines El Español for disclosing minor's identity in assault video El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Jul 27, 2026
€2,000 HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant… Art. 4, 5, 12 +8 Jul 24, 2026
RON 30 ANSPDCP (Romania) - Fine against There's an AI for that S.R.L In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal –… Art. 4 Jul 24, 2026
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Jul 22, 2026
APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain · Jul 17, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Jul 17, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Jul 16, 2026
€50,000 Italian Garante sanctions Calabrian agency for location tracking of remote workers The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy · ·Art. 5, 6, 13 +3 Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy · ·Art. 3, 5, 6 +2 Jul 14, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Jul 13, 2026
RON 26,172 ANSPDCP fines Banca Transilvania RON 26,172 for inadequate security over unauthorized The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed that… Romania ·Art. 32 Jul 3, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy · ·Art. 5, 6, 12 +2 Jun 18, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom May 20, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
HUF 10M NAIH fines online store HUF 10M for missing and inadequate privacy notice The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Apr 30, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Apr 16, 2026
Austrian DSB rules 360-degree feedback unlawful without specific works agreement The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department,… 2025-0.960.016 ·Austria ·Art. 6, 88 Mar 20, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Feb 11, 2026
€284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… UNITED KINGDOM · ·Insufficient legal basis for data processing Feb 5, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Jan 19, 2026
DSB Austria: No fine imposed on COVID mask shop for cookie consent failure Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Art. 5, 12, 13 Jan 16, 2026
GBP 120,000 ICO (UK) - Allay Claims Ltd Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000… United Kingdom Jan 15, 2026
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE · ·Art. 32 Dec 31, 2025
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE · ·Art. 5, 6, 7 +2 Dec 31, 2025
€10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… GREECE · ·Art. 32 Dec 31, 2025
€588 Alza.cz a.s.: Insufficient legal basis for data processing The company obtained a copy of photographic ID of the personal data subject with his consent, however did not react to his consent withdrawal and continued in processing of his… CZECH REPUBLIC · ·Art. 6, 7 Dec 30, 2025
SLOVENAKIË, Dataprotectieautoriteit: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Slovaakse Autoriteit voor de Bescherming van Persoonsgegevens. SLOVAKIA · ·Art. 5, 6 Dec 30, 2025
€10,000 Ikea Ibérica: Insufficient legal basis for data processing The company installed cookies on an end users terminal device without prior consent of the data subject. SPAIN · ·Art. 6 Dec 30, 2025
€588 Alza.cz a.s.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 588 euro - opgelegd door de Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC · ·Art. 6, 7 Dec 30, 2025
€3,140 UniCredit Bank Tsjechië en Slowakije, a.s.: Onvoldoende juridische basis voor de verwerking van gegevens. Boete van €3.140 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC · ·Art. 6 Dec 30, 2025
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing The bank established a personal bank account for a data subject without his consent or knowledge. The bank supposedly had his personal data available because the subject had… ·Art. 6 ·Insufficient legal basis for data processing Dec 30, 2025
SLOVAKIA DPA: Insufficient legal basis for data processing Personal data have been unlawfully published on the website of a city within the framework of fulfilling its disclosure obligation under the Freedom of Information Act. However,… ·Art. 5, 6 ·Insufficient legal basis for data processing Dec 30, 2025
€10,000 Ikea Ibérica: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van €10.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 6 Dec 30, 2025
€300,000 Aimag S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 300.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 7 +4 Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Nov 27, 2025
€300,000 Aimag S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Aimag S.p.A. The controller offered its customers a service that allowed them to view their consumption data on the… ITALY · ·Art. 5, 6, 7 +4 Nov 27, 2025
€72,000 AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Nov 14, 2025
€2,000 Whitedecor SRL: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 6, 7, 12 +3 Nov 10, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Onvoldoende overeenkomst met betrekking tot gegevensverwerking. Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 28 Oct 22, 2025
€15,000 Vimar S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 13 Sep 25, 2025
€200M GOOGLE LLC: Onvoldoende juridische basis voor de verwerking van gegevens. 200 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE · ·Art. 82 Sep 1, 2025
€125M GOOGLE IRELAND LIMITED: Onvoldoende juridische basis voor de verwerking van gegevens. 125.000.000 euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE · ·Art. 82 Sep 1, 2025
€125M GOOGLE IRELAND LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 125,000,000 on GOOGLE IRELAND LIMITED. While creating an account for the controller's services, the controller designed the cookie consent… FRANCE · ·Art. 82 Sep 1, 2025
€200M GOOGLE LLC: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 200,000,000 on GOOGLE LLC. While creating an account for the controller's services, the controller designed the cookie consent process in… FRANCE · ·Art. 82 Sep 1, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 150,000,000 on INFINITE STYLES SERVICES CO. LIMITED, which operates under the name 'SHEIN'. The controller used cookies unlawfully on its… FRANCE · ·Art. 82 Sep 1, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 150 miljoen euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE · ·Art. 82 Sep 1, 2025