Skip to content
Content type · 126 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 126 sort newestlargest fineoldest
HUF 2M NAIH fines online store HUF 2M for unclear and incomplete privacy notice The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Personal Data Processing Jul 22, 2026
€12,000 Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Garante per la protezione dei dati personali ·Art. 4, 5, 6 +2 Personal Data Health Data Healthcare Jul 20, 2026
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Right to Restriction Jul 18, 2026
APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Catalonia Anonymization Professional Secrecy Integrity and Confidentiality Principle Jul 17, 2026
€16,000 Italian Garante: OPI of Pisa must remove residential addresses from public register The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Italy ·Garante per la protezione dei dati personali ·Art. 1, 5, 6 +3 Personal Data Fairness & Transparency Retention Period Jul 16, 2026
€50,000 Italian Garante sanctions Calabrian agency for location tracking of remote workers The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 Monitoring DPIA Privacy Impact Assessment Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Controllers Personal Data Processing Jul 14, 2026
IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Personal Data Controllers Information Provision Modalities and Communication Methods Jul 3, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Representatives Controllers AI Information Duties Jul 3, 2026
€6,600 Italian Garante: Employer's recording of locker opening and destruction of contents The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Garante per la protezione dei dati personali ·Art. 2, 4, 5 +2 Personal Data Legitimate Interest Controllers Jun 18, 2026
€5,000 Italian DPA: Vasto municipality breached transparency duties over traffic cameras The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 DPIA Privacy Impact Assessment Personal Data Jun 18, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 Legitimate Interest Storage Limitation Monitoring Jun 18, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Transparency Personal Data Information Provision Modalities and Communication Methods May 12, 2026
HUF 10M NAIH fines online store HUF 10M for missing and inadequate privacy notice The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Controllers Accountability Apr 30, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
DSB Austria: No fine imposed on COVID mask shop for cookie consent failure Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Art. 5, 12, 13 Cookies Personal Data IP Address Jan 16, 2026
€1,500 Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +2 Video Surveillance Controllers Fairness & Transparency Jan 16, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. De Roemeense toezichthouder ANSPDCP heeft aan Money Seeds S.R.L., een financiële en consultancyonderneming, een boete van 2.000 euro opgelegd wegens het niet honoreren van een… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Supervisory Authorities Controllers NL Jan 8, 2026
€2,000 Orde van Algemene Verpleegkundigen, Verloskundigen en Medische Assistenten van Roemenië – Afdeling Neamt: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Video Surveillance Processing Healthcare NL Dec 29, 2025
€3,600 RISING SUN CAR RENTAL S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. De Spaanse autoriteit voor gegevensbescherming (DPA) heeft RISING SUN CAR RENTAL S.L. een boete van 3.600 euro opgelegd. De verantwoordelijke partij gebruikte videobewaking om de… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Processing Data Controller NL Dec 1, 2025
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +4 Data Processor Processors Controllers NL Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·azop ·Art. 5, 6, 12 +4 Employees Processing Agreement Telecommunications Nov 24, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Overtreding van de algemene principes voor gegevensverwerking. 800 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13 Video Surveillance Processing Controllers NL Nov 19, 2025
€6,000 Gemeente Orte: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance Processing Education NL Nov 13, 2025
€15,000 Gemeente Curtarolo: Onvoldoende wettelijke basis voor de verwerking van gegevens. Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 Video Surveillance Processing Controllers NL Oct 23, 2025
€492,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. 492.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Meaningful Human Review and Decision-Making Processing Transparency NL Sep 30, 2025
€600 Eigenaar van een Tesla-auto: Niet-naleving van algemene principes voor gegevensverwerking. 600 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·dsb ·Art. 5, 6, 12 +1 Processing Personal Data Healthcare NL Sep 29, 2025
€3,960 Gemeente Pazzano: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van €3.960 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 13, 58 Education Public Authority Supervisory Authorities NL Sep 25, 2025
€1,000 Green.mec. s.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 13, 15 Personal Data Right of Access Data Controller NL Sep 25, 2025
€6,000 Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 13 Video Surveillance Processing Personal Data NL Sep 11, 2025
€2,000 GESTIÓN DE VENTAS IBERIA S.L.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 14 Personal Data Controllers Data Controller NL Aug 31, 2025
€300 Rijschool: Onvoldoende nakoming van de informatieverplichtingen. Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 13 Education Video Surveillance Processing NL Aug 26, 2025
€1,200 TRUEBA SPORT S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13 Security Controllers Data Controller NL Jul 17, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 13 Education Personal Data Processing NL Jun 20, 2025
€22,000 Gemeente Kristiansand: Onvoldoende juridische basis voor gegevensverwerking. 22.000 euro boete - Noorse Toezichtsautoriteit (Datatilsynet). NORWAY ·Datatilsynet ·Art. 6, 12, 13 Education Processing Public Authority NL Jun 10, 2025
€12,000 Data Diggers Market Research SRL: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van €12.000 - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Personal Data Processing Data Controller NL May 21, 2025
€6,600 Eigenaar van een apotheek: Overtreding van de algemene principes van gegevensverwerking. Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14, 32 Health Data Data Controller Processing NL May 8, 2025
€20,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 20.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 12 +4 Processing Personal Data Marketing NL Apr 22, 2025
€260,000 CAMERDATA, S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 260.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14 Processing Personal Data Telecommunications NL Apr 15, 2025
€5,000 Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Health Data Personal Data Healthcare NL Apr 9, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Onvoldoende juridische basis voor de verwerking van gegevens. 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14 Data Controller Processing Controllers NL Mar 28, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the Istituto di Istruzione Superiore 'P. Galluppi' Tropea. The controller processed biometric data of its employees to control… ITALY ·Garante ·Art. 5, 6, 9 Employees Fairness & Transparency Special Categories of Data Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Processing Special Categories of Data Controllers NL Mar 27, 2025
€40,000 Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +3 Notified Body Responsibilities and Operational Obligations Processing Professional Secrecy NL Mar 24, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 13, 14, 25 +1 Health Data Healthcare Personal Data NL Mar 24, 2025
€50,000 Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC): Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 50,000 on the Regional agency for development and services in agriculture (ARSAC). The controller processed geographic data of its employees… ITALY ·Garante ·Art. 5, 6, 13 +3 Fairness & Transparency Education Controllers Mar 13, 2025
€15M OpenAI OpCo LLC: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15 million on OpenAI in connection with the operation of the generative AI chatbot “ChatGPT”. The DPA found that OpenAI had violated… ITALY ·Garante ·Art. 5, 6, 12 +4 Fairness & Transparency IP Address Transparency Nov 2, 2024