Skip to content
Content type · 2,798 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 2,798 sort newestlargest fineoldest
€1,282 Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal… Slovenia ·IP ·Art. 28 Controllers Processors Processing Agreement Aug 11, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 Data Breaches DPIA Security Jun 11, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Transparency Personal Data Controllers May 12, 2026
€2,415 UODO (Poland) - DKN.5131.7.2022 An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Art. 5, 24, 25 +2 Data Breaches Notification Obligation Processors Apr 13, 2026
€1,000 Spain DPA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined an unnamed party €1,000 on 2026-03-01 for: Non-compliance with general data processing principles. aepd ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Agreement Supervisory Authorities Mar 1, 2026
€15,000 Ministero delle Imprese e del Made in Italy: Insufficient data processing agreement Italian Data Protection Authority (Garante) fined Ministero delle Imprese e del Made in Italy €15,000 on 2026-02-26 for: Insufficient data processing agreement. Garante ·Art. 28 ·Insufficient data processing agreement Processing Agreement Public Authority Education Feb 26, 2026
€5,000 KEAT - Centre for Education & Rehabilitation of the Blind: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined KEAT - Centre for Education & Rehabilitation of the Blind €5,000 on 2026-02-20 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15 Personal Data Education Supervisory Authorities Feb 20, 2026
€5,500 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €5,500 on 2026-02-16 for: Insufficient technical and organisational measures to ensure… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities IP Address Feb 16, 2026
€30,000 Vodafone – PANAFON A.E.E.T.: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined Vodafone – PANAFON A.E.E.T. €30,000 on 2026-02-11 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15, 18 Personal Data Telecommunications Supervisory Authorities Feb 11, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Personal Data Integrity and Confidentiality Principle Access Controls Feb 11, 2026
€1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… SPAIN ·aepd ·Art. 6 Video Surveillance Controllers Monitoring Feb 6, 2026
€284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Minors Controllers Consent Feb 5, 2026
€20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… ROMANIA ·ANSPDCP ·Art. 58, 83 Supervisory Authorities Supervision Controllers Feb 5, 2026
€2.7M DPD Polska sp. z o.o.: Insufficient data processing agreement Polish National Personal Data Protection Office (UODO) fined DPD Polska sp. z o.o. €2,682,000 on 2026-02-05 for: Insufficient data processing agreement. Poland ·UODO ·Art. 5, 24, 29 +1 Processing Agreement Personal Data Data Processor Feb 5, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Access Controls Security Controllers Feb 4, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… SPAIN ·aepd ·Art. 32 Encryption Integrity and Confidentiality Principle Security Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Processing Agreement Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Health Data Jan 30, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Health Data Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Jan 22, 2026
€4,850 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €4,850 on 2026-01-20 for: Insufficient technical and organisational measures to ensure… Art. 25 ·Insufficient technical and organisational measures to ensure information security Supervisory Authorities Security Processing Agreement Jan 20, 2026
€15,000 Continental Automotive Products SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 32 Security Controllers Accountability NL Jan 19, 2026
€1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… SPAIN ·aepd ·Art. 5 Video Surveillance Employees Controllers Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA ·ANSPDCP ·Art. 5, 32 Security Controllers Processing Agreement Jan 19, 2026
€1,500 Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +2 Video Surveillance Controllers Fairness & Transparency Jan 16, 2026
€21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… NORWAY ·Datatilsynet ·Art. 15 Personal Data IP Address Controllers Jan 16, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Law Enforcement Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Processors NL Jan 13, 2026
€500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… SPAIN ·aepd ·Art. 6 Social Media Personal Data Controllers Jan 10, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… aepd ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers IP Address Jan 10, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Health Data Healthcare Jan 9, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. De Roemeense toezichthouder ANSPDCP heeft aan Money Seeds S.R.L., een financiële en consultancyonderneming, een boete van 2.000 euro opgelegd wegens het niet honoreren van een… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Data Controller Controllers NL Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Data Breaches Security Access Controls Jan 8, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Health Data Healthcare Controllers Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Access Controls Security Jan 8, 2026
€232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… POLAND ·UODO ·Art. 38 Supervisory Authorities Public Authority Public Sector Jan 2, 2026
€10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… GREECE ·HDPA ·Art. 32 Processors Controllers Telecommunications Dec 31, 2025
€6,000 I Mathisi: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined I Mathisi €6,000 on 2025-12-31 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15, 31 Personal Data Education Supervisory Authorities Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Processing Agreement Controllers Processors Dec 31, 2025