Content type · 472 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€12,000 Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy · ·Art. 4, 5, 6 +2 Jul 20, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Jul 16, 2026
€200,000 AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack… Spain ·Art. 5, 35, 58 Jul 16, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Jun 19, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 Jun 11, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy · ·Art. 5, 9 May 28, 2026
€5M IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) fined IQVIA OPERATIONS FRANCE €5,000,000 on 2026-05-26 for: Non-compliance with general data processing principles. ·Art. 14, 25 ·Non-compliance with general data processing principles May 26, 2026
€1,400 Elektronikus Egészségügyi Szolgáltatási Tér: Insufficient technical and organisational measures to ensure information security Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Elektronikus Egészségügyi Szolgáltatási Tér €1,400 on 2026-05-20 for: Insufficient… Hungary · ·Art. 5, 6, 9 May 20, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 May 19, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Apr 16, 2026
€2,000 Physician: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Physician €2,000 on 2026-03-26 for: Insufficient fulfilment of data subjects rights. Italy · ·Art. 13 Mar 26, 2026
€600 CENTRO MEDICO REY FERNANDO, S.L.P.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined CENTRO MEDICO REY FERNANDO, S.L.P. €600 on 2026-03-13 for: Insufficient fulfilment of data subjects rights. Spain · ·Art. 12 Mar 13, 2026
€2,000 SC Hayat Dent SRL: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SC Hayat Dent SRL €2,000 on 2026-02-20 for: Insufficient cooperation with supervisory… Romania · ·Art. 83 Feb 20, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA · ·Art. 5, 6, 9 +6 Jan 30, 2026
€5,000 Dr. Paolo Montemurro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Dr. Paolo Montemurro €5,000 on 2026-01-29 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 9 Jan 29, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 22, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Jan 12, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND · ·Non-compliance with general data processing principles Jan 9, 2026
€18,500 Commandant van de Stedelijke Politie van Krakau: Niet-naleving van de algemene principes voor gegevensverwerking. 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Non-compliance with general data processing principles Jan 9, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE · ·Art. 5 Jan 8, 2026
€50,000 Social Insurance Agency: Insufficient technical and organisational measures to ensure information security Applications for social benefits from Slovak citizens were sent by post to foreign authorities. These were lost by post, with the result that the whereabouts of these personal… SLOVAKIA · ·Art. 32 Dec 30, 2025
€50,000 Sociale verzekeringsinstantie: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA · ·Art. 32 Dec 30, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY · ·Art. 5, 6, 9 +2 Dec 4, 2025
Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Dec 3, 2025
€400,000 Verisure Italy s.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Nov 27, 2025
€1.2M IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies… SPAIN · ·Art. 6, 9, 25 Nov 21, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND · ·Art. 5, 24, 25 +1 Nov 15, 2025
€4,750 De districtsinspecteur voor volksgezondheid in Police: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 5, 24, 25 +1 Nov 15, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,400 on AXARQUIA VELEZ DENTAL, S.L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN · ·Art. 5 Nov 14, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Nov 14, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 6,000 on APARELLS ORTOPEDICS CURTO, S.L. The controller was unable to retain the data it was required to ensure the availability of,… SPAIN · ·Art. 5 Oct 28, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Oct 28, 2025
€9,450 Gynaecologisch centrum: Onvoldoende naleving van de verplichtingen om datalekken te melden. Boete van €9.450 - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND · ·Insufficient fulfilment of data breach notification obligations Oct 27, 2025
€9,450 Gynecological Center: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 9,450 on a Gynecological Center. The controller sufferd a data breach and failed to report this to the DPO. POLAND · ·Insufficient fulfilment of data breach notification obligations Oct 27, 2025
€1,000 Burgemeester van de gemeente Calvi Risorta: Er is onvoldoende juridische basis voor de verwerking van gegevens. Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 Oct 23, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Mayor of the Municipality of Calvi Risorta. The controller published citizens' health data during the Covid-19 pandemic… ITALY · ·Art. 5, 6, 9 Oct 23, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Oct 10, 2025
€16,000 Orde van Verpleegkundigen van Pisa: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 16.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6 Oct 9, 2025
€6,000 Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of… ITALY · ·Art. 5, 6, 37 Oct 9, 2025