Content type · 621 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€30,000 Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the… Italy ·Art. 5, 6, 9 Sep 29, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Sep 15, 2026
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Sep 15, 2026
€10,000 Garante · 551/2026 The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based… Italy ·Art. 5, 6, 9
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy · ·Art. 5, 9, 25 +1 Sep 3, 2026
€5,320 Slovenian DPA fines controller €5,320 for leaving employee personal data documents Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents… Slovenia · ·Art. 5, 32 Sep 1, 2026
€23,750 Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car On 4 January 2024, the newspaper “Il Fatto Quotidiano” (‘the controller’) published an article pertaining to the cable car accident of the data subject. The data subject sent a… Italy · ·Art. 5, 83 Aug 26, 2026
RON 285,395 AMATO BESTSELLER S.R.L. A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order… Romania · ·Art. 5, 9, 12 +2 Aug 18, 2026
Finnish DPA examines anti-doping organization's GDPR compliance over public suspension An athlete (the data subject) gave a doping sample containing a low concentration of a banned substance in August 2020. The national anti-doping organisation (the controller)… TSV/179/2021 ·Finland · Aug 4, 2026
€10,000 Bologna University Hospital IRCCS: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Bologna University Hospital IRCCS €10,000 for processing personal data without a sufficient legal basis. The Garante found… Italy · ·Art. 5, 6, 9 Jul 23, 2026
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France · ·Art. 32, 34 Jul 21, 2026
€12,000 Garante · 10254256 The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Art. 4, 5, 6 +2
€20,000 Garante · 471/2026 The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Art. 5, 6, 10 +1 Jul 18, 2026
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain · Jul 16, 2026
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3
€10,000 Giuliano Isontina University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Giuliano Isontina University Health Authority €10,000 for failing to implement adequate technical and organizational… Italy · ·Art. 5, 9, 25 +1 Jul 3, 2026
Persónuvernd (Island) - 2025010358 The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Art. 5, 32 Jul 1, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Jun 19, 2026
€450,000 InMedica UAB: Insufficient technical and organisational measures to ensure information security The Lithuanian Data Protection Authority (VDAI) fined InMedica UAB €450,000 for failing to implement sufficient technical and organizational measures to ensure information… Lithuania · ·Art. 5, 24, 32 Jun 19, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Jun 11, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland · ·Art. 5, 28, 30 +2 Jun 11, 2026
€70,518 IndaNext Hungary Kft. (legal successor of Blikk Kft.): Insufficient legal basis for data processing The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined IndaNext Hungary Kft., as legal successor to Blikk Kft., €70,518 for publishing… ·Art. 6, 9, 12 ·Insufficient legal basis for data processing May 29, 2026
€6,000 A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller) The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the… 382/2026 ·Italy · May 28, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 May 28, 2026
€700 Italian Red Cross: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Italian Red Cross €700 for violating general data processing principles under GDPR Articles 5(1)(c), 5(1)(f), and 9. The… Italy · ·Art. 5, 9 May 28, 2026
€5M IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) fined IQVIA OPERATIONS FRANCE €5,000,000 on 2026-05-26 for: Non-compliance with general data processing principles. ·Art. 14, 25 ·Non-compliance with general data processing principles May 26, 2026
€1,400 Elektronikus Egészségügyi Szolgáltatási Tér: Insufficient technical and organisational measures to ensure information security Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Elektronikus Egészségügyi Szolgáltatási Tér €1,400 on 2026-05-20 for: Insufficient… Hungary · ·Art. 5, 6, 9 May 20, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland · ·Art. 5, 24, 25 +3 May 19, 2026
€15,000 Monaldi-Cotugno-CTO: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Monaldi-Cotugno-CTO hospital entity €15,000 for violating general data processing principles under the GDPR. The… Italy · ·Art. 5, 9, 13 +2 May 14, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 May 13, 2026
€5,000 Dr. Guzzo: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Dr. Guzzo €5,000 for processing personal data without a sufficient legal basis. The violation concerned healthcare data and… Italy · ·Art. 5, 9 Apr 29, 2026
€8,600 Matera Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Matera Local Health Authority €8,600 for failing to implement sufficient technical and organizational measures to ensure… Italy · ·Art. 5, 32 Apr 29, 2026
€12,000 Ministry of Justice: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Ministry of Justice €12,000 for insufficient legal basis for personal data processing. The enforcement action, decided on… Italy · ·Art. 5, 6, 9 Apr 29, 2026
€4,000 Montelibretti State Comprehensive School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Montelibretti State Comprehensive School €4,000 for lacking a sufficient legal basis for its data processing activities. The… Italy · ·Art. 5, 6, 9 Apr 29, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia · Apr 16, 2026
€2,000 Physician: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Physician €2,000 on 2026-03-26 for: Insufficient fulfilment of data subjects rights. Italy · ·Art. 13 Mar 26, 2026
€2,000 Copacabana s.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Copacabana s.r.l. €2,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 13, 88 Mar 26, 2026
€600 CENTRO MEDICO REY FERNANDO, S.L.P.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined CENTRO MEDICO REY FERNANDO, S.L.P. €600 on 2026-03-13 for: Insufficient fulfilment of data subjects rights. Spain · ·Art. 12 Mar 13, 2026
€2,000 Hanako s.r.l.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Hanako s.r.l. €2,000 on 2026-03-12 for: Insufficient technical and organisational measures to ensure information security. Italy · ·Art. 5, 13, 32 Mar 12, 2026
€2,000 MALAGASUITE SHOWROOM, S.L.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined MALAGASUITE SHOWROOM, S.L. €2,000 on 2026-03-02 for: Insufficient fulfilment of data subjects rights. Spain · ·Art. 13 Mar 2, 2026
€2,000 SC Hayat Dent SRL: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SC Hayat Dent SRL €2,000 on 2026-02-20 for: Insufficient cooperation with supervisory… Romania · ·Art. 83 Feb 20, 2026
€1,500 Sole Trader: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Sole Trader €1,500 on 2026-02-12 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 13, 25 Feb 12, 2026
€2,000 Sole Trader: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Sole Trader €2,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 6, 13 +1 Feb 12, 2026
€1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… SPAIN · ·Art. 6 Feb 6, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026