Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topic- Cookies and tracking €1.67bn 52 % · 13 cases
- International data transfers €924.5m 29 % · 5 cases
- Data breaches and data security €429.9m 13 % · 52 cases
- Marketing and consent €98m 3 % · 12 cases
- Data processors €51.7m 2 % · 10 cases
- Data subject rights and transparency €28.6m 1 % · 35 cases
- Employee data €20.3m 1 % · 12 cases
- Video surveillance €1.74m 0 % · 11 cases
- no topic €617,568 0 % · 11 cases
Who?
by sectorAll sectors
- Telecoms, IT and software €1.31bn 40 % · 22 cases
- Media and online platforms €1.21bn 38 % · 17 cases
- Transport, logistics and shipping €413.3m 13 % · 11 cases
- Retail and e-commerce €154.3m 5 % · 15 cases
- Energy and utilities €81.2m 3 % · 8 cases
- Other €29.5m 1 % · 19 cases
- Financial services and insurance €20.2m 1 % · 23 cases
- Public sector €7.35m 0 % · 16 cases
- Healthcare €3.53m 0 % · 17 cases
- Automotive €722,653 0 % · 3 cases
- 4 more€406,377
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 3 | €5.49m |
| Q1 2024 | 4 | €82.3m |
| Q2 2024 | 4 | €13.9m |
| Q3 2024 | 9 | €386.9m |
| Q4 2024 | 18 | €261.9m |
| Q1 2025 | 12 | €4.6m |
| Q2 2025 | 16 | €580.6m |
| Q3 2025 | 17 | €480.4m |
| Q4 2025 | 22 | €1.23bn |
| Q1 2026 | 19 | €51.8m |
| Q2 2026 | 23 | €117.4m |
| Q3 2026 | 14 | €7.03m |
161 cases
31 Oct 2025 Google LLCTexas: Google pays $1.375 billion over location, incognito and biometric data €1.19bn
Texas, represented by the Office of the Attorney General, had sued Google for unlawfully collecting location data, activity in incognito mode and biometric identifiers. Google signed a settlement of $1.375 billion, concluding two sets of proceedings.
Settings such as location history or incognito mode must deliver what they promise users – otherwise billion-dollar risks loom, even at the level of individual US states.
- Authority / court
- Office of the Attorney General of Texas
- Area of law
- Data protection · Cookies and tracking
- Action
- Other
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 31 Oct 2025
Original amount 1,375,000,000 USD, converted at the ECB reference rate of 31 Oct 2025.
- Attorney General Ken Paxton Finalizes Historic Settlement with Google and Secures $1.375 Billion Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator €8,000
Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.
Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante – Provvedimento n. 619 del 3 settembre 2026 [10294255] (ASIS Trento) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records €645,000
In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.
Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.
Physical security and retention of paper records
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 2 Sep 2026
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Press release of an authority
- EDPB – DPC announces Final Decision following Inquiry into the HSE Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls €54,316
Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.
Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.
Training employees in handling customer data; consent for advertising calls
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 6 Aug 2026
Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.
- ANSPDCP – Comunicat de presă 06.08.2026 (AMATO BESTSELLER S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Jul 2026 Metropolitan Police ServiceICO: order and reprimand against London's Met Police after disclosure of sensitive data Order
The Metropolitan Police handed a defendant unredacted documents containing the new address and telephone number of a stalking victim, and in a circular e-mail disclosed 18 people with a parliamentary connection in an open recipient list. The UK Information Commissioner's Office (ICO) ordered improvements within 3 and 12 months, including in data protection training completion rates.
Policies are not enough if mandatory training goes uncompleted for years – monitor and enforce training completion rates.
Redacting documents, e-mail distribution lists (BCC), data protection training
Missing or inadequate training played a role in the decision.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Data Protection Act 2018, Section 40
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Culpability
- negligent
- Published
- 5 Aug 2026
- Metropolitan Police Service issued with enforcement notice and reprimand following data protection failures Press release of an authority
- ICO Enforcement notice: Metropolitan Police Service Enforcement database of an authority
- ICO Reprimand: Metropolitan Police Service Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system €99,969
A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 17 Jul 2026
Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.
- ANSPDCP – Comunicat de presă 17.07.2026 (Orange România SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles Order
The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.
Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.
Consent and proportionality in employee monitoring
- Authority / court
- Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 7 Jul 2026
- Upravno sodišče znova potrdilo prakso IP: sistematično GPS sledenje zaposlenim ni dopustno brez tehtnega razloga Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR €5,002
At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Access logs and clear rules against ‘favour queries’ are a duty for every bank.
Access to customer data for business purposes only; handling requests from third parties
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 2 Jul 2026
Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.
- ANSPDCP – Comunicat de presă 02.07.2026 (Banca Transilvania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR €1,000
In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.
Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.
Cookie banners and cooperation with the supervisory authority
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Repeat case
- yes
- DVI Lēmums Par soda piemērošanu (SIA 4YOU MEBELES), 02.07.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR €13m
The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).
Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.
- Authority / court
- Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
- Published
- 16 Jul 2026
- VwGH 24.06.2026, Ro 2025/04/0007 Court decision
- VwGH bestätigt unrechtmäßige Verarbeitung von Partei-Affinitäten und setzt Geldbuße mit EUR 13 Mio. fest Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data Order
The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.
Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.
- Authority / court
- Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 6, Art. 19, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 20 Aug 2026
- Bundesverwaltungsgericht bestätigt Entscheid des EDÖB Press release of an authority
- Urteil des Bundesverwaltungsgerichts A-3891/2025 vom 22. Juni 2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis Reprimand or warning
The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.
Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.
Use of cameras in vehicles
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 6 Abs. 1
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Defence and security
- IMY – Tillsyn Securitas Sverige Aktiebolag Decision of an authority
- IMY – Beslut Securitas Sverige AB Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR €1,948
An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.
Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.
Access to surveillance rooms; staff bound by instructions
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 15 Jun 2026
Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.
- ANSPDCP – Comunicat de presă 15.06.2026 (SSG SELECT SOLUTIONS S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit €792,639
The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.
Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.
- Authority / court
- Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Retail and e-commerce
- Published
- 18 Jun 2026
- Supreme Administrative Court upholds the administrative fine imposed on Verkkokauppa.com Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage €95,000
A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.
Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.
Handling video footage and access requests
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Απόφαση 10/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function Fine
In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.
Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.
- Authority / court
- Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5, Art. 25 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Liability of senior managers
- According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
- Published
- 10 Jun 2026
- Landgericht Berlin bestätigt Verstoß der Deutsche Wohnen SE gegen die DSGVO Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) €110,000
Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.
Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Επιβολή προστίμου σε πάροχο ηλεκτρικής ενέργειας και σε τράπεζα για παραβάσεις του ΓΚΠΔ (Απόφαση 8/2026) Decision of an authority
- Αρχή Προστασίας Δεδομένων – Απόφαση 8/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students Order
According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.
Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- FTC Act (Verbot unlauterer und irreführender Praktiken)
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 5 Jun 2026
- FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students' Personal Data Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters €140,706
On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.
Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.
Handling leaked personal data in newsrooms
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- intentional
- Published
- 26 May 2026
Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.
- NAIH/962-10/2026 – Határozat (Mediaworks Hungary Zrt.) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff €1.72m
Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.
Staff in branches and partner shops must verify alleged support calls before granting access.
Social engineering / fake IT support
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO (Integrität und Vertraulichkeit, Art. 32)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 16 Jul 2026
- Newsletter del 16 luglio 2026 – Data breach, il Garante privacy sanziona Wind Tre per 1,7 milioni di euro Press release of an authority
- Garante – Provvedimento del 14 maggio 2026 [10263796] (Wind Tre) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency €86,000
The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.
Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.
Recording of customer calls
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- APD – Décision quant au fond n° 102/2026 du 12 mai 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls €277,500
Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).
Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.
Identity verification by telephone (vishing)
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 8 May 2026
- Data Protection Commission Publishes Final Decision Following Inquiry into Permanent TSB Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 May 2026 South Staffordshire Plc und South Staffordshire Water PlcICO: almost £1 million against water supplier South Staffordshire after cyber attack €1.12m
In 2020, malware entered the water supplier's network via a phishing e-mail and remained undetected for around 20 months; in 2022, attackers obtained administrator rights and stole data on 633,887 people, which ended up on the dark web. The UK Information Commissioner's Office (ICO) criticised, among other things, monitoring of only 5% of the IT environment, outdated software such as Windows Server 2003 and a lack of vulnerability and patch management.
Utilities in critical infrastructure must also monitor their entire IT estate and replace legacy systems – an attack must not only come to light through performance problems.
Recognising phishing
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Culpability
- negligent
- Mitigating circumstances
- 40% reduction for early admission of liability; payment agreed without appeal.
- Published
- 11 May 2026
Original amount 963,900 GBP, converted at the ECB reference rate of 7 May 2026.
- Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach Press release of an authority
- ICO Enforcement: South Staffordshire Plc and South Staffordshire Water Plc Enforcement database of an authority
- ICO Monetary Penalty Notice: South Staffordshire Plc and South Staffordshire Water Plc Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 May 2026 Canada Revenue Agency (CRA)Privacy Commissioner: Canada's tax authority CRA must strengthen protection against account takeovers Other
Since 2020, the Canada Revenue Agency (CRA) has experienced more than 42,000 individual breaches in which unauthorised persons accessed tax accounts or changed data in order to redirect benefits. In a special report to Parliament, the Privacy Commissioner of Canada criticised, among other things, the delayed introduction of mandatory MFA and incomplete incident recording, and made nine recommendations, eight of which were accepted in full and one in part.
Online accounts with payment functions need mandatory strong authentication and complete recording of incidents.
- Authority / court
- Office of the Privacy Commissioner of Canada (OPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Privacy Act (Kanada)
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 7 May 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection €1,000
Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.
An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.
Passing marketing objections on to service providers (suppression lists)
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- IDPC Commissioner's Decision (4. Mai 2026) Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late Reprimand or warning
A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.
Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.
Reporting process for data breaches and management of service providers
- Authority / court
- Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Mitigating circumstances
- BVG has announced measures against similar incidents.
- Published
- 4 May 2026
- Datenschutzbeauftragte verwarnt BVG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising Order
Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.
An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.
Handling objections to advertising and deletion requests
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Published
- 26 Jun 2026
- Verfügung des EDÖB gegen Cream della Cream Switzerland GmbH und Philipp Plein International AG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment Order
The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.
Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.
Consent and transparency for health data; cooperation with the supervisory authority
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data processors
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus isikuandmete kaitse asjas nr 2.1-1/24/397-890-38 (Fullgevity OÜ), 16.04.2026 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles €6,000
A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.
GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.
GPS tracking and employee data protection
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Liability of senior managers
- Additional fine of 600 EUR on the responsible person.
- Published
- 15 Apr 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years Fine
The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.
‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Mitigating circumstances
- Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.
- Datatilsynet – Gyldendal indstilles til bøde (Opdatering: afgjort 14. april 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware €71,474
An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.
Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.
Permissible monitoring of employees and IT use
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- Liability of senior managers
- Additional fine of 4,000 EUR on the responsible person.
- Published
- 9 Apr 2026
- Delodajalcu, ki je prikrito nadzoroval vse aktivnosti zaposlenih na računalnikih, izrečena globa več kot 70.000 EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia €100m
Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.
Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR €125,083
In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).
Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 25 Mar 2026
Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.
- ANSPDCP – Comunicat de presă 25.03.2026 (RENAULT COMMERCIAL ROUMANIE S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR €1,500
A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.
Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.
Handling data subject requests and correspondence from authorities
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „Fitsypro“), 24.03.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link