Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topic- Data breaches and data security 52 cases 33 % · €429.9m
- Data subject rights and transparency 35 cases 22 % · €28.6m
- Cookies and tracking 13 cases 8 % · €1.67bn
- Marketing and consent 12 cases 8 % · €98m
- Employee data 11 cases 7 % · €20.3m
- Video surveillance 11 cases 7 % · €1.74m
- no topic 11 cases 7 % · €617,568
- Data processors 10 cases 6 % · €51.7m
- International data transfers 5 cases 3 % · €924.5m
Who?
by sectorAll sectors
- Financial services and insurance 23 cases 14 % · €20.2m
- Telecoms, IT and software 22 cases 14 % · €1.31bn
- Other 19 cases 12 % · €29.5m
- Media and online platforms 17 cases 11 % · €1.21bn
- Healthcare 16 cases 10 % · €3.53m
- Public sector 16 cases 10 % · €7.35m
- Retail and e-commerce 15 cases 9 % · €154.3m
- Transport, logistics and shipping 11 cases 7 % · €413.3m
- Energy and utilities 8 cases 5 % · €81.2m
- Construction and real estate 5 cases 3 % · €204,275
- 4 more8 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 3 | €5.49m |
| Q1 2024 | 4 | €82.3m |
| Q2 2024 | 4 | €13.9m |
| Q3 2024 | 9 | €386.9m |
| Q4 2024 | 18 | €261.9m |
| Q1 2025 | 12 | €4.6m |
| Q2 2025 | 16 | €580.6m |
| Q3 2025 | 16 | €480.4m |
| Q4 2025 | 22 | €1.23bn |
| Q1 2026 | 19 | €51.8m |
| Q2 2026 | 23 | €117.4m |
| Q3 2026 | 14 | €7.03m |
160 cases
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator €8,000
Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.
Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante – Provvedimento n. 619 del 3 settembre 2026 [10294255] (ASIS Trento) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records €645,000
In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.
Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.
Physical security and retention of paper records
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 2 Sep 2026
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Press release of an authority
- EDPB – DPC announces Final Decision following Inquiry into the HSE Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls €54,316
Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.
Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.
Training employees in handling customer data; consent for advertising calls
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 6 Aug 2026
Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.
- ANSPDCP – Comunicat de presă 06.08.2026 (AMATO BESTSELLER S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Jul 2026 Metropolitan Police ServiceICO: order and reprimand against London's Met Police after disclosure of sensitive data Order
The Metropolitan Police handed a defendant unredacted documents containing the new address and telephone number of a stalking victim, and in a circular e-mail disclosed 18 people with a parliamentary connection in an open recipient list. The UK Information Commissioner's Office (ICO) ordered improvements within 3 and 12 months, including in data protection training completion rates.
Policies are not enough if mandatory training goes uncompleted for years – monitor and enforce training completion rates.
Redacting documents, e-mail distribution lists (BCC), data protection training
Missing or inadequate training played a role in the decision.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Data Protection Act 2018, Section 40
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Culpability
- negligent
- Published
- 5 Aug 2026
- Metropolitan Police Service issued with enforcement notice and reprimand following data protection failures Press release of an authority
- ICO Enforcement notice: Metropolitan Police Service Enforcement database of an authority
- ICO Reprimand: Metropolitan Police Service Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system €99,969
A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 17 Jul 2026
Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.
- ANSPDCP – Comunicat de presă 17.07.2026 (Orange România SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles Order
The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.
Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.
Consent and proportionality in employee monitoring
- Authority / court
- Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 7 Jul 2026
- Upravno sodišče znova potrdilo prakso IP: sistematično GPS sledenje zaposlenim ni dopustno brez tehtnega razloga Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR €5,002
At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Access logs and clear rules against ‘favour queries’ are a duty for every bank.
Access to customer data for business purposes only; handling requests from third parties
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 2 Jul 2026
Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.
- ANSPDCP – Comunicat de presă 02.07.2026 (Banca Transilvania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR €1,000
In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.
Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.
Cookie banners and cooperation with the supervisory authority
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Repeat case
- yes
- DVI Lēmums Par soda piemērošanu (SIA 4YOU MEBELES), 02.07.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR €13m
The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).
Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.
- Authority / court
- Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
- Published
- 16 Jul 2026
- VwGH 24.06.2026, Ro 2025/04/0007 Court decision
- VwGH bestätigt unrechtmäßige Verarbeitung von Partei-Affinitäten und setzt Geldbuße mit EUR 13 Mio. fest Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data Order
The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.
Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.
- Authority / court
- Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 6, Art. 19, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 20 Aug 2026
- Bundesverwaltungsgericht bestätigt Entscheid des EDÖB Press release of an authority
- Urteil des Bundesverwaltungsgerichts A-3891/2025 vom 22. Juni 2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis Reprimand or warning
The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.
Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.
Use of cameras in vehicles
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 6 Abs. 1
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Defence and security
- IMY – Tillsyn Securitas Sverige Aktiebolag Decision of an authority
- IMY – Beslut Securitas Sverige AB Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR €1,948
An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.
Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.
Access to surveillance rooms; staff bound by instructions
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 15 Jun 2026
Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.
- ANSPDCP – Comunicat de presă 15.06.2026 (SSG SELECT SOLUTIONS S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit €792,639
The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.
Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.
- Authority / court
- Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Retail and e-commerce
- Published
- 18 Jun 2026
- Supreme Administrative Court upholds the administrative fine imposed on Verkkokauppa.com Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage €95,000
A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.
Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.
Handling video footage and access requests
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Απόφαση 10/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function Fine
In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.
Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.
- Authority / court
- Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5, Art. 25 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Liability of senior managers
- According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
- Published
- 10 Jun 2026
- Landgericht Berlin bestätigt Verstoß der Deutsche Wohnen SE gegen die DSGVO Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) €110,000
Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.
Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Επιβολή προστίμου σε πάροχο ηλεκτρικής ενέργειας και σε τράπεζα για παραβάσεις του ΓΚΠΔ (Απόφαση 8/2026) Decision of an authority
- Αρχή Προστασίας Δεδομένων – Απόφαση 8/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students Order
According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.
Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- FTC Act (Verbot unlauterer und irreführender Praktiken)
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 5 Jun 2026
- FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students' Personal Data Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters €140,706
On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.
Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.
Handling leaked personal data in newsrooms
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- intentional
- Published
- 26 May 2026
Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.
- NAIH/962-10/2026 – Határozat (Mediaworks Hungary Zrt.) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff €1.72m
Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.
Staff in branches and partner shops must verify alleged support calls before granting access.
Social engineering / fake IT support
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO (Integrität und Vertraulichkeit, Art. 32)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 16 Jul 2026
- Newsletter del 16 luglio 2026 – Data breach, il Garante privacy sanziona Wind Tre per 1,7 milioni di euro Press release of an authority
- Garante – Provvedimento del 14 maggio 2026 [10263796] (Wind Tre) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency €86,000
The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.
Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.
Recording of customer calls
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- APD – Décision quant au fond n° 102/2026 du 12 mai 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls €277,500
Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).
Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.
Identity verification by telephone (vishing)
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 8 May 2026
- Data Protection Commission Publishes Final Decision Following Inquiry into Permanent TSB Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 May 2026 South Staffordshire Plc und South Staffordshire Water PlcICO: almost £1 million against water supplier South Staffordshire after cyber attack €1.12m
In 2020, malware entered the water supplier's network via a phishing e-mail and remained undetected for around 20 months; in 2022, attackers obtained administrator rights and stole data on 633,887 people, which ended up on the dark web. The UK Information Commissioner's Office (ICO) criticised, among other things, monitoring of only 5% of the IT environment, outdated software such as Windows Server 2003 and a lack of vulnerability and patch management.
Utilities in critical infrastructure must also monitor their entire IT estate and replace legacy systems – an attack must not only come to light through performance problems.
Recognising phishing
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Culpability
- negligent
- Mitigating circumstances
- 40% reduction for early admission of liability; payment agreed without appeal.
- Published
- 11 May 2026
Original amount 963,900 GBP, converted at the ECB reference rate of 7 May 2026.
- Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach Press release of an authority
- ICO Enforcement: South Staffordshire Plc and South Staffordshire Water Plc Enforcement database of an authority
- ICO Monetary Penalty Notice: South Staffordshire Plc and South Staffordshire Water Plc Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 May 2026 Canada Revenue Agency (CRA)Privacy Commissioner: Canada's tax authority CRA must strengthen protection against account takeovers Other
Since 2020, the Canada Revenue Agency (CRA) has experienced more than 42,000 individual breaches in which unauthorised persons accessed tax accounts or changed data in order to redirect benefits. In a special report to Parliament, the Privacy Commissioner of Canada criticised, among other things, the delayed introduction of mandatory MFA and incomplete incident recording, and made nine recommendations, eight of which were accepted in full and one in part.
Online accounts with payment functions need mandatory strong authentication and complete recording of incidents.
- Authority / court
- Office of the Privacy Commissioner of Canada (OPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Privacy Act (Kanada)
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 7 May 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection €1,000
Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.
An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.
Passing marketing objections on to service providers (suppression lists)
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- IDPC Commissioner's Decision (4. Mai 2026) Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late Reprimand or warning
A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.
Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.
Reporting process for data breaches and management of service providers
- Authority / court
- Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Mitigating circumstances
- BVG has announced measures against similar incidents.
- Published
- 4 May 2026
- Datenschutzbeauftragte verwarnt BVG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising Order
Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.
An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.
Handling objections to advertising and deletion requests
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Published
- 26 Jun 2026
- Verfügung des EDÖB gegen Cream della Cream Switzerland GmbH und Philipp Plein International AG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment Order
The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.
Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.
Consent and transparency for health data; cooperation with the supervisory authority
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data processors
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus isikuandmete kaitse asjas nr 2.1-1/24/397-890-38 (Fullgevity OÜ), 16.04.2026 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles €6,000
A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.
GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.
GPS tracking and employee data protection
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Liability of senior managers
- Additional fine of 600 EUR on the responsible person.
- Published
- 15 Apr 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years Fine
The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.
‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Mitigating circumstances
- Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.
- Datatilsynet – Gyldendal indstilles til bøde (Opdatering: afgjort 14. april 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware €71,474
An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.
Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.
Permissible monitoring of employees and IT use
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- Liability of senior managers
- Additional fine of 4,000 EUR on the responsible person.
- Published
- 9 Apr 2026
- Delodajalcu, ki je prikrito nadzoroval vse aktivnosti zaposlenih na računalnikih, izrečena globa več kot 70.000 EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia €100m
Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.
Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR €125,083
In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).
Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 25 Mar 2026
Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.
- ANSPDCP – Comunicat de presă 25.03.2026 (RENAULT COMMERCIAL ROUMANIE S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR €1,500
A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.
Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.
Handling data subject requests and correspondence from authorities
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „Fitsypro“), 24.03.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis €1,274
A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.
Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.
Access to health data and access requests
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 20 Mar 2026
Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.
- NAIH-273-7/2026 – Jogalap nélküli hozzáférés az EESZT rendszeréhez Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2026 Amazon Europe Core S.à r.l.Luxembourg: Cour administrative annuls 746 million EUR fine against Amazon but confirms infringements overturned
In 2021, the Luxembourg data protection authority (CNPD) had imposed 746 million EUR and an order to bring processing into compliance on account of behavioural online advertising; the Administrative Tribunal (Tribunal administratif) confirmed this on 18 March 2025. On 12 March 2026, the Administrative Court (Cour administrative) confirmed that legitimate interest was not a sound legal basis and that the information was insufficient, but annulled the fine on the basis of more recent CJEU case law on the requirement of culpability; the CNPD is re-examining the sanction.
Personalised advertising cannot be based on legitimate interest – and courts now scrutinise culpability closely when it comes to fines.
- Authority / court
- Cour administrative (Luxemburg); Verfahren der CNPD
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 12 ff. DSGVO
- Action
- Order
- Status of proceedings
- overturned
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Mitigating circumstances
- Amazon had implemented the compliance order before the hearing.
- La CNPD obtient la mise en conformité effective des traitements d'Amazon (Arrêt de la Cour administrative du 12 mars 2026) Press release of an authority
- Décision concernant Amazon Europe Core S.À R.L. (Tribunal administratif, 18 mars 2025) Press release of an authority
- Justice Luxembourg – Arrêt de la Cour administrative du 12 mars 2026 (n° 52757C du rôle), Amazon/CNPD Court press release
- Justice Luxembourg – Jugement du tribunal administratif du 18 mars 2025, Amazon/CNPD Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2026 Loblaw Companies LimitedOPC: Loblaw must change retention of PC Optimum data after account deletion Other
During a wave of boycotts in 2024, Loblaw did not process deletion requests in time and retained purchase and usage data from the loyalty programme (more than 17 million members) even after accounts were closed, without demonstrating effective anonymisation. Loblaw undertook to the Office of the Privacy Commissioner of Canada (OPC) to have the anonymisation independently reviewed and to carry out annual deletions.
Companies that continue to use data as anonymous after account deletion must be able to demonstrate the re-identification risk – IP addresses are often enough to link data to a person.
- Authority / court
- Office of the Privacy Commissioner of Canada (OPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- PIPEDA
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 5 Mar 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order €8,031
Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.
Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.
Handling access requests (Art. 15 GDPR)
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.
- Datatilsynet – Klein2 ApS og Nordic Cleaning ApS indstilles til bøde (Opdatering: afgjort 2. marts 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy €5,000
Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.
Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.
Right of access to call recordings
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15 Abs. 1 und 3
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 25 Mar 2026
- Finlex – Tietosuojavaltuutettu 2.3.2026 (puhelutallenteet) Decision of an authority
- Tietosuojavaltuutettu – Suomen Numerokeskukselle seuraamusmaksu puutteista puhelutallenteiden antamisessa (25.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR €1,999
The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.
Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.
Taking patient data when leaving; cooperation with the supervisory authority
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 20 Feb 2026
Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.
- ANSPDCP – Comunicat de presă 20.02.2026 (SC Hayat Dent SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis €1.4m
Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.
Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.
Copying identity documents and data minimisation
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 16 Mar 2026
Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.
- Nie można kopiować dokumentów bez podstawy prawnej - kara dla Glovo Press release of an authority
- Decyzja DKN.5112.33.2022 z 19 lutego 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files €100,000
An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).
Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.
Data minimisation for ID copies, retention periods
Missing or inadequate training played a role in the decision.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- negligent
- Mitigating circumstances
- No damage to data subjects was found.
- Published
- 19 Feb 2026
- Agenciji za nekretnine izrečena kazna u iznosu od 100.000,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Other
Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.
Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.
Unauthorised viewing of patient records (snooping)
- Authority / court
- Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
- Published
- 18 Feb 2026
- Investigation reveals 71 snooping incidents by 36 healthcare workers following Lapu Lapu Day tragedy Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Feb 2026 Disney DTC, LLC und ABC Enterprises, Inc. (The Walt Disney Company)California: $2.75 million against Disney over incomplete opt-outs for streaming €2.31m
Disney implemented objections to the sale and sharing of data only for individual services or devices rather than across the whole account, continued to disclose data via embedded ad-tech providers and offered no opt-out in connected TV apps. It was the largest CCPA settlement at the time of the agreement with the Attorney General of California.
An opt-out must take effect across all services, devices and integrated third-party providers of an account.
- Authority / court
- Attorney General of California (California Department of Justice)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 11 Feb 2026
Original amount 2,750,000 USD, converted at the ECB reference rate of 11 Feb 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data €564,626
The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).
Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
- Published
- 26 Jan 2026
Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.
- IMY – Tillsyn Sportadmin i Skandinavien AB Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2025-7801 (26.01.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack €5m
In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.
Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.
Social engineering and account takeover
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 29 Jan 2026
- Violation de données : sanction de 5 millions d'euros à l'encontre de FRANCE TRAVAIL Press release of an authority
- CNIL – Les sanctions prononcées par la CNIL (Eintrag 22/01/2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants €25,500
The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).
Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.
Recording of telephone calls and applicant data
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Employees
- Under 50
- Mitigating circumstances
- No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.
- Datenschutzbehörde, Straferkenntnis 2025-1.049.138 vom 19.01.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR €14,997
An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.
Handling employees’ health data, e-mail distribution lists
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 19 Jan 2026
Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.
- ANSPDCP – Comunicat de presă 19.01.2026 (Continental Automotive Products SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts €42m
Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.
Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
- Published
- 14 Jan 2026
- Violation de données : sanction de 42 millions d'euros à l'encontre des sociétés FREE MOBILE et FREE Press release of an authority
- Délibération SAN-2026-001 du 8 janvier 2026 (FREE MOBILE) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log €10,000
In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.
Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.
Confidential handling of employees’ health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Απόφαση 1/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent €232,208
The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.
Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Repeat case
- yes
- Mitigating circumstances
- During the proceedings the function was made independent and placed directly under the management board.
- Published
- 26 Jan 2026
Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.
- Kara dla Poczty Polskiej za brak zapewnienia niezależności sprawowania funkcji IOD Press release of an authority
- Decyzja DKN.5131.4.2025 z 2 stycznia 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier €80,000
Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).
Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.
Checking consent before telemarketing
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5, 6, 7, 29, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Απόφαση 44/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Dec 2025 Rickenbacher Data LLC (Datamasters)CPPA: $45,000 against data broker Datamasters over failure to register €38,275
Without registering as a data broker, the Texas reseller traded in the names and contact details of millions of people, sorted by illnesses such as Alzheimer's or addiction, by age, presumed ethnicity and political views. In addition to the fine, the California Privacy Protection Agency (CPPA) requires it to stop selling data on all Californians.
Companies that buy or sell address lists for advertising must check registration obligations – health-related lists are particularly risky.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- California Delete Act (Registrierungspflicht für Datenhändler)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Published
- 8 Jan 2026
Original amount 45,000 USD, converted at the ECB reference rate of 30 Dec 2025.
- CalPrivacy Data Broker Enforcement Strike Force: enforcement actions Press release of an authority
- CPPA Order of Decision: Rickenbacher Data LLC d/b/a Datamasters (ENF25-172-D-DA) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2025 Amazon France Logistique SASConseil d'État reduces CNIL fine against Amazon France Logistique to 15 million EUR €15m
In 2023, the French data protection authority (CNIL) had imposed 32 million EUR for the real-time monitoring of warehouse staff through scanner metrics. France's supreme administrative court (Conseil d'État) held that three metrics (‘Stow Machine Gun’, ‘Idle Time’, ‘Latency’) were covered by legitimate interest, but upheld the findings on the 31-day retention of all metrics, information deficiencies and security flaws in the video surveillance, and reduced the fine to 15 million EUR.
Store employee performance metrics only for as long and in as much detail as their specific purpose requires.
- Authority / court
- Conseil d'État
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c, Art. 12, 13, 32 DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Conseil d'État, décision n° 492830 du 23 décembre 2025 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws €1.7m
As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.
Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Délibération SAN-2025-015 du 22 décembre 2025 (NEXPUBLICA FRANCE) Decision of an authority
- Les sanctions prononcées par la CNIL Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 Curenergía Comercializador de Último Recurso, S.A.U.AEPD: 500,000 EUR against energy supplier Curenergía after misdirected message in dual chat €500,000
An employee of the customer service provider was serving two customers in chat at the same time and assigned one customer's e-mail address to the other; as a result, the complainant received the name, debts and billing data of a stranger. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) saw the cause in the process design, which allowed parallel chats, and imposed 500,000 EUR for lack of data protection by design; the request for reconsideration was rejected.
Design service channels so that mix-ups between customers are technically harder – an individual error can be an organisational failure.
Diligence in customer service / misdirected messages
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 25 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- AEPD Resolución PS/00190/2024 (EXP202316394) Decision of an authority
- AEPD Resolución recurso de reposición PS/00190/2024 (Datum der Ausgangsentscheidung 22.12.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers €1.5m
The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).
Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 18 Dec 2025
- Banci izrečena upravna novčana kazna u iznosu od 1,5 milijuna eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi: 120,000 EUR for monitoring field staff's driving style €120,000
At the instruction of a group company based in Switzerland, the seed company had telematics devices installed in company cars that also recorded private journeys and assigned employees scores for their driving behaviour. Italy's data protection authority (Garante per la protezione dei dati personali) found breaches of transparency, purpose limitation, data minimisation and employee protection rules, imposed 120,000 EUR and ordered the deletion of the data on private journeys.
Group-wide telematics requirements must be assessed against local employment and data protection law before roll-out – especially where vehicles are also used privately.
Employee monitoring through telematics
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a-c, 6 Abs. 1 lit. f, 13, 28, 88; Codice privacy Art. 2-quaterdecies, 113, 114
- Action
- Fine
- Status of proceedings
- final
- Sector
- Food and agriculture
- Mitigating circumstances
- Small number of data subjects (five employees), immediate suspension of the processing.
- Provvedimento del 18 dicembre 2025 [10213711] (Reg. 755/2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack €175,000
In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.
Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Mitigating circumstances
- Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
- Published
- 17 Dec 2025
- HAN krijgt boete van 175.000 euro voor onvoldoende beveiliging van persoonsgegevens Press release of an authority
- Boete HAN Decision of an authority
- AP: Besluit tot oplegging van een bestuurlijke boete aan Stichting Hogeschool van Arnhem en Nijmegen Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ €1.5m
When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.
Cookie settings must apply across all domains of a service – including when users move to affiliated sites.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Corrections during the proceedings, cooperation.
- CNIL, Délibération SAN-2025-011 du 27 novembre 2025 (Légifrance) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis €5,000
The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.
Data brokers must be able to prove for every record on which legal basis it was collected and resold.
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Telecoms, IT and software
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Nov 2025 SIA "EUROPARK LATVIA"Europark Latvia pays 25,000 EUR for payment reminders sent to outdated addresses €25,000
Following several complaints, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined how the parking operator collects contractual penalties: invoices were sent to previous rather than current registered addresses, claims were handed over to debt collection services and entered in the database of Kredītinformācijas Birojs. The authority found breaches of the principles of lawfulness, data minimisation and confidentiality and of the accountability obligation and imposed 25,000 EUR (previous year’s turnover according to the decision: 8,323,178 EUR).
Anyone collecting debts or reporting them to credit agencies must first ensure that address data are up to date.
Data quality in receivables management
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection
- Legal basis
- Art. 5 Abs. 1 lit. a, c, f und Abs. 2, Art. 83 Abs. 5 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Culpability
- intentional
- Mitigating circumstances
- Practice changed after the proceedings began; contracts concluded with the population and vehicle registers (PMLP, CSDD)
- DVI Lēmums Nr. 01630000100425-3 Par soda piemērošanu (SIA „EUROPARK LATVIA“), 24.11.2025 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database €1.39m
In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.
Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.
Separation of personal and work devices and credentials
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 11 Dec 2025
Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.
- Password manager provider fined £1.2m by ICO for data breach Press release of an authority
- ICO Enforcement: LastPass UK Ltd Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 Les Publications Condé NastCNIL: 750,000 EUR against Vanity Fair publisher Condé Nast over cookies without consent €750,000
On vanityfair.fr, cookies requiring consent were set before any interaction with the banner, trackers were labelled as ‘strictly necessary’ and cookies continued to be placed even after ‘Reject all’. Following a complaint by noyb, the publisher had already received a formal notice in 2021; follow-up inspections in 2023 and 2025 by the French data protection authority (CNIL) showed continuing infringements.
A cookie banner must technically deliver what it promises: after ‘Reject’, no further trackers may be set – and this should be tested regularly.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- yes
- Published
- 27 Nov 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses €4.5m
The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.
Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 14 Nov 2025
- AZOP: Administrative Fine of EUR 4.5 Million Imposed on a Telecommunications Operator (14.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Oct 2025 Google LLCTexas: Google pays $1.375 billion over location, incognito and biometric data €1.19bn
Texas, represented by the Office of the Attorney General, had sued Google for unlawfully collecting location data, activity in incognito mode and biometric identifiers. Google signed a settlement of $1.375 billion, concluding two sets of proceedings.
Settings such as location history or incognito mode must deliver what they promise users – otherwise billion-dollar risks loom, even at the level of individual US states.
- Authority / court
- Office of the Attorney General of Texas
- Area of law
- Data protection · Cookies and tracking
- Action
- Other
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 31 Oct 2025
Original amount 1,375,000,000 USD, converted at the ECB reference rate of 31 Oct 2025.
- Attorney General Ken Paxton Finalizes Historic Settlement with Google and Secures $1.375 Billion Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login €865,000
Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.
Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 28 Oct 2025
- Finlex – Tietosuojavaltuutettu 23.10.2025 (pankin tunnistamispalvelun muutosprosessi) Decision of an authority
- Tietosuojavaltuutettu – Aktialle seuraamusmaksu tietoturvapuutteista vahvan sähköisen tunnistamisen palvelussa (28.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Comune di CurtaroloMunicipality of Curtarolo: 15,000 EUR for video surveillance of streets and employees €15,000
The municipality in the province of Padua monitored public streets and work areas without a sound legal basis, without adequate information and without a data protection impact assessment; recordings were used for disciplinary purposes, and an employee was secretly filmed while on sick leave. Italy's data protection authority (Garante per la protezione dei dati personali) imposed a fine of 15,000 EUR (5,000 EUR for public surveillance, 10,000 EUR for workplace surveillance).
Do not repurpose video recordings for disciplinary proceedings; specific employment law protections apply to employees.
Purpose limitation in video surveillance and employee data
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 5, 6, 12, 13, 35, 88
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Provvedimento del 23 ottobre 2025 [10196164] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Oct 2025 Capita plc und Capita Pension Solutions LimitedICO: £14 million against Capita after ransomware attack affecting 6.6 million people €16.1m
In March 2023, an employee unintentionally downloaded malicious files; although an alert was triggered after ten minutes, the device was only isolated after 58 hours. Attackers stole around one terabyte of data on 6.6 million people (including pension data and criminal record information). Fines imposed by the UK Information Commissioner's Office (ICO): £8 million against Capita plc and £6 million against Capita Pension Solutions.
Security alerts need binding response times and an adequately staffed SOC – known vulnerabilities must be remedied across the group.
Handling malicious downloads and security alerts
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- £45 million had provisionally been proposed; reduced, among other things, for security improvements, credit monitoring for those affected and cooperation with authorities and the NCSC.
- Published
- 15 Oct 2025
Original amount 14,000,000 GBP, converted at the ECB reference rate of 15 Oct 2025.
- Capita fined £14m for data breach affecting over 6m people Press release of an authority
- ICO Enforcement: Capita plc Enforcement database of an authority
- ICO Monetary Penalty Notice: Capita plc and Capita Pension Solutions Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers €17,600
The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.
New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Mitigating circumstances
- Partial immediate payment (20% reduction under Art. 85 LPACAP).
- AEPD Resolución PS/00160/2024 (EXP202308414) Decision of an authority
- AEPD Resolución recurso de reposición PS/00160/2024 (Datum der Ausgangsentscheidung 13.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients Order
Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.
Access requests concerning health data require a fixed procedure with deadlines – in small practices too.
Handling access requests from patients
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus nr 2.1-1/25/737-1585-20 (Nura OÜ), 13.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script Order
The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.
Publicly accessible register data remain personal data – automated scraping requires its own legal basis.
Public registers are no licence for data collection
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Other
- Ettekirjutus-hoiatus nr 2.1.-4/25/1239-2660-6 (Zu Disain OÜ), 06.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests €195,000
A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).
Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.
Timely handling of access requests
- Authority / court
- Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Betroffenenrechte)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 30 Sep 2025
- Zwischenbilanz 2025: HmbBfDI verhängt Bußgelder von insgesamt 775.000 Euro Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2025 Tractor Supply CompanyCPPA: $1.35 million against Tractor Supply over missing opt-out mechanisms €1.16m
The rural retail giant inadequately informed consumers and job applicants about their rights, offered no effective means of opting out of the sale and sharing of data (including no Global Privacy Control) and passed data on to third parties without the required contracts. An officer must certify compliance annually for four years, as required by the California Privacy Protection Agency (CPPA).
Privacy notices must also cover job applicants, and browser opt-out signals such as GPC must be implemented technically.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 30 Sep 2025
Original amount 1,350,000 USD, converted at the ECB reference rate of 26 Sep 2025.
- CPPA: Tractor Supply Company enforcement decision Press release of an authority
- CPPA Order of Decision and Stipulated Final Order: Tractor Supply Company (ENF24-M-TR-04) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link