Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUData protection Clear all filters
136cases from 25 jurisdictions
€2bnTotal of monetary amounts (114 cases with an amount)
€530mLargest single case: TikTok Technology Limited
€115,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20233€5.49m
Q1 20244€82.3m
Q2 20243€13.9m
Q3 20248€386m
Q4 202418€261.9m
Q1 20259€343,078
Q2 202513€577.5m
Q3 202513€477.9m
Q4 202518€26.8m
Q1 202616€49.5m
Q2 202618€116.3m
Q3 202613€7.03m

136 cases

22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak SwedenData breaches and data security €160,053

The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.

What organisations can take from it

Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
22 Sep 2026

Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection ItalyMarketing and consent €5.51m

For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).

What organisations can take from it

An objection to advertising must take effect immediately and reliably across all channels – including app messages.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record ItalyEmployee data €24,000

Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).

What organisations can take from it

Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.

Relevance to training and awareness

Purpose limitation when accessing patient records

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator ItalyVideo surveillance €8,000

Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.

What organisations can take from it

Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records IrelandData breaches and data security €645,000

In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.

What organisations can take from it

Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.

Relevance to training and awareness

Physical security and retention of paper records

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Public sector
Employees
10,000 or more
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system RomaniaData breaches and data security €99,969

A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
17 Jul 2026

Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online GreeceData breaches and data security €25,000

From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).

What organisations can take from it

Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.

Relevance to training and awareness

Publication of documents containing health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles SloveniaEmployee data Order

The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.

What organisations can take from it

Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.

Relevance to training and awareness

Consent and proportionality in employee monitoring

Authority / court
Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
Area of law
Data protection · Employee data
Legal basis
Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
7 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR RomaniaData breaches and data security €5,002

At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Access logs and clear rules against ‘favour queries’ are a duty for every bank.

Relevance to training and awareness

Access to customer data for business purposes only; handling requests from third parties

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1, 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Jul 2026

Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR LatviaCookies and tracking €1,000

In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.

What organisations can take from it

Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.

Relevance to training and awareness

Cookie banners and cooperation with the supervisory authority

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR AustriaMarketing and consent €13m

The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).

What organisations can take from it

Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.

Authority / court
Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
Action
Fine
Status of proceedings
reduced
Sector
Other
Culpability
negligent
Mitigating circumstances
Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis SwedenVideo surveillance Reprimand or warning

The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.

What organisations can take from it

Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.

Relevance to training and awareness

Use of cameras in vehicles

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 6 Abs. 1
Action
Reprimand or warning
Status of proceedings
final
Sector
Defence and security
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit FinlandData subject rights and transparency €792,639

The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.

What organisations can take from it

Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.

Authority / court
Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
18 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage GreeceVideo surveillance €95,000

A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.

What organisations can take from it

Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.

Relevance to training and awareness

Handling video footage and access requests

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function GermanyData breaches and data security Fine

In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.

What organisations can take from it

Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.

Authority / court
Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5, Art. 25 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Liability of senior managers
According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
Published
10 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) GreeceData subject rights and transparency €110,000

Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.

What organisations can take from it

Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters HungaryData protection €140,706

On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.

What organisations can take from it

Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.

Relevance to training and awareness

Handling leaked personal data in newsrooms

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection
Legal basis
DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
intentional
Published
26 May 2026

Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff ItalyData breaches and data security €1.72m

Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.

What organisations can take from it

Staff in branches and partner shops must verify alleged support calls before granting access.

Relevance to training and awareness

Social engineering / fake IT support

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO (Integrität und Vertraulichkeit, Art. 32)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency BelgiumData subject rights and transparency €86,000

The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.

What organisations can take from it

Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.

Relevance to training and awareness

Recording of customer calls

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
Action
Fine
Status of proceedings
under appeal
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection MaltaMarketing and consent €1,000

Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.

What organisations can take from it

An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.

Relevance to training and awareness

Passing marketing objections on to service providers (suppression lists)

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late GermanyData processors Reprimand or warning

A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.

What organisations can take from it

Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.

Relevance to training and awareness

Reporting process for data breaches and management of service providers

Authority / court
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Mitigating circumstances
BVG has announced measures against similar incidents.
Published
4 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment EstoniaData processors Order

The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.

What organisations can take from it

Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.

Relevance to training and awareness

Consent and transparency for health data; cooperation with the supervisory authority

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data processors
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles SloveniaEmployee data €6,000

A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.

What organisations can take from it

GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.

Relevance to training and awareness

GPS tracking and employee data protection

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Liability of senior managers
Additional fine of 600 EUR on the responsible person.
Published
15 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years DenmarkData protection Fine

The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.

What organisations can take from it

‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware SloveniaEmployee data €71,474

An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.

What organisations can take from it

Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.

Relevance to training and awareness

Permissible monitoring of employees and IT use

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional
Liability of senior managers
Additional fine of 4,000 EUR on the responsible person.
Published
9 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia NetherlandsInternational data transfers €100m

Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.

What organisations can take from it

Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR RomaniaData processors €125,083

In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).

What organisations can take from it

Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data processors
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
25 Mar 2026

Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR LatviaData subject rights and transparency €1,500

A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.

What organisations can take from it

Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.

Relevance to training and awareness

Handling data subject requests and correspondence from authorities

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis HungaryData subject rights and transparency €1,274

A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.

What organisations can take from it

Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.

Relevance to training and awareness

Access to health data and access requests

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
20 Mar 2026

Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Amazon Europe Core S.à r.l.Luxembourg: Cour administrative annuls 746 million EUR fine against Amazon but confirms infringements LuxembourgMarketing and consent overturned

In 2021, the Luxembourg data protection authority (CNPD) had imposed 746 million EUR and an order to bring processing into compliance on account of behavioural online advertising; the Administrative Tribunal (Tribunal administratif) confirmed this on 18 March 2025. On 12 March 2026, the Administrative Court (Cour administrative) confirmed that legitimate interest was not a sound legal basis and that the information was insufficient, but annulled the fine on the basis of more recent CJEU case law on the requirement of culpability; the CNPD is re-examining the sanction.

What organisations can take from it

Personalised advertising cannot be based on legitimate interest – and courts now scrutinise culpability closely when it comes to fines.

Authority / court
Cour administrative (Luxemburg); Verfahren der CNPD
Area of law
Data protection · Marketing and consent
Legal basis
Art. 6 Abs. 1 lit. f, Art. 12 ff. DSGVO
Action
Order
Status of proceedings
overturned
Sector
Retail and e-commerce
Employees
10,000 or more
Mitigating circumstances
Amazon had implemented the compliance order before the hearing.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order DenmarkData subject rights and transparency €8,031

Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.

What organisations can take from it

Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.

Relevance to training and awareness

Handling access requests (Art. 15 GDPR)

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
Action
Fine
Status of proceedings
final
Sector
Other

Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy FinlandData subject rights and transparency €5,000

Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.

What organisations can take from it

Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.

Relevance to training and awareness

Right of access to call recordings

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15 Abs. 1 und 3
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR RomaniaData protection €1,999

The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.

What organisations can take from it

Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.

Relevance to training and awareness

Taking patient data when leaving; cooperation with the supervisory authority

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
20 Feb 2026

Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis PolandData subject rights and transparency €1.4m

Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.

What organisations can take from it

Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.

Relevance to training and awareness

Copying identity documents and data minimisation

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
16 Mar 2026

Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files CroatiaData subject rights and transparency €100,000

An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.

Relevance to training and awareness

Data minimisation for ID copies, retention periods

Missing or inadequate training played a role in the decision.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
negligent
Mitigating circumstances
No damage to data subjects was found.
Published
19 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data SwedenData breaches and data security €564,626

The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).

What organisations can take from it

Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
Published
26 Jan 2026

Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack FranceData breaches and data security €5m

In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.

What organisations can take from it

Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.

Relevance to training and awareness

Social engineering and account takeover

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants AustriaData subject rights and transparency €25,500

The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).

What organisations can take from it

Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.

Relevance to training and awareness

Recording of telephone calls and applicant data

Authority / court
Datenschutzbehörde
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
Action
Fine
Status of proceedings
under appeal
Sector
Other
Employees
Under 50
Mitigating circumstances
No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR RomaniaEmployee data €14,997

An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.

Relevance to training and awareness

Handling employees’ health data, e-mail distribution lists

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
19 Jan 2026

Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts FranceData breaches and data security €42m

Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.

What organisations can take from it

Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
Published
14 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log GreeceEmployee data €10,000

In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.

What organisations can take from it

Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.

Relevance to training and awareness

Confidential handling of employees’ health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent PolandData protection €232,208

The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.

What organisations can take from it

Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Repeat case
yes
Mitigating circumstances
During the proceedings the function was made independent and placed directly under the management board.
Published
26 Jan 2026

Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier GreeceMarketing and consent €80,000

Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).

What organisations can take from it

Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.

Relevance to training and awareness

Checking consent before telemarketing

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5, 6, 7, 29, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2025 Amazon France Logistique SASConseil d'État reduces CNIL fine against Amazon France Logistique to 15 million EUR FranceEmployee data €15m

In 2023, the French data protection authority (CNIL) had imposed 32 million EUR for the real-time monitoring of warehouse staff through scanner metrics. France's supreme administrative court (Conseil d'État) held that three metrics (‘Stow Machine Gun’, ‘Idle Time’, ‘Latency’) were covered by legitimate interest, but upheld the findings on the 31-day retention of all metrics, information deficiencies and security flaws in the video surveillance, and reduced the fine to 15 million EUR.

What organisations can take from it

Store employee performance metrics only for as long and in as much detail as their specific purpose requires.

Authority / court
Conseil d'État
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. c, Art. 12, 13, 32 DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Transport, logistics and shipping
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws FranceData processors €1.7m

As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.

What organisations can take from it

Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Curenergía Comercializador de Último Recurso, S.A.U.AEPD: 500,000 EUR against energy supplier Curenergía after misdirected message in dual chat SpainData processors €500,000

An employee of the customer service provider was serving two customers in chat at the same time and assigned one customer's e-mail address to the other; as a result, the complainant received the name, debts and billing data of a stranger. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) saw the cause in the process design, which allowed parallel chats, and imposed 500,000 EUR for lack of data protection by design; the request for reconsideration was rejected.

What organisations can take from it

Design service channels so that mix-ups between customers are technically harder – an individual error can be an organisational failure.

Relevance to training and awareness

Diligence in customer service / misdirected messages

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data processors
Legal basis
Art. 25 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers CroatiaData subject rights and transparency €1.5m

The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).

What organisations can take from it

Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi: 120,000 EUR for monitoring field staff's driving style ItalyEmployee data €120,000

At the instruction of a group company based in Switzerland, the seed company had telematics devices installed in company cars that also recorded private journeys and assigned employees scores for their driving behaviour. Italy's data protection authority (Garante per la protezione dei dati personali) found breaches of transparency, purpose limitation, data minimisation and employee protection rules, imposed 120,000 EUR and ordered the deletion of the data on private journeys.

What organisations can take from it

Group-wide telematics requirements must be assessed against local employment and data protection law before roll-out – especially where vehicles are also used privately.

Relevance to training and awareness

Employee monitoring through telematics

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
DSGVO Art. 5 Abs. 1 lit. a-c, 6 Abs. 1 lit. f, 13, 28, 88; Codice privacy Art. 2-quaterdecies, 113, 114
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Mitigating circumstances
Small number of data subjects (five employees), immediate suspension of the processing.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack NetherlandsData breaches and data security €175,000

In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.

What organisations can take from it

Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Mitigating circumstances
Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts EU levelData subject rights and transparency —

On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.

What organisations can take from it

Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.

Authority / court
Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
Status of proceedings
unknown
Sector
Media and online platforms
Published
2 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ FranceCookies and tracking €1.5m

When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.

What organisations can take from it

Cookie settings must apply across all domains of a service – including when users move to affiliated sites.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Corrections during the proceedings, cooperation.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis BelgiumMarketing and consent €5,000

The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.

What organisations can take from it

Data brokers must be able to prove for every record on which legal basis it was collected and resold.

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
Action
Fine
Status of proceedings
reduced
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Nov 2025 SIA "EUROPARK LATVIA"Europark Latvia pays 25,000 EUR for payment reminders sent to outdated addresses LatviaData protection €25,000

Following several complaints, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined how the parking operator collects contractual penalties: invoices were sent to previous rather than current registered addresses, claims were handed over to debt collection services and entered in the database of Kredītinformācijas Birojs. The authority found breaches of the principles of lawfulness, data minimisation and confidentiality and of the accountability obligation and imposed 25,000 EUR (previous year’s turnover according to the decision: 8,323,178 EUR).

What organisations can take from it

Anyone collecting debts or reporting them to credit agencies must first ensure that address data are up to date.

Relevance to training and awareness

Data quality in receivables management

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection
Legal basis
Art. 5 Abs. 1 lit. a, c, f und Abs. 2, Art. 83 Abs. 5 lit. a DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Culpability
intentional
Mitigating circumstances
Practice changed after the proceedings began; contracts concluded with the population and vehicle registers (PMLP, CSDD)

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 Les Publications Condé NastCNIL: 750,000 EUR against Vanity Fair publisher Condé Nast over cookies without consent FranceCookies and tracking €750,000

On vanityfair.fr, cookies requiring consent were set before any interaction with the banner, trackers were labelled as ‘strictly necessary’ and cookies continued to be placed even after ‘Reject all’. Following a complaint by noyb, the publisher had already received a formal notice in 2021; follow-up inspections in 2023 and 2025 by the French data protection authority (CNIL) showed continuing infringements.

What organisations can take from it

A cookie banner must technically deliver what it promises: after ‘Reject’, no further trackers may be set – and this should be tested regularly.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
yes
Published
27 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses CroatiaInternational data transfers €4.5m

The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.

What organisations can take from it

Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
14 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login FinlandData breaches and data security €865,000

Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.

What organisations can take from it

Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
28 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Comune di CurtaroloMunicipality of Curtarolo: 15,000 EUR for video surveillance of streets and employees ItalyVideo surveillance €15,000

The municipality in the province of Padua monitored public streets and work areas without a sound legal basis, without adequate information and without a data protection impact assessment; recordings were used for disciplinary purposes, and an employee was secretly filmed while on sick leave. Italy's data protection authority (Garante per la protezione dei dati personali) imposed a fine of 15,000 EUR (5,000 EUR for public surveillance, 10,000 EUR for workplace surveillance).

What organisations can take from it

Do not repurpose video recordings for disciplinary proceedings; specific employment law protections apply to employees.

Relevance to training and awareness

Purpose limitation in video surveillance and employee data

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 5, 6, 12, 13, 35, 88
Action
Fine
Status of proceedings
final
Sector
Public sector
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers SpainData subject rights and transparency €17,600

The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.

What organisations can take from it

New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Mitigating circumstances
Partial immediate payment (20% reduction under Art. 85 LPACAP).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients EstoniaData subject rights and transparency Order

Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.

What organisations can take from it

Access requests concerning health data require a fixed procedure with deadlines – in small practices too.

Relevance to training and awareness

Handling access requests from patients

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script EstoniaData protection Order

The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.

What organisations can take from it

Publicly accessible register data remain personal data – automated scraping requires its own legal basis.

Relevance to training and awareness

Public registers are no licence for data collection

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests GermanyData subject rights and transparency €195,000

A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).

What organisations can take from it

Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.

Relevance to training and awareness

Timely handling of access requests

Authority / court
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Betroffenenrechte)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
30 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN PolandData protection €2,669

For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.

What organisations can take from it

This also applies in small practices and companies: management cannot be its own data protection officer.

Relevance to training and awareness

Role and independence of the data protection officer; release of patient records

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
An independent external data protection officer was appointed in July 2024.
Published
29 Sep 2025

Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service FinlandData breaches and data security €1.8m

After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.

What organisations can take from it

Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
Published
10 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 SIA "ZZ Dats"IT service provider ZZ Dats pays 300,000 EUR after data leak as processor LatviaData breaches and data security €300,000

Unknown persons accessed the system operator’s databases via several websites and obtained personal data. The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) initially imposed 400,000 EUR; in the objection procedure, the director set aside the allegation relating to the company’s role as controller because ZZ Dats was a processor, and set the fine at 300,000 EUR for insufficient security measures under Art. 32 GDPR. The company has brought an action.

What organisations can take from it

Processors are also independently liable for the security of the systems they operate.

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2, Art. 83 Abs. 4 lit. a DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB EU levelData subject rights and transparency —

The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.

What organisations can take from it

Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.

Authority / court
Gerichtshof der Europäischen Union, Rs. C-413/23 P
Area of law
Data protection · Data subject rights and transparency
Legal basis
Verordnung (EU) 2018/1725 (Informationspflicht)
Status of proceedings
under appeal
Sector
Public sector
Published
4 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Sep 2025 IDdesign A/SIDdesign: High Court raises GDPR fine to 1.5 million DKK – group turnover counts DenmarkData protection €200,986

The furniture retailer had stored data of around 385,000 customers in a legacy system without retention periods. The district court had imposed 100,000 DKK; following a referral to the CJEU on whether the fine is to be calculated on the basis of the turnover of the entire group, the High Court increased the fine to 1.5 million DKK.

What organisations can take from it

Retention periods also apply to legacy systems in individual branches – and the group turnover counts when setting the fine.

Authority / court
Vestre Landsret (auf Anzeige der Datatilsynet)
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 83
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Original amount 1,500,000 DKK, converted at the ECB reference rate of 2 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Google LLC und Google Ireland LimitedGoogle: 325 million EUR – advertising cookies at account creation and ads in the Gmail inbox FranceCookies and tracking €325m

When creating a Google account, users were not sufficiently informed that advertising cookies were necessarily placed in the process; in addition, Google displayed advertisements between e-mails in Gmail without prior consent. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 200 million EUR on Google LLC and 125 million EUR on Google Ireland and ordered remedial action within six months, subject to a penalty payment of 100,000 EUR per day.

What organisations can take from it

Do not tacitly tie advertising cookies to account creation – and advertising in the inbox counts as direct marketing requiring consent.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés; Art. L. 34-5 Code des postes et des communications électroniques
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Infinite Styles Services Co. Limited (Shein)Shein: 150 million EUR – cookies without consent and despite rejection FranceCookies and tracking €150m

On shein.com, advertising cookies were placed without consent as soon as the site was accessed; in addition to an incomplete cookie banner, there was an advertising pop-up without an option to reject. After clicking ‘Reject all’ or withdrawing consent, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 150 million EUR.

What organisations can take from it

A cookie banner must work technically: rejecting and withdrawing consent must actually stop cookies from being placed and read.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Umsetzung von Art. 5 Abs. 3 ePrivacy-Richtlinie)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR RomaniaData breaches and data security €2,990

A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.

What organisations can take from it

Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.

Relevance to training and awareness

Identity verification and fraud detection in remote applications

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
12 Aug 2025

Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner AustriaCookies and tracking €6,200

In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.

What organisations can take from it

Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2025 ESTO ASData protection authority requires ESTO AS to stop creating accounts for non-customers EstoniaData subject rights and transparency Order

The instalment payment provider created customer profiles without a contract for persons who signed in via retailer checkouts, refused former customers the closure of their accounts and continued to send them transactional e-mails with advertising content. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered transparent information, valid consent, erasure options under Art. 17 GDPR and the separation of transactional and advertising e-mails; a penalty payment of 5,000 EUR is threatened for each item not fulfilled.

What organisations can take from it

Customer accounts must not be created for non-customers ‘on the side’ – and erasure must work once the contract has ended.

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 4 Nr. 11, 5, 6, 7, 12–14, 17 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords CroatiaData breaches and data security €320,000

The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).

What organisations can take from it

Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.

Relevance to training and awareness

Secure password storage in software development

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 31, Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
22 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data CroatiaData breaches and data security €101,000

Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.

Relevance to training and awareness

Access control and deletion periods for register data

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cap due to public tasks (Art. 44 of the Implementing Act).
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names GreeceData processors €700,000

Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.

What organisations can take from it

Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.

Relevance to training and awareness

Identity verification when concluding contracts in partner distribution

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2025 Waxholms Ångfartygs AktiebolagWaxholmsbolaget: fine for processing a captain’s breathalyser test results SwedenEmployee data €6,801

The shipping company processed results of on-board breath alcohol tests that could be attributed to a complainant employed as a captain. The Swedish Authority for Privacy Protection (IMY) regarded this as processing without a legal basis and as unlawful processing of health data and imposed 75,000 SEK.

What organisations can take from it

Monitoring data such as alcohol test results are employees’ health data – access, storage and legal basis must be settled before such tests are introduced.

Relevance to training and awareness

Employee health data (alcohol tests)

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Employee data
Legal basis
DSGVO Art. 6, Art. 9
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
18 Jun 2025

Original amount 75,000 SEK, converted at the ECB reference rate of 18 Jun 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Load 20 more of 56

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial