In a case of non-cooperation, the Romanian data protection authority ANSPDCP imposed a fine of 2,000 euros on a dental clinic. The case began when the clinic itself reported a data breach to the authority.
A company received a data access request under GDPR Article 15. The data subject received a 15-page document labeled as a data privacy disclosure. At the same time the company confirmed that the data subject’s personal data...
The Spanish supervisory authority Agencia española protección datos (AEPD) imposed several fines on a pharmacy in Catalonia. The pharmacy had accessed the health data of nursing home residents without legal basis...
Hamburg sets a precedent for automated decisions. A company in Hamburg was fined ( 492,000 EURO ) for rejecting credit applications through fully automated algorithms without proper explanation or human review.
The UK Information Commissioner's Office (ICO) has fined the service provider Capita £14 million. The reason: inadequate security measures, which led to a massive hacker attack in March 2023.
The importance of complying with cookie consent requirements under the GDPR and ePrivacy Directive was also emphasized upon by other national authorities. On September 1st 2025, France’s data protection authority (CNIL) fined...
The UK’s Information Commissioner’s Office (ICO) has fined Advanced, a leading IT services provider, £3.07 million for failing to protect sensitive data, following a major ransomware attack in 2022. The breach...
The Irish Data Protection Commission (DPC) has issued a staggering €310 million fine to LinkedIn Ireland, marking the highest GDPR penalty of the year, issued in October. This penalty resulted...
The Advanced Computer Software Group Ltd has failed to implement measures to protect personal data of almost 83’000 individuals, which also included sensitive data. It is assumed that this was possible through a hacker attack in August 2022...