Securitas Direct fined €100,000: why data-subject rights must be genuinely free
The Spanish DPA fined Securitas Direct €100,000 after a chargeable phone number made data-subject rights harder to exercise. Here is…
Follow significant enforcement decisions from European data protection authorities, including Ireland’s DPC, France’s CNIL, Italy’s Garante and the Dutch AP. Each case analysis explains the regulator’s findings and the operational lessons for organisations processing personal data across Europe. Explore recent decisions on AI, health data, security, international transfers and individual rights below, or view the wider data protection enforcement and fines collection.
The Spanish DPA fined Securitas Direct €100,000 after a chargeable phone number made data-subject rights harder to exercise. Here is…
On 9 September 2026, the CNIL published a decision fining EXTIA €300,000 after the IT and engineering company failed to…
A €500,000 CNIL fine against Hôpital Privé de la Loire is a reminder that healthcare security has to be designed…
The Dutch Data Protection Authority (AP) has fined Uber €825 million over automated driver-account deactivations. The decision, reported on 21…
Italy's Garante fined Emirates €180,000 over MEDIF health-data transparency and retention. Practical lessons for accessibility and assisted-travel data.
The Irish Data Protection Commission has fined the Health Service Executive €300,000 after a ransomware attack on the laboratory information…
On 26 May 2026, the French data protection authority CNIL fined IQVIA Operations France €5 million over failures in two…
Irish DPC fined Permanent TSB €277,500 after phone-based impersonation attacks exposed weak contact-centre controls and late GDPR breach reporting.
The Dutch AP fined Yango operator MLU B.V. €100 million over personal data transfers to Russia. Here is the board-level…