What the supervisory authority penalised — and what any organisation can learn from these cases.
In the final months of 2025, the supervisory authority issued several fines that show, once again, that complying with the GDPR is not just a formality, but a real responsibility of any organisation that processes personal data.
In one of the cases, sensitive personal data of a data subject was made public on a social network by an employee. The investigation revealed a lack of sufficient security and internal control measures, as well as inadequate training of the staff who had access to the data.
The provisions breached were mainly those concerning the processing of data only on the controller's instructions and the obligation to ensure its confidentiality and security (Articles 29 and 32 of the GDPR).
This type of situation occurs frequently when organisations treat data protection as a purely technical matter. Without clear rules, internal procedures and ongoing training, the risk of accidental or deliberate disclosure increases significantly.
Another case concerned how a request for access to personal data was handled. The data subject did not receive a complete response within the legal deadline, and the controller could not prove that it had communicated in a compliant manner.
The articles breached were those relating to transparency and the exercise of data subjects' rights (Articles 12 and 15 of the GDPR).
For management, this type of fine highlights the need for clear internal workflows to handle GDPR requests. It is not enough to have an email address or a procedure on paper. It is essential that the responsible staff know exactly what information must be provided, within what deadline, and how each response is documented.
Another example of a fine concerned the use of cookies that were not strictly technically necessary, without properly informing users and without obtaining prior consent.
In this case, the provisions of the electronic communications legislation were breached — legislation that sets out clear conditions for storing information on users' devices.
Although it is often perceived as a minor area, the misconfiguration of cookie banners remains one of the most frequent sources of fines. Management should make sure that the technical solutions implemented genuinely respect users' choices and that the information provided is clear, complete and easily accessible.
Another case analysed concerned the installation of surveillance cameras in workspaces, without adequately informing the data subjects, without prior consultation of employees, and without demonstrating a solid legal basis.
Breaches were found of the principles of lawfulness, transparency and data minimisation, as well as the lack of adequate security measures (Articles 5, 6, 12, 13 and 32 of the GDPR).
This type of fine draws attention to the fact that monitoring employees is an extremely sensitive area. Management must assess whether the intended purpose can be achieved through less intrusive methods, and must thoroughly document any decision to implement video surveillance.
In another case, an online platform was affected by repeated cyberattacks, which led to unauthorised access to a large volume of personal data. The investigation showed that adequate technical and organisational measures had not been implemented relative to the existing risks.
The obligations breached were those concerning the security of processing and the controller's accountability (Articles 32 and 24 of the GDPR).
For the leadership of organisations, this type of fine underlines the importance of periodically assessing risks, testing IT systems and updating security measures.
Beyond the amounts imposed, these fines send a clear message: most violations can be prevented through basic measures, applied consistently. Training employees, clear procedures, the involvement of the data protection officer, risk assessment and documenting decisions are essential elements of compliance.
The GDPR does not penalise isolated mistakes, but rather the absence of a coherent data protection system. Organisations that treat compliance as part of their internal culture significantly reduce the risk of fines and, at the same time, win the trust of their clients and partners.
The most frequent cases fined in 2025 concerned: the unauthorised disclosure of personal data, failure to respect data subjects' right of access, the use of cookies without consent, video surveillance in the workplace without an adequate legal basis and information, and the lack of adequate security measures against cyberattacks. The articles most often invoked were Articles 5, 6, 12, 13, 15, 24, 29 and 32 of the GDPR.
Most fines start from the lack of adequate technical and organisational measures (Article 32 of the GDPR): data disclosure by employees, successful cyberattacks, and misconfigured cookie banners. The common denominator is not an isolated mistake, but the absence of a coherent data protection system — procedures, training and internal control.
Most violations can be prevented through basic measures applied consistently: training employees, clear procedures for data subject requests, involving the data protection officer, periodic risk assessment, correct cookie configuration, and documenting decisions. Compliance treated as part of the internal culture significantly reduces the risk of fines.
Beyond the amounts imposed in each case, the authority's message is that the fine reflects the seriousness and repeated nature of the non-compliance, not an isolated mistake. The GDPR penalises the absence of a coherent data protection system, and the level of the fine depends on the nature of the processing, the missing measures, and the impact on data subjects.
We assess your GDPR compliance and tell you clearly what risks you have and what needs to be fixed first.