Skip to content

GDPR enforcement in 2019

171 decisions · €88.8M total fines · ← 2018 · 2020 →

Date ↓ Company / party Authority Articles Fine
2019-12-19 Aegean Marine Petroleum Network Inc.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 5Art. 6Art. 32 €150,000
2019-12-18 Telekom Romania Mobile Communications SA
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €2,000
2019-12-17 Doorstep Dispensaree Ltd. (Pharmacy)
Insufficient technical and organisational measures to ensure information security
🇪🇺 Information Commissioner (ICO) Art. 32 €320,000
2019-12-17 Website providing legal information
Insufficient fulfilment of information obligations
🇪🇺 Belgian Data Protection Authority (APD) Art. 6Art. 12Art. 13 €15,000
2019-12-17 Nursing Care Organisation
Insufficient fulfilment of data subjects rights
🇪🇺 Belgian Data Protection Authority (APD) Art. 12Art. 15Art. 17 €2,000
2019-12-16 Nusvar AB
Insufficient legal basis for data processing
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 6 €35,000
2019-12-16 SC Enel Energie S.A. (Electricity Distributor)
Insufficient legal basis for data processing
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 6Art. 7Art. 21 €6,000
2019-12-16 Globus Score SRL
Insufficient cooperation with supervisory authority
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 58 €2,000
2019-12-13 Entirely Shipping & Trading S.R.L.
Non-compliance with general data processing principles
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 6Art. 7Art. 9 €5,000
2019-12-13 Entirely Shipping & Trading S.R.L.
Non-compliance with general data processing principles
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 6Art. 7 €5,000
2019-12-13 Legal Person
Insufficient fulfilment of data subjects rights
🇪🇺 Czech Data Protection Auhtority (UOOU) Art. 15 €2,000
2019-12-11 Eni Gas e Luce
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 17Art. 21 €8,500,000
2019-12-11 Eni Gas e Luce
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6 €3,000,000
2019-12-11 Unknown Company
Non-compliance with general data processing principles
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 5Art. 6Art. 13Art. 24 €1,430
2019-12-10 Hora Credit IFN SA
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 25Art. 32Art. 33 €14,000
2019-12-10 Shop Macoyn, S.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 32 €5,000
2019-12-10 Megastar SL
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 13 €1,600
2019-12-09 Rapidata GmbH
Insufficient involvement of data protection officer
🇪🇺 The Federal Commissioner for Data Protection and Freedom of Information (BfDI) Art. 37 €10,000
2019-12-04 S CNTAR TAROM SA (Airline)
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €20,000
2019-12-03 Hospital
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Rheinland-Pfalz Art. 32 €105,000
2019-12-03 Linea Directa Aseguradora
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €5,000
2019-12-03 Cerrajeria Verin S.L.
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €1,500
2019-12-02 Nicola Medical Team 17 SRL
Insufficient cooperation with supervisory authority
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 58 €2,000
2019-11-29 Royal President S.R.L.
Insufficient fulfilment of data subjects rights
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 15Art. 6Art. 32 €2,500
2019-11-29 Homeowners Association
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €500