GDPR enforcement in 2019
171 decisions · €88.8M total fines · ← 2018 · 2020 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2019-12-19 | Aegean Marine Petroleum Network Inc. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 5Art. 6Art. 32 | €150,000 |
| 2019-12-18 | Telekom Romania Mobile Communications SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €2,000 |
| 2019-12-17 | Doorstep Dispensaree Ltd. (Pharmacy) Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 32 | €320,000 |
| 2019-12-17 | Website providing legal information Insufficient fulfilment of information obligations | 🇪🇺 Belgian Data Protection Authority (APD) | Art. 6Art. 12Art. 13 | €15,000 |
| 2019-12-17 | Nursing Care Organisation Insufficient fulfilment of data subjects rights | 🇪🇺 Belgian Data Protection Authority (APD) | Art. 12Art. 15Art. 17 | €2,000 |
| 2019-12-16 | Nusvar AB Insufficient legal basis for data processing | 🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) | Art. 6 | €35,000 |
| 2019-12-16 | SC Enel Energie S.A. (Electricity Distributor) Insufficient legal basis for data processing | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 5Art. 6Art. 7Art. 21 | €6,000 |
| 2019-12-16 | Globus Score SRL Insufficient cooperation with supervisory authority | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 58 | €2,000 |
| 2019-12-13 | Entirely Shipping & Trading S.R.L. Non-compliance with general data processing principles | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 5Art. 6Art. 7Art. 9 | €5,000 |
| 2019-12-13 | Entirely Shipping & Trading S.R.L. Non-compliance with general data processing principles | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 5Art. 6Art. 7 | €5,000 |
| 2019-12-13 | Legal Person Insufficient fulfilment of data subjects rights | 🇪🇺 Czech Data Protection Auhtority (UOOU) | Art. 15 | €2,000 |
| 2019-12-11 | Eni Gas e Luce Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 17Art. 21 | €8,500,000 |
| 2019-12-11 | Eni Gas e Luce Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6 | €3,000,000 |
| 2019-12-11 | Unknown Company Non-compliance with general data processing principles | 🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Art. 5Art. 6Art. 13Art. 24 | €1,430 |
| 2019-12-10 | Hora Credit IFN SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 5Art. 25Art. 32Art. 33 | €14,000 |
| 2019-12-10 | Shop Macoyn, S.L. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 32 | €5,000 |
| 2019-12-10 | Megastar SL Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 13 | €1,600 |
| 2019-12-09 | Rapidata GmbH Insufficient involvement of data protection officer | 🇪🇺 The Federal Commissioner for Data Protection and Freedom of Information (BfDI) | Art. 37 | €10,000 |
| 2019-12-04 | S CNTAR TAROM SA (Airline) Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €20,000 |
| 2019-12-03 | Hospital Insufficient technical and organisational measures to ensure information security | 🇪🇺 Data Protection Authority of Rheinland-Pfalz | Art. 32 | €105,000 |
| 2019-12-03 | Linea Directa Aseguradora Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €5,000 |
| 2019-12-03 | Cerrajeria Verin S.L. Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €1,500 |
| 2019-12-02 | Nicola Medical Team 17 SRL Insufficient cooperation with supervisory authority | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 58 | €2,000 |
| 2019-11-29 | Royal President S.R.L. Insufficient fulfilment of data subjects rights | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 15Art. 6Art. 32 | €2,500 |
| 2019-11-29 | Homeowners Association Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €500 |
1–25 of 171 next →