Content type ยท 15 documents
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Country: Malta (15) Clear filter
Filter by Topic Supervisory Authorities3518 Processing Agreement2798 Processing2594 Personal Data2548 Controllers2165 Data Controller1854 Law Enforcement1541 IP Address1278 Security1007 Supervision854 Monitoring523 Consent498
โฌ20,000 Hospital: Non-compliance with general data processing principles Data Protection Commissioner of Malta fined Hospital โฌ20,000 on 2025-04-02 for: Non-compliance with general data processing principles. Apr 2, 2025
โฌ2,500 MALTA DPA: Insufficient fulfilment of data subjects rights Multiple data protection shortcomings Jan 1, 2023
โฌ5,000 MALTA DPA: Non-compliance with general data processing principles The controller unlawfully gained access to audio recordings from a surveillance camera. Jan 1, 2023
โฌ65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed ofโฆ Jan 17, 2022
โฌ2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Jan 1, 2022
โฌ250,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has failed to implement appropriate technical and organizational measures to protect personal data. Jan 1, 2022
โฌ65,000 MALTA DPA: Non-compliance with general data processing principles The controller has violated numerous GDPR regulations, involving special categories of personal data of numerous individuals. Jan 1, 2022
โฌ2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Jan 1, 2020
โฌ2,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security A third party has gained unauthorized access to another person's account. Jan 1, 2020
โฌ5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Jan 1, 2020
โฌ4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply withโฆ Jan 1, 2020
โฌ20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Jan 1, 2020
โฌ2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Jan 1, 2020
โฌ2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security Accidental loss of personal data. Jan 1, 2020
โฌ5,000 Lands Authority: Insufficient technical and organisational measures to ensure information security As a result of the lack of appropriate security measures on the Lands Authority website, over 10 gigabytes of personal data became easily accessible to the public via a simpleโฆ Feb 18, 2019