Skip to content
Content type · 3,833 documents in this view · 3,838 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2901–2950 of 3,833 sort newestlargest fineoldest
€2,000 Body Tonic Shop S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 2,000 on Body Tonic Shop S.L.. The data subject had signed a contract with the gym Fitness Place. In this contract, the data… SPAIN ·AEPD ·Art. 6 Personal Data Supervisory Authorities Processing Jul 27, 2021
€2,000 Gerco Fit S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 2,000 on Gerco Fit S.L.. The data subject had signed a contract with the gym Fitness Place. In this contract, the data subject… SPAIN ·AEPD ·Art. 6 Personal Data Supervisory Authorities Processing Jul 27, 2021
€1,000 APARTAMENTOS PLAYA DE COVACHOS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) imposed a fine of EUR 1,000 on APARTAMENTOS PLAYA DE COVACHOS, S.L.. The controller had installed a video surveillance system at its resort and informed… SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Monitoring Jul 27, 2021
€3,000 INSTAPACK, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on INSTAPACK, S.L.. A data subject had filed a complaint with the DPA. The reason for the complaint is that he had been… SPAIN ·AEPD ·Art. 5, 6 Personal Data Controllers Processing Jul 27, 2021
€900 Owners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on an owners' association. A data subject claimed to the DPA that the controller had installed a camera on one of his houses, which… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Jul 27, 2021
€2,000 Vasco Andaluza de Inversiones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 2,000 on Vasco Andaluza de Inversiones S.L.. The data subject had signed a contract with the gym Fitness Place. In this contract,… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Jul 27, 2021
€2,000 Fincas Miguel García S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined Fincas Miguel García S.L. in the amount of EUR 2,000. A data subject had filed a complaint against the controller, alleging a breach of Art. 13… SPAIN ·AEPD ·Art. 13 Personal Data Legitimate Interest Controllers Jul 26, 2021
€400,000 Monsanto Company: Insufficient fulfilment of information obligations The French DPA (CNIL) has fined MONSANTO EUR 400,000. In May 2019, several media revealed that MONSANTO was in possession of a file containing the personal data of more than 200… FRANCE ·CNIL ·Art. 14, 28 Processors Personal Data Controllers Jul 26, 2021
€2,000 Intersumi S.C.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 2,000 on Intersumi S.C.. The controller failed to provide an adequate privacy statement on its website. SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Jul 26, 2021
€2.5M Mercadona S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals… SPAIN ·AEPD ·Art. 5, 6, 9 +4 Criminal Data Retention Period Personal Data Jul 26, 2021
€200,000 Regione Lombardia: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on the Region of Lombardy. The region had published on its website the personal data of more than 100,000 students who… ITALY ·Garante ·Art. 5, 6 Personal Data Public Authority Identification Jul 22, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Controllers Integrity and Confidentiality Principle Processors Jul 22, 2021
APDCAT advises Catalan draft law transposing EU 2019/1153 lacks data minimization and The Catalan DPA issued an opinion at the request of the Ministry of the Interior in order to evaluate the Law proposal that will transpose the Directive (EU) 2019/1153, laying… PD 6/2021 ·Spain ·Art. 7 Personal Data Retention Period Security Jul 22, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… Garante ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles Controllers Privacy by Design & Default DPIA Jul 22, 2021
€30,000 Flowbird Italia s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 30,000 on Flowbird Italia s.r.l.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 Supervisory Authorities Processing Fines Jul 22, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 +1 Integrity and Confidentiality Principle Storage Limitation Retention Period Jul 22, 2021
€1.8M SGAM AG2R LA MONDIALE: Non-compliance with general data processing principles The French DPA (CNIL) has fined private insurer SGAM AG2R LA MONDIALE EUR 1,750,000. The CNIL had carried out an inspection at the AG2R LA MONDIALE group in 2019. On this… FRANCE ·CNIL ·Art. 5, 13, 14 Storage Limitation Retention Period Controllers Jul 20, 2021
€746M Amazon Europe Core S.à.r.l.: Non-compliance with general data processing principles In its quarterly report, Amazon.com Inc. announced that the DPA from Luxembourg (CNPD) had fined Amazon Europe Core S.à r.l. EUR 746,000,000 for failing to process personal data… LUXEMBOURG ·CNPD (LU) ·Non-compliance with general data processing principles Personal Data Supervisory Authorities Processing Jul 16, 2021
€67,900 Region of Syddanmark: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has fined the Region of Syddanmark EUR 67,900 for failing to comply with its obligation as a data controller to implement adequate security measures.… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Controllers Personal Data Jul 16, 2021
€45,000 Telefónica Móviles España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Telefónica Mobiles España, S.A.U. EUR 45,000. A data subject filed a complaint against the controller with the DPA. His complaint was based on the… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jul 12, 2021
€80,700 Medicals Nordic I/S: Non-compliance with general data processing principles The Danish DPA (Datatilsynet) has fined Medicals Nordic I/S EUR 80,700. In January 2021, the DPA became aware that Medicals Nordic was using WhatsApp to transmit confidential… DENMARK ·Datatilsynet (DK) ·Non-compliance with general data processing principles Healthcare Health Data Human Resources Jul 9, 2021
€1,500 Aparcamiento Arcusa S.L.U.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on Aparcamiento Arcusa S.L.U. The controller had installed video surveillance cameras which, among other things, also… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jul 9, 2021
€50,000 Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 50,000 on Caixabank S.A.. A data subject had filed a complaint with the DPA because he had received commercial advertising from… SPAIN ·AEPD ·Art. 6 Direct Marketing Personal Data Right to Object Jul 8, 2021
€4,000 Malagatrom S.L.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Malagatrom S.L.U.. The data subject had purchased a product from the controller via the platform 'Amazon', which was… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Supervisory Authorities Jul 8, 2021
€5,000 Pediatrician: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined a pediatrician EUR 5,000. A father had asked the controller to view the medical records contained in his child's patient file via e-mail. However, the… GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Jul 8, 2021
€2,000 Homeowners Association: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public space in violation of the principle of data minimisation. SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Jul 7, 2021
€53,800 Nordbornholms Byggeforretning Aps: Insufficient legal basis for data processing The Danish DPA ( Datatilsynet) has imposed a fine of EUR 53,800 on Nordbornholms Byggeforretning Aps. In 2018, the DPA was contacted by a data subject who complained that his… DENMARK ·Datatilsynet (DK) ·Art. 5, 6 Legitimate Interest Personal Data Controllers Jul 7, 2021
€4,200 Marbella Resorts S.L.: Insufficient data processing agreement The Spanish DPA (AEPD) has imposed a fine of EUR 7,000 on Marbella Resorts S.L.. In the case at hand, the data subject had booked a room in the hotel complex of the controller. On… SPAIN ·AEPD ·Art. 28 Controllers Personal Data Processors Jul 6, 2021
€29,000 Mermaids: Insufficient technical and organisational measures to ensure information security The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR.… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Encryption Pseudonymization Jul 5, 2021
€25,000 Higher Education Institution: Non-compliance with general data processing principles The Finnish DPA imposed a fine of EUR 25,000 on a higher education institution for data protection violations in the processing of employee location data. The controller had… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6 Retention Period Controllers Processing Jul 5, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Jul 5, 2021
Insurance company: Insufficient fulfilment of information obligations The DPA has ex officio, without prior notice, conducted a direct supervision over an insurance company based in Zagreb. Upon inspection of its business facility for carrying out… CROATIA ·AZOP ·Art. 13, 14 Controllers Supervisory Authorities Supervision Jul 5, 2021
€1,500 Private Individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. That private individual had published personal data of the data subject on a website without her… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Processing Jul 2, 2021
€1,000 SPAIN DPA: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000 on a company. The controller had used the personal data of a third party in order to obtain a microcredit. The DPA states… AEPD ·Art. 6 ·Insufficient legal basis for data processing Controllers Personal Data Supervisory Authorities Jul 1, 2021
€6,000 Private Individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of Euro 6,000 on a private individual. On July 8, 2020, the DPA became aware of the dissemination on social networks of a video showing… SPAIN ·AEPD ·Art. 6 Minors Supervisory Authorities Processing Jul 1, 2021
€3,000 Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 30, 2021
€12,500 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 12,500 on a company. The company had installed a video surveillance system for the purpose of protecting company property,… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers Jun 29, 2021
€8,500 Magazine publisher: Insufficient legal basis for data processing The Finnish DPA has imposed a fine of EUR 8,500 on a magazine publisher. The DPA received four complaints against the magazine publisher for unsolicited telephone advertising.The… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 7, 12 +3 Direct Marketing Right to Object Consent Jun 24, 2021
€24,800 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 14,800 on a company. The background to the case is a complaint by a former employee who learned that the company's… Datatilsynet (NO) ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Supervisory Authorities Right to Object Controllers Jun 22, 2021
€10,000 TNT EXPRESS WORLDWIDE SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 10,000 on TNT EXPRESS WORLDWIDE SPAIN, S.L.. The data subject had placed a private order with the controller and had entered the… AEPD ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers Processing Jun 22, 2021
€35,300 Sopockie Towarzystwo Ubezpieczeń ERGO Hestia S.A.: Insufficient fulfilment of data breach notification obligations The controller had sent an email to that contained personal data of a customer to the wrong recipient. The leaked data included data such as the name, postal address of the data… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 21, 2021
€20,000 UAB VS FITNESS: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) has imposed a fine of EUR 20,000 on UAB VS FITNESS. After receiving a notification from an individual stating that scanning a fingerprint was necessary… LITHUANIA ·VDAI ·Art. 5, 9, 13 +2 Controllers DPIA Types of Special Categories of Personal Data Jun 21, 2021
€1.6M Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has fined Storstockholms Lokaltrafik (Stockholm Local Transport Company) EUR 1,600,000. The controller had equipped ticket inspectors with body-worn cameras, which… SWEDEN ·IMY ·Art. 5, 6, 13 Retention Period Identification Fairness & Transparency Jun 21, 2021
€28,400 Magyar Telekom Nyrt.: Insufficient fulfilment of data subjects rights The Hungarian DPA (NAIH) has imposed a fine of EUR 28,400 on Magyar Telekom Nyrt. The controller had mistakenly sent an e-mail newsletter to the data subject. This occurred due to… HUNGARY ·NAIH ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Jun 18, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Jun 16, 2021
€34,000 Huppuís ehf: Non-compliance with general data processing principles The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 34,000 on Huppuís ehf. A former employee filed a complaint against the controller with the DPA. The reason for this was… ICELAND ·Persónuvernd ·Art. 5, 6, 12 +1 Legitimate Interest Controllers Personal Data Jun 15, 2021
€1,200 Inmopiso Zaragoza S.L.: Insufficient fulfilment of information obligations The controller failed to provide accurate information about the data collection in accordance with Art. 13 GDPR. The original fine of EUR 2,000 was reduced to EUR 1,200 due to… SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Jun 14, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Retention Period Personal Data Jun 14, 2021
€7,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,600 on a company. This company had installed a video surveillance system for the purpose of protecting the company's… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers Jun 11, 2021
€7,200 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,200 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD (LU) ·Art. 5, 13, 32 ·Non-compliance with general data processing principles Supervisory Authorities Storage Limitation Retention Period Jun 11, 2021