Skip to content
Content type · 3,833 documents in this view · 3,838 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3501–3550 of 3,833 sort newestlargest fineoldest
€1,000 Non-profit organisation: Insufficient fulfilment of data subjects rights The Belgian data protection authority has imposed a fine of EUR 1000 on a non-profit organisation for sending out direct marketing messages, despite the fact that data subjects… BELGIUM ·APD/GBA ·Art. 6, 21 Personal Data Direct Marketing Legitimate Interest May 29, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6, 35 Retention Period DPIA Marketing May 29, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ÚOOÚ (CZ) ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Controllers Processing May 26, 2020
€12,500 Unknown Company: Insufficient legal basis for data processing Processing of employee data without sufficient legal basis. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6 Processing Employees Human Resources May 22, 2020
€100,000 Posti Group Oyj: Insufficient fulfilment of data subjects rights The decision relates to complaints alleging that data subjects received direct marketing from the company although they had requested that their postal data be deleted.… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 13, 14 +1 Personal Data Marketing Direct Marketing May 22, 2020
€16,000 Kymen Vesi Oy: Non-compliance with general data processing principles Fine for failure to carry out a data protection impact assessment ('DPIA') for the processing of location data of employees with a vehicle information system FINLAND ·Deputy Data Protection Ombudsman ·Art. 35 DPIA Processing Employees May 22, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·DPC ·Art. 5, 6 Public Authority Personal Data Processing May 17, 2020
€6,700 JobTeam A/S DKK: Insufficient fulfilment of data subjects rights The company has deleted personal data affected by a request for access without legal reason. DENMARK ·Datatilsynet (DK) ·Art. 15 Personal Data Supervisory Authorities Employees May 15, 2020
€50,000 Social Media Provider: Insufficient legal basis for data processing The company has sent invitations to contacts uploaded by its users without their consent or any other legal basis. BELGIUM ·APD/GBA ·Art. 6 Consent Social Media Processing May 14, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·IMY ·Art. 5, 6 Personal Data Public Authority Processing May 12, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance May 5, 2020
€134,000 Telenor Norge AS: Insufficient technical and organisational measures to ensure information security Fines for security breaches in a voice mailbox function. NORWAY ·Datatilsynet (NO) ·Art. 32 Security Telecommunications Fines May 3, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS ·AP ·Art. 5, 9 Consent Personal Data Processing Apr 30, 2020
€500 Housing Association: Insufficient legal basis for data processing Fine of EUR 500 against a housing association for publishing photos showing members of the association without their consent. ESTONIA ·AKI ·Art. 6 Consent Processing Supervisory Authorities Apr 30, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·IMY ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 29, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM ·APD/GBA ·Art. 31, 37, 58 Supervisory Authorities Data Breaches Notification Obligation Apr 28, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Apr 23, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ANSPDCP ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Personal Data Healthcare Types of Special Categories of Personal Data Apr 23, 2020
€2,000 Political Party: Insufficient legal basis for data processing Forging signatures on a voters' list. BULGARIA ·CPDP ·Art. 6 Public Authority Education Processing Apr 14, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE ·HDPA ·Art. 5, 6 Retention Period Controllers Processing Apr 7, 2020
€2,890 Bank: Insufficient legal basis for data processing Due to an administrative error, the personal data of the data subject were registered and transferred to the Central Credit Information System (CCI) in connection with a loan… HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 26, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Mar 25, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 25, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Mar 25, 2020
€3,000 Dante International: Insufficient legal basis for data processing The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. ROMANIA ·ANSPDCP ·Art. 6, 21 Personal Data Processing Supervision Mar 25, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company did not provide the data protection authority with the requested information in a timely manner. The AEPD's request was preceded by a request from a data subject for… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS ·AP ·Art. 9, 32 Security Healthcare Controllers Mar 24, 2020
€8,000 Speech and Special Education Centre - Mihou Dimitra: Insufficient fulfilment of data subjects rights The complainant had requested access to his child's data and to tax information. This request was rejected by the data controller. In addition, the data controller had violated an… GREECE ·HDPA ·Art. 15, 58 Personal Data Controllers Processing Mar 20, 2020
€6,000 Oliveros Ustrell, S.L.: Insufficient legal basis for data processing The company forwarded an unsigned porting contract to the operator Vodafone. However, the data controller was unable to provide evidence of the order. For this reason, the… SPAIN ·AEPD ·Art. 5, 6 Controllers Personal Data Processing Mar 19, 2020
€5,800 Unknown Company: Insufficient fulfilment of data subjects rights The data controller has not complied with its obligation regarding the right of access to video recordings and was also unable to demonstrate that his data processing activities… HUNGARY ·NAIH ·Art. 6, 15 Personal Data Right of Access Controllers Mar 19, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 18, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Mar 16, 2020
€4,000 Private Person: Insufficient legal basis for data processing On a beach, a private person secretly photographed female bathers. The incident was reported to the AEPD by the local police. SPAIN ·AEPD ·Art. 5, 6 Processing Supervisory Authorities Mar 16, 2020
€6,000 Amalfi Servicios de Restauracion S.L.: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·AEPD ·Art. 5, 13, 14 Retention Period Processing Supervisory Authorities Mar 16, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA ·AZOP ·Art. 15 Personal Data Right of Access Supervisory Authorities Mar 13, 2020
€2,000 Homeowners Association: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·AEPD ·Art. 5, 13, 14 Retention Period Processing Supervisory Authorities Mar 12, 2020
€5M Google LLC: Insufficient fulfilment of data subjects rights Original Fine Summary: The Swedish data protection authority has fined Google LLC € 7 million for failing to adequately comply with its obligations regarding the right of data… SWEDEN ·IMY ·Art. 5, 6, 17 Personal Data Telecommunications Supervisory Authorities Mar 11, 2020
€9,000 Breiðholt Upper Secondary School: Insufficient technical and organisational measures to ensure information security In violation of Art. 32 GDPR, a teacher had sent an e-mail to his students and their parents with an attachment containing data on their well-being, academic performance and… ICELAND ·Persónuvernd ·Art. 5, 32 Security Education Public Authority Mar 10, 2020
€20,600 National Center of Addiction Medicine ('SAA'): Insufficient technical and organisational measures to ensure information security Persónuvernd noted that a former employee of the SAA received boxes of allegedly personal belongings that he had left there, but which also contained patient data, including the… ICELAND ·Persónuvernd ·Art. 5, 32 Security Healthcare Health Data Mar 10, 2020
€7,000 Hørsholm Municipality: Insufficient technical and organisational measures to ensure information security A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Security Personal Data Public Authority Mar 10, 2020
€14,000 Gladsaxe Municipality: Insufficient technical and organisational measures to ensure information security A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Encryption Security Personal Data Mar 10, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Mar 9, 2020
€4,400 Vis Consulting Sp. z o.o.: Insufficient cooperation with supervisory authority The company prevented an inspection by the data protection authority. As a result, the company has violated Article 31 in conjunction with Article 58(1)(e) and (f) of the GDPR. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Mar 9, 2020
€870 Creditor: Insufficient legal basis for data processing Sending of SMS to a data subject as a reminder for a debt, even when the debt has already been paid. HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 9, 2020
€3,200 Retailer: Insufficient fulfilment of information obligations Insufficient declaration of video surveillance. SPAIN ·AEPD ·Art. 13, 14 Supervisory Authorities Video Surveillance Monitoring Mar 6, 2020
€4,000 Liceo Artistico Statale di Napoli: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information in the teacher rankings published on the Institute's website. This… ITALY ·Garante ·Art. 5, 6, 9 Retention Period Fairness & Transparency Public Authority Mar 6, 2020
€4,000 Liceo Scientifico Nobel di Torre del Greco: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information of more than 2000 teachers in the teacher rankings published on the… ITALY ·Garante ·Art. 5, 6, 9 Retention Period Fairness & Transparency Public Authority Mar 6, 2020
€4,000 Private individual: Non-compliance with general data processing principles Unlawful usage of video surveillance cameras which also monitored parts of the public space (violation of principle of data minimization). SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Mar 6, 2020
€3,000 San Giorgio Jonico: Insufficient legal basis for data processing Publication of a citizen's personal data on a website and failure to comply with requests for deletion. ITALY ·Garante ·Art. 5, 6, 17 Personal Data Public Authority Processing Mar 5, 2020
School in Gdansk (Danzig) (fine imposed against town of Gdansk): Insufficient legal basis for data processing Original summary: A school in Gdansk used biometric fingerprint scanners to authenticate students for the payment process in the school canteen. Although the parents had given… POLAND ·UODO ·Art. 5, 9 Consent Personal Data Processing Mar 4, 2020