Skip to content
Content type · 3,833 documents in this view · 3,838 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3651–3700 of 3,833 sort newestlargest fineoldest
€2,000 Nursing Care Organisation: Insufficient fulfilment of data subjects rights The company failed to act on requests from the data subject to get access to his data and to have his data erased. BELGIUM ·APD/GBA ·Art. 12, 15, 17 Personal Data Supervisory Authorities Dec 17, 2019
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM ·APD/GBA ·Art. 6, 12, 13 Personal Data Fairness & Transparency IP Address Dec 17, 2019
€35,000 Nusvar AB: Insufficient legal basis for data processing Nusvar AB, operator of the website Mrkoll.se, which provides information on all Swedes over 16 years of age, had published information on people who are overdue. SWEDEN ·IMY ·Art. 6 Processing Supervisory Authorities Dec 16, 2019
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Dec 16, 2019
€6,000 SC Enel Energie S.A. (Electricity Distributor): Insufficient legal basis for data processing The sanctions were imposed following a complaint alleging that Enel Energie had unlawfully processed an individual's personal data and was unable to prove that it had obtained the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Right to Object Personal Data Consent Dec 16, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company processed biometric data (fingerprints) of the employees for access to certain rooms tough less intrusive means for the privacy of the data subjects could be used… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Retention Period Types of Special Categories of Personal Data Personal Data Dec 13, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company has excessively processed the personal data of his employees through the video cameras installed in the offices and in the places where there are cabinets where the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Retention Period Personal Data Processing Dec 13, 2019
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused provided the data subject with access to their personal data only after being requested to do so by… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Agreement Dec 13, 2019
€1,430 Unknown Company: Non-compliance with general data processing principles The employer restored the mailbox of a director who had left the company a year before and found an email containing a work-related document. The director received no warning that… HUNGARY ·NAIH ·Art. 5, 6, 13 +2 Processing Representatives Employees Dec 11, 2019
€8.5M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6, 17 +1 Integrity and Confidentiality Principle Storage Limitation Direct Marketing Dec 11, 2019
€3M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Processing Dec 11, 2019
€1,600 Megastar SL: Non-compliance with general data processing principles The company operated a video surveillance system in which the observation angle of the cameras extended unnecessarily far into the public traffic area. Furthermore, no sign with… SPAIN ·AEPD ·Art. 5, 13 Processing Supervisory Authorities Video Surveillance Dec 10, 2019
€5,000 Shop Macoyn, S.L.: Insufficient technical and organisational measures to ensure information security The company has sent advertising e-mails to several recipients where the e-mail addresses of all other recipients were visible to all recipients, because the recipient addresses… SPAIN ·AEPD ·Art. 32 Security Recipient Direct Marketing Dec 10, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Supervision Security Dec 10, 2019
€10,000 Rapidata GmbH: Insufficient involvement of data protection officer Despite repeated requests of the BfDI the company (an internet provider) did not comply with its legal obligation under Article 37 GDPR to appoint a data protection officer. GERMANY ·BfDI ·Art. 37 Supervisory Authorities Telecommunications Dec 9, 2019
€20,000 S CNTAR TAROM SA (Airline): Insufficient technical and organisational measures to ensure information security The Romanian data protection authority imposed a sanction on an airline because it has not taken appropriate measures to ensure that any natural person acting under its… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Dec 4, 2019
€1,500 Cerrajeria Verin S.L.: Insufficient fulfilment of information obligations The company collected personal data without providing accurate information on their data processing activities in their privacy policy published on their website. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Processing Dec 3, 2019
€5,000 Linea Directa Aseguradora: Insufficient legal basis for data processing The insurance company has sent advertising e-mails for the 'Reto Nuez' platform without the required consent. SPAIN ·AEPD ·Art. 6 Consent Insurance Direct Marketing Dec 3, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Dec 2, 2019
€2,500 Royal President S.R.L.: Insufficient fulfilment of data subjects rights Royal President refused a request for access to personal data pursuant to Article 15 of the GDPR and disclosed personal data without the consent of the data subjects. In addition,… ROMANIA ·ANSPDCP ·Art. 6, 15, 32 Personal Data Right of Access Security Nov 29, 2019
€500 Homeowners Association: Insufficient technical and organisational measures to ensure information security The association used video surveillance systems without proper information according to Art. 13 GDPR and without adequate security measures regarding the persons having access to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Supervision Nov 29, 2019
€75,000 Curenergía Comercializador de último recurso: Insufficient legal basis for data processing An individual filed a complaint against the company alleging that the company had used its personal data as a former customer, such as first and last name, VAT identification… SPAIN ·AEPD ·Art. 6 Personal Data Processing Identification Nov 28, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance Nov 28, 2019
€5,000 Mayor: Insufficient legal basis for data processing Fine for sending election mailings without a sufficient legal basis. The e-mail addresses used have not been collected for this purpose. BELGIUM ·APD/GBA ·Art. 6 Public Authority Processing Supervisory Authorities Nov 28, 2019
€5,000 Municipal alderman: Insufficient legal basis for data processing Fine for sending election mailings without a sufficient legal basis. The e-mail addresses used have not been collected for this purpose. BELGIUM ·APD/GBA ·Art. 6 Public Authority Processing Supervisory Authorities Nov 28, 2019
€3,000 Modern Barber: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Nov 26, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Controllers Nov 25, 2019
€2,000 BNP Paribas Personal Finance S.A.: Insufficient fulfilment of data subjects rights BNP Paribas Personal Finance did not react to a request for erasure within the period set by the GDPR. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Supervision Supervisory Authorities Nov 22, 2019
€60,000 Viaqua Xestión Integral Augas de Galicia: Insufficient legal basis for data processing Processing (modification) of the personal data of a customer included in a contract by a third party without the consent of the customer. SPAIN ·AEPD ·Art. 6 Personal Data Consent Processing Nov 21, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE ·CNIL ·Art. 5, 6, 13 +4 Personal Data Processing Supervisory Authorities Nov 21, 2019
€6,000 Sports Bar: Non-compliance with general data processing principles The sports bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Monitoring Nov 19, 2019
€60,000 Corporación radiotelevisión espanola: Insufficient technical and organisational measures to ensure information security CORPORACIÓN RADIOTELEVISIÓN ESPAÑOLA and the trade union have reported a security breach to the AEPD after six unencrypted USB sticks containing personal data were lost. The… SPAIN ·AEPD ·Art. 32 Encryption Security Personal Data Nov 19, 2019
€60,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security An individual complainant had received an SMS from Xfera Móviles which was to be addressed to a third party and which allowed him to access the account and personal data of this… SPAIN ·AEPD ·Art. 32 Personal Data Security Telecommunications Nov 19, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN ·AEPD ·Art. 5 Accountability Processing Telecommunications Nov 14, 2019
€3,000 General Confederation of Labour ('CGT'): Insufficient legal basis for data processing The CGT, with the aim of convening a meeting, e-mailed personal data of the complainant, including her home address, family relationship, pregnancy status and the date of an… SPAIN ·AEPD ·Art. 6 Personal Data Consent Processing Nov 13, 2019
€900 TODOTECNICOS24H S.L.: Insufficient fulfilment of information obligations TODOTECNICOS24H had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Transparency Nov 7, 2019
€900 Cerrajero Online: Insufficient fulfilment of information obligations The company had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Transparency Nov 6, 2019
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone has sent the customer's invoice data to unauthorised third parties following a customer invoice complaint. Originally, a fine of EUR 75,000 was threatened, but was… SPAIN ·AEPD ·Art. 6 Telecommunications Processing Supervisory Authorities Nov 6, 2019
€150,000 LATVIA DPA: Insufficient legal basis for data processing Unlawful data processing. No further information available yet. DSI ·Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Agreement Processing Nov 1, 2019
€1,770 L. Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA (UODO) imposed a fine of EUR 1,770 on L. Sp. z o.o. for the video surveillance of a residential community, which was not in compliance with the provisions of the… POLAND ·UODO ·Art. 5 Processing Personal Data Video Surveillance Nov 1, 2019
€5,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Retention Period Processing Video Surveillance Nov 1, 2019
€50,000 Menzis (Health Insurance Company): Non-compliance with general data processing principles Marketing staff had access to patient data. Among other things, this violated the purpose limitation principle. THE NETHERLANDS ·AP ·Art. 5 Insurance Processing Direct Marketing Oct 31, 2019
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS ·AP ·Art. 32 Security Insurance Healthcare Oct 31, 2019
€6,000 Jocker Premium Invex: Insufficient legal basis for data processing After registering for a local census, Jocker Premium Invex had sent the applicant postal advertisements and commercial offers, although data such as first name, surname and postal… SPAIN ·AEPD ·Art. 6 Public Authority Processing Supervisory Authorities Oct 31, 2019
Deutsche Wohnen SE: Non-compliance with general data processing principles In addition to sanctioning violations of privacy by design principles (Art. 5 GDPR, Art. 25 GDPR - see separate entry), the Berlin data protection commissioner imposed further… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Privacy by Design Privacy by Design & Default Privacy by Default Oct 30, 2019
€16M Austrian Post: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 16,000,000 on the Austrian Post. The controller had sold information regarding the political affinity to third parties without a… AUSTRIA ·DSB ·Art. 5, 6 Controllers Processing Supervisory Authorities Oct 29, 2019
€511 Employer: Insufficient fulfilment of data subjects rights The pecuniary sanction of EUR 511 was imposed on an employer for refusal to grant access to the personal data of a data subject who submitted an application for access to his… BULGARIA ·CPDP ·Art. 12, 15 Personal Data Employees Oct 28, 2019
€10,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Cyprus DPA ·Art. 6, 9 Types of Special Categories of Personal Data Personal Data Processing Oct 25, 2019
€70,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Cyprus DPA ·Art. 6, 9 Types of Special Categories of Personal Data Personal Data Processing Oct 25, 2019