Skip to content
Content type · 960 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–500 of 960 sort newestlargest fineoldest
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·aepd ·Art. 5, 25, 32 Privacy by Default Privacy by Design Accountability Oct 26, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·aepd ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Social Media Oct 25, 2023
€3,000 Mensajero SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Mensajero SRL. The controller had suffered a data breach where a link on the controller's website was publicly accessible… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Oct 24, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN ·aepd ·Art. 25, 32 Security Privacy by Design & Default Processing Agreement Oct 20, 2023
€70,000 Scionti Selezioni Superiori S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on Scionti Selezioni Superiori S.r.l.. The controller had made unsolicited marketing calls, in some cases to individuals who were… ITALY ·Garante ·Art. 5, 6, 7 +7 Personal Data Data Subject Rights Exercise Modalities and Procedures Controllers Oct 12, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·azop ·Art. 5, 6, 12 +2 Personal Data Controllers Insurance Oct 5, 2023
€1,000 Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Cez Vânzare S.A.. The controller had accidentally sent emails containing personal customer data to the wrong recipients. The… ROMANIA ·ANSPDCP ·Art. 32 Security IP Address Controllers Oct 2, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Healthcare Healthcare Sep 28, 2023
€25,000 RESTART ENERGY ONE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on RESTART ENERGY ONE S.A.. During its investigation, the DPA found that there existed a publicly accessible file on the… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Sep 26, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·azop ·Art. 6, 13, 32 +1 Notified Body Responsibilities and Operational Obligations Controllers IP Address Sep 26, 2023
€25,000 Zagreb Holding d.o.o.: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed a fine of EUR 25,000 on Zagreb Holding d.o.o., utilities company owned by the city of Zagreb. The DPA had received a complaint from a citizen… CROATIA ·azop ·Art. 13, 25 Controllers Personal Data Education Sep 13, 2023
€345M TikTok Limited: Non-compliance with general data processing principles The Irish DPA (DPC), has imposed a fine of EUR 345 million on TikTok Limited. The DPC conducted an investigation primarily focused on the processing of personal data between July… IRELAND ·Art. 5, 12, 13 +2 ·Non-compliance with general data processing principles Social Media IP Address Processing Sep 1, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Recipient IP Address Aug 28, 2023
DPC (Ireland) - 06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Art. 5, 24, 35 Video Surveillance Monitoring DPIA Aug 22, 2023
€70,000 Uipath SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 70,000 on Uipath SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. During its investigation, the DPA… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security IP Address Aug 21, 2023
€2.5M Open Bank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined Open Bank, S.A. EUR 2,5 million. A data subject had filed a complaint with the DPA after being asked to provide proof of origin for payments on their… SPAIN ·aepd ·Art. 25, 32 Security Processing Agreement Personal Data Jul 28, 2023
€1,200 FONTANORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on FONTANORTE, S.L.. The controller had disposed of documents containing personal data in publicly accessible trash containers. The original… SPAIN ·aepd ·Art. 32 Controllers Security Personal Data Jul 27, 2023
€3,400 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,400 on a company. The controller had reported a data breach to the DPA. The company car of a senior employee had been broken into,… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Data Breaches Security Jul 18, 2023
€40,000 Compara Facile S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Compara Facile S.r.l.. The controller had made unsolicited marketing calls, in some cases to individuals who were registered in… ITALY ·Garante ·Art. 5, 6, 7 +8 Personal Data IP Address Controllers Jul 18, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jul 18, 2023
€15,000 RCL CRUISES LTD: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on RCL CRUISES LTD. An individual had filed a complaint with the DPA. The individual, after requesting information about a cruise… SPAIN ·aepd ·Art. 5, 32 Processing Agreement Controllers IP Address Jul 7, 2023
€25,000 CaixaBank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 25,000 on CaixaBank, S.A.. An individual had filed a complaint with the DPA due to the fact that when they requested information from the… SPAIN ·aepd ·Art. 32 Security Controllers Privacy by Design & Default Jul 4, 2023
€81,000 Heilsuveru: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has fined Heilsuveru EUR 81,000. The controller had reported a data breach to the DPA, as two unauthorized persons had managed to view personal data. During its… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jul 3, 2023
€1M Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Privacy Shield Processing Agreement International Transfer Jun 30, 2023
€25,000 CDON AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Privacy Shield Processing Agreement International Transfer Jun 30, 2023
Greek DPA: Google breached Art. 17 GDPR erasure right over outdated criminal case links In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links -… 54/2024 ·Greece ·HDPA Right to be Forgotten Personal Data Accuracy Jun 29, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Security Access Controls Jun 28, 2023
€2,500 Farmacia Ardealul SRL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 2,500 on Farmacia Ardealul SRL. The controller had reported a data breach to the DPA. During its investigation, the DPA found that an… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Jun 27, 2023
€205,000 Digi Telecommunications and Services Ltd.: Insufficient technical and organisational measures to ensure information security The Hungarian DPA has imposed a fine of EUR 205,000 against Digi Telecommunications and Services Ltd. The controller had suffered a data breach in which an unauthorized party… HUNGARY ·NAIH ·Art. 5, 32 Data Breaches Security Telecommunications Jun 22, 2023
€8,000 Artima S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on Artima S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that employees of… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Video Surveillance Security Jun 15, 2023
€210,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 210,000 on Piraeus Bank. During its investigation, the DPA found that the bank had processed personal data of customers in violation of… GREECE ·HDPA ·Art. 5, 6, 15 +1 Personal Data IP Address Insurance Jun 12, 2023
DSB (Austria) - DSB-D124.4462 On 03 May 2021, the data subject sent a request to the controller for the erasure of their financial asset information. The controller did not respond to their erasure request. On… DSB-D124.4462 ·Art. 55, 77 Supervisory Authorities Personal Data Controllers Jun 12, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest IP Address Jun 8, 2023
€84,000 UNITED PARCEL SERVICE ESPAÑA LTD. Y CIA SRC: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on UNITED PARCEL SERVICE ESPAÑA LTD. Y CIA SRC a fine. A person had filed a complaint against the controller because a package addressed to them… SPAIN ·aepd ·Art. 5, 32 Controllers Processing Agreement Security Jun 7, 2023
€3,000 Private individual: Non-compliance with general data processing principles The Spanish DPA has fined a private individual EUR 3,000. An individual had filed a complaint with the DPA against the controller due to the fact that the controller had provided… SPAIN ·aepd ·Art. 5, 32 Personal Data Controllers IP Address Jun 6, 2023
€10,000 Camedi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Camedi s.r.l. Medical Center. A person had filed a complaint with the DPA because they had received invoices as well as… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Healthcare Security Jun 1, 2023
€42,000 PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA. An individual had filed a complaint with the DPA because the controller had disclosed… SPAIN ·aepd ·Art. 5, 32 Insurance Security IP Address Jun 1, 2023
€10,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 10,600 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During its… POLAND ·UODO ·Art. 5, 25, 32 +2 Security Privacy by Design & Default Personal Data May 31, 2023
€380,000 Sports betting operator: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 380,000 on a sports betting operator. AZOP had received a complaint from a data subject, stating that the controller had obtained… CROATIA ·azop ·Art. 6, 13, 25 +1 Controllers Personal Data Retention Period May 18, 2023
€18,000 AUTOMOBILE BAVARIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 18,000 on AUTOMOBILE BAVARIA SRL. The data controller had notified the authority of a data breach pursuant to Art. 33 GDPR. Unknown… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Controllers May 18, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY ·Garante ·Art. 5, 6, 32 Security Health Data Healthcare May 17, 2023
€6,700 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,700 on a municipality. The controller had reported a data breach to the DPA. During its investigation, the DPA found that the controller… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Privacy by Design & Default May 16, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€2,200 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,200 on a municipality. The controller had reported a data breach to the DPA. An employee had unauthorizedly copied a document containing… POLAND ·UODO ·Art. 5, 25, 32 Data Breaches Security Public Authority May 5, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·azop ·Art. 6, 13, 28 +1 Security Controllers Personal Data May 4, 2023
€200,000 GSMA LTD.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 200,000 against GSMA LTD.. An individual had filed a complaint with the DPA because they had to transfer special categories of personal… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Controllers May 3, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default May 2, 2023
€12,000 ALBERO FORTE COMPOSITE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on ALBERO FORTE COMPOSITE, S.L.. The company had taken pictures of employees at the entrance for the purpose of recording their working… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Employees Apr 28, 2023
€240,000 Benetton Group S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 240,000 on Benetton Group S.r.l.. The controller had stored a large amount of customer data indefinitely. The DPA also found that the… ITALY ·Garante ·Art. 5, 32 IP Address Controllers Processing Agreement Apr 27, 2023