Content type · 960 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN · ·Art. 5, 25, 32 Oct 26, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN · ·Art. 5, 32, 33 +2 Oct 25, 2023
€3,000 Mensajero SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Mensajero SRL. The controller had suffered a data breach where a link on the controller's website was publicly accessible… ROMANIA · ·Art. 32 Oct 24, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN · ·Art. 25, 32 Oct 20, 2023
€70,000 Scionti Selezioni Superiori S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on Scionti Selezioni Superiori S.r.l.. The controller had made unsolicited marketing calls, in some cases to individuals who were… ITALY · ·Art. 5, 6, 7 +7 Oct 12, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA · ·Art. 5, 6, 12 +2 Oct 5, 2023
€1,000 Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Cez Vânzare S.A.. The controller had accidentally sent emails containing personal customer data to the wrong recipients. The… ROMANIA · ·Art. 32 Oct 2, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY · ·Art. 5, 25, 32 Sep 28, 2023
€25,000 RESTART ENERGY ONE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on RESTART ENERGY ONE S.A.. During its investigation, the DPA found that there existed a publicly accessible file on the… ROMANIA · ·Art. 32 Sep 26, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA · ·Art. 6, 13, 32 +1 Sep 26, 2023
€25,000 Zagreb Holding d.o.o.: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed a fine of EUR 25,000 on Zagreb Holding d.o.o., utilities company owned by the city of Zagreb. The DPA had received a complaint from a citizen… CROATIA · ·Art. 13, 25 Sep 13, 2023
€345M TikTok Limited: Non-compliance with general data processing principles The Irish DPA (DPC), has imposed a fine of EUR 345 million on TikTok Limited. The DPC conducted an investigation primarily focused on the processing of personal data between July… IRELAND ·Art. 5, 12, 13 +2 ·Non-compliance with general data processing principles Sep 1, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Aug 28, 2023
DPC (Ireland) - 06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Art. 5, 24, 35 Aug 22, 2023
€70,000 Uipath SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 70,000 on Uipath SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. During its investigation, the DPA… ROMANIA · ·Art. 25, 32 Aug 21, 2023
€2.5M Open Bank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined Open Bank, S.A. EUR 2,5 million. A data subject had filed a complaint with the DPA after being asked to provide proof of origin for payments on their… SPAIN · ·Art. 25, 32 Jul 28, 2023
€1,200 FONTANORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on FONTANORTE, S.L.. The controller had disposed of documents containing personal data in publicly accessible trash containers. The original… SPAIN · ·Art. 32 Jul 27, 2023
€3,400 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,400 on a company. The controller had reported a data breach to the DPA. The company car of a senior employee had been broken into,… POLAND · ·Art. 5, 24, 25 +1 Jul 18, 2023
€40,000 Compara Facile S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Compara Facile S.r.l.. The controller had made unsolicited marketing calls, in some cases to individuals who were registered in… ITALY · ·Art. 5, 6, 7 +8 Jul 18, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA · ·Art. 32 Jul 18, 2023
€15,000 RCL CRUISES LTD: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on RCL CRUISES LTD. An individual had filed a complaint with the DPA. The individual, after requesting information about a cruise… SPAIN · ·Art. 5, 32 Jul 7, 2023
€25,000 CaixaBank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 25,000 on CaixaBank, S.A.. An individual had filed a complaint with the DPA due to the fact that when they requested information from the… SPAIN · ·Art. 32 Jul 4, 2023
€81,000 Heilsuveru: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has fined Heilsuveru EUR 81,000. The controller had reported a data breach to the DPA, as two unauthorized persons had managed to view personal data. During its… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Jul 3, 2023
€1M Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Jun 30, 2023
€25,000 CDON AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Jun 30, 2023
Greek DPA: Google breached Art. 17 GDPR erasure right over outdated criminal case links In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links -… 54/2024 ·Greece · Jun 29, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Jun 28, 2023
€2,500 Farmacia Ardealul SRL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 2,500 on Farmacia Ardealul SRL. The controller had reported a data breach to the DPA. During its investigation, the DPA found that an… ROMANIA · ·Art. 32 Jun 27, 2023
€205,000 Digi Telecommunications and Services Ltd.: Insufficient technical and organisational measures to ensure information security The Hungarian DPA has imposed a fine of EUR 205,000 against Digi Telecommunications and Services Ltd. The controller had suffered a data breach in which an unauthorized party… HUNGARY · ·Art. 5, 32 Jun 22, 2023
€8,000 Artima S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on Artima S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that employees of… ROMANIA · ·Art. 32 Jun 15, 2023
€210,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 210,000 on Piraeus Bank. During its investigation, the DPA found that the bank had processed personal data of customers in violation of… GREECE · ·Art. 5, 6, 15 +1 Jun 12, 2023
DSB (Austria) - DSB-D124.4462 On 03 May 2021, the data subject sent a request to the controller for the erasure of their financial asset information. The controller did not respond to their erasure request. On… DSB-D124.4462 ·Art. 55, 77 Jun 12, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE · ·Art. 5, 6, 9 +6 Jun 8, 2023
€84,000 UNITED PARCEL SERVICE ESPAÑA LTD. Y CIA SRC: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on UNITED PARCEL SERVICE ESPAÑA LTD. Y CIA SRC a fine. A person had filed a complaint against the controller because a package addressed to them… SPAIN · ·Art. 5, 32 Jun 7, 2023
€3,000 Private individual: Non-compliance with general data processing principles The Spanish DPA has fined a private individual EUR 3,000. An individual had filed a complaint with the DPA against the controller due to the fact that the controller had provided… SPAIN · ·Art. 5, 32 Jun 6, 2023
€10,000 Camedi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Camedi s.r.l. Medical Center. A person had filed a complaint with the DPA because they had received invoices as well as… ITALY · ·Art. 5, 9, 32 Jun 1, 2023
€42,000 PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA. An individual had filed a complaint with the DPA because the controller had disclosed… SPAIN · ·Art. 5, 32 Jun 1, 2023
€10,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 10,600 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During its… POLAND · ·Art. 5, 25, 32 +2 May 31, 2023
€380,000 Sports betting operator: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 380,000 on a sports betting operator. AZOP had received a complaint from a data subject, stating that the controller had obtained… CROATIA · ·Art. 6, 13, 25 +1 May 18, 2023
€18,000 AUTOMOBILE BAVARIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 18,000 on AUTOMOBILE BAVARIA SRL. The data controller had notified the authority of a data breach pursuant to Art. 33 GDPR. Unknown… ROMANIA · ·Art. 25, 32 May 18, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY · ·Art. 5, 6, 32 May 17, 2023
€6,700 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,700 on a municipality. The controller had reported a data breach to the DPA. During its investigation, the DPA found that the controller… POLAND · ·Art. 5, 24, 25 +1 May 16, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA · ·Art. 32 May 12, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA · ·Art. 32 May 12, 2023
€2,200 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,200 on a municipality. The controller had reported a data breach to the DPA. An employee had unauthorizedly copied a document containing… POLAND · ·Art. 5, 25, 32 May 5, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA · ·Art. 6, 13, 28 +1 May 4, 2023
€200,000 GSMA LTD.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 200,000 against GSMA LTD.. An individual had filed a complaint with the DPA because they had to transfer special categories of personal… SPAIN · ·Art. 35 May 3, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security May 2, 2023
€12,000 ALBERO FORTE COMPOSITE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on ALBERO FORTE COMPOSITE, S.L.. The company had taken pictures of employees at the entrance for the purpose of recording their working… SPAIN · ·Art. 35 Apr 28, 2023
€240,000 Benetton Group S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 240,000 on Benetton Group S.r.l.. The controller had stored a large amount of customer data indefinitely. The DPA also found that the… ITALY · ·Art. 5, 32 Apr 27, 2023