Skip to content
Content type · 1,013 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–500 of 1,013 sort newestlargest fineoldest
€2,000 IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 8, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·AEPD ·Art. 32, 33 Data Breaches Security Personal Data May 8, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… AEPD ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data May 7, 2024
€8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers IP Address Apr 30, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Security Encryption Privacy by Design & Default Apr 29, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Apr 23, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·AEPD ·Art. 6 Consent Personal Data Security Apr 12, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Insurance Apr 12, 2024
€25,000 Innova Camara: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 25,000 on Innova Camara. The controller had suffered a cyber attack in which databases were accessed and malicious files (backdoors) were… ITALY ·Garante ·Art. 5 Security Controllers Personal Data Apr 11, 2024
€20,000 Istituto Nazionale di Previdenza Sociale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Italian National Institute of Social Security (INPS). The controller had published personal data of participants in a… ITALY ·Garante ·Art. 2, 5, 6 Controllers Personal Data Security Apr 11, 2024
€175,000 Greek Ministry of Immigration and Asylum: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 175,000 on the Greek Ministry of Immigration and Asylum. The DPA found that the controller had failed to properly carry out a required… GREECE ·HDPA ·Art. 25, 31, 35 DPIA Controllers Security Apr 2, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Mar 21, 2024
Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by… 2021-0518 ·European Union ·Art. 5, 6, 28 +1 International Transfer Controllers Processors Mar 8, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 5, 2024
€3M Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ): Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 2,995,140 on the Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ). The controller had suffered a data breach which resulted in… GREECE ·HDPA ·Art. 5, 32 Security Controllers Personal Data Feb 28, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 26, 2024
€365,000 CTC EXTERNALIZACIÓN, S.L: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested… SPAIN ·AEPD ·Art. 13, 32, 35 Controllers DPIA Supervisory Authorities Feb 12, 2024
€79M Enel Energia SpA: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by… Garante Security Supervisory Authorities Human Resources Feb 8, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY ·Garante ·Art. 5, 32 Security Controllers Identification Feb 8, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Security Personal Data Healthcare Feb 8, 2024
€3M IBERDROLA, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although… SPAIN ·AEPD ·Art. 5, 32 Security Processing Law Enforcement Feb 7, 2024
€3.5M I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3.5 million on I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U. The controller had suffered a cyber attack on its GEA web application resulting… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Feb 5, 2024
€5,000 Dentist: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5,000 on a dentist due to a lack of data security and a failure to respect the right of access of a data subject. FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Inspection Access Rights and Cooperation Obligations Jan 31, 2024
€10,000 FRANCE DPA: €10,000 fine The French DPA has imposed a fine of EUR 10,000 on a data controller due to data security vulnerabilities. CNIL ·Unknown Supervisory Authorities Controllers Security Jan 31, 2024
€20,000 Website editor: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a website editor for data security vulnerabilities. FRANCE ·CNIL ·Unknown Supervisory Authorities Security Jan 31, 2024
€20,000 Pharmaceutical wholesaler: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a pharmaceutical wholesaler due to violations of several regulations, including a lack of data security and insufficient… FRANCE ·CNIL ·Unknown Controllers Accountability Processors Jan 24, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Encryption Healthcare Controllers Jan 17, 2024
€3,000 TECHNINK LEB SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on TECHNINK LEB SRL. The controller had suffered a data breach in which personal customer data had been unlawfully disclosed.… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jan 15, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS ·AP ·Art. 35 DPIA Personal Data Security Jan 15, 2024
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine on a company due to technical security vulnerabilities in its support ticket systems. GERMANY ·HmbBfDI ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Jan 1, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2024
€11,500 Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg imposed a fine of EUR 11,500 on a company operating in the advertising industry for failing to comply with its deletion obligations. In addition, it was found… GERMANY ·HmbBfDI ·Insufficient technical and organisational measures to ensure information security Security Direct Marketing Supervisory Authorities Jan 1, 2024
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine on a company due to technical security vulnerabilities in its support ticket systems. GERMANY ·HmbBfDI ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Jan 1, 2024
€2,500 Doctor´s Office: Insufficient technical and organisational measures to ensure information security The DPA of Hessen has imposed a fine of EUR 2,500 on a doctor´s office. The controller hired an office manager who worked partly from home. The manager worked with patient files,… GERMANY ·Art. 5, 6, 9 +1 ·Insufficient technical and organisational measures to ensure information security Controllers Security Healthcare Jan 1, 2024
€32,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 32,000 on a logistics company for incorrectly disposing of delivery lists. GERMANY ·HmbBfDI ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Jan 1, 2024
€6.5M THE PHONE HOUSE SPAIN, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6.5 million on THE PHONE HOUSE SPAIN, S.L. The controller had suffered a ransomware attack affecting personal data of 13 million… AEPD ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Dec 27, 2023
Municipality: Non-compliance with general data processing principles Fine against municipality for lack of security measures (insufficient passwords) FRANCE ·CNIL ·Non-compliance with general data processing principles Public Authority Security Processing Dec 22, 2023
€23,000 Polish Minister of Health: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 23,000 on the Polish Minister of Health. The controller had accessed information via a database relating to a physician who had prescribed… POLAND ·UODO ·Art. 25, 32, 34 Controllers Security Personal Data Dec 20, 2023
€400,000 UK Ministry of Defense: Insufficient technical and organisational measures to ensure information security The UK DPA has fined the Ministry of Defense EUR 400,000 for disclosing personal data of individuals who were to be relocated to the UK after the Taliban took control of… UNITED KINGDOM ·ICO ·Insufficient technical and organisational measures to ensure information security Personal Data Public Authority Human Resources Dec 13, 2023
€3,000 Veranda Obor S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Veranda Obor S.A.. The controller had disclosed personal data (e.g. name, e-mail adress etc.) of lottery participants on its… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Controllers Dec 11, 2023
€24,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 24,000 on Hora Credit IFN SA. The controller had accidentally sent documents containing the personal data of another person to a customer by… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Personal Data Controllers Security Dec 7, 2023
€1,000 Techno Security s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Techno Security s.r.l.. A data subject had filed a complaint with the DPA due to the controller's failure to respond to a… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 30, 2023
€26,500 Östersund Municipality's Department for Children and Education: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 26,500 on the Östersund Municipality's Department for Children and Education. The authority had failed to carry out a data protection… SWEDEN ·Art. 35 ·Insufficient technical and organisational measures to ensure information security DPIA Supervisory Authorities Security Nov 28, 2023
€1.7M Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 1.7 million on Arbeids- og velferdsetaten, the Norwegian Labor and Welfare Administration (NAV). During its investigation, the DPA… NORWAY ·Datatilsynet (NO) ·Art. 5, 24, 25 +1 Security Privacy by Design & Default Right of Access Nov 27, 2023
€45,000 Open University of Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 45,000 on Open University of Cyprus. The university had suffered a data breach involving hackers publishing personal data of students,… Cyprus DPA ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Data Breaches Nov 22, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Controllers Nov 13, 2023
€43,000 Indcap AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 43,000 on Indecap AB. The controller had accidentally sent an email to a large number of its customers containing an Excel document… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 7, 2023
€2,000 SINDICATO LIBRE DE TRANSPORTES: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on SINDICATO LIBRE DE TRANSPORTES. A member of the union had shared the data subject's payslip in a WhatsApp group without the data subject's… SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Supervisory Authorities Nov 3, 2023