Skip to content
Content type · 482 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–482 of 482 sort newestlargest fineoldest
€44,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The company had sent a contract with personal data, including the applicant's name, address and telephone number, to the wrong recipient. SPAIN ·AEPD ·Art. 5 Personal Data Processing Recipient Jan 7, 2020
€3,850 Television broadcaster: Insufficient fulfilment of information obligations A TV broadcaster had provided information on its website about the processing of personal data, which was however hidden and inaccurate (links to outdated legal provisions). CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Telecommunications Processing Jan 1, 2020
€2,700 Mall.tv: Insufficient legal basis for data processing The Czech DPA (UOOU) fined Mall.tv EUR 2,700 for recording parts of the public space without a legal basis. The subject of the DPA's investigation was the operation of two cameras… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6 Identification Processing Telecommunications Jan 1, 2020
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Telecommunications Dec 18, 2019
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM ·APD/GBA ·Art. 6, 12, 13 Personal Data Fairness & Transparency IP Address Dec 17, 2019
€10,000 Rapidata GmbH: Insufficient involvement of data protection officer Despite repeated requests of the BfDI the company (an internet provider) did not comply with its legal obligation under Article 37 GDPR to appoint a data protection officer. GERMANY ·BfDI ·Art. 37 Supervisory Authorities Telecommunications Dec 9, 2019
€60,000 Corporación radiotelevisión espanola: Insufficient technical and organisational measures to ensure information security CORPORACIÓN RADIOTELEVISIÓN ESPAÑOLA and the trade union have reported a security breach to the AEPD after six unencrypted USB sticks containing personal data were lost. The… SPAIN ·AEPD ·Art. 32 Encryption Security Personal Data Nov 19, 2019
€60,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security An individual complainant had received an SMS from Xfera Móviles which was to be addressed to a third party and which allowed him to access the account and personal data of this… SPAIN ·AEPD ·Art. 32 Personal Data Security Telecommunications Nov 19, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN ·AEPD ·Art. 5 Accountability Processing Telecommunications Nov 14, 2019
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone has sent the customer's invoice data to unauthorised third parties following a customer invoice complaint. Originally, a fine of EUR 75,000 was threatened, but was… SPAIN ·AEPD ·Art. 6 Telecommunications Processing Supervisory Authorities Nov 6, 2019
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The claimant, whose data had been provided to the company by his daughter, as authorised by him, received a call from the company offering its services, which he refused. However,… SPAIN ·AEPD ·Art. 5, 6 Consent Personal Data Processing Oct 25, 2019
€60,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles Vodafone sent an invoice history to the subscriber as part of the invoice complaint by the subscriber. The history also contained invoice data of an unknown third party. SPAIN ·AEPD ·Art. 5 Processing Telecommunications Supervisory Authorities Oct 23, 2019
€20,000 Wind Hellas Telecommunications: Insufficient fulfilment of data subjects rights Among other things, the company has ignored objections raised by affected parties against advertising calls. GREECE ·HDPA ·Art. 21 Right to Object Direct Marketing Personal Data Oct 18, 2019
€60,000 Xfera Moviles S.A.: Insufficient legal basis for data processing Xfera Movile has used personal data without a legal basis for the conclusion of a telephone contract and has continued to process personal data even when the data subject… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Oct 16, 2019
€200,000 Telecommunication Service Provider: Non-compliance with general data processing principles A large number of customers were subject to telemarketing calls, although they had declared an opt-out for this. This was ignored due to technical errors. GREECE ·HDPA ·Art. 5, 25 Processing Direct Marketing Telecommunications Oct 7, 2019
€200,000 Telecommunication Service Provider: Non-compliance with general data processing principles Inappropriate technical measures resulted in the data of 8,000 customers not being deleted upon request. GREECE ·HDPA ·Art. 21, 25 Privacy by Design & Default Processing Telecommunications Oct 7, 2019
€9,000 Inteligo Media SA: Insufficient legal basis for data processing As part of the registration process on the webseite avocatnet.ro, the operator used an unfilled checkbox, by means of which users could declare that they did not wish to receive… ROMANIA ·ANSPDCP ·Art. 5, 6 Consent Personal Data Processing Sep 26, 2019
€11,760 Commercial representative of telecommunication service provider: Insufficient legal basis for data processing The pecuniary sanction of EUR 11, 760 was imposed on the commercial representative of telecommunications service provider for unlawful processing of the personal data of a data… BULGARIA ·CPDP ·Art. 6 Personal Data Representatives Integrity and Confidentiality Principle Sep 3, 2019
€1,022 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·CPDP ·Art. 6, 25 Personal Data Consent Integrity and Confidentiality Principle Sep 3, 2019
€5,113 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·CPDP ·Art. 6, 25 Personal Data Consent Integrity and Confidentiality Principle Sep 3, 2019
€92,146 Organizer of SZIGET festival and VOLT festival: Insufficient legal basis for data processing The NAIH found that there were inappropriate legal bases is use and that the controller did not comply with the principle of purpose limitation. Also, information on the data… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Processing May 23, 2019
€27,100 Telecommunication service provider: Insufficient legal basis for data processing Repeated registration of prepaid services without the knowledge and consent of the data subject Employees of the telecommunications provider have used personal data and registered… BULGARIA ·CPDP ·Art. 5, 6 Personal Data Consent Identification Feb 26, 2019
€50M Google LLC: Insufficient legal basis for data processing The fine was imposed on the basis of complaints from the Austrian organisation 'None Of Your Business' and the French NGO 'La Quadrature du Net'. The complaints were filed on 25th… FRANCE ·CNIL ·Art. 5, 6, 13 +1 Transparency Fairness & Transparency Consent Jan 21, 2019
€51,000 Facebook Germany GmbH: Insufficient involvement of data protection officer Whereas Facebook Ireland had appointed a data proteciton officer for all group companies located in the EU, this appontment was not notfied to the DPA Hamburg, competent for… HmbBfDI ·Art. 37 ·Insufficient involvement of data protection officer Supervisory Authorities Social Media Notified Body Reporting and Notification Obligations Jan 1, 2019
€40,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The company had charged a Netflix service that had not been solicited by the claimant. The claimant could prove that the service had been used by another household which allegedly… SPAIN ·AEPD ·Art. 6 Consent Telecommunications Processing Jan 1, 2019
€10,000 Newspaper: Insufficient legal basis for data processing The publication of the newspaper, both in hard copy and in electronic form, allegedly involved inconvenience, unnecessary and unlawful detention of a citizen, and revealed the… CYPRUS ·Cyprus DPA ·Art. 6 Telecommunications Processing Law Enforcement Jan 1, 2019
€48,000 VODAFONE ONO, S.A.U.: Insufficient technical and organisational measures to ensure information security Customers could access personal data of other customers in the customer area. The initial fine of EUR 60.000 was reduced to EUR 48.000. SPAIN ·AEPD ·Art. 32 Security Personal Data Telecommunications Jan 1, 2019
€21,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone had processed personal data of the claimant (bank details, name, surname and national identification number) years after the contractual relationsid had ended. The fine… SPAIN ·AEPD ·Art. 6 Personal Data Telecommunications Identification Jan 1, 2019
€36,000 VODAFONE ONO, S.A.U.: Non-compliance with general data processing principles The company sent a marketing email to a large number of recipients (clients) without using the blind copy feature. The initial fine of EUR 60.000 was reduced to EUR 36.000. SPAIN ·AEPD ·Art. 5 Processing Direct Marketing Telecommunications Jan 1, 2019
€30,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security Disclosure of customer personal data (i.a. purchase history) via an SMS to another customer. The initial fine of EUR 50.000 was reduced to EUR 30.000. SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Telecommunications Jan 1, 2019
€48,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The claimant's bank account was charged by the company with two invoices for the services he had contracted, however, displaying personal data of another customer. The initial… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications Jan 1, 2019
€20,000 Knuddels.de: Insufficient technical and organisational measures to ensure information security After a hacker attack in July personal data of approx. 330.000 users, including passwords and email addresses had been revealed. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Nov 21, 2018