Skip to content
Content type · 760 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–500 of 760 sort newestlargest fineoldest
€5,000 Tehnoplus Industry SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 5,000 on Tehnoplus Industry SRL. An employee of the company had filed a complaint with the DPA because the controller had installed a… ROMANIA ·ANSPDCP ·Art. 5, 6 Audit Logs IP Address Controllers Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Recipient Healthcare Health Data Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Healthcare Healthcare Recipient Mar 16, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Encryption Data Breaches Security Mar 15, 2023
€10,000 Alianța pentru Unirea Românilor: Non-compliance with general data processing principles The Romanian DPA imposed a fine of EUR 10,000 on Alianța pentru Unirea Românilor. During its investigation, the DPA found that the controller collected personal data on its… ROMANIA ·ANSPDCP ·Art. 5 Personal Data Controllers IP Address Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Right of Access Mar 14, 2023
€2,000 Modaone SRL: Insufficient fulfilment of information obligations The Romanian DPA has imposed a fine of EUR 2,000 on Modaone SRL. An individual had filed a complaint with the DPA for having received advertising messages by e-mail, although they… ROMANIA ·ANSPDCP ·Art. 12, 13 Personal Data Controllers Direct Marketing Mar 13, 2023
€220,000 Argon Medical Devices: Insufficient fulfilment of data breach notification obligations The Norwegian DPA has fined Argon Medical Devices EUR 220,000. The controller failed to notify the DPA of a data breach that involved personal data of all its European employees… NORWAY ·Datatilsynet ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Mar 8, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Privacy by Design & Default Mar 6, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Privacy by Design & Default Mar 6, 2023
€440,000 Suomen Asiakastieto Oy: Insufficient cooperation with supervisory authority The Finnish DPA has imposed a fine of EUR 440,000 on Suomen Asiakastieto Oy for failing to comply with an order issued by the DPA. During an investigation, the DPA found that the… FINLAND ·Deputy Data Protection Ombudsman ·Art. 58 Supervisory Authorities Supervision Processing Agreement Feb 17, 2023
€5,000 Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Medijobs Platform SRL. The controller had informed the DPA about a data breach according to Art. 33 GDPR. Unauthorized third… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 8, 2023
€900,000 Sats ASA: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 900,000 on the fitness chain 'Sats'. The DPA had received several complaints from customers who had submitted requests for information… NORWAY ·Datatilsynet ·Art. 5, 6, 12 +3 Personal Data Processing Agreement Supervisory Authorities Feb 6, 2023
€1,000 Tensa Art Design SA: Insufficient fulfilment of data subjects rights The Romanian data protection authority (AEPD) has imposed a fine of EUR 1,000 on Tensa Art Design SA. A data subject had objected to a further newsletter subscription and however… ROMANIA ·ANSPDCP ·Art. 21 Personal Data Controllers IP Address Feb 1, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Health Data Healthcare Jan 31, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA ·ANSPDCP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 31, 2023
€4,100 Company: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 4,100 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Jan 25, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Security Education Jan 19, 2023
€5.5M WhatsApp Ireland Ltd.: Insufficient legal basis for data processing The Irish DPA (DPC) has fined WhatsApp Ireland Ltd. EUR 5.5 million. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of an… Art. 6, 12, 13 ·Insufficient legal basis for data processing Fairness & Transparency Notified Body Competence Challenges and Dispute Resolution Processing Agreement Jan 19, 2023
€1,000 Dante Internațional SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dante Internațional SA. A data subject had filed a complaint with the DPA against the controller due to the fact that the… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Controllers Processing Agreement Jan 18, 2023
€50,000 DPC (Ireland) - 05/SIU/2018 This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Video Surveillance Legitimate Interest Monitoring Jan 16, 2023
€50,000 Intellexa SA: Insufficient cooperation with supervisory authority The Hellenic DPA has fined Intellexa SA EUR 50,000. The controller had not properly cooperated with the DPA during an investigation. GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Controllers Jan 13, 2023
€1,000 EDITORIAL RIBADEO S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on EDITORIAL RIBADEO S.L. for failing to comply with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Jan 13, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€3,000 Apă Canal Ilfov SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Apă Canal Ilfov SA. The controller sent an e-mail with personal data to several recipients in an open distribution list. This… ROMANIA ·ANSPDCP ·Art. 32 IP Address Controllers Personal Data Jan 4, 2023
€390M Meta Platforms Ireland Limited: Non-compliance with general data processing principles The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook… Social Media Notified Body Competence Challenges and Dispute Resolution Fairness & Transparency Jan 4, 2023
€500 Homeowners Association: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 500 on a homeowners' association. The controller had publicly posted a list with the first and last names of all members of the… ROMANIA ·ANSPDCP ·Art. 5 Controllers IP Address Personal Data Jan 3, 2023
€5,000 Company: Insufficient cooperation with supervisory authority Fine of EUR 5,000 for failing to sufficiently cooperate with the DPA. GERMANY ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Jan 1, 2023
€6,300 Company: Insufficient cooperation with supervisory authority The Polish DPA has fined a company EUR 6,300 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Personal Data Dec 30, 2022
€3M CNIL fines VOODOO for cookie and tracker consent failures in mobile games VOODOO ('provider') was a mobile game developer. The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of… France ·Art. 4, 5, 82 Cookies Telecommunications Direct Marketing Dec 29, 2022
€3,000 ADENET SYSTEMS, S.L.: Insufficient cooperation with supervisory authority Failure to provide requested information to the Spanish DPA (AEPD) within the required timeframe in violation of Art. 58 GDPR. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 29, 2022
€3,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The controller had reported a data breach to the DPA according to Art. 33 GDPR. An employee had taken… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Video Surveillance Security Dec 27, 2022
€10,000 SUDREZIDENȚIAL Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on SUDREZIDENȚIAL Broker S.R.L.. An employee of the controller had unauthorizedly published an Excel spreadsheet containing… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Insurance Dec 22, 2022
€5,000 Societatea Energetică Electrica S.A.: Insufficient data processing agreement The Romanian DPA has fined Societatea Energetică Electrica S.A. EUR 5,000 for a violation of Art. 28 (3) a) GDPR. ROMANIA ·ANSPDCP ·Art. 28 Processing Agreement Data Processor Processing Dec 15, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Dec 9, 2022
€1,800 ALPA 57 PRODUCCIONES, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) has fined ALPA 57 PRODUCCIONES, S.L. for failing to provide information requested by the DPA during an investigation. The original fine of EUR 3,000 was… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Nov 25, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Right of Access Nov 25, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Healthcare Recipient Nov 24, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Nov 21, 2022
€300 Homeowners Association Bld. Pipera 1-2E: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined Homeowners Association 'Bld. Pipera 1-2E' EUR 300 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision IP Address Nov 18, 2022
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Nov 16, 2022
€1,000 SC Das Sense Society SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Das Sense Society SRL EUR 1,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Nov 9, 2022
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide access to information about the purpose of the processing, the storage period, the… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Controllers Data Controller Nov 9, 2022
€5,000 SC Prestige Media PHG SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on SC Prestige Media PHG SRL. The controller had published 23 documents containing information on the termination of employment… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers IP Address Personal Data Nov 8, 2022
€2,000 Romanian Post: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on the Romanian Post. The Post suffered a data breach where staff lost several mailings containing pension statements, employment… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Nov 7, 2022
€150 Private individual: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 150 on a private individual. The individual had made unauthorized use of another person's personal data without their consent. ROMANIA ·ANSPDCP ·Art. 6 Personal Data Consent Processing Oct 18, 2022
€2,000 SC Materiale Constructii Online SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Materiale Constructii Online SRL EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 18, 2022
€150 Website operator: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 150 on a website operator. The controller had published unauthorized personal data such as telephone number, ID number and series,… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data IP Address Controllers Oct 3, 2022
Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Art. 28, 36, 58 DPIA Privacy Impact Assessment Controllers Sep 28, 2022
Datatilsynet (Denmark) - 2020-422-0026 The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Art. 5 Processors Controllers Processing Sep 28, 2022