Skip to content
Content type · 568 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

501–550 of 568 sort newestlargest fineoldest
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·IMY ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Encryption Personal Data Jun 7, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jun 7, 2021
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Retention Period Personal Data May 13, 2021
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Persónuvernd ·Art. 32 Data Breaches Security Controllers Apr 29, 2021
€50,000 Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Equifax Iberica S.L. EUR 50,000 for a violation of Art. 6 (1) f) GDPR. The controller had added the data subject to a debtor register without… SPAIN ·AEPD ·Art. 6 Legitimate Interest Personal Data Controllers Mar 10, 2021
Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Encryption Controllers Processing Mar 3, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Cyprus DPA ·Art. 12, 15, 31 +1 Right of Access Personal Data Supervisory Authorities Mar 3, 2021
Deutsche Wohnen SE: Non-compliance with general data processing principles Originally, a fine in the amount of EUR 14.500.000 was issued against Deutsche Wohnen SE for using an archiving system for the storage of personal data of tenants that, according… GERMANY ·Art. 5, 25 ·Non-compliance with general data processing principles Controllers Personal Data Processing Feb 23, 2021
€1,200 Individual: Non-compliance with general data processing principles The controller installed cameras on his building, which were directed towards parts of the public space. However, no recording took place, as the cameras only served as a… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Jan 20, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent unsolicited commercial communications to the complainant and failed to respond to their repeated… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jan 19, 2021
Police officer: Insufficient legal basis for data processing A police officer used a witness's personal data to contact her personally. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer accused in a criminal case intended to use the information from the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
€400 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes. The officer had purchased a notebook for private use on an Internet platform. Since the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Scientific Research Jan 1, 2021
€16,000 Electronics store: Non-compliance with general data processing principles The DPA from Lower Saxony has imposed a fine of EUR 16,000 on an electronics store. The company had installed a video surveillance system which permanently recorded employees,… GERMANY ·Art. 5, 17, 35 ·Non-compliance with general data processing principles Retention Period DPIA Monitoring Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried his stepson's investigative process in order to prepare him for… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer repeatedly had accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Public Authority Personal Data Supervisory Authorities Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried the investigation process of a friend against the background of a… GERMANY ·Insufficient legal basis for data processing Public Authority Scientific Research Human Resources Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully accessed data in a police database. For this reason, the DPA of Brandenburg imposed a fine for a violation of § 32 (1) BbgDSG. The Brandenburg Data… GERMANY ·Insufficient legal basis for data processing Public Authority Supervisory Authorities Processing Jan 1, 2021
€1,800 Police officer: Insufficient legal basis for data processing A police officer repeatedly had accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
€600 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes in order to obtain information about his ex-wife's new address. He discovered where his… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives Personal Data Supervision Dec 20, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Dec 17, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·IMY ·Art. 5, 32 Security Encryption Controllers Dec 11, 2020
€2,850 Smart Cities Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the Polish DPA (UODO). The controller failed to provide personal data and other information requested by UODO for investigative… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Dec 9, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of Eur 2,000 on a legal person. The accused failed to comply with the request to erase the auction notice with the personal data and failed to… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Nov 30, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Healthcare Nov 19, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY ·Garante ·Art. 5, 6, 7 +7 Direct Marketing Accountability Personal Data Nov 12, 2020
€200 Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Encryption Controllers Processing Oct 24, 2020
€5,000 Caja Rural San José de Nules S. Cooperativa de Crédito: Non-compliance with general data processing principles The company published information with the names and surnames of its employees, which led to the disclosure of the data subject's financial situation. SPAIN ·AEPD ·Art. 5 Personal Data Processing Employees Oct 9, 2020
Datatilsynet (Norway)- 20/02254 The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Datatilsynet (NO) ·Art. 57, 58 Telecommunications Supervision Supervisory Authorities Sep 7, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The complainant, through her attorney, requested access to her personal data. The accused failed to respond, even… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Insurance Aug 31, 2020
€48 Police Officer: Insufficient legal basis for data processing Acess to personal data in a police database for private research activities. ESTONIA ·AKI ·Art. 5, 6 Personal Data Processing Scientific Research Aug 17, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide evidence that the data subject had consented to the scanning or copying of their ID card… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 7 +3 Personal Data Identification Consent Jul 14, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Jul 9, 2020
€6,000 National Police Brigade: Insufficient legal basis for data processing Making copies of a company's business records in the context of investigations which contained data from third parties and for which there was no legal basis for processing. SPAIN ·AEPD ·Art. 5, 6 Processing Public Authority Supervisory Authorities Jun 19, 2020
€4,010 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 4,010 on a legal person. The order was issued based on the carried out inspection. The accused failed to respond to numerous requests to… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Jun 11, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Jun 11, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM ·APD/GBA ·Art. 31, 37, 58 Supervisory Authorities Data Breaches Personal Data Apr 28, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Privacy by Design & Default Apr 23, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 18, 2020
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine was preceded by a complaint from the data subject, who argued that he had received an e-mail from Vodafone España, which contained the billing of a telephone line that… SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Feb 3, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Cyprus DPA ·Art. 32 Right of Access Personal Data Security Jan 13, 2020
€400 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
€300 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·HmbBfDI ·Art. 26 Personal Data Processing Agreement Processors Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·HmbBfDI ·Art. 6, 32 Security Personal Data Privacy by Design & Default Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020