Skip to content
Content type · 760 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

501–550 of 760 sort newestlargest fineoldest
€2,000 Bitfactor SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Bitfactor SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to a malfunction of an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Sep 22, 2022
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Controllers Right of Access Personal Data Sep 22, 2022
€5,000 Curtea Veche Publishing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Curtea Veche Publishing SRL. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. In the first… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Encryption Integrity and Confidentiality Principle Sep 21, 2022
€2,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Banca Comercială Română SA. The bank had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to an error in the IT… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Processing Agreement Sep 19, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN ·aepd ·Art. 6 Lawful Basis Social Media Personal Data Sep 16, 2022
€2,000 SC Raiffeisen Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on SC Raiffeisen Bank SA. An individual had filed a complaint with the DPA for receiving text messages about money transfers to… ROMANIA ·ANSPDCP ·Art. 5 Insurance Personal Data IP Address Sep 9, 2022
€8,000 Realmedia Network SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Realmedia Network SA EUR 8,000. The company had suffered security breaches on a website it operates. This allowed it to leak and access unauthorized… ROMANIA ·ANSPDCP ·Art. 32 Security Telecommunications Privacy by Design & Default Sep 8, 2022
€405M Meta Platforms, Inc.: Non-compliance with general data processing principles The Irish DPA (DPC) has imposed a fine of EUR 405,000,000 on Meta Platforms, Inc. (Instagram). Following the investigation, the DPC submitted a draft decision under Art. 60 GDPR… IRELAND ·Art. 5, 6, 12 +3 ·Non-compliance with general data processing principles Notified Body Competence Challenges and Dispute Resolution Social Media IP Address Sep 5, 2022
€1,450 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 1,450 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Controllers Supervision Aug 31, 2022
€6,800 TIMSHEL Sp. z o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined TIMSHEL Sp. z o.o. EUR 6,800 for failing to provide information requested by the DPA during an investigation POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Processing Agreement Aug 30, 2022
€1,000 Alpha Bank Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Alpha Bank Romania SA. The bank had accidentally sent a document to the wrong recipient via WhatsApp. The document contained… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Recipient Security IP Address Aug 29, 2022
€20,000 Recover AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined Recover AS EUR 20,000. The controller had carried out a credit check on the data subject without any valid legal basis for doing so. NORWAY ·Datatilsynet ·Art. 6 Controllers Personal Data Processing Agreement Aug 25, 2022
€10,000 Enel Energie Muntenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Enel Energie Muntenia S.A. EUR 10,000. A customer had mistakenly received an email addressed to another customer containing documents with personal data… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default Processing Agreement Aug 22, 2022
€1,000 Wabag Water Services SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on SC Wabag Water Services SRL. An employee of the company had filed a complaint with the DPA due to the fact that their employer… ROMANIA ·ANSPDCP ·Art. 5, 6 Consent Employees Personal Data Aug 9, 2022
€7,000 CDI Transport Intern și Internațional SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 7,000 on CDI Transport Intern și Internațional SRL. During its investigation, the DPA found that the company's website did not provide… ROMANIA ·ANSPDCP ·Art. 12, 58 Personal Data Processing Agreement Supervisory Authorities Aug 9, 2022
€2,000 Sephora Cosmetics România SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Sephora Cosmetics România SA. A data subject had received promotional SMS from Sephora despite having objected several times to… ROMANIA ·ANSPDCP ·Art. 21 Personal Data Direct Marketing Marketing Aug 4, 2022
€30,200 Krokatjønnvegen 15 AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined Krokatjønnvegen 15 AS EUR 30,200. The controller had carried out credit checks on two data subject without any contractual basis for… NORWAY ·Datatilsynet ·Art. 6 Controllers Personal Data Processing Agreement Aug 2, 2022
€600 Private individual: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 600 on a private individual. The individual had failed to implement measures repeatedly ordered by the DPA in due time. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Jul 19, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Lawful Basis Controllers Jul 19, 2022
€202,000 Manx Care Ltd: Non-compliance with general data processing principles The DPA of Isle of Man has imposed a fine of EUR 202,000 on Manx Care Ltd. Manx Care had emailed an unsecured attachment containing a patient's confidential health information to… ISLE OF MAN ·Art. 5, 24, 25 +3 ·Non-compliance with general data processing principles Data Breaches Healthcare IP Address Jul 13, 2022
€4,000 E Software Concept SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on E Software Concept SRL. The company had uploaded certain documents on its website that were publicly accessible. Among other… ROMANIA ·ANSPDCP ·Art. 32, 58 Recipient Security IP Address Jul 7, 2022
Garante per la protezione dei dati personali (Italy) - 9788429 Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Social Media Cookies Legitimate Interest Jul 7, 2022
€2,000 Continental Automotive Romania SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Continental Automotive Romania SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Video Surveillance Security Jun 30, 2022
€3,000 Pediatric psychologist: Insufficient cooperation with supervisory authority The Hellenic DPA has fined a pediatric psychologist EUR 3,000. The psychologist had not properly cooperated with the DPA during an investigation. GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Processing Agreement Jun 29, 2022
Persónuvernd (Iceland) - 2020061979 The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Art. 38, 39 Supervisory Authorities Notified Body Responsibilities and Operational Obligations Scientific Panel Independence Jun 29, 2022
€1,000 SC Interactions Marketing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on SC Interactions Marketing SRL. The controller had sent advertising messages by e-mail to several people on behalf of another… ROMANIA ·ANSPDCP ·Art. 32 IP Address Controllers Direct Marketing Jun 20, 2022
€7,000 Asociația de Proprietari Aviației Park: Insufficient legal basis for data processing The Romanian DPA has fined Asociația de Proprietari Aviației Park, operator of a residential facility, EUR 7,000. The controller had processed personal data (surname, first name,… ROMANIA ·ANSPDCP ·Art. 5, 6 Retention Period Storage Limitation Video Surveillance Jun 20, 2022
€3,000 S.C. Wine Point S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on S.C. Wine Point S.R.L.. A data subject had filed a complaint with the DPA for having received an advertising e-mail from the… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Professional Secrecy Security Jun 15, 2022
Austrian DPA: Court's publication of full divorce settlement in land register violates The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·DSB Controllers Material scope (GDPR) Integrity and Confidentiality Principle Jun 9, 2022
€1,500 Wens Experience SRL: Insufficient data processing agreement The Romanian DPA has imposed a fine of EUR 1,500 on Wens Experience SRL. In the course of its investigation, the DPA found that Wens Experience, in the course of acting as a… ROMANIA ·ANSPDCP ·Art. 28 Controllers Processors Processing Agreement Jun 8, 2022
€2,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland România SCS. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. An employee who… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jun 3, 2022
€50 APD/GBA (Belgium) - 85/2022 On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Art. 4, 5, 6 +3 Cookies Telecommunications Direct Marketing May 25, 2022
€5,000 MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on MED LIFE S.A.. The company had disposed of documents containing sensitive patient data in a publicly accessible garbage can. An… ROMANIA ·ANSPDCP ·Art. 32 Health Data Healthcare Security May 24, 2022
€5,000 Kredyt Inkaso Investments RO S.A: Insufficient legal basis for data processing The Romanian DPA has fined Kredyt Inkaso Investments RO S.A. EUR 5,000. A data subject had filed a complaint with the DPA against the controller for having disclosed their… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +1 Data Breaches Personal Data Insurance May 18, 2022
€18,000 RAMONA FILMS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) has fined RAMONA FILMS, S.L. for failing to provide information requested by the DPA during an investigation. The original fine of EUR 30,000 was reduced to… SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Law Enforcement May 17, 2022
€1,500 MAYR MELNHOF PACKAGING ROMANIA S.R.L.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,500 on MAYR MELNHOF PACKAGING ROMANIA S.R.L.. The controller had installed video surveillance cameras in the premises for the purpose… ANSPDCP ·Art. 5, 6 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address May 17, 2022
€14,500 Arbeidstilsynet: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined the Norwegian Labor Inspectorate 'Arbeidstilsynet' EUR 14,500. The controller had carried out a credit check on the data subject without… NORWAY ·Datatilsynet ·Art. 6 Education Public Authority Controllers May 16, 2022
€1,000 LORIS FUEL SHOP SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on the gas station operator LORIS FUEL SHOP SRL. A person had filed a complaint with the DPA because pictures of him were… ROMANIA ·ANSPDCP ·Art. 29, 32 Video Surveillance Integrity and Confidentiality Principle Security May 12, 2022
€4,000 Concordia Capital IFN S.A.: Insufficient legal basis for data processing The Romanian DPA has fined Concordia Capital IFN S.A. EUR 4,000. The controller had unlawfully installed audio and video cameras in the offices of its employees. The video… ROMANIA ·ANSPDCP ·Art. 5, 6 Video Surveillance Monitoring Insurance May 4, 2022
€4,000 Megareduceri TV S.R.L.: Insufficient cooperation with supervisory authority Failure to provide requested information to the Romanian DPA within the required timeframe in violation of Art. 58 GDPR. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Agreement May 3, 2022
€8,300 Telemarketing company: Insufficient cooperation with supervisory authority The Finnish DPA has imposed a fine of EUR 8,300 on a telemarketing company for non-compliance with a DPA order. A customer of the company had requested access to the recording of… FINLAND ·Deputy Data Protection Ombudsman ·Art. 58 Supervisory Authorities Supervision Direct Marketing Apr 29, 2022
€600 DOOR2DOOR SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine on DOOR2DOOR SPAIN, S.L.. The controller had failed to implement measures repeatedly ordered by the DPA in due time. Also, the controller had… aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Law Enforcement Apr 19, 2022
€1,800 FLORAQUEEN FLOWERING THE WORLD S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined FLORAQUEEN FLOWERING THE WORLD S.L. for failing to provide information requested by the DPA during an investigation. The original fine of EUR 3,000 was… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Apr 18, 2022
€1,000 IKEA România S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on IKEA România S.R.L.. A data subject had complained to the DPA that IKEA had failed to comply with their requests to delete the… ROMANIA ·ANSPDCP ·Art. 12 Personal Data Processing Agreement Processing Apr 18, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Security Storage Limitation Apr 7, 2022
€500 Property owners' association: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined a property owners' association EUR 500 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Apr 7, 2022
€2,000 Condor SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Mar 28, 2022
€2,000 Kaufland Romania SCS: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland Romania SCS. A data subject had filed a complaint with the DPA concerning the controller's failure to comply with… ANSPDCP ·Art. 15 ·Insufficient fulfilment of data subjects rights Video Surveillance Monitoring Personal Data Mar 25, 2022
€490 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 490 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Mar 23, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… Art. 5, 24 Social Media Processing Agreement Security Mar 15, 2022