Skip to content
Content type · 1,013 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

551–600 of 1,013 sort newestlargest fineoldest
€12,000 ALBERO FORTE COMPOSITE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on ALBERO FORTE COMPOSITE, S.L.. The company had taken pictures of employees at the entrance for the purpose of recording their working… SPAIN ·AEPD ·Art. 35 DPIA Security Supervisory Authorities Apr 28, 2023
€240,000 Benetton Group S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 240,000 on Benetton Group S.r.l.. The controller had stored a large amount of customer data indefinitely. The DPA also found that the… ITALY ·Garante ·Art. 5, 32 Security Controllers Personal Data Apr 27, 2023
€17,600 Skåne region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has fined Skåne region EUR 17,600. An employee of the region had lost an unencrypted USB stick containing the social security numbers and sensitive personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Encryption Personal Data Apr 26, 2023
€5,400 Disciplinary officer: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 5,400 on a disciplinary officer of the Polish Bar Association after an unencrypted USB stick containing personal data was lost. POLAND ·UODO ·Art. 5, 25, 32 Encryption Security Personal Data Apr 20, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Retention Period Storage Limitation Security Apr 20, 2023
€237,800 Green Network S.p.A.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 237,800 against Green Network S.p.A.. The DPA had received several complaints from data subjects regarding unauthorized telemarketing.… ITALY ·Garante ·Art. 5, 25 Privacy by Design & Default Security Controllers Apr 14, 2023
€676,956 Sorgenia S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 676,956 against Sorgenia S.p.a.. The DPA had received several complaints from data subjects regarding unauthorized telemarketing. During… ITALY ·Garante ·Art. 5, 12, 25 Privacy by Design & Default Security Controllers Apr 14, 2023
€3,000 REGENCY COMPANY SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on REGENCY COMPANY SRL. The controller had installed video surveillance cameras in its premises for the purpose of monitoring… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Consent Processing Apr 7, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 9, 32 Security Personal Data Healthcare Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Integrity and Confidentiality Principle Data Breaches Processors Mar 23, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Security Data Breaches Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€145,000 AFIANZA ASESORES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 145,000 on AFIANZA ASESORES S.L.. The controller had reported a data breach to the DPA, stating that a backpack containing a USB stick… SPAIN ·AEPD ·Art. 5, 32 Encryption Security Controllers Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€100,000 ORANGE ESPAGNE S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 100,000 on ORANGE ESPAGNE S.A.U.. A customer who had purchased a cell phone from ORANGE had filed a complaint with the DPA. As a… SPAIN ·AEPD ·Art. 5 Personal Data Security Processing Mar 16, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Security Encryption Right of Access Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 14, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€1,800 WUNSCHURLAUB S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined WUNSCHURLAUB S.L. for storing passwords in plain text on its website www.meine-auszeit-jetzt.de. The DPA considered this to be a violation of Art. 32… SPAIN ·AEPD ·Art. 32 Security Supervisory Authorities Feb 28, 2023
€750,000 Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Data Breaches Feb 27, 2023
€7,200 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,200 on a company. The controller had suffered a data breach that resulted in the loss of personal data. During its investigation, the… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Privacy by Design & Default Controllers Feb 8, 2023
€5,000 Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Medijobs Platform SRL. The controller had informed the DPA about a data breach according to Art. 33 GDPR. Unauthorized third… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 8, 2023
€3,250 Epic Ltd.: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 3,250 on Epic Ltd. The contoller had made unsolicited calls to 332 former customers without a valid legal basis. The DPA also found that… CYPRUS ·Cyprus DPA ·Art. 6, 24, 32 Controllers Security Processing Feb 3, 2023
€5,000 Azienda ULSS n.5 Polesana: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 5,000 on Azienda ULSS n.5 Polesana. The healthcare facility had mistakenly sent a patient medical record to the wrong patient. The DPA… ITALY ·Garante ·Art. 5, 9, 32 Security Healthcare Personal Data Jan 26, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 32, 75 Security Personal Data Controllers Jan 26, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·DPC ·Art. 5, 32 Security Controllers Personal Data Jan 23, 2023
€6,400 Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,400 on the Szczecin-Centrum District Court. The court had reported a data breach to the DPA involving the loss of three data carriers.… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Privacy by Design & Default Security Jan 19, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS ·AP ·Art. 32 Security Controllers Personal Data Jan 19, 2023
€1,020 Telecommunications Operator: Non-compliance with general data processing principles The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient technical and organisational measures to ensure… BULGARIA ·CPDP ·Art. 5, 6 Security Controllers Telecommunications Jan 17, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·IMY ·Art. 32 Security Personal Data Privacy by Design & Default Jan 17, 2023
€50,000 DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Legitimate Interest Controllers Personal Data Jan 16, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€3,000 Apă Canal Ilfov SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Apă Canal Ilfov SA. The controller sent an e-mail with personal data to several recipients in an open distribution list. This… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Controllers Security Jan 4, 2023
€3,000 Transport Workers' Union of Aragon: Non-compliance with general data processing principles The Spanish DPA has fined the Transport Workers' Union of Aragon EUR 3,000. The union had published a document with personal data (surname, first name and identity card number) of… SPAIN ·AEPD ·Art. 5, 32 Security Personal Data Processing Jan 3, 2023
€3,600 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records containing patient data in a public waste disposal site. GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Jan 1, 2023
Daycare center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a four-figure fine on a daycare center that had disposed of documents containing personal data of children and their parents in a publicly… GERMANY ·HmbBfDI ·Art. 32 Security Personal Data Education Jan 1, 2023
€75,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg imposed a fine of EUR 75,000 on a company. An employee had lodged a complaint with the DPA due to the fact that they had to report their sickness-related… GERMANY ·HmbBfDI ·Art. 9, 32 Security Recipient Employees Jan 1, 2023
Operator of a dating platform: Insufficient technical and organisational measures to ensure information security The DPA of Bremen has imposed a fine on the operator of an online dating platform. The controller had not provided an email verification procedure for registration on its dating… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Personal Data Jan 1, 2023
€15,000 A&G Couriers Limited T/A Fastway Couriers (Ireland): Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined A&G Couriers Limited T/A Fastway Couriers (Ireland) EUR 15,000. During a changeover of its IT systems, the controller had suffered a cyberattack in… DPC ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Right of Access Dec 30, 2022
€3,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The controller had reported a data breach to the DPA according to Art. 33 GDPR. An employee had taken… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Dec 27, 2022
€100,000 VIEC Limited: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… IRELAND ·DPC ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 22, 2022
€10,000 SUDREZIDENȚIAL Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on SUDREZIDENȚIAL Broker S.R.L.. An employee of the controller had unauthorizedly published an Excel spreadsheet containing… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Dec 22, 2022
€120,000 Eurosanità S.P.A.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 120,000 on Eurosanità S.P.A.. The controller operates various healthcare facilities. An individual had filed a complaint with the DPA for… ITALY ·Garante ·Art. 5, 9, 32 Security Healthcare Controllers Dec 15, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Dec 9, 2022
€300,000 FREE SAS: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 300,000 on FREE SAS. The DPA had received several complaints from individuals experiencing difficulties in exercising their rights to… FRANCE ·CNIL ·Art. 12, 15, 17 +2 Data Breaches Personal Data Encryption Dec 8, 2022
€3,000 INDECEMI, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,000 on INDECEMI, S.L.. A person had filed a complaint with the DPA against the controller after receiving an email from the controller… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Controllers Dec 3, 2022
€265M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Meta Platforms Ireland Limited EUR 265 million. The DPA had launched an investigation against Meta in 2021 after media reports indicated that a dataset… DPC Privacy by Design & Default Security Personal Data Nov 25, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 25, 2022
€600,000 ÉLECTRICITÉ DE FRANCE: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on ÉLECTRICITÉ DE FRANCE (EDF), France's largest electricity supplier. The DPA had received several complaints that individuals… CNIL ·Art. 7, 12, 13 +3 ·Insufficient fulfilment of data subjects rights Right to Object Personal Data Direct Marketing Nov 24, 2022