Content type · 960 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA · ·Art. 25, 32 Nov 16, 2022
€80,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANKINTER, S.A.. A person had filed a complaint with the DPA as personal data of a third person were also displayed to them when accessing… SPAIN · ·Art. 5, 32 Nov 15, 2022
€48,000 Banco Bilbao Vizcaya Argentaria S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. An individual had filed a complaint with the DPA due to requesting information on one of their… SPAIN · ·Art. 5, 32 Nov 11, 2022
€40,000 Azienda Usl Valle d'Aosta: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Usl Valle d'Aosta EUR 40,000. An employee and patient of the health department had filed a complaint with the DPA because a colleague who had… ITALY · ·Art. 5, 9, 25 +1 Nov 10, 2022
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE · ·Art. 5, 13, 25 +2 Nov 10, 2022
€2,000 Romanian Post: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on the Romanian Post. The Post suffered a data breach where staff lost several mailings containing pension statements, employment… ROMANIA · ·Art. 32 Nov 7, 2022
€70,000 UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC (UPS). A person had filed a complaint with the DPA because UPS had delivered a… SPAIN · ·Art. 5, 32 Nov 3, 2022
€1,700 Mayor: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1,700 on the mayor of Dobrzyniewo Duże municipality. The mayor had reported a data breach to the DPA pursuant to Art. 33 GDPR. An… POLAND · ·Art. 5, 25, 32 Nov 2, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL · ·Art. 5, 9, 12 +5 Nov 2, 2022
€5,000 CÍTRICOS TANTA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 5,000 on CÍTRICOS TANTA, S.L.. The controller had entered personal data of an employee in the Social Security General Employee Register… SPAIN · ·Art. 6 Nov 2, 2022
€70,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A customer of the bank had filed a complaint with the DPA. The customer had in the past,… SPAIN · ·Art. 5, 32 Oct 31, 2022
€56,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA for having unsuccessfully requested a copy of their phone contract from… SPAIN · ·Art. 5, 32 Oct 31, 2022
DKK 500,000 Datatilsynet (Denmark) - 2022-63-0003 A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Art. 5, 9, 24 +2 Oct 28, 2022
€6,400 AIO E-COMMERCE, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on AIO E-COMMERCE, S.L.. The controller had suffered a data breach resulting in personal data such as bank details being siphoned off and… SPAIN · ·Art. 5 Oct 26, 2022
€9,000 Azienda Ospedaliero-Universitaria Careggi di Firenze: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 9,000 on Azienda Ospedaliero-Universitaria Careggi di Firenze. The controller had mistakenly sent a patient medical record to the wrong… ITALY · ·Art. 5, 9, 32 Oct 20, 2022
€5,000 RESTEXPERIENCE, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined RESTEXPERIENCE, S.L. EUR 5,000. The controller had accidentally sent an email containing tax information of 36 individuals to 11 unauthorized… SPAIN · ·Art. 5, 32 Oct 19, 2022
€5M Interserve Group Limited: Insufficient technical and organisational measures to ensure information security The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Interserve… UNITED KINGDOM · ·Art. 5, 32 Oct 19, 2022
€35,000 OES GLOBAL ENERGY S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 35,000 on OES GLOBAL ENERGY S.L.. A customer of the controller had filed a complaint with the DPA after receiving an e-mail from the… SPAIN · ·Art. 5, 32 Oct 17, 2022
€64,000 EVERIS SPAIN S.L: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of… ·Art. 5, 32 ·Non-compliance with general data processing principles Oct 9, 2022
€4,000 PUNTO BADAL-BCN S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on the real estate agency PUNTO BADAL-BCN S.L.. The controller had sent marketing e-mails to several people in an open distribution list, making… SPAIN · ·Art. 5, 32 Oct 9, 2022
€900 Private individual: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on a private individual. The individual unauthorizedly sent e-mails with personal data to several recipients in an open distribution list. This… SPAIN · ·Art. 5, 32 Oct 9, 2022
€2M Alpha Exploration: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2 million on Alpha Exploration. Alpha Exploration operates the social network Clubhouse. In the course of its investigation, the DPA… ITALY · ·Art. 5, 6, 7 +7 Oct 6, 2022
€15,000 Servizio Idrico Integrato S.c.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Servizio Idrico Integrato S.c.p.a. EUR 15,000. The controller had operated a website where personal data was being processed without using an SSL form.… ITALY · ·Art. 5, 32 Oct 6, 2022
€6,000 Club Náutico el Estacio: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on Club Náutico el Estacio. A data subject filed a complaint against the controller with the AEPD. The complaint is based on… SPAIN · ·Art. 5, 32 Oct 4, 2022
Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Art. 28, 36, 58 Sep 28, 2022
Datatilsynet (Denmark) - 2020-422-0026 The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Art. 5 Sep 28, 2022
€31,200 BAYARD REVISTAS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on Bayard Revistas S.A.. Unauthorized persons had accessed the Bayard database and thus unauthorizedly siphoned off location and contact data of… SPAIN · ·Art. 5, 32, 33 Sep 28, 2022
€1,200 URBANO DIVERTIA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on URBANO DIVERTIA S.L.. A customer had filed a complaint with the DPA, for having received a document from the controller with data relating to… SPAIN · ·Art. 5 Sep 23, 2022
€2,000 Bitfactor SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Bitfactor SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to a malfunction of an… ROMANIA · ·Art. 25, 32 Sep 22, 2022
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Sep 22, 2022
€5,000 Curtea Veche Publishing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Curtea Veche Publishing SRL. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. In the first… ROMANIA · ·Art. 32 Sep 21, 2022
€2,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Banca Comercială Română SA. The bank had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to an error in the IT… ROMANIA · ·Art. 25, 32 Sep 19, 2022
€250,000 GIE INFOGREFFE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 250,000 on GIE INFOGREFFE. The portal operates a website where people can access legal information about companies and order documents… FRANCE · ·Art. 5, 32 Sep 13, 2022
€6,700 Hørsholm municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Hørsholm municipality. The municipality had reported a data breach to the DPA pursuant to Art. 33 GDPR. An employee's work… DENMARK · ·Art. 32 Sep 12, 2022
€8,000 Realmedia Network SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Realmedia Network SA EUR 8,000. The company had suffered security breaches on a website it operates. This allowed it to leak and access unauthorized… ROMANIA · ·Art. 32 Sep 8, 2022
€530 Sułkowice Cultural Center: Insufficient data processing agreement The Polish DPA has imposed a fine of EUR 530 on the Sułkowice Cultural Center. During its investigation, the DPA found that the controller had transferred the processing of… POLAND · ·Art. 28 Sep 7, 2022
€1,000 Alpha Bank Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Alpha Bank Romania SA. The bank had accidentally sent a document to the wrong recipient via WhatsApp. The document contained… ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Aug 29, 2022
€2,500 Company: Insufficient technical and organisational measures to ensure information security The Belgian DPA has imposed a fine of EUR 2,500 on a company. The company operates a digital management platform where suppliers and customers can communicate and upload… BELGIUM · ·Art. 5, 24, 32 Aug 23, 2022
€10,000 Enel Energie Muntenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Enel Energie Muntenia S.A. EUR 10,000. A customer had mistakenly received an email addressed to another customer containing documents with personal data… ROMANIA · ·Art. 32 Aug 22, 2022
€20,000 Medical laboratory: Insufficient technical and organisational measures to ensure information security The Belgian DPA imposed a fine of EUR 20,000 on a medical laboratory. During its investigation, the DPA found that the laboratory had failed to conduct a data protection impact… BELGIUM · ·Art. 5, 12, 13 +3 Aug 19, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK · ·Art. 32 Aug 11, 2022
€5,000 IDIKA SA: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on IDIKA SA. IDIKA was operating in the context of providing free COVID-19 tests. The DPA found that IDIKA, in the course of its… GREECE · ·Art. 5, 25 Aug 8, 2022
€20,000 Cosmopol Security S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Cosmopol Security S.p.A. EUR 20,000. An individual had filed a complaint with the DPA against the controller. The individual had received invoices… ITALY · ·Art. 12, 15 Aug 5, 2022
€2,000 JAÉN SENTIDO Y COMÚN: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 2,000 on JAÉN SENTIDO Y COMÚN. The controller had sent an e-mail to 241 people in an open distribution list, making the email addresses… SPAIN · ·Art. 5, 32 Aug 4, 2022
€3,000 ESTUDIOS EUROPEOS DE POSTGRADO Y EMPRESA, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3,000 on ESTUDIOS EUROPEOS DE POSTGRADO Y EMPRESA, S.L.. An employee had filed a complaint with the DPA. The employee stated that she had… SPAIN · ·Art. 5, 32 Jul 29, 2022
€800 EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. EUR 800. A trade union had filed a complaint with the DPA because the company had unauthorizedly shared… SPAIN · ·Art. 5 Jul 26, 2022
€285,000 Telecommunications company: Insufficient technical and organisational measures to ensure information security The Croatian DPA has fined a telecommunications company EUR 285,000. The company had suffered a data breach. Attackers had managed to access data from about 100,000 data subjects.… CROATIA · ·Art. 25, 32 Jul 21, 2022
€3,000 Azienda Socio Sanitaria Territoriale Rhodense: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Socio Sanitaria Territoriale Rhodense EUR 3,000. The healthcare facility had reported the loss of a patient's medical record. The file contained… ITALY · ·Art. 5, 32 Jul 21, 2022
€4,000 Bookstore employee: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Agency has imposed a fine of EUR 4,000 on an employee of a bookstore. An individual had filed a complaint with the DPA because he had received an… SPAIN · ·Art. 5, 32 Jul 19, 2022
€56,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 56,000 on BANKINTER, S.A.. The controller had inadvertently sent a report on the data subject's investment portfolio to a third party.… SPAIN · ·Art. 5 Jul 18, 2022