Skip to content
Content type · 760 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

551–600 of 760 sort newestlargest fineoldest
€9,700 Company: Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact… NORWAY ·Datatilsynet ·Art. 6, 13, 21 Right to Object Controllers Processing Agreement Mar 15, 2022
€10,000 Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 10,000 on Alfa Shipyard s.r.l.. The controller had failed to implement measures ordered by the DPA in due time. ITALY ·Garante ·Art. 58 Supervisory Authorities Supervision Law Enforcement Mar 10, 2022
€2,000 Operatorul Briza Land S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has fined Operatorul Briza Land S.R.L. EUR 2,000. The controller failed to properly respond to a request for information. ROMANIA ·ANSPDCP ·Art. 15 Controllers Personal Data Supervisory Authorities Mar 10, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Access Controls Security Mar 4, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Public Authority Education Feb 24, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Agreement Feb 22, 2022
€1,000 MALAGATROM, S.L.U.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on MALAGATROM, S.L.U. for failing to comply with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Feb 22, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA ·ANSPDCP ·Art. 12, 13, 21 Personal Data Video Surveillance Controllers Feb 22, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet ·Art. 5, 6, 32 Data Breaches Education Security Feb 2, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY ·Datatilsynet ·Art. 6 Controllers Insurance Supervisory Authorities Feb 1, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Controllers Processing Agreement Feb 1, 2022
BfDI (Germany) - 24-191 II The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Art. 15, 20, 95 Recipient Telecommunications Data Portability Jan 27, 2022
Belgian DPA rules on competence in cross-border cookie consent complaint involving The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·APD/GBA Supervisory Authorities Legitimate Interest Cookies Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Right of Access Procedures Right of Access Personal Data Jan 20, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS ·AP ·Art. 12 Personal Data Controllers Data Controller Jan 14, 2022
€1,500 Physician: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. The DPA had conducted an investigation against the physician for the unlawful operation of a video surveillance… CYPRUS ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Monitoring Video Surveillance Jan 1, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Processors Controllers Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Five fines for failing to comply with orders issued by the DPA. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Fines Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Six fines for failing to provide information requested by the DPA during an investigation. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Fines Supervision Jan 1, 2022
€5,000 Cyprus Judo Federation: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine on the Cyprus Judo Federation. The father of a member had filed a complaint with the DPA because the judo coach of his minor son had published… Art. 31 ·Insufficient cooperation with supervisory authority Social Media Supervisory Authorities Supervision Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Public Sector Jan 1, 2022
€2,000 Oroklini Municipal Council: Insufficient cooperation with supervisory authority The Cypriot DPA has fined the Oroklini Municipal Council EUR 2,000 for not properly cooperating with the DPA during an investigation. CYPRUS ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Public Authority Jan 1, 2022
€150M CNIL rejects Google's stay request and ne bis in idem challenge in cookie consent case Google LLC is a subsidiary owned wholly by Alphabet Inc. Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and… France ·Art. 56 Cookies Telecommunications Material scope (GDPR) Dec 31, 2021
€3,900 T. Stene Transport AS: €3,900 fine The Norwegian DPA has fined T. Stene Transport AS EUR 3,900 due to an unfair credit check on a data subject. NORWAY ·Datatilsynet ·Unknown Processing Agreement Personal Data Supervisory Authorities Dec 17, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY ·Datatilsynet ·Art. 6, 9 IP Address Fines Direct Marketing Dec 13, 2021
€20,000 Elektro & Automasjon Systemer AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Elektro & Automasjon Systemer AS EUR 20,000. The controller had carried out a credit check on an individual, although there was no legal… NORWAY ·Datatilsynet ·Art. 6 Controllers Processing Agreement Processing Dec 13, 2021
€2,000 SC Nobiotic Pharma SRL: Insufficient cooperation with supervisory authority Failure to provide requested information to the Romanian DPA within the required timeframe in violation of Art. 58 GDPR. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 13, 2021
€6,000 Telekom Romania Communications SA: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) imposed a fine of EUR 6,000 on Telekom Romania Communications SA. A data subject had complained that the controller had sent invoices and messages to… ANSPDCP ·Art. 5, 17 ·Non-compliance with general data processing principles Personal Data IP Address Controllers Dec 6, 2021
€4,000 Pactum Poland Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Data Breaches Supervisory Authorities Supervision Dec 1, 2021
€2,000 Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Valoris Center S.R.L.. The controller notified the DPA of a data breach pursuant to Art. 33 GDPR. A call center… ROMANIA ·ANSPDCP ·Art. 29, 32 Data Breaches Security Right of Access Nov 26, 2021
€2.8M Dutch Minister of Finance: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the Minister of Finance EUR 2,75 million. In the context of childcare benefit applications, tax offices had processed data on the dual nationality of… THE NETHERLANDS ·AP ·Art. 5, 6, 8 IP Address Public Authority Personal Data Nov 25, 2021
€98,000 Norwegian State Pension Fund (SPK): Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 98,000 on the Norwegian State Pension Fund (SPK). The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… NORWAY ·Datatilsynet ·Art. 5, 6, 9 Data Breaches Healthcare Education Nov 24, 2021
€3,000 FUENSANTA S.L.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Spanish DPA (AEPD) for investigative purposes. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Nov 23, 2021
€2,900 Vodafone România SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,900 on VODAFONE România S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 3, 32 Data Breaches Integrity and Confidentiality Principle Telecommunications Nov 14, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Access Controls Security Nov 12, 2021
€3,000 AD735 DATA MEDIA ADVERTISING S.L.: Insufficient cooperation with supervisory authority Failure to provide requested information to the Spanish DPA (AEPD) within the required timeframe in violation of Art. 58 GDPR. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Nov 12, 2021
€5,000 S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security IP Address Nov 1, 2021
€1,000 IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,000 on IKEA ROMÂNIA SA. The controller had sent a notification to the DPA about a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Notification Obligation Data Breaches Security Nov 1, 2021
€3,000 MERCEDES GERENCIA, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on MERCEDES GERENCIA, S.L.. The controller failed to respond to a request for information from the DPA in a timely manner. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Oct 25, 2021
€5,000 Glove Technology SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on Glove Technology SRL. The controller had installed a video surveillance system that audiovisually monitored employees… ROMANIA ·ANSPDCP ·Art. 5, 6 Video Surveillance Monitoring Controllers Oct 21, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY ·Datatilsynet ·Art. 5, 32 Encryption Access Controls Security Oct 18, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet ·Art. 5, 28, 32 +1 Processors Controllers Processing Agreement Sep 27, 2021
€12,500 Ultra-Technology AS: Insufficient legal basis for data processing The Norwegian Data Protection Authority has imposed a fine of EUR 12,500 on Ultra-Technology AS. Background of the fine is a complaint from a data subject who was credit-checked… NORWAY ·Datatilsynet ·Art. 6 Insurance Personal Data IP Address Sep 21, 2021
€75,600 ST. OLAVS HOSPITAL HF: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had… NORWAY ·Datatilsynet ·Art. 32 Healthcare Healthcare Access Controls Sep 20, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet ·Art. 32 Data Breaches Health Data Security Sep 20, 2021
€10,000 Mediterranean Hospital of Cyprus: Insufficient cooperation with supervisory authority The Cypriot DPA has fined Mediterranean Hospital of Cyprus EUR 10,000 for failing to provide information requested by the DPA during an investigation. Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Healthcare Sep 17, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Notified Body Competence Challenges and Dispute Resolution Social Media Fairness & Transparency Sep 2, 2021
€3,000 Actamedica SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has fined Actamedica SRL EUR 3,000. The controller had informed a private individual about the loss of her biological samples and a sum of money sent… ROMANIA ·ANSPDCP ·Art. 28, 32, 33 Data Breaches Security Healthcare Aug 24, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND ·UODO ·Art. 5, 25, 32 Encryption Data Breaches Security Aug 13, 2021
€9,600 Waxing Palace AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 9,600 on the waxing salon operator of Waxing Palace AS. The controller had camera surveillance of the controller's… NORWAY ·Datatilsynet ·Art. 5, 6, 13 Video Surveillance Monitoring Controllers Aug 12, 2021