Content type · 854 documents in this view · 3,831 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3594 Processing 2644 Personal Data 2403 Controllers 2026 Processing Agreement 1114 Security 1018 Supervision 854 Healthcare 622 Law Enforcement 568 Monitoring 553 Public Authority 542 Consent 508
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA · ·Art. 32 Mar 14, 2023
€2,000 Modaone SRL: Insufficient fulfilment of information obligations The Romanian DPA has imposed a fine of EUR 2,000 on Modaone SRL. An individual had filed a complaint with the DPA for having received advertising messages by e-mail, although they… ROMANIA · ·Art. 12, 13 Mar 13, 2023
€220,000 Argon Medical Devices: Insufficient fulfilment of data breach notification obligations The Norwegian DPA has fined Argon Medical Devices EUR 220,000. The controller failed to notify the DPA of a data breach that involved personal data of all its European employees… NORWAY · ·Art. 33 Mar 8, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA · ·Art. 32 Mar 6, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA · ·Art. 32 Mar 6, 2023
€440,000 Suomen Asiakastieto Oy: Insufficient cooperation with supervisory authority The Finnish DPA has imposed a fine of EUR 440,000 on Suomen Asiakastieto Oy for failing to comply with an order issued by the DPA. During an investigation, the DPA found that the… FINLAND · ·Art. 58 Feb 17, 2023
€5,000 Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Medijobs Platform SRL. The controller had informed the DPA about a data breach according to Art. 33 GDPR. Unauthorized third… ROMANIA · ·Art. 32 Feb 8, 2023
€900,000 Sats ASA: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 900,000 on the fitness chain 'Sats'. The DPA had received several complaints from customers who had submitted requests for information… NORWAY · ·Art. 5, 6, 12 +3 Feb 6, 2023
€1,000 Tensa Art Design SA: Insufficient fulfilment of data subjects rights The Romanian data protection authority (AEPD) has imposed a fine of EUR 1,000 on Tensa Art Design SA. A data subject had objected to a further newsletter subscription and however… ROMANIA · ·Art. 21 Feb 1, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA · ·Art. 33 Jan 31, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA · ·Art. 6, 9 Jan 31, 2023
€4,100 Company: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 4,100 for failing to provide information requested by the DPA during an investigation. POLAND · ·Art. 31, 58 Jan 25, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS · ·Art. 32 Jan 19, 2023
€5.5M WhatsApp Ireland Ltd.: Insufficient legal basis for data processing The Irish DPA (DPC) has fined WhatsApp Ireland Ltd. EUR 5.5 million. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of an… ·Art. 6, 12, 13 ·Insufficient legal basis for data processing Jan 19, 2023
€1,000 Dante Internațional SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dante Internațional SA. A data subject had filed a complaint with the DPA against the controller due to the fact that the… ROMANIA · ·Art. 17 Jan 18, 2023
€50,000 DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Jan 16, 2023
€1,000 EDITORIAL RIBADEO S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on EDITORIAL RIBADEO S.L. for failing to comply with an order issued by the DPA. SPAIN · ·Art. 58 Jan 13, 2023
€50,000 Intellexa SA: Insufficient cooperation with supervisory authority The Hellenic DPA has fined Intellexa SA EUR 50,000. The controller had not properly cooperated with the DPA during an investigation. GREECE · ·Art. 31 Jan 13, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA · ·Art. 32 Jan 12, 2023
€390M Meta Platforms Ireland Limited: Non-compliance with general data processing principles The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook… Jan 4, 2023
€3,000 Apă Canal Ilfov SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Apă Canal Ilfov SA. The controller sent an e-mail with personal data to several recipients in an open distribution list. This… ROMANIA · ·Art. 32 Jan 4, 2023
€500 Homeowners Association: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 500 on a homeowners' association. The controller had publicly posted a list with the first and last names of all members of the… ROMANIA · ·Art. 5 Jan 3, 2023
€5,000 Company: Insufficient cooperation with supervisory authority Fine of EUR 5,000 for failing to sufficiently cooperate with the DPA. GERMANY ·Art. 31 ·Insufficient cooperation with supervisory authority Jan 1, 2023
€6,300 Company: Insufficient cooperation with supervisory authority The Polish DPA has fined a company EUR 6,300 for failing to provide information requested by the DPA during an investigation. POLAND · ·Art. 58 Dec 30, 2022
€3M VOODOO ('provider') was a mobile game developer The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of the provider's mobile applications on iOS, in… SAN-2022-026 ·France · Dec 29, 2022
€3,000 ADENET SYSTEMS, S.L.: Insufficient cooperation with supervisory authority Failure to provide requested information to the Spanish DPA (AEPD) within the required timeframe in violation of Art. 58 GDPR. SPAIN · ·Art. 58 Dec 29, 2022
€3,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The controller had reported a data breach to the DPA according to Art. 33 GDPR. An employee had taken… ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Dec 27, 2022
€10,000 SUDREZIDENȚIAL Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on SUDREZIDENȚIAL Broker S.R.L.. An employee of the controller had unauthorizedly published an Excel spreadsheet containing… ROMANIA · ·Art. 32 Dec 22, 2022
€5,000 Societatea Energetică Electrica S.A.: Insufficient data processing agreement The Romanian DPA has fined Societatea Energetică Electrica S.A. EUR 5,000 for a violation of Art. 28 (3) a) GDPR. ROMANIA · ·Art. 28 Dec 15, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA · ·Art. 25, 32 Dec 9, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Nov 25, 2022
€1,800 ALPA 57 PRODUCCIONES, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) has fined ALPA 57 PRODUCCIONES, S.L. for failing to provide information requested by the DPA during an investigation. The original fine of EUR 3,000 was… SPAIN · ·Art. 58 Nov 25, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA · ·Art. 32 Nov 24, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA · ·Art. 32 Nov 21, 2022
€300 Homeowners Association Bld. Pipera 1-2E: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined Homeowners Association 'Bld. Pipera 1-2E' EUR 300 for failing to provide information requested by the DPA during an investigation. ROMANIA · ·Art. 58 Nov 18, 2022
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA · ·Art. 25, 32 Nov 16, 2022
€1,000 SC Das Sense Society SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Das Sense Society SRL EUR 1,000 for failing to provide information requested by the DPA during an investigation. ROMANIA · ·Art. 58 Nov 9, 2022
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide access to information about the purpose of the processing, the storage period, the… CZECH REPUBLIC · ·Art. 15 Nov 9, 2022
€5,000 SC Prestige Media PHG SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on SC Prestige Media PHG SRL. The controller had published 23 documents containing information on the termination of employment… ROMANIA · ·Art. 5, 6 Nov 8, 2022
€2,000 Romanian Post: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on the Romanian Post. The Post suffered a data breach where staff lost several mailings containing pension statements, employment… ROMANIA · ·Art. 32 Nov 7, 2022
€2,000 SC Materiale Constructii Online SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Materiale Constructii Online SRL EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA · ·Art. 58 Oct 18, 2022
€150 Private individual: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 150 on a private individual. The individual had made unauthorized use of another person's personal data without their consent. ROMANIA · ·Art. 6 Oct 18, 2022
€150 Website operator: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 150 on a website operator. The controller had published unauthorized personal data such as telephone number, ID number and series,… ROMANIA · ·Art. 5, 6 Oct 3, 2022
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·
Danish DPA reprimands Region Syddanmark for inadequate processor audit procedures The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Denmark ·
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Sep 22, 2022
€2,000 Bitfactor SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Bitfactor SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to a malfunction of an… ROMANIA · ·Art. 25, 32 Sep 22, 2022
€5,000 Curtea Veche Publishing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Curtea Veche Publishing SRL. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. In the first… ROMANIA · ·Art. 32 Sep 21, 2022
€2,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Banca Comercială Română SA. The bank had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to an error in the IT… ROMANIA · ·Art. 25, 32 Sep 19, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN · ·Art. 6 Sep 16, 2022