Content type · 760 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€9,700 Company: Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact… NORWAY · ·Art. 6, 13, 21 Mar 15, 2022
€10,000 Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 10,000 on Alfa Shipyard s.r.l.. The controller had failed to implement measures ordered by the DPA in due time. ITALY · ·Art. 58 Mar 10, 2022
€2,000 Operatorul Briza Land S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has fined Operatorul Briza Land S.R.L. EUR 2,000. The controller failed to properly respond to a request for information. ROMANIA · ·Art. 15 Mar 10, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY · ·Art. 5, 32 Mar 4, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS · ·Art. 13, 32 Feb 24, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA · ·Art. 5, 6 Feb 22, 2022
€1,000 MALAGATROM, S.L.U.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on MALAGATROM, S.L.U. for failing to comply with an order issued by the DPA. SPAIN · ·Art. 58 Feb 22, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA · ·Art. 12, 13, 21 Feb 22, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY · ·Art. 5, 6, 32 Feb 2, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY · ·Art. 6 Feb 1, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA · ·Art. 6, 9 Feb 1, 2022
BfDI (Germany) - 24-191 II The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Art. 15, 20, 95 Jan 27, 2022
Belgian DPA rules on competence in cross-border cookie consent complaint involving The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium · Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA · ·Art. 15 Jan 20, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS · ·Art. 12 Jan 14, 2022
€1,500 Physician: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. The DPA had conducted an investigation against the physician for the unlawful operation of a video surveillance… CYPRUS ·Art. 31 ·Insufficient cooperation with supervisory authority Jan 1, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Five fines for failing to comply with orders issued by the DPA. ·Art. 58 ·Insufficient cooperation with supervisory authority Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Six fines for failing to provide information requested by the DPA during an investigation. ·Art. 58 ·Insufficient cooperation with supervisory authority Jan 1, 2022
€5,000 Cyprus Judo Federation: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine on the Cyprus Judo Federation. The father of a member had filed a complaint with the DPA because the judo coach of his minor son had published… Art. 31 ·Insufficient cooperation with supervisory authority Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€2,000 Oroklini Municipal Council: Insufficient cooperation with supervisory authority The Cypriot DPA has fined the Oroklini Municipal Council EUR 2,000 for not properly cooperating with the DPA during an investigation. CYPRUS ·Art. 31 ·Insufficient cooperation with supervisory authority Jan 1, 2022
€150M CNIL rejects Google's stay request and ne bis in idem challenge in cookie consent case Google LLC is a subsidiary owned wholly by Alphabet Inc. Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and… France ·Art. 56 Dec 31, 2021
€3,900 T. Stene Transport AS: €3,900 fine The Norwegian DPA has fined T. Stene Transport AS EUR 3,900 due to an unfair credit check on a data subject. NORWAY · ·Unknown Dec 17, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY · ·Art. 6, 9 Dec 13, 2021
€20,000 Elektro & Automasjon Systemer AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Elektro & Automasjon Systemer AS EUR 20,000. The controller had carried out a credit check on an individual, although there was no legal… NORWAY · ·Art. 6 Dec 13, 2021
€2,000 SC Nobiotic Pharma SRL: Insufficient cooperation with supervisory authority Failure to provide requested information to the Romanian DPA within the required timeframe in violation of Art. 58 GDPR. ROMANIA · ·Art. 58 Dec 13, 2021
€6,000 Telekom Romania Communications SA: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) imposed a fine of EUR 6,000 on Telekom Romania Communications SA. A data subject had complained that the controller had sent invoices and messages to… ·Art. 5, 17 ·Non-compliance with general data processing principles Dec 6, 2021
€4,000 Pactum Poland Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Dec 1, 2021
€2,000 Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Valoris Center S.R.L.. The controller notified the DPA of a data breach pursuant to Art. 33 GDPR. A call center… ROMANIA · ·Art. 29, 32 Nov 26, 2021
€2.8M Dutch Minister of Finance: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the Minister of Finance EUR 2,75 million. In the context of childcare benefit applications, tax offices had processed data on the dual nationality of… THE NETHERLANDS · ·Art. 5, 6, 8 Nov 25, 2021
€98,000 Norwegian State Pension Fund (SPK): Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 98,000 on the Norwegian State Pension Fund (SPK). The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… NORWAY · ·Art. 5, 6, 9 Nov 24, 2021
€3,000 FUENSANTA S.L.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Spanish DPA (AEPD) for investigative purposes. SPAIN · ·Art. 58 Nov 23, 2021
€2,900 Vodafone România SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,900 on VODAFONE România S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. In the… ROMANIA · ·Art. 3, 32 Nov 14, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS · ·Art. 32 Nov 12, 2021
€3,000 AD735 DATA MEDIA ADVERTISING S.L.: Insufficient cooperation with supervisory authority Failure to provide requested information to the Spanish DPA (AEPD) within the required timeframe in violation of Art. 58 GDPR. SPAIN · ·Art. 58 Nov 12, 2021
€5,000 S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection… ROMANIA · ·Art. 32 Nov 1, 2021
€1,000 IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,000 on IKEA ROMÂNIA SA. The controller had sent a notification to the DPA about a personal data breach under Art. 33 GDPR.… ROMANIA · ·Art. 32 Nov 1, 2021
€3,000 MERCEDES GERENCIA, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on MERCEDES GERENCIA, S.L.. The controller failed to respond to a request for information from the DPA in a timely manner. SPAIN · ·Art. 58 Oct 25, 2021
€5,000 Glove Technology SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on Glove Technology SRL. The controller had installed a video surveillance system that audiovisually monitored employees… ROMANIA · ·Art. 5, 6 Oct 21, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY · ·Art. 5, 32 Oct 18, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY · ·Art. 5, 28, 32 +1 Sep 27, 2021
€12,500 Ultra-Technology AS: Insufficient legal basis for data processing The Norwegian Data Protection Authority has imposed a fine of EUR 12,500 on Ultra-Technology AS. Background of the fine is a complaint from a data subject who was credit-checked… NORWAY · ·Art. 6 Sep 21, 2021
€75,600 ST. OLAVS HOSPITAL HF: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had… NORWAY · ·Art. 32 Sep 20, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY · ·Art. 32 Sep 20, 2021
€10,000 Mediterranean Hospital of Cyprus: Insufficient cooperation with supervisory authority The Cypriot DPA has fined Mediterranean Hospital of Cyprus EUR 10,000 for failing to provide information requested by the DPA during an investigation. Art. 31, 58 ·Insufficient cooperation with supervisory authority Sep 17, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Sep 2, 2021
€3,000 Actamedica SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has fined Actamedica SRL EUR 3,000. The controller had informed a private individual about the loss of her biological samples and a sum of money sent… ROMANIA · ·Art. 28, 32, 33 Aug 24, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND · ·Art. 5, 25, 32 Aug 13, 2021
€9,600 Waxing Palace AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 9,600 on the waxing salon operator of Waxing Palace AS. The controller had camera surveillance of the controller's… NORWAY · ·Art. 5, 6, 13 Aug 12, 2021