Content type · 622 documents in this view · 3,831 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3594 Processing 2644 Personal Data 2403 Controllers 2026 Processing Agreement 1114 Security 1018 Supervision 854 Healthcare 622 Law Enforcement 568 Monitoring 553 Public Authority 542 Consent 508
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Nov 5, 2020
€20M Marriott International, Inc: Insufficient technical and organisational measures to ensure information security Original Summary: The ICO issued a notice of its intention to fine Marriott International Inc due to a cyber incident which was notified to the ICO by Marriott in November 2018. A… UNITED KINGDOM · ·Art. 32 Oct 30, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY · ·Art. 5, 9 Oct 26, 2020
€600 Private Individual: Insufficient legal basis for data processing Between February and June 2020, a private individual published information about patients on his personal Facebook page. The information included health data in terms of Art. 4… AUSTRIA · ·Art. 5, 9 Oct 19, 2020
€50,000 Centro de Investigación y Estudio para la Obesidad, SL: Insufficient legal basis for data processing Fines for the transfer of the data subject's personal data to Evo Finance EFC, SA in the course of processing a health insurance application, without a sufficient legal basis for… SPAIN · ·Art. 5, 6 Oct 9, 2020
€900 Café Restaurante B.B.B: Non-compliance with general data processing principles The cafe used CCTV cameras which also captured the public space outside resulting in a violation of the so called principle of data minimisation. SPAIN · ·Art. 5 Oct 9, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 13 +2 Sep 30, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 9 +1 Sep 30, 2020
€2,000 Istituto Comprensivo Statale Crucoli Torretta: Insufficient technical and organisational measures to ensure information security Publication of personal data of students on the website of the Institute with, inter alia, notes about health and progress in school due to technical failure. ITALY · ·Art. 5, 32 Sep 7, 2020
€65,000 Cork University Maternity Hospital: Insufficient technical and organisational measures to ensure information security The „Data Protection Authority of Ireland“ imposed a fine on Cork University Maternity Hospital (CUMH) after the personal data of 78 patients was discovered disposed of in a… IRELAND · ·Art. 5, 32 Aug 18, 2020
€56 Health care worker: Insufficient legal basis for data processing Acess to personal data in a health database for private research activities. ESTONIA · ·Art. 5, 6 Aug 17, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Installation of CCTV surveillance cameras that were also monitoring the public space and without proper information. SPAIN · ·Art. 5, 12, 13 Aug 5, 2020
€5,000 National Institute for Social Security - Department of the Province of Brescia: Insufficient fulfilment of data subjects rights ⇄ Failure to graint access to personal health data of a data subject according to Art. 15 GDPR. ITALY · ·Art. 15 Aug 4, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK · ·Art. 5 Jul 28, 2020
€5,000 Global Business Travel Spain SLU: Insufficient technical and organisational measures to ensure information security The fine was preceded by an employee's access to health data of a person concerned. In the course of its investigations, the Data Protection Authority found that Global Business… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jul 10, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY · ·Art. 32, 35 Jul 10, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Jun 30, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY · ·Art. 32 Jun 22, 2020
€2,000 Café Bar: Non-compliance with general data processing principles Illegal use of CCTV cameras (recording of third parties) and insufficient fulfilment of information obligations. SPAIN · ·Art. 5, 6, 13 +1 Jun 16, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN · ·Art. 5, 6 May 12, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Apr 23, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA · ·Art. 58 Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS · ·Art. 9, 32 Mar 24, 2020
€8,000 Speech and Special Education Centre - Mihou Dimitra: Insufficient fulfilment of data subjects rights The complainant had requested access to his child's data and to tax information. This request was rejected by the data controller. In addition, the data controller had violated an… GREECE · ·Art. 15, 58 Mar 20, 2020
€6,000 Amalfi Servicios de Restauracion S.L.: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN · ·Art. 5, 13, 14 Mar 16, 2020
€20,600 National Center of Addiction Medicine ('SAA'): Insufficient technical and organisational measures to ensure information security Persónuvernd noted that a former employee of the SAA received boxes of allegedly personal belongings that he had left there, but which also contained patient data, including the… ICELAND · ·Art. 5, 32 Mar 10, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN · ·Art. 5 Mar 9, 2020
€4,000 Liceo Scientifico Nobel di Torre del Greco: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information of more than 2000 teachers in the teacher rankings published on the… ITALY · ·Art. 5, 6, 9 Mar 6, 2020
€4,000 Liceo Artistico Statale di Napoli: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information in the teacher rankings published on the Institute's website. This… ITALY · ·Art. 5, 6, 9 Mar 6, 2020
€6,000 Casa Gracio Operation: Non-compliance with general data processing principles The company used CCTV cameras in the premises of a hotel which also captured the public roads outside the hotel resulting in a violation of the so called principle of data… SPAIN · ·Art. 5 Feb 25, 2020
€48,000 HM Hospitales: Insufficient legal basis for data processing The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the… SPAIN · ·Art. 5, 6 Feb 25, 2020
€4,000 Comune di Urago: Insufficient legal basis for data processing The local council has published on its website information containing a person's personal data, including health information. ITALY · ·Art. 5, 6 Feb 13, 2020
€1,500 Cafetería Nagasaki: Insufficient legal basis for data processing The AEPD found that the Nagasaki Cafetería did not comply with its obligations under the GDPR, as it placed its surveillance cameras in such a way as to monitor the public space… SPAIN · ·Art. 5, 6 Feb 4, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY · ·Art. 5, 32 Jan 23, 2020
€10,000 Community of Francavilla Fontana: Insufficient legal basis for data processing The community published on its website information about a court trial, including personal data such as health data about a data subject. ITALY · ·Art. 5, 6 Jan 15, 2020
€3,600 Zhang Bordeta 2006, S.L. (Store and Restaurant): Non-compliance with general data processing principles The store and restaurant owner installed a video surveillance system which, among others, also took pictures of the sidewalk and thus of the public space, which violates the… SPAIN · ·Art. 5 Jan 14, 2020
€10,000 Asociación de Médicos Demócratas: Insufficient legal basis for data processing The Asociación de Médicos Demócratas has processed personal data of its members, despite having been warned by the AEPD that it carried out the processing without the consent of… SPAIN · ·Art. 6 Jan 7, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY · ·Art. 32 Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC · ·Art. 24, 32 Jan 1, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC · ·Art. 5, 12, 28 Jan 1, 2020
Medical assistant: Insufficient legal basis for data processing A medical assistant at a doctor's office stored a patient's telephone number in her mobile phone and then contacted him for private purposes. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY · ·Art. 5 Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY · ·Art. 32 Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY · ·Art. 32 Jan 1, 2020
€10,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2020
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM · ·Art. 32 Dec 17, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA · ·Art. 58 Dec 2, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE · ·Art. 5, 6, 13 +4 Nov 21, 2019
€6,000 Sports Bar: Non-compliance with general data processing principles The sports bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. SPAIN · ·Art. 5 Nov 19, 2019