Content type · 622 documents in this view · 3,831 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3594 Processing 2644 Personal Data 2403 Controllers 2026 Processing Agreement 1114 Security 1018 Supervision 854 Healthcare 622 Law Enforcement 568 Monitoring 553 Public Authority 542 Consent 508
€60,000 Corporación radiotelevisión espanola: Insufficient technical and organisational measures to ensure information security CORPORACIÓN RADIOTELEVISIÓN ESPAÑOLA and the trade union have reported a security breach to the AEPD after six unencrypted USB sticks containing personal data were lost. The… SPAIN · ·Art. 32 Nov 19, 2019
€5,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Nov 1, 2019
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS · ·Art. 32 Oct 31, 2019
€50,000 Menzis (Health Insurance Company): Non-compliance with general data processing principles Marketing staff had access to patient data. Among other things, this violated the purpose limitation principle. THE NETHERLANDS · ·Art. 5 Oct 31, 2019
€7,400 Military Hospital: Insufficient fulfilment of data breach notification obligations A military hospital did not meet the reporting deadline for data breaches. Another part of the fine relates to a lack of technical and organisational measures. HUNGARY · ·Art. 32, 33 Oct 24, 2019
€100,000 Food company: Insufficient technical and organisational measures to ensure information security The company had set up an applicant portal on its website where interested parties could submit their application documents online. However, the company did not offer an encrypted… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Oct 24, 2019
€511 B.D.: Insufficient cooperation with supervisory authority The fine of EUR 511 was imposed on B.D. for failure to provide access to information which the Commission for Personal Data Protection needed for performance of its tasks and… BULGARIA · ·Art. 31 Oct 7, 2019
€2,000 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused circumvented the law when, instead of providing social services with proper authorization, it did so… CZECH REPUBLIC · ·Art. 5, 12, 30 Oct 4, 2019
€195,407 Delivery Hero: Insufficient fulfilment of data subjects rights According to the findings of the Berlin data protection officer, Delivery Hero Germany GmbH had not deleted accounts of former customers in ten cases, even though those data… GERMANY ·Art. 15, 17, 21 ·Insufficient fulfilment of data subjects rights Sep 19, 2019
€25,000 Company in the medical sector: Insufficient fulfilment of information obligations The (none-final) fine was imposed on a company in the medical sector for non-compliance with information obligations and for not appointing a data protection officer. Update: The… AUSTRIA · ·Art. 13, 35, 37 Aug 1, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA · ·Art. 32 Jul 2, 2019
€350,000 Haga Hospital: Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data… THE NETHERLANDS · ·Art. 32 Jun 18, 2019
€400,000 SERGIC (Real Estate): Insufficient technical and organisational measures to ensure information security The CNIL based the penalty on two grounds: Lack of basic security measures and excessive data storage. As to the first, sensitive user documents uploaded by rental candidates… FRANCE · ·Art. 5 May 28, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA · ·Art. 5, 6, 9 Apr 8, 2019
€14,000 Doctor: Insufficient legal basis for data processing A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS · ·Art. 5, 6 Jan 1, 2019
€5,000 State Hospital: Insufficient fulfilment of data subjects rights A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS · ·Art. 15 Jan 1, 2019
€80,000 GERMANY DPA: Insufficient technical and organisational measures to ensure information security ⇄ In a digital publication, health data was accidentally published due to inadequate internal control mechanisms. Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2019
€294,000 GERMANY DPA: Non-compliance with general data processing principles A company was fined EUR 294 000 for 'unnecessarily long' storage and retention of personnel files and for 'excessive' data collection in the personnel selection process, during… Art. 5 ·Non-compliance with general data processing principles Jan 1, 2019
€2,000 Restaurant: Non-compliance with general data processing principles Video surveillance cameras have been used in violation of principle of data minimisation (monitoring also of customer areas in restaurants). GERMANY ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2019
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL · ·Art. 5, 32 Jul 17, 2018
€1,800 Kebab restaurant: Insufficient legal basis for data processing CCTV was unlawfully used. Sufficient information about the video surveillance was missing. In addition, the storage period of 14 days was too long and therefore against the… AUSTRIA · ·Art. 5, 13, 14 Jan 1, 2018
Norwegian DPA: Legelisten.no may process healthcare reviews without prior consent Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Norway · Nov 8, 2017