Content type · 960 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND · ·Art. 5, 24, 25 +2 Jan 19, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND · ·Art. 28, 32 Jan 19, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Jan 17, 2022
€2,400 PHARMA TALENTS, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's… SPAIN · ·Art. 5, 32 Jan 14, 2022
€14,000 Azienda sanitaria unica regionale Marche: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 14,000 on Azienda sanitaria unica regionale Marche. The DPA launched an investigation against the health department following media… ITALY · ·Art. 5, 32, 35 Jan 13, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Jan 5, 2022
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Art. 24, 28 ·Insufficient data processing agreement Jan 1, 2022
€1,000 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records of positive and negative Covid-19 Antigen Rapid test results from patients in a public waste disposal site. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€2,700 Covid-19 test center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€17,000 Bank of Cyprus Public Company Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€5,000 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on DW Dynamic Works LIMITED. The controller operated as a processor for Hermes Airport Ltd.. Hermes had suffered a cyberattack… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
Logistics company: Insufficient technical and organisational measures to ensure information security A logistics company had disposed of delivery lists in a public waste paper container. The lists contained a large amount of detailed information, such as the first and last names… GERMANY ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€8,900 Company: Insufficient technical and organisational measures to ensure information security The DPA of Niedersachsen imposed a fine of EUR 8,900 on a company. The company had a customer database on the Internet with thousands of entries. During its investigation, the DPA… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€250,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has failed to implement appropriate technical and organizational measures to protect personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€7,500 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 7,500 on DW Dynamic Works LIMITED. The controller operated as a processor for the Cypriot Ministry of Denfese. The minsitry had suffered… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€5,000 Cyprus Electricity Authority: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€75,000 Greek Ministry of Tourism: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 75,000 on the Greek Ministry of Tourism. A data breach had occurred at the authority. According to the DPA, an attempt by a citizen to… GREECE · ·Art. 13, 32, 33 +1 Dec 29, 2021
€300,000 FREE MOBILE: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has imposed a fine of EUR 300,000 on FREEE MOBILE. The CNIL had received numerous complaints regarding the company's failure to comply with data subjects'… FRANCE · ·Art. 12, 15, 21 +2 Dec 28, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE · ·Art. 28, 32, 34 Dec 28, 2021
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK · ·Art. 32 Dec 16, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY · ·Art. 5, 25, 32 +1 Dec 16, 2021
€6,500 Travel agency: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 6,500 on a travel agency. A customer of the travel agency informed the DPA to suspect that the company might not process the data of its… FINLAND · ·Art. 5, 17, 25 +1 Dec 16, 2021
€10,000 Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Warsaw University of Technology EUR 10,000. The university had reported a data breach to the authority pursuant to Art. 33 GDPR. One of the… POLAND · ·Art. 5, 24, 25 +1 Dec 9, 2021
€30,000 One Way Private Company: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 30,000 on One Way Private Company. The DPA received 17 complaints regarding illegal telephone calls for the purpose of advertising. The… GREECE · ·Art. 11, 28, 32 Dec 8, 2021
€608,000 Psykoterapiakeskus Vastaamo: Non-compliance with general data processing principles The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An… FINLAND · ·Art. 5, 33, 34 Dec 7, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY · ·Art. 5, 32 Dec 2, 2021
€60,000 Irish Teacher Council: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 60,000 on the Irish Teaching Council. The Council notified the DPA of a data breach under Art. 33 of the GDPR. Accordingly, two employees… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Dec 2, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY · ·Art. 5, 32 Dec 2, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY · ·Art. 5, 32 Dec 2, 2021
€110,000 UAB Prime Leasing: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000. The DPA conducted the investigation on its own initiative… LITHUANIA · ·Art. 32 Nov 29, 2021
€2,000 Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Valoris Center S.R.L.. The controller notified the DPA of a data breach pursuant to Art. 33 GDPR. A call center… ROMANIA · ·Art. 29, 32 Nov 26, 2021
€585,000 Cabinet Office: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Cabinet Office EUR 585,000. On December 27, 2019, the Cabinet Office published a file on GOV.UK containing the names and uncensored addresses of… UNITED KINGDOM · ·Art. 5, 32 Nov 25, 2021
€51,000 Icelandic Ministry of Industry and Innovation: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 7 +4 ·Non-compliance with general data processing principles Nov 23, 2021
€27,200 YAY ehf.: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 28 +1 ·Non-compliance with general data processing principles Nov 23, 2021
€2,900 Vodafone România SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,900 on VODAFONE România S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. In the… ROMANIA · ·Art. 3, 32 Nov 14, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS · ·Art. 32 Nov 12, 2021
€400,000 Régie autonome des transports parisiens: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine of EUR 400,000 on RATP (the operator of the public transport system in Paris). In May 2020, a trade union filed a complaint with the CNIL… FRANCE · ·Art. 5, 32 Nov 4, 2021
€1,000 IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,000 on IKEA ROMÂNIA SA. The controller had sent a notification to the DPA about a personal data breach under Art. 33 GDPR.… ROMANIA · ·Art. 32 Nov 1, 2021
€5,000 S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection… ROMANIA · ·Art. 32 Nov 1, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY · ·Art. 5, 32 Oct 18, 2021
€11,800 HIV Scotland: Insufficient technical and organisational measures to ensure information security The British DPA (ICO) has imposed a fine of EUR 11,800 on the non-profit organization HIV Scotland. The controller had sent an e-mail to 105 people, with e-mail addresses on the… UNITED KINGDOM · ·Art. 5, 32 Oct 18, 2021
€40,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A woman filed a complaint against the controller based on the fact that the controller had sent telephone bills… SPAIN · ·Art. 5, 32 Oct 13, 2021
DSB (Austria) - 2021-0.698.184 The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered… 2021-0.698.184 ·Art. 6, 51, 57 +1 Oct 8, 2021
€5,000 CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L. EUR 5,000 for unlawfully processing an individual's data. Previously, CYNGASA, S.L. had… SPAIN · ·Art. 6 Oct 4, 2021