Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

651–700 of 2,273 sort newestlargest fineoldest
€180 Website operator: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the operator of a website for storing data of a data subject for an excessively long period of time and contrary to the principle of storage… SPAIN ·aepd ·Art. 5 Storage Limitation Retention Period IP Address Jun 5, 2024
Company: Non-compliance with general data processing principles The French DPA has imposed a fine on a company. The company published a promotional video on its website and social networks in which images of patient files of one of its… FRANCE ·CNIL ·Art. 5 Personal Data IP Address Direct Marketing Jun 5, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jun 5, 2024
€6,000 Ambitious People Group B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 6,000 on the recruitment company Ambitious People Group B.V. . The controller had not deleted the data of data subjects after they had… THE NETHERLANDS ·AP ·Art. 12, 17 Controllers Personal Data Data Controller Jun 4, 2024
€600,000 GSMA Limited: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 600,000 on GSMA Limited. In 2022, GSMA Limited required employees of its suppliers to register on an online platform and upload proof of… SPAIN ·aepd ·Art. 6, 9, 14 Archiving Processing Agreement Personal Data May 31, 2024
€2,000 Corint Logistic SRL.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Corint Logistic SRL. A customer had filed a complaint with the DPA because they had received advertising text messages from the… ROMANIA ·ANSPDCP ·Art. 5, 17, 21 Right to be Forgotten Data Subject Rights Exercise Modalities and Procedures Personal Data May 30, 2024
€4,200 PILLOW HOTELS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PILLOW HOTELS, S.L.. A person had filed a complaint with the DPA. The individual had made a booking for an overnight stay with the controller… SPAIN ·aepd ·Art. 5, 32, 33 Data Breaches Controllers Security May 30, 2024
€70,000 CAIXABANK S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK S.A.. A person had filed a complaint with the DPA because an employee of the controller had accidentally disclosed… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Insurance May 28, 2024
€400,000 Ministry of Interior (Greece): Insufficient technical and organisational measures to ensure information security The Hellenic DPA imposed a fine of EUR 400,000 on the Ministry of Interior for leaking email addresses from the voter registry of Greek expatriates. These personal data, which… HDPA ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Education Personal Data Public Authority May 27, 2024
€600 President of a workers' council: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the president of the workers' council of a company following a complaint by a former employee. During their employment, the company carried… SPAIN ·aepd ·Art. 5 Employees Personal Data IP Address May 23, 2024
€4,500 Azienda Socio-sanitaria Territoriale Rhodense: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,500 on Azienda Socio-sanitaria Territoriale Rhodense. An individual had filed a complaint with the DPA because the controller had not… ITALY ·Garante ·Art. 5, 12, 16 Controllers Healthcare Personal Data May 23, 2024
€3,500 Professional association: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 3,500 on a professional association. An individual had filed a complaint with the DPA, for the unlawful publication of their personal… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data IP Address Education May 23, 2024
€336,000 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 336,000 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During… POLAND ·UODO ·Art. 5, 32 Security Privacy by Design & Default Healthcare May 20, 2024
Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data… 74/2024 ·Belgium ·APD/GBA Legitimate Interest Direct Marketing Marketing May 16, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… Autoriteit Persoonsgegevens Social Media Fairness & Transparency Inspection Access Rights and Cooperation Obligations May 16, 2024
€1,600 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a homeowners' association. A person had filed a complaint with the DPA due to the fact that the data controller had published a picture with… SPAIN ·aepd ·Art. 5, 32 Controllers Personal Data IP Address May 9, 2024
€10,000 Azzurro Club Hotels S.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on Azzurro Club Hotels S.r.l.. The controller had sent a data subject unsolicited advertising e-mail and failed to respond… ITALY ·Garante ·Art. 6, 12, 15 +1 Controllers Personal Data Direct Marketing May 9, 2024
€2,000 IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the… ROMANIA ·ANSPDCP ·Art. 32 IP Address Security Controllers May 9, 2024
€3,000 Polisportiva Mimmo Ferrito s.r.l..: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 3,000 on Polisportiva Mimmo Ferrito s.r.l.. A data subject had filed a complaint with the DPA due to the controller's failure to respond… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities May 9, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA ·ANSPDCP ·Art. 32 Healthcare Healthcare Health Data May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Healthcare May 8, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·aepd ·Art. 32, 33 Data Breaches Security Healthcare May 8, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… aepd ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement May 7, 2024
€1,200 ARRENDAMIENTOS DEUDORES, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ARRENDAMIENTOS DEUDORES, S.L.. The controller had carried out a credit check on the data subject without any valid legal basis for this. The… SPAIN ·aepd ·Art. 6 Controllers Insurance Personal Data May 7, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS ·AP ·Art. 5 Cookies Controllers Personal Data May 2, 2024
€210 Association: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an association EUR 210 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Apr 30, 2024
€1,200 DELPASO CAR HIRE, S.L.U.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on DELPASO CAR HIRE, S.L.U.. A data subject had filed a complaint against the controller with the DPA due to the controller's failure to… SPAIN ·aepd ·Art. 15 Personal Data Controllers Supervisory Authorities Apr 30, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Data Breaches Encryption Security Apr 29, 2024
€16,000 Association: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 16,000 on an association for processing personal data without a sufficient legal basis. FRANCE ·CNIL ·Art. 6 Personal Data Processing Processing Agreement Apr 25, 2024
€10,000 C.I.E.L. S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on C.I.E.L. S.p.A.. An employee working for the controller filed a complaint with the DPA due to the controller's failure to grant… ITALY ·Garante ·Art. 12, 15 Controllers Personal Data Employees Apr 24, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Apr 24, 2024
€30,000 Rossi Carta S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 30,000 on Rossi Carta S.r.l.. An individual had filed a complaint with the DPA after repeatedly receiving unsolicited advertising emails… ITALY ·Garante ·Art. 6, 7, 12 +1 Data Subject Rights Exercise Modalities and Procedures Personal Data Controllers Apr 24, 2024
€3,000 I.N.P.A.S.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on I.N.P.A.S. (Istituto Nazionale di Previdenza e di Assistenza Sociale). During its investigation, the DPA found that a former… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Education IP Address Apr 24, 2024
€30,000 Gestore Dei Servizi Energetici - Gse S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA imposed a fine of EUR 30,000 against Gestore Dei Servizi Energetici - Gse S.p.A. for failing to comply with a former employee's request for access to their… ITALY ·Garante ·Art. 12, 15 Personal Data Employees Supervisory Authorities Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Apr 23, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Cookies Fairness & Transparency Direct Marketing Apr 22, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Fairness & Transparency Cookies IP Address Apr 22, 2024
€2,000 S.C. Tensa Art Design S.A..: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on S.C. Tensa Art Design S.A.. The controller had processed the personal data of a data subject for marketing purposes without the… ROMANIA ·ANSPDCP ·Art. 6 Personal Data Direct Marketing Controllers Apr 22, 2024
€14M Avast Software s.r.o.: €13,900,000 fine The Czech DPA has fined Avast Software s.r.o. EUR 13.9 million. The company had disclosed the personal data of around 100 million users of its antivirus software to the US company… CZECH REPUBLIC ·UOOU ·Unknown Processing Agreement Anonymization Personal Data Apr 15, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·aepd ·Art. 6 Processing Agreement Consent Personal Data Apr 12, 2024
€20,000 Istituto Nazionale di Previdenza Sociale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Italian National Institute of Social Security (INPS). The controller had published personal data of participants in a… ITALY ·Garante ·Art. 2, 5, 6 Education Personal Data Public Authority Apr 11, 2024
€100,000 Facile.Energy S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Facile.Energy S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of… ITALY ·Garante ·Art. 5, 6, 24 +3 IP Address Controllers Processing Agreement Apr 11, 2024
€25,000 Innova Camara: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 25,000 on Innova Camara. The controller had suffered a cyber attack in which databases were accessed and malicious files (backdoors) were… ITALY ·Garante ·Art. 5 Security Privacy by Design & Default Education Apr 11, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 IP Address Processing Agreement Controllers Apr 11, 2024
€1,000 Store owner: Insufficient fulfilment of information obligations The Italian DPA has fined a store owner EUR 1,000. The controller had installed video surveillance cameras in its premises without properly informing data subjects about the… ITALY ·Garante ·Art. 5, 13 Video Surveillance Personal Data Monitoring Apr 11, 2024
€525,000 HUBSIDE.STORE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 525,000 on HUBSIDE.STORE. The company had used data from data brokers for commercial acquisition campaigns without ensuring that the data… FRANCE ·CNIL ·Art. 6, 14 Processing Agreement Consent Personal Data Apr 4, 2024
€500 JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT. The controller had installed a video surveillance system without… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Mar 21, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·aepd ·Art. 5, 32 Video Surveillance Social Media Monitoring Mar 21, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A data subject had filed a complaint against the data controller as unauthorized fraudsters… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Mar 15, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Mar 15, 2024