Skip to content
Content type · 760 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

651–700 of 760 sort newestlargest fineoldest
€1,000 Qualitance QBS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Qualitance QBS SA EUR 1,000 for a violation of Art. 32 GDPR. The company had sent information by email to 295 individuals, disclosing the email… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Security Professional Secrecy Dec 29, 2020
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 28, 2020
€2,000 S.C. C&V Water Control S.A.: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) fined S.C. C&V Water Control S.A. EUR 2,000 for failure to comply with the data protection authority's request for information in the course of an… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 22, 2020
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives IP Address Personal Data Dec 20, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 17, 2020
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Right of Access Right of Access Procedures Supervisory Authorities Dec 11, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 10, 2020
€2,850 Smart Cities Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the Polish DPA (UODO). The controller failed to provide personal data and other information requested by UODO for investigative… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Dec 9, 2020
€35M CNIL fines Amazon Europe Core €35M for placing cookies without consent Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating… France ·Art. 6, 9, 83 +1 Cookies Telecommunications Direct Marketing Dec 7, 2020
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet ·Art. 6, 32 Education Personal Data Public Authority Dec 3, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Privacy by Design & Default Personal Data Nov 24, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Telecommunications Personal Data Processing Agreement Nov 23, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Fairness & Transparency Right of Access Procedures Nov 19, 2020
€2,000 Anmavas 61, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning… SPAIN ·aepd ·Art. 58 Right to be Forgotten Supervisory Authorities Data Subject Rights Exercise Modalities and Procedures Nov 18, 2020
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company had not provided the ANSPDCP with requested information. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Oct 20, 2020
€30,000 AEPD (Spain) - PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Art. 22 Cookies Consent Information Provision Modalities and Communication Methods Oct 16, 2020
€3,000 S.C. Marsorom S.R.L.: Insufficient technical and organisational measures to ensure information security Disclosure of personal data of customers on the companies website due to inadequate technical and organisational measures to ensure information security. ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 15, 2020
€2,000 Asociația de proprietari Militari R: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA ·ANSPDCP ·Art. 31, 58 Supervision Supervisory Authorities Processing Oct 1, 2020
€3,000 Megareduceri TV S.R.L.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA ·ANSPDCP ·Art. 31, 58 Supervision Supervisory Authorities Processing Oct 1, 2020
€13,900 Odin Flissenter AS: Insufficient legal basis for data processing The company assessed the credibility of another company and thereby, according to Datatilsynet, processed personal data relating to a natural person (the owner of the company… NORWAY ·Datatilsynet ·Art. 5, 6 Personal Data Processing Supervisory Authorities Sep 25, 2020
€2,000 Sanatatea Press Group S.R.L.: Insufficient technical and organisational measures to ensure information security Sending the personal data collected for the registration for an online course to other participants due to a technical failure. ROMANIA ·ANSPDCP ·Art. 5, 32 Security Personal Data Telecommunications Sep 8, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Telecommunications Cookies Supervisory Authorities Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Security Education Sep 3, 2020
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing According to the supervisory authority, the company processed personal data without sufficient legal basis, with the result that the data subject received several hundred… SPAIN ·aepd ·Art. 5, 6 Personal Data Telecommunications Processing Sep 1, 2020
€500 Apartment building owners association: Insufficient legal basis for data processing Export of a still image from a video surveillance system and posting of the image on the billboard of the building without sufficient legal basis. In addition, violation of the… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +3 Video Surveillance Monitoring Security Sep 1, 2020
€250,000 Spartoo: Non-compliance with general data processing principles A fine of EUR 250000 was imposed on the online retailer Spartoo. The reason for this was that the company, which has its headquarters in France but supplies a large number of… FRANCE ·CNIL ·Art. 5, 13, 14 IP Address Encryption Personal Data Aug 5, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Insurance Human Resources Jul 30, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA ·ANSPDCP ·Art. 32 Anonymization Controllers Personal Data Jul 30, 2020
€4,000 Region of Campania: Insufficient legal basis for data processing Publication of an enforcement order in civil proceedings on the Region's website. The document listed the names and place of residence and the amount of the claim. ITALY ·Garante ·Art. 5, 6 Education Public Authority Processing Jul 29, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK ·Datatilsynet ·Art. 5 Retention Period Personal Data IP Address Jul 28, 2020
€5,000 SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security Unauthorised disclosure of the data of five Tarom passengers due to inadequate technical and organisational measures for secure data processing. Among other things, the company… ROMANIA ·ANSPDCP ·Art. 32 Notified Body Responsibilities and Operational Obligations Security Notified Body Assessment Procedures Jul 27, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority Following a complaint, Xfera Móviles was requested by the AEPD to submit certain information and documents, but did not do so within the provided time limit. SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Telecommunications Jul 23, 2020
€40,000 Iberia Lae SA Operadora Unipersonal: Insufficient cooperation with supervisory authority The company did not grant the data subject access to telephone records. The applicant's request for access did not receive a reply, despite the prior order of the AEPD. SPAIN ·aepd ·Art. 58 Right of Access Right of Access Procedures Supervisory Authorities Jul 20, 2020
€22,300 Office for geodesy and cartography: Insufficient cooperation with supervisory authority Refusal of access to the premises by the supervisory authority in the course of an audit. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Public Authority Jul 15, 2020
€3,400 East Power Sp. z o.o.: Insufficient cooperation with supervisory authority After three subpoenas to East Power, in which the latter failed to provide sufficient explanations on a direct marketing complaint, the data protection authority found that East… POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Law Enforcement Jul 10, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet ·Art. 32, 35 DPIA Privacy Impact Assessment Health Data Jul 10, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA ·ANSPDCP ·Art. 32 Right of Access Security Social Media Jul 9, 2020
€830,000 Bureau Krediet Registration ('BKR'): Insufficient fulfilment of data subjects rights BKR had required the payment of a fee when individuals requested access to their personal data and only provided access to their data once a year free of charge by post. THE NETHERLANDS ·AP ·Art. 12, 15 Personal Data Insurance Supervisory Authorities Jul 6, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company had not cooperated sufficiently with the data protection authority. SPAIN ·aepd ·Art. 31, 58 Supervisory Authorities Supervision Telecommunications Jul 2, 2020
Odin Flissenter AS: Insufficient legal basis for data processing On July 2, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Odin Flissenter AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR. This fine has been… NORWAY ·Datatilsynet ·Art. 5, 6 Processing Agreement Processing Supervisory Authorities Jul 2, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY ·Datatilsynet ·Art. 32 Healthcare Health Data Healthcare Jun 22, 2020
Aquateknikk AS: Insufficient legal basis for data processing On June 19, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Aquateknikk AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR . This fine has been… NORWAY ·Datatilsynet ·Art. 5, 6 Processing Agreement Processing Supervisory Authorities Jun 19, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Processing Jun 18, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 16, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Telecommunications Jun 11, 2020
€4,000 Iberdrola Clientes: Insufficient cooperation with supervisory authority The company was asked to provide the AEPD with specific information in relation to a complaint. However, the company had not replied to the data protection authorities request for… SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Jun 4, 2020
€1,168 Entrepreneur running a non-public nursery and pre-school: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. POLAND ·UODO ·Art. 31, 58 Data Breaches Supervision Supervisory Authorities Jun 3, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Personal Data May 5, 2020
€134,000 Telenor Norge AS: Insufficient technical and organisational measures to ensure information security Fines for security breaches in a voice mailbox function. NORWAY ·Datatilsynet ·Art. 32 Telecommunications Security Fines May 3, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS ·AP ·Art. 5, 9 Consent Employees Biometric Data Apr 30, 2020