Skip to content
Content type · 854 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

651–700 of 854 sort newestlargest fineoldest
€1,000 MALAGATROM, S.L.U.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on MALAGATROM, S.L.U. for failing to comply with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Processing Agreement Feb 22, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Consent Feb 22, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA ·ANSPDCP ·Art. 12, 13, 21 Personal Data Controllers Supervisory Authorities Feb 22, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 32 Security Personal Data Public Authority Feb 2, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 1, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Insurance Processing Agreement Feb 1, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Data Portability Recipient Personal Data Jan 27, 2022
APD/GBA · 11/2022 The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·Art. 4, 5, 7 +2 Supervisory Authorities Legitimate Interest Personal Data Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Right of Access Personal Data Controllers Jan 20, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS ·AP ·Art. 12 Personal Data Controllers Supervisory Authorities Jan 14, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Cyprus DPA ·Art. 24, 32 Security Controllers Processors Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Six fines for failing to provide information requested by the DPA during an investigation. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Fines Jan 1, 2022
€5,000 Cyprus Judo Federation: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine on the Cyprus Judo Federation. The father of a member had filed a complaint with the DPA because the judo coach of his minor son had published… Cyprus DPA ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Social Media Jan 1, 2022
€2,000 Oroklini Municipal Council: Insufficient cooperation with supervisory authority The Cypriot DPA has fined the Oroklini Municipal Council EUR 2,000 for not properly cooperating with the DPA during an investigation. CYPRUS ·Cyprus DPA ·Art. 31 Supervisory Authorities Supervision Public Authority Jan 1, 2022
€1,500 Physician: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. The DPA had conducted an investigation against the physician for the unlawful operation of a video surveillance… CYPRUS ·Cyprus DPA ·Art. 31 Supervisory Authorities Supervision Monitoring Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Cyprus DPA ·Art. 24, 32 Security Controllers Processors Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Five fines for failing to comply with orders issued by the DPA. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Jan 1, 2022
€150M Google LLC is a subsidiary owned wholly by Alphabet Inc Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out… SAN-2021-023 ·France ·CNIL Material scope (GDPR) Supervision Supervisory Authorities Dec 31, 2021
€3,900 T. Stene Transport AS: €3,900 fine The Norwegian DPA has fined T. Stene Transport AS EUR 3,900 due to an unfair credit check on a data subject. NORWAY ·Datatilsynet (NO) ·Unknown Personal Data Supervisory Authorities Supervision Dec 17, 2021
€20,000 Elektro & Automasjon Systemer AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Elektro & Automasjon Systemer AS EUR 20,000. The controller had carried out a credit check on an individual, although there was no legal… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Supervisory Authorities Supervision Dec 13, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY ·Datatilsynet (NO) ·Art. 6, 9 Personal Data Consent Types of Special Categories of Personal Data Dec 13, 2021
€2,000 SC Nobiotic Pharma SRL: Insufficient cooperation with supervisory authority Failure to provide requested information to the Romanian DPA within the required timeframe in violation of Art. 58 GDPR. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Dec 13, 2021
€6,000 Telekom Romania Communications SA: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) imposed a fine of EUR 6,000 on Telekom Romania Communications SA. A data subject had complained that the controller had sent invoices and messages to… ANSPDCP ·Art. 5, 17 ·Non-compliance with general data processing principles Personal Data Controllers Processing Dec 6, 2021
€4,000 Pactum Poland Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Data Breaches Dec 1, 2021
€2,000 Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Valoris Center S.R.L.. The controller notified the DPA of a data breach pursuant to Art. 33 GDPR. A call center… ROMANIA ·ANSPDCP ·Art. 29, 32 Data Breaches Security Right of Access Nov 26, 2021
€2.8M Dutch Minister of Finance: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the Minister of Finance EUR 2,75 million. In the context of childcare benefit applications, tax offices had processed data on the dual nationality of… THE NETHERLANDS ·AP ·Art. 5, 6, 8 Personal Data Processing Education Nov 25, 2021
€98,000 Norwegian State Pension Fund (SPK): Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 98,000 on the Norwegian State Pension Fund (SPK). The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 9 Data Breaches Controllers Healthcare Nov 24, 2021
€3,000 FUENSANTA S.L.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Spanish DPA (AEPD) for investigative purposes. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Nov 23, 2021
€2,900 Vodafone România SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,900 on VODAFONE România S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 3, 32 Data Breaches Security Personal Data Nov 14, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS ·AP ·Art. 32 Security Personal Data Data Breaches Nov 12, 2021
€3,000 AD735 DATA MEDIA ADVERTISING S.L.: Insufficient cooperation with supervisory authority Failure to provide requested information to the Spanish DPA (AEPD) within the required timeframe in violation of Art. 58 GDPR. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Direct Marketing Nov 12, 2021
€5,000 S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Nov 1, 2021
€1,000 IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,000 on IKEA ROMÂNIA SA. The controller had sent a notification to the DPA about a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Nov 1, 2021
€3,000 MERCEDES GERENCIA, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on MERCEDES GERENCIA, S.L.. The controller failed to respond to a request for information from the DPA in a timely manner. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Oct 25, 2021
€5,000 Glove Technology SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on Glove Technology SRL. The controller had installed a video surveillance system that audiovisually monitored employees… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Processing Personal Data Oct 21, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Encryption Personal Data Security Oct 18, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet (NO) ·Art. 5, 28, 32 +1 Processors Controllers International Transfer Sep 27, 2021
€12,500 Ultra-Technology AS: Insufficient legal basis for data processing The Norwegian Data Protection Authority has imposed a fine of EUR 12,500 on Ultra-Technology AS. Background of the fine is a complaint from a data subject who was credit-checked… NORWAY ·Datatilsynet (NO) ·Art. 6 Personal Data Insurance Supervisory Authorities Sep 21, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet (NO) ·Art. 32 Data Breaches Security Personal Data Sep 20, 2021
€75,600 ST. OLAVS HOSPITAL HF: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Supervisory Authorities Supervision Sep 20, 2021
€10,000 Mediterranean Hospital of Cyprus: Insufficient cooperation with supervisory authority The Cypriot DPA has fined Mediterranean Hospital of Cyprus EUR 10,000 for failing to provide information requested by the DPA during an investigation. Cyprus DPA ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Healthcare Sep 17, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… DPC ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Transparency Information Provision Modalities and Communication Methods Fairness & Transparency Sep 2, 2021
€3,000 Actamedica SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has fined Actamedica SRL EUR 3,000. The controller had informed a private individual about the loss of her biological samples and a sum of money sent… ROMANIA ·ANSPDCP ·Art. 28, 32, 33 Data Breaches Security Personal Data Aug 24, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND ·UODO ·Art. 5, 25, 32 Encryption Security Personal Data Aug 13, 2021
€9,600 Waxing Palace AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 9,600 on the waxing salon operator of Waxing Palace AS. The controller had camera surveillance of the controller's… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 13 Controllers Supervisory Authorities Supervision Aug 12, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·DSB ·Art. 9 Personal Data Processors Legitimate Interest Aug 5, 2021
€200 Private Individual: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on a private individual due to the unlawful disclosure of personal data. The controller had disclosed personal data of… ROMANIA ·ANSPDCP ·Art. 5, 6, 14 Personal Data Controllers Processing Jul 30, 2021
Insurance company: Insufficient fulfilment of information obligations The DPA has ex officio, without prior notice, conducted a direct supervision over an insurance company based in Zagreb. Upon inspection of its business facility for carrying out… CROATIA ·AZOP ·Art. 13, 14 Controllers Supervisory Authorities Supervision Jul 5, 2021
€24,800 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 14,800 on a company. The background to the case is a complaint by a former employee who learned that the company's… Datatilsynet (NO) ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Supervisory Authorities Right to Object Controllers Jun 22, 2021
€2,000 La Santrade S.R.L.: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined La Santrade S.R.L. EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 31, 58 Supervisory Authorities Supervision Personal Data Jun 9, 2021