Skip to content
Content type · 2,802 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

651–700 of 2,802 sort newestlargest fineoldest
€600 BAR GIOIA: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on a BAR GIOIA. The controller installed two surveillance cameras without the necessary information signs, and the cameras were also… ITALY ·Garante ·Art. 5 Video Surveillance Monitoring Controllers Jan 16, 2025
€2,000 Municipality of Cori: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Municipality of Cori. The controller published the names of those receiving food cards intended for people in need on its… ITALY ·Garante ·Art. 6 Controllers IP Address Public Authority Jan 16, 2025
€2,000 Alessandro Volta Classical and Scientific High School in Como: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Alessandro Volta Classical and Scientific High School in Como. The controller published the results of the state exam,… ITALY ·Garante ·Art. 5, 6 Education Controllers Processing Agreement Jan 16, 2025
€120,000 National Bank of Greece S.A: Insufficient technical and organisational measures to ensure information security Hellenic Data Protection Authority (HDPA) fined National Bank of Greece S.A €120,000 on 2025-01-10 for: Insufficient technical and organisational measures to ensure information… HDPA ·Art. 5, 15, 25 +3 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Processing Agreement Jan 10, 2025
Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Notified Body Responsibilities and Operational Obligations Security Genetic Data Jan 10, 2025
€175,000 Credit Institution: Insufficient fulfilment of data subjects rights The DPA of Luxembourg has issued a fine of EUR 175,000 on a Credit Institution. The controller failed to respond to information requests within the timeframe specified in Art. 12… LUXEMBOURG ·CNPD ·Art. 12 Supervisory Authorities Controllers Personal Data Jan 6, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA ·ANSPDCP ·Art. 24, 32 Healthcare Healthcare Controllers Jan 3, 2025
€40,000 Coolblue B.V: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of €40,000 on Coolblue. The company collected personal data via cookies without users' explicit consent, relying on pre-ticked consent boxes. THE NETHERLANDS ·AP ·Art. 5, 6 Cookies Consent Processing Agreement Dec 23, 2024
€15,000 HSSERVICE LIZCON SOLUTIONS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 15,000 on HSSERVICE LIZCON SOLUTIONS, S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€2,000 AUTOMOCIÓN 1972, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 2,000 on AUTOMOCIÓN 1972, S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN ·aepd ·Art. 6, 28 Insurance Personal Data Controllers Dec 23, 2024
€9,000 CRIDOLMA BARCELONA S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 9,000 on CRIDOLMA BARCELONA S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€357,000 Panek SA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 357,000 on Panek SA. During the reconstruction of its website, the controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 32 Security Processing Agreement Controllers Dec 23, 2024
€600 ENERGY WINNER, S.L.: Insufficient cooperation with supervisory authority Fine of EUR 600 for failure to provide information to the Spanish DPA within the required timeframe SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Security Dec 20, 2024
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND ·UODO ·Art. 30, 35, 38 Privacy Impact Assessment DPIA Security Dec 18, 2024
€100,000 ATRIUM LEX SFC: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 100,000 on the real estate management company ATRIUM LEX SFC. An investor had filed a complaint with the DPA because the controller had… SPAIN ·aepd ·Art. 13, 32 Controllers Processing Agreement Processing Dec 18, 2024
€200,000 Hospital: Insufficient technical and organisational measures to ensure information security The Belgian DPA has fined a hospital EUR 200,000. The hospital had suffered a ransomware attack through a vulnerability in the server, which paralyzed parts of the computer system… BELGIUM ·APD ·Art. 5, 24, 32 +1 DPIA Security Privacy Impact Assessment Dec 17, 2024
€950,000 Sambla Group Oy: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 950,000 on Sambla Group Oy. Security vulnerabilities in two of its comparison portals allowed unauthorized persons to access personal… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Insurance Personal Data Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN ·aepd ·Art. 5 Controllers Employees Personal Data Dec 16, 2024
€2,000 Torre Annunziata municipality: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on Torre Annunziata municipality for failing to provide the DPA with the contact details of their data protection officer in good… ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Public Sector Dec 14, 2024
€2,000 Maddaloni municipality: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on Maddaloni municipality for failing to provide the DPA with the contact details of their data protection officer in good time. ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Public Sector Dec 14, 2024
€3.5M CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a… SPAIN ·aepd ·Art. 5, 25 Privacy by Default Privacy by Design Privacy by Design & Default Dec 12, 2024
€20,000 Physician: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on a physician who had published images of a patient who had undergone cosmetic surgery on a social network without their consent. ITALY ·Garante ·Art. 2, 5, 9 Healthcare Consent Processing Agreement Dec 12, 2024
€18,400 Granit Bostad Beritsholm AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 18,400 on the Granit Bostad Beritsholm AB. The controller, a property management company, installed CCTV cameras in an apartment complex… SWEDEN ·Art. 6, 13 ·Insufficient legal basis for data processing Video Surveillance Monitoring Controllers Dec 11, 2024
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN ·aepd ·Art. 5, 25, 32 +1 Data Breaches Insurance Security Dec 10, 2024
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a data controller. The controller had installed a video surveillance system without adequately providing information for data… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Dec 3, 2024
Lyngby-Taarbæk Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine between EUR 46,900 and EUR 53,600 on the Lyngby-Taarbæk Municipality. The controller failled to implement sufficient security measures resulting… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Public Authority Nov 27, 2024
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Nov 26, 2024
€4.8M Netflix International B.V.: Insufficient fulfilment of information obligations The Dutch DPA has imposed a fine of EUR 4.75 million on Netflix. This fine is based on a complaint filed by the Austrian organization 'noyb'. During its investigation, the DPA… THE NETHERLANDS ·AP ·Art. 5, 12, 13 +1 Telecommunications Personal Data Processing Nov 26, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN ·aepd ·Art. 15, 35 DPIA Privacy Impact Assessment Employees Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN ·aepd ·Art. 15, 35 Personal Data Biometric Data Employees Nov 22, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Education IP Address Nov 22, 2024
€4,700 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4,700 on a subcontractor that was contracted to redesign the website of another company. This fine is linked to ETid-2491. Due to an error… UODO ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Privacy by Design & Default Nov 20, 2024
€358,000 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted… UODO ·Art. 5, 25, 28 +1 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processing Agreement Nov 20, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period IP Address Nov 20, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individua had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Nov 19, 2024
€2.4M Posti Jakelu Oy: Insufficient legal basis for data processing The Finnish DPA imposed a fine of EUR 2.4 million on Posti Jakelu Oy following an investigation. It was found that Posti had automatically set up an electronic mailbox for… FINLAND ·Deputy Data Protection Ombudsman ·Art. 6 Consent Processing Agreement Processing Nov 13, 2024
€5M Foodinho Srl: Non-compliance with general data processing principles The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the… ITALY ·Garante ·Art. 2, 5, 6 +11 IP Address Employees Personal Data Nov 13, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Video Surveillance Security IP Address Nov 13, 2024
€2,500 COYARE SLU: Non-compliance with general data processing principles The Spanish DPA fined COYARE SLU EUR 2,500 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the unauthorized… SPAIN ·aepd ·Art. 5, 32 IP Address Insurance Processing Agreement Nov 13, 2024
€678,897 Illumia Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints… ITALY ·Garante ·Art. 5, 6, 7 +4 Security Privacy by Design & Default Processing Agreement Nov 13, 2024
€500 4T OCIO Y CAFÉ 2009: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on 4T OCIO Y CAFÉ 2009, S.L. for installing a video surveillance system without the express consent of the owners' association of the… SPAIN ·aepd ·Art. 6 Video Surveillance Monitoring Consent Nov 13, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Nov 12, 2024
€900,000 Debt collection service provider: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 900,000 on a debt collection service provider. The company had unlawfully stored personal data (amounting to a six-digit number of… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Insurance Personal Data Processing Nov 12, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN ·aepd ·Art. 5, 32 Security Privacy by Design & Default Controllers Nov 11, 2024
€2,000 KAFFA KOFFEE ORGANISATION, S.L.: Non-compliance with general data processing principles The Spanish DPA fined KAFFA KOFFEE ORGANISATION, S.L. EUR 2,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Processing Nov 7, 2024
€1,000 MINAS DE VALDECASTILLO, S.A..: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on MINAS DE VALDECASTILLO, S.A.. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers Monitoring Nov 6, 2024
€1,000 Blackcab Systems SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Blackcab Systems SRL. A individual lodged a complaint with the DPA, alleging that the controller had failed to properly respond… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Processing Agreement Nov 4, 2024