Skip to content
Content type · 960 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

701–750 of 960 sort newestlargest fineoldest
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK ·Datatilsynet ·Art. 32 Notification Obligation Data Breaches Integrity and Confidentiality Principle Sep 29, 2021
€5,000 CYNGASA, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on CYNGASA, S.L.. The data subject, when requesting a work report, discovered that the controller had disclosed his personal… SPAIN ·aepd ·Art. 6 Personal Data Controllers Employees Sep 29, 2021
€3,000 Bar owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a bar owner EUR 3,000. A data subject had filed a complaint with the DPA. He had suffered an accident in the bar which was recorded by the… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers Sep 28, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet ·Art. 5, 28, 32 +1 Processors Controllers Processing Agreement Sep 27, 2021
€75,600 ST. OLAVS HOSPITAL HF: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had… NORWAY ·Datatilsynet ·Art. 32 Healthcare Healthcare Access Controls Sep 20, 2021
€18,000 CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of… SPAIN ·aepd ·Art. 5 Insurance Healthcare Health Data Sep 20, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet ·Art. 32 Data Breaches Security Health Data Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Notification Obligation Healthcare Sep 17, 2021
€10,000 Favrskov municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Encryption Notification Obligation Sep 16, 2021
€5,000 Ciechi Ardizzone Gioeni di Catania: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Ciechi Ardizzone Gioeni di Catania residential home for blind people. A visitor to the residence filed a complaint… ITALY ·Garante ·Art. 5, 12, 13 +1 Video Surveillance Integrity and Confidentiality Principle Fairness & Transparency Sep 16, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet ·Art. 32 Healthcare Security Health Data Sep 8, 2021
€40,000 AC Omonia: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club AC Omonia. Due to a lack of security measures in the club's ticket sales system, it was possible for an… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Processing Agreement Sep 6, 2021
€40,000 APOEL FC: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club APOEL FC. Due to a lack of security measures in the club's ticket sales system, it was possible for an… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Processing Agreement Sep 6, 2021
€25,000 Hellenic Technical Enterprises Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 25,000 on Hellenic Technical Enterprises Ltd.. The controller hat designed the ticket sales system of the soccer clubs AC Omonia and… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Sep 6, 2021
€4,000 Automecanica Jerez, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Automecanica Jerez, S.L. EUR 4,000. The controller had sent commercial e-mails to a large number of people without their consent. In doing so, the… SPAIN ·aepd ·Art. 5, 21, 32 IP Address Personal Data Security Sep 2, 2021
€120,000 Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. The reason for this had been a complaint from a person relating to a lack of authentication.… SPAIN ·aepd ·Art. 32 Access Controls Security Privacy by Design & Default Aug 25, 2021
€3,000 Actamedica SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has fined Actamedica SRL EUR 3,000. The controller had informed a private individual about the loss of her biological samples and a sum of money sent… ROMANIA ·ANSPDCP ·Art. 28, 32, 33 Data Breaches Security Healthcare Aug 24, 2021
€1,800 Agency: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on an agency. The controller had disposed of documents containing personal data of its clients in the garbage. The AEPD considered this… SPAIN ·aepd ·Art. 32 Security Processors Controllers Aug 23, 2021
€1,500 MOVE Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to… Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Aug 20, 2021
€20,100 Danish Immigration Agency: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 20,100 on the Danish Immigration Agency. Media reports brought the DPA's attention to possible logging errors in one of the agency's IT… DENMARK ·Datatilsynet ·Art. 5, 32 Security Audit Logs Public Sector Aug 17, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND ·UODO ·Art. 5, 25, 32 Encryption Data Breaches Security Aug 13, 2021
€600 DSB Austria: sharing medical assessment with municipality lacked Art. 9(2) legal basis Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had… Art. 4, 5, 9 +1 Personal Data Health Data Healthcare Aug 5, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·dsb ·Art. 9 Personal Data Political Opinions Controllers Aug 5, 2021
€135,000 Insurance company: Insufficient technical and organisational measures to ensure information security The DPA of Luxembourg has imposed a fine of EUR 135,000 on an insurance company. On October 19, 2018, an employee of the controller had sent an e-mail to an uninvolved third party… LUXEMBOURG ·CNPD ·Art. 5, 32, 33 Data Breaches Security Insurance Aug 5, 2021
€3,000 Club Náutico el Estacio: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on Club Náutico el Estacio. A data subject filed a complaint against the controller with the AEPD. The complaint is based on… SPAIN ·aepd ·Art. 32 Inspection Access Rights and Cooperation Obligations Personal Data Security Aug 2, 2021
€3,000 UST GLOBAL ESPAÑA, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on UST GLOBAL ESPAÑA, S.A.. An employee filed a complaint against the controller with the DPA. UST GLOBAL ESPAÑA, S.A. was… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Data Breaches IP Address Jul 27, 2021
€400,000 Monsanto Company: Insufficient fulfilment of information obligations The French DPA (CNIL) has fined MONSANTO EUR 400,000. In May 2019, several media revealed that MONSANTO was in possession of a file containing the personal data of more than 200… FRANCE ·CNIL ·Art. 14, 28 Social Media Fairness & Transparency Right to Object Jul 26, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… Garante ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles DPIA Privacy Impact Assessment Fairness & Transparency Jul 22, 2021
APDCAT (Catalonia) - PD 6/2021 The Catalan DPA issued an opinion at the request of the Ministry of the Interior in order to evaluate the Law proposal that will transpose the Directive (EU) 2019/1153, laying… PD 6/2021 ·Spain ·Art. 7 Security Personal Data Special Categories of Data Jul 22, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 +1 Fines Integrity and Confidentiality Principle IP Address Jul 22, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Controllers Integrity and Confidentiality Principle Processors Jul 22, 2021
€67,900 Region of Syddanmark: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has fined the Region of Syddanmark EUR 67,900 for failing to comply with its obligation as a data controller to implement adequate security measures.… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Integrity and Confidentiality Principle Notification Obligation Jul 16, 2021
€50,000 Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 50,000 on Caixabank S.A.. A data subject had filed a complaint with the DPA because he had received commercial advertising from… SPAIN ·aepd ·Art. 6 Personal Data Legitimate Interest Controllers Jul 8, 2021
€50,000 AEPD (Spain) - PS/00259/2020 A data subject exercised their right to object to receiving commercial communications against a bank (Bankia/Caixabank), after what whose DPO confirmed that the right had been… Art. 6, 22 Legitimate Interest Marketing Right to Object Jul 6, 2021
€29,000 Mermaids: Insufficient technical and organisational measures to ensure information security The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR.… UNITED KINGDOM ·ICO ·Art. 5, 32 Encryption Security Data Breaches Jul 5, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·azop ·Art. 32 Data Breaches Processors Security Jul 5, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Security Public Authority Jun 16, 2021
€34,000 Huppuís ehf: Non-compliance with general data processing principles The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 34,000 on Huppuís ehf. A former employee filed a complaint against the controller with the DPA. The reason for this was… ICELAND ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Video Surveillance Employees Monitoring Jun 15, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Personal Data Retention Period Jun 14, 2021
€40,000 Aeroporto Guglielmo Marconi di Bologna S.p.a.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 5, 25, 32 Encryption Security Integrity and Confidentiality Principle Jun 10, 2021
€2.6M Foodinho s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Foodinho s.r.l. EUR 2,600,000. Foodinho is an Italian food delivery service. The investigation against Foodinho mainly focused on the drivers… ITALY ·Garante ·Art. 5, 13, 22 +5 DPIA Privacy Impact Assessment IP Address Jun 10, 2021
€40,000 aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 28, 32 Security Integrity and Confidentiality Principle Encryption Jun 10, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Encryption Security Jun 7, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·Art. 5, 6, 9 +2 ·Non-compliance with general data processing principles Data Breaches Integrity and Confidentiality Principle Healthcare Jun 7, 2021
€50,000 Region Stockholm: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·Art. 5, 13, 14 ·Insufficient fulfilment of information obligations Data Breaches Healthcare Healthcare Jun 7, 2021
€19,600 Radiotelevisión del principado de Asturias: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 26,000 on Radiotelevisión del principado de Asturias. The fine consists of EUR 20,000 due to a violation of Art. 5 (1) c) GDPR and… SPAIN ·aepd ·Art. 5, 12 Video Surveillance Monitoring Audit Logs Jun 7, 2021
€25,000 Region Sörmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Sörmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·Art. 5, 13 ·Insufficient fulfilment of information obligations Healthcare Data Breaches Encryption Jun 7, 2021
€25,000 Region Värmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Värmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·Art. 5, 13 ·Insufficient fulfilment of information obligations Data Breaches Healthcare Encryption Jun 7, 2021
€49,200 Moss municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the… NORWAY ·Datatilsynet ·Art. 32 Data Breaches Security Healthcare Jun 4, 2021
€450,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen) EUR 450,000. The UWV had not properly secured the… THE NETHERLANDS ·AP ·Art. 32 Insurance Security Healthcare May 31, 2021