Skip to content
Content type · 1,941 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

701–750 of 1,941 sort newestlargest fineoldest
€8,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Insurance Controllers Jan 17, 2025
€200,000 CAJA RURAL DE SALAMANCA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE SALAMANCA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€88,000 CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€76,000 CAJA RURAL DE GIJÓN, S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE GIJÓN, S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€12,000 CAJA RURAL GRANADA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL GRANADA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€2,000 DELIVERY SOLUTIONS S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on DELIVERY SOLUTIONS S.A. A security incident led to the unauthorized disclosure of personal data (name, address, telephone… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Privacy by Design & Default Jan 17, 2025
€1,500 Macelleria La Costata s.r.I.s: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on Macelleria La Costata s.r.I.s. The controller used video surveillance in its butcher's shop without installing the necessary… ITALY ·Garante ·Art. 5, 6, 13 Video Surveillance Controllers Monitoring Jan 16, 2025
€72,000 CAJA RURAL CENTRAL, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL CENTRAL, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Processing Agreement Insurance Jan 16, 2025
€2,000 Municipality of Cori: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Municipality of Cori. The controller published the names of those receiving food cards intended for people in need on its… ITALY ·Garante ·Art. 6 IP Address Public Authority Controllers Jan 16, 2025
€600 Pro Loco Tourist Association of Cittareale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on the Pro Loco Tourist Association of Cittareale. The controller published personal data of its members on its website without a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Agreement Jan 16, 2025
€6,000 San Pio Hospital in Benevento: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the San Pio Hospital in Benevento. The controller did not ensure that only entitled employees had access to technical… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Employees Jan 16, 2025
€100,000 Realmaps S.r.l.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 100,000 on Realmaps S.r.l. The controller collects data on every real estate owner and sells it to customers who use it for direct marketing… ITALY ·Garante ·Art. 5, 6, 7 +12 Controllers IP Address Marketing Jan 16, 2025
€400,000 CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 16, 2025
€600 BAR GIOIA: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on a BAR GIOIA. The controller installed two surveillance cameras without the necessary information signs, and the cameras were also… ITALY ·Garante ·Art. 5 Video Surveillance Monitoring Controllers Jan 16, 2025
€2,000 Alessandro Volta Classical and Scientific High School in Como: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Alessandro Volta Classical and Scientific High School in Como. The controller published the results of the state exam,… ITALY ·Garante ·Art. 5, 6 Education Controllers Processing Agreement Jan 16, 2025
€175,000 Credit Institution: Insufficient fulfilment of data subjects rights The DPA of Luxembourg has issued a fine of EUR 175,000 on a Credit Institution. The controller failed to respond to information requests within the timeframe specified in Art. 12… LUXEMBOURG ·CNPD ·Art. 12 Supervisory Authorities Controllers Personal Data Jan 6, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA ·ANSPDCP ·Art. 24, 32 Healthcare Healthcare Security Jan 3, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Controllers Processors IP Address Jan 1, 2025
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN ·aepd ·Art. 6, 28 Insurance Personal Data Controllers Dec 23, 2024
€357,000 Panek SA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 357,000 on Panek SA. During the reconstruction of its website, the controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 32 Security Processing Agreement Controllers Dec 23, 2024
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Security Dec 20, 2024
€100,000 ATRIUM LEX SFC: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 100,000 on the real estate management company ATRIUM LEX SFC. An investor had filed a complaint with the DPA because the controller had… SPAIN ·aepd ·Art. 13, 32 Controllers Processing Agreement Processing Dec 18, 2024
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… Data Breaches Notification Obligation Social Media Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN ·aepd ·Art. 5 Controllers Employees IP Address Dec 16, 2024
€18,400 Granit Bostad Beritsholm AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 18,400 on the Granit Bostad Beritsholm AB. The controller, a property management company, installed CCTV cameras in an apartment complex… SWEDEN ·Art. 6, 13 ·Insufficient legal basis for data processing Video Surveillance Controllers Monitoring Dec 11, 2024
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN ·aepd ·Art. 5, 25, 32 +1 Data Breaches Insurance Security Dec 10, 2024
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a data controller. The controller had installed a video surveillance system without adequately providing information for data… SPAIN ·aepd ·Art. 13 Video Surveillance Controllers Monitoring Dec 3, 2024
Lyngby-Taarbæk Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine between EUR 46,900 and EUR 53,600 on the Lyngby-Taarbæk Municipality. The controller failled to implement sufficient security measures resulting… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Public Authority Nov 27, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Education Controllers Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN ·aepd ·Art. 15, 35 DPIA Privacy Impact Assessment Employees Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN ·aepd ·Art. 15, 35 Personal Data Employees Biometric Data Nov 22, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period Controllers Nov 20, 2024
€358,000 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted… UODO ·Art. 5, 25, 28 +1 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processing Agreement Nov 20, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Video Surveillance Security IP Address Nov 13, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Nov 12, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN ·aepd ·Art. 5, 32 Security Controllers IP Address Nov 11, 2024
€1,000 MINAS DE VALDECASTILLO, S.A..: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on MINAS DE VALDECASTILLO, S.A.. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers Monitoring Nov 6, 2024
€1,000 Blackcab Systems SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Blackcab Systems SRL. A individual lodged a complaint with the DPA, alleging that the controller had failed to properly respond… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Processing Agreement Nov 4, 2024
€15,000 Untold SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Untold SRL. During its investigation, the DPA found that the controller had failed to properly comply with a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Data Controller Oct 30, 2024
€10,000 Profi Rom Food SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 10,000 on Profi Rom Food SRL. During its investigation, the DPA found that the controller had forwarded copies of several employees' ID… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Employees Processing Agreement Oct 23, 2024
€5,800 POLAND DPA: Insufficient involvement of data protection officer The Polish DPA has imposed a fine of EUR 5,800 on a data controller. The controller failed to appoint a data protection officer and to provide the DPA with the contact details in… UODO ·Art. 37 ·Insufficient involvement of data protection officer Controllers Supervisory Authorities Processing Agreement Oct 18, 2024
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Your Consulting SRL. The controller had suffered a data breach involving the unauthorized disclosure of personal data. During… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Oct 16, 2024
€5,000 Company: Lack of appointment of data protection officer The Austrian DPA has imposed a fine on a company. The controller appointed a DPO who had a conflict of interest, meaning the person was not suitable for the role. AUSTRIA ·dsb ·Art. 38 Notified Body Responsibilities and Operational Obligations Supervisory Authorities Controllers Oct 16, 2024
Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·APD/GBA Cookies Direct Marketing Telecommunications Oct 11, 2024
€5,000 ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. The controller, a law firm, published the names and photos of its… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Insurance Oct 4, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers IP Address Processors Sep 26, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers Prior Consultation IP Address Sep 26, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·aepd ·Art. 5 Telecommunications IP Address Security Sep 26, 2024