Content type · 1,941 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€8,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN · ·Art. 5 Jan 17, 2025
€200,000 CAJA RURAL DE SALAMANCA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE SALAMANCA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN · ·Art. 5 Jan 17, 2025
€88,000 CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN · ·Art. 5 Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN · ·Art. 5 Jan 17, 2025
€76,000 CAJA RURAL DE GIJÓN, S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE GIJÓN, S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN · ·Art. 5 Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN · ·Art. 5 Jan 17, 2025
€12,000 CAJA RURAL GRANADA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL GRANADA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN · ·Art. 5 Jan 17, 2025
€2,000 DELIVERY SOLUTIONS S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on DELIVERY SOLUTIONS S.A. A security incident led to the unauthorized disclosure of personal data (name, address, telephone… ROMANIA · ·Art. 32 Jan 17, 2025
€1,500 Macelleria La Costata s.r.I.s: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on Macelleria La Costata s.r.I.s. The controller used video surveillance in its butcher's shop without installing the necessary… ITALY · ·Art. 5, 6, 13 Jan 16, 2025
€72,000 CAJA RURAL CENTRAL, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL CENTRAL, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN · ·Art. 5 Jan 16, 2025
€2,000 Municipality of Cori: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Municipality of Cori. The controller published the names of those receiving food cards intended for people in need on its… ITALY · ·Art. 6 Jan 16, 2025
€600 Pro Loco Tourist Association of Cittareale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on the Pro Loco Tourist Association of Cittareale. The controller published personal data of its members on its website without a… ITALY · ·Art. 5, 6 Jan 16, 2025
€6,000 San Pio Hospital in Benevento: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the San Pio Hospital in Benevento. The controller did not ensure that only entitled employees had access to technical… ITALY · ·Art. 5, 6, 9 Jan 16, 2025
€100,000 Realmaps S.r.l.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 100,000 on Realmaps S.r.l. The controller collects data on every real estate owner and sells it to customers who use it for direct marketing… ITALY · ·Art. 5, 6, 7 +12 Jan 16, 2025
€400,000 CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN · ·Art. 5 Jan 16, 2025
€600 BAR GIOIA: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on a BAR GIOIA. The controller installed two surveillance cameras without the necessary information signs, and the cameras were also… ITALY · ·Art. 5 Jan 16, 2025
€2,000 Alessandro Volta Classical and Scientific High School in Como: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Alessandro Volta Classical and Scientific High School in Como. The controller published the results of the state exam,… ITALY · ·Art. 5, 6 Jan 16, 2025
€175,000 Credit Institution: Insufficient fulfilment of data subjects rights The DPA of Luxembourg has issued a fine of EUR 175,000 on a Credit Institution. The controller failed to respond to information requests within the timeframe specified in Art. 12… LUXEMBOURG · ·Art. 12 Jan 6, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA · ·Art. 24, 32 Jan 3, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… Jan 1, 2025
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN · ·Art. 6, 28 Dec 23, 2024
€357,000 Panek SA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 357,000 on Panek SA. During the reconstruction of its website, the controller failed to implement adequate technical and organisational… POLAND · ·Art. 32 Dec 23, 2024
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN · ·Art. 35 Dec 20, 2024
€100,000 ATRIUM LEX SFC: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 100,000 on the real estate management company ATRIUM LEX SFC. An investor had filed a complaint with the DPA because the controller had… SPAIN · ·Art. 13, 32 Dec 18, 2024
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN · ·Art. 5 Dec 16, 2024
€18,400 Granit Bostad Beritsholm AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 18,400 on the Granit Bostad Beritsholm AB. The controller, a property management company, installed CCTV cameras in an apartment complex… SWEDEN ·Art. 6, 13 ·Insufficient legal basis for data processing Dec 11, 2024
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN · ·Art. 5, 25, 32 +1 Dec 10, 2024
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a data controller. The controller had installed a video surveillance system without adequately providing information for data… SPAIN · ·Art. 13 Dec 3, 2024
Lyngby-Taarbæk Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine between EUR 46,900 and EUR 53,600 on the Lyngby-Taarbæk Municipality. The controller failled to implement sufficient security measures resulting… DENMARK · ·Insufficient technical and organisational measures to ensure information security Nov 27, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN · ·Art. 15, 35 Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN · ·Art. 15, 35 Nov 22, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG · ·Art. 5, 6, 13 +2 Nov 20, 2024
€358,000 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted… ·Art. 5, 25, 28 +1 ·Insufficient technical and organisational measures to ensure information security Nov 20, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Nov 13, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK · ·Insufficient technical and organisational measures to ensure information security Nov 12, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN · ·Art. 5, 32 Nov 11, 2024
€1,000 MINAS DE VALDECASTILLO, S.A..: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on MINAS DE VALDECASTILLO, S.A.. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN · ·Art. 5, 13 Nov 6, 2024
€1,000 Blackcab Systems SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Blackcab Systems SRL. A individual lodged a complaint with the DPA, alleging that the controller had failed to properly respond… ROMANIA · ·Art. 12, 15 Nov 4, 2024
€15,000 Untold SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Untold SRL. During its investigation, the DPA found that the controller had failed to properly comply with a data subject's… ROMANIA · ·Art. 12, 15, 17 Oct 30, 2024
€10,000 Profi Rom Food SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 10,000 on Profi Rom Food SRL. During its investigation, the DPA found that the controller had forwarded copies of several employees' ID… ROMANIA · ·Art. 5, 6 Oct 23, 2024
€5,800 POLAND DPA: Insufficient involvement of data protection officer The Polish DPA has imposed a fine of EUR 5,800 on a data controller. The controller failed to appoint a data protection officer and to provide the DPA with the contact details in… ·Art. 37 ·Insufficient involvement of data protection officer Oct 18, 2024
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Your Consulting SRL. The controller had suffered a data breach involving the unauthorized disclosure of personal data. During… ROMANIA · ·Art. 25, 32 Oct 16, 2024
€5,000 Company: Lack of appointment of data protection officer The Austrian DPA has imposed a fine on a company. The controller appointed a DPO who had a conflict of interest, meaning the person was not suitable for the role. AUSTRIA · ·Art. 38 Oct 16, 2024
Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium · Oct 11, 2024
€5,000 ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. The controller, a law firm, published the names and photos of its… SPAIN · ·Art. 6 Oct 4, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE · ·Art. 5, 9 Sep 26, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE · ·Art. 5, 9 Sep 26, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN · ·Art. 5 Sep 26, 2024