Skip to content
Content type · 2,802 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

701–750 of 2,802 sort newestlargest fineoldest
€15M OpenAI OpCo LLC: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15 million on OpenAI in connection with the operation of the generative AI chatbot “ChatGPT”. The DPA found that OpenAI had violated… ITALY ·Garante ·Art. 5, 6, 12 +4 Fairness & Transparency IP Address Transparency Nov 2, 2024
€4,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined GESTIÓN DE VENTAS IBERIA S.L. EUR 4000 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€12,000 NEGOCIOS R&R 2020 S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined NEGOCIOS R&R 2020 S.L. EUR 12,000 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€900 RIVENDELL TECHNOLOGY, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 900 on RIVENDELL TECHNOLOGY, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€15,000 Untold SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Untold SRL. During its investigation, the DPA found that the controller had failed to properly comply with a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Processing Agreement Oct 30, 2024
€5,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA fined Vodafone Romania S.A. EUR 5,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Telecommunications IP Address Security Oct 28, 2024
€310M LinkedIn: Insufficient legal basis for data processing The Irish DPA (DPC) has fined LinkedIn EUR 310 million. This decision is related to an investigation following a complaint in 2018 from the French NGO 'La Quadrature Du Net'. In… Art. 60 Social Media Direct Marketing Processing Agreement Oct 24, 2024
€10,000 Profi Rom Food SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 10,000 on Profi Rom Food SRL. During its investigation, the DPA found that the controller had forwarded copies of several employees' ID… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Employees Processing Agreement Oct 23, 2024
€180,000 IBERCAJA BANCO, S.A.: Insufficient legal basis for data processing The Spanish DPA has fined IBERCAJA BANCO, S.A. for unlawfully accessing a customer’s credit file after the termination of their contractual relationship. The DPA concluded that… SPAIN ·aepd ·Art. 6 Insurance IP Address Processing Agreement Oct 22, 2024
€20,800 Grue municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA fined Grue municipality EUR 20,800 following the municipality's notification of a data breach. The municipality reported that personal data of students had been… NORWAY ·Datatilsynet ·Art. 24, 32 Data Breaches Security Education Oct 21, 2024
€5,800 POLAND DPA: Insufficient involvement of data protection officer The Polish DPA has imposed a fine of EUR 5,800 on a data controller. The controller failed to appoint a data protection officer and to provide the DPA with the contact details in… UODO ·Art. 37 ·Insufficient involvement of data protection officer Controllers Supervisory Authorities Processing Oct 18, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individual had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6 Telecommunications Personal Data Processing Agreement Oct 18, 2024
€9,000 Vilnius District Municipality Administration: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has imposed a fine of EUR 1,000 on the Vilnius District Municipality Administration. The Municipality Administration had been hacked. The attack resulted in… LITHUANIA ·VDAI ·Art. 5, 32, 34 Security Public Authority Public Sector Oct 18, 2024
€1,000 KUR KLINIKUM, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1000 on KUR KLINIKUM, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 17, 2024
€5,000 Company: Lack of appointment of data protection officer The Austrian DPA has imposed a fine on a company. The controller appointed a DPO who had a conflict of interest, meaning the person was not suitable for the role. AUSTRIA ·dsb ·Art. 38 Notified Body Responsibilities and Operational Obligations Supervisory Authorities Controllers Oct 16, 2024
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Your Consulting SRL. The controller had suffered a data breach involving the unauthorized disclosure of personal data. During… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Oct 16, 2024
€900 Private individual: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 900 on a private individual for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 4, 2024
€5,000 ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. The controller, a law firm, published the names and photos of its… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement Oct 4, 2024
€600 VOLTIUM CONSULTORES 2020: Insufficient cooperation with supervisory authority The Spanish DPA has fined VOLTIUM CONSULTORES 2020 EUR 600 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 4, 2024
€91M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 91 million on Meta Platforms Ireland Limited (MPIL). The DPC had initiated an investigation after MPIL reported that user passwords… Encryption Data Breaches Security Sep 27, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·aepd ·Art. 5 Telecommunications IP Address Security Sep 26, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers IP Address Prior Consultation Sep 26, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers Processors Direct Marketing Sep 26, 2024
€4,000 CI & DI Food s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA imposed a fine of EUR 4,000 against CI & DI Food s.r.l. for failing to comply with a former employee's request for access to their personal data. ITALY ·Garante ·Art. 12, 15 Personal Data Employees Supervisory Authorities Sep 26, 2024
€2,000 PPC ENERGIE MUNTENIA S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on PPC ENERGIE MUNTENIA S.A. for failing to respond to a data subject's request for the deletion of their personal data in a… ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Processing Agreement Supervisory Authorities Sep 23, 2024
€1,400 Attorney: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 1,400 on an attorney. An individual had filed a complaint with the DPA because the controller did not adequately respond to their… GREECE ·HDPA ·Art. 12, 31 Personal Data Controllers Supervisory Authorities Sep 23, 2024
€3,000 Constanța South Container Terminal SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Constanța South Container Terminal SRL. The controller had suffered a data breach in which personal data of employees had been… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Sep 17, 2024
€3,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on Vodafone România SA for failing to respond to a data subject's request for access and deletion of their personal data in a… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Telecommunications Processing Agreement Sep 16, 2024
€1,000 SC Class IT Outsourcing SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on SC Class IT Outsourcing SRL for failing to respond to a data subject's request for the deletion of their personal data in a… ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Processing Agreement Supervisory Authorities Sep 16, 2024
€35,700 Company: €35,700 fine The Croatian DPA (AZOP) has imposed fines totaling EUR 35,700 on nine companies for failing to adequately indicate their video surveillance areas and for failing to provide all… CROATIA ·azop ·Unknown Video Surveillance Fines Monitoring Sep 13, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·azop ·Art. 5, 6, 12 +4 Data Breaches Healthcare Healthcare Sep 13, 2024
€45,000 Hotel: €45,000 fine The Croatian DPA (AZOP) has imposed a fine of EUR 45,000 on two hotels for unlawfully processing personal data through the use of cookies. CROATIA ·azop ·Unknown Cookies Personal Data Processing Agreement Sep 13, 2024
€842,062 Sky Italia S.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Sky Italia EUR 842,062 for unlawful telemarketing. The investigation revealed that Sky contacted individuals without proper consent, including those… ITALY ·Garante ·Art. 5, 6, 130 Direct Marketing Telecommunications Right to Object Sep 12, 2024
€400 Private individual: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 400 on a private individual. The individual had installed video surveillance cameras, which however also recorded parts of neighboring… ITALY ·Garante ·Art. 5, 6 Video Surveillance Monitoring Processing Sep 12, 2024
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE ·CNIL ·Art. 5, 66 Anonymization Healthcare IP Address Sep 12, 2024
€5,000 Top Quality Corporation s.r.l.s.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Top Quality Corporation s.r.l.s. A data subject (former emplyee) had filed a complaint with the DPA due to the controller's… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Employees Sep 12, 2024
€600 KVIKU SPAIN, S.L: Insufficient cooperation with supervisory authority The Spanish DPA has fined KVIKU SPAIN, S.L. EUR 600 for failing to provide information requested by the DPA. aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Sep 11, 2024
€20,900 Eidskog municipality: Insufficient legal basis for data processing The Norwegian DPA imposed a fine of EUR 20,900 on Eidskog municipality for giving two former employees access to a whistleblower’s report without redacting sensitive health and… NORWAY ·Datatilsynet ·Art. 6 Education Public Authority Healthcare Sep 6, 2024
€3,000 PLAY FUL KIDS, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 3,000 on PLAY FUL KIDS, S.L. due to an incident that occurred during a children's birthday party on the premises of the controller involving… SPAIN ·aepd ·Art. 6 Controllers Monitoring Processing Sep 5, 2024
€3,000 Senira Limited: Insufficient cooperation with supervisory authority The Cypriot DPA fined Senira Limited EUR 3,000 for failing to sufficiently cooperate with the DPA. CYPRUS ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Sep 4, 2024
€12,700 University of Agder: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the University of Agder (UiA) EUR 12,700. An employee of UiA had discovered that documents containing personal data of employees, students and external… NORWAY ·Datatilsynet ·Art. 24, 32 Personal Data Security Education Sep 4, 2024
€19,800 National Prosecutor's Office: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 19,800 on the National Prosecutor's Office. During a press conference, the public prosecutor's office disclosed an individual's personal… POLAND ·UODO ·Art. 6, 9, 33 +1 Data Breaches Personal Data Public Authority Sep 2, 2024
€4,500 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 4,500 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Aug 30, 2024
€698,000 Apohem AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 698,000 on Apohem AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Social Media Security Healthcare Aug 29, 2024
€3.2M Apoteket AB.: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 3.2 million on Apoteket AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Social Media Security Privacy by Design & Default Aug 29, 2024
€50,000 SANTANDER CONSUMER FINANCE, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 50,000 on SANTANDER CONSUMER FINANCE, S.A.. The fine followed a complaint from an individual who received advertising from the company,… SPAIN ·aepd ·Art. 6 Personal Data Controllers Insurance Aug 22, 2024
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Aug 20, 2024
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Notification Obligation Data Breaches Recipient Aug 20, 2024
€1.5M IKEA: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 1,500,000 on IKEA. The controller used excessive video surveillance, including in public spaces and the checkout area. Additionally, the… AUSTRIA ·dsb ·Art. 5, 6 Video Surveillance Monitoring Controllers Aug 16, 2024
€1.5M Company: €1,500,000 fine The Austrian DPA has imposed a fine of EUR 1,500,000 on a company, that is part of a group. The controller installed video surveillance devices that did not comply with the GDPR,… AUSTRIA ·dsb ·Unknown Video Surveillance Monitoring Controllers Aug 16, 2024