Skip to content
Content type · 1,013 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

751–800 of 1,013 sort newestlargest fineoldest
DSB Austria: Publishing companies-register data on free ad-funded platform unlawful The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered… 2021-0.698.184 ·Art. 6, 51, 57 +1 Legitimate Interest Personal Data Lawful Basis Oct 8, 2021
€5,000 CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L. EUR 5,000 for unlawfully processing an individual's data. Previously, CYNGASA, S.L. had… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Oct 4, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 29, 2021
€5,000 CYNGASA, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on CYNGASA, S.L.. The data subject, when requesting a work report, discovered that the controller had disclosed his personal… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Sep 29, 2021
€3,000 Bar owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a bar owner EUR 3,000. A data subject had filed a complaint with the DPA. He had suffered an accident in the bar which was recorded by the… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Sep 28, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet (NO) ·Art. 5, 28, 32 +1 Processors Controllers International Transfer Sep 27, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet (NO) ·Art. 32 Data Breaches Security Personal Data Sep 20, 2021
€18,000 CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Controllers Sep 20, 2021
€75,600 ST. OLAVS HOSPITAL HF: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Supervisory Authorities Supervision Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 17, 2021
€5,000 Ciechi Ardizzone Gioeni di Catania: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Ciechi Ardizzone Gioeni di Catania residential home for blind people. A visitor to the residence filed a complaint… ITALY ·Garante ·Art. 5, 12, 13 +1 Integrity and Confidentiality Principle Retention Period Monitoring Sep 16, 2021
€10,000 Favrskov municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 16, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Personal Data Supervisory Authorities Sep 8, 2021
€25,000 Hellenic Technical Enterprises Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 25,000 on Hellenic Technical Enterprises Ltd.. The controller hat designed the ticket sales system of the soccer clubs AC Omonia and… CYPRUS ·Cyprus DPA ·Art. 32 Security Controllers Personal Data Sep 6, 2021
€40,000 AC Omonia: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club AC Omonia. Due to a lack of security measures in the club's ticket sales system, it was possible for an… CYPRUS ·Cyprus DPA ·Art. 32 Security Personal Data Supervisory Authorities Sep 6, 2021
€40,000 APOEL FC: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club APOEL FC. Due to a lack of security measures in the club's ticket sales system, it was possible for an… CYPRUS ·Cyprus DPA ·Art. 32 Security Personal Data Supervisory Authorities Sep 6, 2021
€4,000 Automecanica Jerez, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Automecanica Jerez, S.L. EUR 4,000. The controller had sent commercial e-mails to a large number of people without their consent. In doing so, the… SPAIN ·AEPD ·Art. 5, 21, 32 Security Personal Data Controllers Sep 2, 2021
€120,000 Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. The reason for this had been a complaint from a person relating to a lack of authentication.… SPAIN ·AEPD ·Art. 32 Security Personal Data Privacy by Design & Default Aug 25, 2021
€3,000 Actamedica SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has fined Actamedica SRL EUR 3,000. The controller had informed a private individual about the loss of her biological samples and a sum of money sent… ROMANIA ·ANSPDCP ·Art. 28, 32, 33 Data Breaches Security Personal Data Aug 24, 2021
€1,800 Agency: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on an agency. The controller had disposed of documents containing personal data of its clients in the garbage. The AEPD considered this… SPAIN ·AEPD ·Art. 32 Security Controllers Processors Aug 23, 2021
€1,500 MOVE Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data Aug 20, 2021
€20,100 Danish Immigration Agency: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 20,100 on the Danish Immigration Agency. Media reports brought the DPA's attention to possible logging errors in one of the agency's IT… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Security Privacy by Design & Default Public Authority Aug 17, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND ·UODO ·Art. 5, 25, 32 Encryption Security Personal Data Aug 13, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·DSB ·Art. 9 Personal Data Processors Legitimate Interest Aug 5, 2021
€135,000 Insurance company: Insufficient technical and organisational measures to ensure information security The DPA of Luxembourg has imposed a fine of EUR 135,000 on an insurance company. On October 19, 2018, an employee of the controller had sent an e-mail to an uninvolved third party… LUXEMBOURG ·CNPD (LU) ·Art. 5, 32, 33 Data Breaches Security Controllers Aug 5, 2021
€3,000 Club Náutico el Estacio: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on Club Náutico el Estacio. A data subject filed a complaint against the controller with the AEPD. The complaint is based on… SPAIN ·AEPD ·Art. 32 Personal Data Controllers Security Aug 2, 2021
€3,000 UST GLOBAL ESPAÑA, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on UST GLOBAL ESPAÑA, S.A.. An employee filed a complaint against the controller with the DPA. UST GLOBAL ESPAÑA, S.A. was… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Security Jul 27, 2021
€400,000 Monsanto Company: Insufficient fulfilment of information obligations The French DPA (CNIL) has fined MONSANTO EUR 400,000. In May 2019, several media revealed that MONSANTO was in possession of a file containing the personal data of more than 200… FRANCE ·CNIL ·Art. 14, 28 Processors Controllers Personal Data Jul 26, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Integrity and Confidentiality Principle Controllers Processors Jul 22, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 +1 Integrity and Confidentiality Principle Retention Period Storage Limitation Jul 22, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… Garante ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles Privacy by Design & Default DPIA Controllers Jul 22, 2021
APDCAT advises Catalan draft law transposing EU 2019/1153 lacks data minimization and The Catalan DPA issued an opinion at the request of the Ministry of the Interior in order to evaluate the Law proposal that will transpose the Directive (EU) 2019/1153, laying… PD 6/2021 ·Spain ·Art. 7 Personal Data Retention Period Types of Special Categories of Personal Data Jul 22, 2021
€67,900 Region of Syddanmark: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has fined the Region of Syddanmark EUR 67,900 for failing to comply with its obligation as a data controller to implement adequate security measures.… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Personal Data Controllers Jul 16, 2021
€50,000 Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 50,000 on Caixabank S.A.. A data subject had filed a complaint with the DPA because he had received commercial advertising from… SPAIN ·AEPD ·Art. 6 Personal Data Right to Object Direct Marketing Jul 8, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Jul 5, 2021
€29,000 Mermaids: Insufficient technical and organisational measures to ensure information security The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR.… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Encryption Pseudonymization Jul 5, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Jun 16, 2021
€34,000 Huppuís ehf: Non-compliance with general data processing principles The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 34,000 on Huppuís ehf. A former employee filed a complaint against the controller with the DPA. The reason for this was… ICELAND ·Persónuvernd ·Art. 5, 6, 12 +1 Legitimate Interest Controllers Supervisory Authorities Jun 15, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Retention Period Personal Data Jun 14, 2021
€40,000 aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 28, 32 Security Encryption Controllers Jun 10, 2021
€2.6M Foodinho s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Foodinho s.r.l. EUR 2,600,000. Foodinho is an Italian food delivery service. The investigation against Foodinho mainly focused on the drivers… ITALY ·Garante ·Art. 5, 13, 22 +5 Retention Period Privacy by Design & Default DPIA Jun 10, 2021
€40,000 Aeroporto Guglielmo Marconi di Bologna S.p.a.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Encryption Jun 10, 2021
€19,600 Radiotelevisión del principado de Asturias: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 26,000 on Radiotelevisión del principado de Asturias. The fine consists of EUR 20,000 due to a violation of Art. 5 (1) c) GDPR and… SPAIN ·AEPD ·Art. 5, 12 Retention Period Controllers Supervisory Authorities Jun 7, 2021
€50,000 Region Stockholm: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13, 14 Supervisory Authorities Personal Data Security Jun 7, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·IMY ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Personal Data Encryption Jun 7, 2021
€25,000 Region Värmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Värmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€25,000 Region Sörmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Sörmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jun 7, 2021
€49,200 Moss municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Personal Data Public Authority Jun 4, 2021
€450,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen) EUR 450,000. The UWV had not properly secured the… THE NETHERLANDS ·AP ·Art. 32 Security Insurance Healthcare May 31, 2021