Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

751–800 of 2,395 sort newestlargest fineoldest
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Privacy by Design & Default Personal Data Jul 4, 2024
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA ·VDAI ·Art. 5, 12 Transparency Accountability Controllers Jul 2, 2024
€50,000 METRO SA: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 50,000 on METRO SA. A former employee had sent text messages to the private mobile phone of a customer who had a user account in the… GREECE ·HDPA ·Art. 15, 17, 24 +2 Security Personal Data Controllers Jun 27, 2024
€80,000 AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A. y SEUR GEOPOST, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A. y SEUR GEOPOST, S.L.. The controller had suffered a security incident which, according to… SPAIN ·AEPD ·Art. 32 Security Controllers Personal Data Jun 26, 2024
€1,000 Rețele Electrice Dobrogea SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Rețele Electrice Dobrogea SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 25, 2024
€150,000 BANCO CETELEM, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO CETELEM, S.A.. A person had filed a complaint against the controller with the DPA due to the fact that debits had been made from their… SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Insurance Jun 25, 2024
€3,000 Rețele Electrice Muntenia SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Rețele Electrice Muntenia SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 25, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 24, 2024
€10,000 TS Food Processing s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on TS Food Processing s.r.l.. A data subject (former emplyee) had filed a complaint with the DPA due to the controller's failure… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Jun 20, 2024
€4,000 Medical association: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,000 on the medical association 'Ordine dei Medici Chirurghi e degli Odontoiatri'. A patient had filed a complaint with the DPA. During… ITALY ·Garante ·Art. 12, 13, 15 Personal Data Controllers Supervisory Authorities Jun 20, 2024
€20,000 Municipality of Nepi: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 on the municipality of Nepi. The controller had published a document containing the ranking list of a pre-selection test for a… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Controllers Supervisory Authorities Jun 20, 2024
€3,000 20 AÑOS DE MÚSICA A.I.E.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on 20 AÑOS DE MÚSICA A.I.E.. A person had filed a complaint with the DPA due to the fact that in order for minors to attend concerts organized… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jun 17, 2024
€3,000 DQG NORTE A.I.E: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on DQG NORTE A.I.E.. A person had filed a complaint with the DPA due to the fact that in order for minors to attend concerts organized by the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jun 13, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND ·UODO ·Art. 24, 25, 32 +1 Security Privacy by Design & Default Controllers Jun 13, 2024
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A data subject had filed a complaint with the DPA because the controller had proposed to a credit… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Jun 12, 2024
€160,000 ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A person had filed a complaint with the DPA because their ex-partner had been given… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Jun 10, 2024
€100,000 NATURGY IBERIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 100,000 on NATURGY IBERIA, S.A.. A customer had filed a complaint with the DPA because an amendment had been made to their electricity… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Consent Jun 10, 2024
€500 Comune di Ustica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500 on Comune di Ustica. The municipality had published a document, containing personal data (including health data) of private… ITALY ·Garante ·Art. 2, 5, 6 +2 Public Authority Types of Special Categories of Personal Data Healthcare Jun 6, 2024
€100,000 Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data… AUSTRIA ·DSB ·Art. 5, 9, 28 +2 Data Breaches Controllers Processors Jun 6, 2024
€6.4M Eni Plenitude S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6.419.631 on Eni Plenitude S.p.A.. The DPA initiated an investigation against the controller due to 107 notifications and 8 complaints… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Personal Data Jun 6, 2024
€1M CA Autobank S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1 million on CA Autobank S.p.A. A person had filed a complaint with the DPA because a rental car voucher had been refused due to his… ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Processing Agreement Jun 6, 2024
€120,000 Cappello Giovanni & Figli s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 120,000 on Cappello Giovanni & Figli s.r.l.. The controller had used facial recognition technology to monitor the attendance of… ITALY ·Garante ·Art. 5, 6, 9 +1 Types of Special Categories of Personal Data Controllers Consent Jun 6, 2024
FRANCE DPA: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine on a controller for not sufficiently respecting data subjects' rights (exercising the right of access to a medical file). CNIL ·Insufficient fulfilment of data subjects rights Supervisory Authorities Right of Access Inspection Access Rights and Cooperation Obligations Jun 5, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jun 5, 2024
Company: Non-compliance with general data processing principles The French DPA has imposed a fine on a company. The company published a promotional video on its website and social networks in which images of patient files of one of its… FRANCE ·CNIL ·Art. 5 Personal Data Processing Direct Marketing Jun 5, 2024
€180 Website operator: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the operator of a website for storing data of a data subject for an excessively long period of time and contrary to the principle of storage… SPAIN ·AEPD ·Art. 5 Retention Period Storage Limitation Personal Data Jun 5, 2024
€6,000 Ambitious People Group B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 6,000 on the recruitment company Ambitious People Group B.V. . The controller had not deleted the data of data subjects after they had… THE NETHERLANDS ·AP ·Art. 12, 17 Personal Data Controllers Supervisory Authorities Jun 4, 2024
€600,000 GSMA Limited: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 600,000 on GSMA Limited. In 2022, GSMA Limited required employees of its suppliers to register on an online platform and upload proof of… SPAIN ·AEPD ·Art. 6, 9, 14 Personal Data Supervisory Authorities Processing May 31, 2024
€4,200 PILLOW HOTELS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PILLOW HOTELS, S.L.. A person had filed a complaint with the DPA. The individual had made a booking for an overnight stay with the controller… SPAIN ·AEPD ·Art. 5, 32, 33 Data Breaches Controllers Personal Data May 30, 2024
€2,000 Corint Logistic SRL.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Corint Logistic SRL. A customer had filed a complaint with the DPA because they had received advertising text messages from the… ROMANIA ·ANSPDCP ·Art. 5, 17, 21 Right to be Forgotten Personal Data Direct Marketing May 30, 2024
€70,000 CAIXABANK S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK S.A.. A person had filed a complaint with the DPA because an employee of the controller had accidentally disclosed… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing May 28, 2024
€400,000 Ministry of Interior (Greece): Insufficient technical and organisational measures to ensure information security The Hellenic DPA imposed a fine of EUR 400,000 on the Ministry of Interior for leaking email addresses from the voter registry of Greek expatriates. These personal data, which… HDPA ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Education May 27, 2024
€600 President of a workers' council: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the president of the workers' council of a company following a complaint by a former employee. During their employment, the company carried… SPAIN ·AEPD ·Art. 5 Personal Data Processing Employees May 23, 2024
€3,500 Professional association: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 3,500 on a professional association. An individual had filed a complaint with the DPA, for the unlawful publication of their personal… ITALY ·Garante ·Art. 2, 5, 6 +1 Public Authority Personal Data Processing May 23, 2024
€4,500 Azienda Socio-sanitaria Territoriale Rhodense: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,500 on Azienda Socio-sanitaria Territoriale Rhodense. An individual had filed a complaint with the DPA because the controller had not… ITALY ·Garante ·Art. 5, 12, 16 Personal Data Controllers Supervisory Authorities May 23, 2024
€336,000 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 336,000 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During… POLAND ·UODO ·Art. 5, 32 Security Personal Data Privacy by Design & Default May 20, 2024
APD/GBA · 74/2024 On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data… 74/2024 ·Belgium ·Art. 6 Legitimate Interest Personal Data Marketing May 16, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… AP Transparency Personal Data Representatives May 16, 2024
€1,600 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a homeowners' association. A person had filed a complaint with the DPA due to the fact that the data controller had published a picture with… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Processing May 9, 2024
€2,000 IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data May 9, 2024
€10,000 Azzurro Club Hotels S.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on Azzurro Club Hotels S.r.l.. The controller had sent a data subject unsolicited advertising e-mail and failed to respond… ITALY ·Garante ·Art. 6, 12, 15 +1 Personal Data Controllers Supervisory Authorities May 9, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Healthcare May 9, 2024
€3,000 Polisportiva Mimmo Ferrito s.r.l..: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 3,000 on Polisportiva Mimmo Ferrito s.r.l.. A data subject had filed a complaint with the DPA due to the controller's failure to respond… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 8, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·AEPD ·Art. 32, 33 Data Breaches Security Personal Data May 8, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… AEPD ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data May 7, 2024
€1,200 ARRENDAMIENTOS DEUDORES, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ARRENDAMIENTOS DEUDORES, S.L.. The controller had carried out a credit check on the data subject without any valid legal basis for this. The… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance May 7, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS ·AP ·Art. 5 Personal Data Controllers Processing May 2, 2024
€210 Association: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an association EUR 210 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 30, 2024
€1,200 DELPASO CAR HIRE, S.L.U.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on DELPASO CAR HIRE, S.L.U.. A data subject had filed a complaint against the controller with the DPA due to the controller's failure to… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Apr 30, 2024