Content type · 851 documents in this view · 3,835 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3594 Processing 2638 Personal Data 2400 Controllers 2025 Processing Agreement 1114 Security 1016 Supervision 851 Healthcare 622 Law Enforcement 568 Monitoring 551 Public Authority 540 Consent 507
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY · ·Art. 6, 32 Dec 3, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA · ·Art. 32, 33 Nov 24, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA · ·Art. 12, 15, 17 Nov 23, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Nov 19, 2020
€2,000 Anmavas 61, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning… SPAIN · ·Art. 58 Nov 18, 2020
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company had not provided the ANSPDCP with requested information. ROMANIA · ·Art. 58 Oct 20, 2020
€30,000 PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Spain · ·Art. 22 Oct 16, 2020
€3,000 S.C. Marsorom S.R.L.: Insufficient technical and organisational measures to ensure information security Disclosure of personal data of customers on the companies website due to inadequate technical and organisational measures to ensure information security. ROMANIA · ·Art. 32 Oct 15, 2020
€3,000 Megareduceri TV S.R.L.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA · ·Art. 31, 58 Oct 1, 2020
€2,000 Asociația de proprietari Militari R: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA · ·Art. 31, 58 Oct 1, 2020
€13,900 Odin Flissenter AS: Insufficient legal basis for data processing The company assessed the credibility of another company and thereby, according to Datatilsynet, processed personal data relating to a natural person (the owner of the company… NORWAY · ·Art. 5, 6 Sep 25, 2020
€2,000 Sanatatea Press Group S.R.L.: Insufficient technical and organisational measures to ensure information security Sending the personal data collected for the registration for an online course to other participants due to a technical failure. ROMANIA · ·Art. 5, 32 Sep 8, 2020
Datatilsynet (Norway)- 20/02254 The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) · ·Art. 57, 58 Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY · ·Art. 5, 32 Sep 3, 2020
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing According to the supervisory authority, the company processed personal data without sufficient legal basis, with the result that the data subject received several hundred… SPAIN · ·Art. 5, 6 Sep 1, 2020
€500 Apartment building owners association: Insufficient legal basis for data processing Export of a still image from a video surveillance system and posting of the image on the billboard of the building without sufficient legal basis. In addition, violation of the… ROMANIA · ·Art. 5, 6, 12 +3 Sep 1, 2020
€250,000 Spartoo: Non-compliance with general data processing principles A fine of EUR 250000 was imposed on the online retailer Spartoo. The reason for this was that the company, which has its headquarters in France but supplies a large number of… FRANCE · ·Art. 5, 13, 14 Aug 5, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA · ·Art. 32 Jul 30, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA · ·Art. 17 Jul 30, 2020
€4,000 Region of Campania: Insufficient legal basis for data processing Publication of an enforcement order in civil proceedings on the Region's website. The document listed the names and place of residence and the amount of the claim. ITALY · ·Art. 5, 6 Jul 29, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK · ·Art. 5 Jul 28, 2020
€5,000 SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security Unauthorised disclosure of the data of five Tarom passengers due to inadequate technical and organisational measures for secure data processing. Among other things, the company… ROMANIA · ·Art. 32 Jul 27, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority Following a complaint, Xfera Móviles was requested by the AEPD to submit certain information and documents, but did not do so within the provided time limit. SPAIN · ·Art. 58 Jul 23, 2020
€40,000 Iberia Lae SA Operadora Unipersonal: Insufficient cooperation with supervisory authority The company did not grant the data subject access to telephone records. The applicant's request for access did not receive a reply, despite the prior order of the AEPD. SPAIN · ·Art. 58 Jul 20, 2020
€22,300 Office for geodesy and cartography: Insufficient cooperation with supervisory authority Refusal of access to the premises by the supervisory authority in the course of an audit. POLAND · ·Art. 31, 58 Jul 15, 2020
€3,400 East Power Sp. z o.o.: Insufficient cooperation with supervisory authority After three subpoenas to East Power, in which the latter failed to provide sufficient explanations on a direct marketing complaint, the data protection authority found that East… POLAND · ·Art. 31, 58 Jul 10, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY · ·Art. 32, 35 Jul 10, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA · ·Art. 32 Jul 9, 2020
€830,000 Bureau Krediet Registration ('BKR'): Insufficient fulfilment of data subjects rights BKR had required the payment of a fee when individuals requested access to their personal data and only provided access to their data once a year free of charge by post. THE NETHERLANDS · ·Art. 12, 15 Jul 6, 2020
Odin Flissenter AS: Insufficient legal basis for data processing On July 2, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Odin Flissenter AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR. This fine has been… NORWAY · ·Art. 5, 6 Jul 2, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company had not cooperated sufficiently with the data protection authority. SPAIN · ·Art. 31, 58 Jul 2, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY · ·Art. 32 Jun 22, 2020
Aquateknikk AS: Insufficient legal basis for data processing On June 19, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Aquateknikk AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR . This fine has been… NORWAY · ·Art. 5, 6 Jun 19, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA · ·Art. 32 Jun 18, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS · ·Art. 33 Jun 16, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jun 11, 2020
€4,000 Iberdrola Clientes: Insufficient cooperation with supervisory authority The company was asked to provide the AEPD with specific information in relation to a complaint. However, the company had not replied to the data protection authorities request for… SPAIN · ·Art. 58 Jun 4, 2020
€1,168 Entrepreneur running a non-public nursery and pre-school: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. POLAND · ·Art. 31, 58 Jun 3, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA · ·Art. 32 May 5, 2020
€134,000 Telenor Norge AS: Insufficient technical and organisational measures to ensure information security Fines for security breaches in a voice mailbox function. NORWAY · ·Art. 32 May 3, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS · ·Art. 5, 9 Apr 30, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Apr 23, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Apr 23, 2020
€3,000 Dante International: Insufficient legal basis for data processing The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. ROMANIA · ·Art. 6, 21 Mar 25, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company did not provide the data protection authority with the requested information in a timely manner. The AEPD's request was preceded by a request from a data subject for… SPAIN · ·Art. 58 Mar 25, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA · ·Art. 32 Mar 25, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA · ·Art. 58 Mar 25, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS · ·Art. 9, 32 Mar 24, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN · ·Art. 58 Mar 18, 2020