Skip to content
Content type · 851 documents in this view · 3,835 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

751–800 of 851 sort newestlargest fineoldest
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet (NO) ·Art. 6, 32 Personal Data Security Public Authority Dec 3, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Personal Data Supervisory Authorities Nov 24, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Supervisory Authorities Supervision Nov 23, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Fairness & Transparency Integrity and Confidentiality Principle Nov 19, 2020
€2,000 Anmavas 61, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Right to be Forgotten Nov 18, 2020
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company had not provided the ANSPDCP with requested information. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Oct 20, 2020
€30,000 PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Spain ·AEPD ·Art. 22 Consent Personal Data Supervisory Authorities Oct 16, 2020
€3,000 S.C. Marsorom S.R.L.: Insufficient technical and organisational measures to ensure information security Disclosure of personal data of customers on the companies website due to inadequate technical and organisational measures to ensure information security. ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 15, 2020
€3,000 Megareduceri TV S.R.L.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA ·ANSPDCP ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Oct 1, 2020
€2,000 Asociația de proprietari Militari R: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA ·ANSPDCP ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Oct 1, 2020
€13,900 Odin Flissenter AS: Insufficient legal basis for data processing The company assessed the credibility of another company and thereby, according to Datatilsynet, processed personal data relating to a natural person (the owner of the company… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Processing Supervision Sep 25, 2020
€2,000 Sanatatea Press Group S.R.L.: Insufficient technical and organisational measures to ensure information security Sending the personal data collected for the registration for an online course to other participants due to a technical failure. ROMANIA ·ANSPDCP ·Art. 5, 32 Security Personal Data Processing Sep 8, 2020
Datatilsynet (Norway)- 20/02254 The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Datatilsynet (NO) ·Art. 57, 58 Telecommunications Supervision Supervisory Authorities Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Personal Data Security Public Authority Sep 3, 2020
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing According to the supervisory authority, the company processed personal data without sufficient legal basis, with the result that the data subject received several hundred… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Sep 1, 2020
€500 Apartment building owners association: Insufficient legal basis for data processing Export of a still image from a video surveillance system and posting of the image on the billboard of the building without sufficient legal basis. In addition, violation of the… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +3 Personal Data Security Processing Sep 1, 2020
€250,000 Spartoo: Non-compliance with general data processing principles A fine of EUR 250000 was imposed on the online retailer Spartoo. The reason for this was that the company, which has its headquarters in France but supplies a large number of… FRANCE ·CNIL ·Art. 5, 13, 14 Retention Period Supervision Personal Data Aug 5, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA ·ANSPDCP ·Art. 32 Security Pseudonymization Anonymization Jul 30, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Insurance Supervision Jul 30, 2020
€4,000 Region of Campania: Insufficient legal basis for data processing Publication of an enforcement order in civil proceedings on the Region's website. The document listed the names and place of residence and the amount of the claim. ITALY ·Garante ·Art. 5, 6 Processing Public Authority Supervision Jul 29, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK ·Datatilsynet (DK) ·Art. 5 Retention Period Personal Data Processing Jul 28, 2020
€5,000 SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security Unauthorised disclosure of the data of five Tarom passengers due to inadequate technical and organisational measures for secure data processing. Among other things, the company… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Jul 27, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority Following a complaint, Xfera Móviles was requested by the AEPD to submit certain information and documents, but did not do so within the provided time limit. SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Telecommunications Jul 23, 2020
€40,000 Iberia Lae SA Operadora Unipersonal: Insufficient cooperation with supervisory authority The company did not grant the data subject access to telephone records. The applicant's request for access did not receive a reply, despite the prior order of the AEPD. SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Jul 20, 2020
€22,300 Office for geodesy and cartography: Insufficient cooperation with supervisory authority Refusal of access to the premises by the supervisory authority in the course of an audit. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Jul 15, 2020
€3,400 East Power Sp. z o.o.: Insufficient cooperation with supervisory authority After three subpoenas to East Power, in which the latter failed to provide sufficient explanations on a direct marketing complaint, the data protection authority found that East… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Personal Data Jul 10, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet (NO) ·Art. 32, 35 DPIA Security Types of Special Categories of Personal Data Jul 10, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Jul 9, 2020
€830,000 Bureau Krediet Registration ('BKR'): Insufficient fulfilment of data subjects rights BKR had required the payment of a fee when individuals requested access to their personal data and only provided access to their data once a year free of charge by post. THE NETHERLANDS ·AP ·Art. 12, 15 Personal Data Supervision Supervisory Authorities Jul 6, 2020
Odin Flissenter AS: Insufficient legal basis for data processing On July 2, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Odin Flissenter AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR. This fine has been… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Processing Supervisory Authorities Supervision Jul 2, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company had not cooperated sufficiently with the data protection authority. SPAIN ·AEPD ·Art. 31, 58 Supervisory Authorities Supervision Telecommunications Jul 2, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Personal Data Health Data Jun 22, 2020
Aquateknikk AS: Insufficient legal basis for data processing On June 19, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Aquateknikk AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR . This fine has been… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Processing Supervisory Authorities Supervision Jun 19, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Supervision Jun 18, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 16, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Jun 11, 2020
€4,000 Iberdrola Clientes: Insufficient cooperation with supervisory authority The company was asked to provide the AEPD with specific information in relation to a complaint. However, the company had not replied to the data protection authorities request for… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Jun 4, 2020
€1,168 Entrepreneur running a non-public nursery and pre-school: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Data Breaches Jun 3, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance May 5, 2020
€134,000 Telenor Norge AS: Insufficient technical and organisational measures to ensure information security Fines for security breaches in a voice mailbox function. NORWAY ·Datatilsynet (NO) ·Art. 32 Security Telecommunications Fines May 3, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS ·AP ·Art. 5, 9 Consent Personal Data Processing Apr 30, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Privacy by Design & Default Apr 23, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ANSPDCP ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Personal Data Healthcare Types of Special Categories of Personal Data Apr 23, 2020
€3,000 Dante International: Insufficient legal basis for data processing The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. ROMANIA ·ANSPDCP ·Art. 6, 21 Personal Data Processing Supervision Mar 25, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company did not provide the data protection authority with the requested information in a timely manner. The AEPD's request was preceded by a request from a data subject for… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Personal Data Mar 25, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Mar 25, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Mar 25, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS ·AP ·Art. 9, 32 Security Healthcare Controllers Mar 24, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 18, 2020