Skip to content
Content type · 1,114 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

751–800 of 1,114 sort newestlargest fineoldest
€3,000 Senira Limited: Insufficient cooperation with supervisory authority The Cypriot DPA fined Senira Limited EUR 3,000 for failing to sufficiently cooperate with the DPA. CYPRUS ·Cyprus DPA ·Art. 31 Supervisory Authorities Supervision Processing Agreement Sep 4, 2024
€4,500 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 4,500 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Aug 30, 2024
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 20, 2024
€1.5M The Austrian DPA has imposed a fine of EUR 1,500,000 on a company, that is part of a group The controller installed video surveillance devices that did not comply with the GDPR, resulting in the company being fined. Company: €1,500,000 fine ·AUSTRIA ·DSB Monitoring Video Surveillance Controllers Aug 16, 2024
€1.5M IKEA: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 1,500,000 on IKEA. The controller used excessive video surveillance, including in public spaces and the checkout area. Additionally, the… AUSTRIA ·DSB ·Art. 5, 6 Controllers Processing Video Surveillance Aug 16, 2024
€270,000 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA. An individual who provided services to the controller filed a complaint with the DPA due to the fact… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Aug 12, 2024
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual for installing video surveillance cameras without a valid legal basis. SPAIN ·AEPD ·Art. 6 Video Surveillance Monitoring Supervisory Authorities Aug 6, 2024
€1,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual EUR 1,000. The controller had uploaded images from their video surveillance camera to Instagram showing, amongst others, a minor and… SPAIN ·AEPD ·Art. 6 Controllers Social Media Video Surveillance Aug 6, 2024
€80,000 Selectra S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access… ITALY ·Garante ·Art. 5, 13, 88 +1 Storage Limitation Retention Period Controllers Jul 17, 2024
€5M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5 million on Hera Comm S.p.A. The investigation was launched following numerous complaints. The energy supplier had failed to take… ITALY ·Garante ·Art. 5, 12, 15 +3 Controllers Personal Data Supervisory Authorities Jul 17, 2024
€30,000 Pere Sihtkapital SA: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 30,000 on Pere Sihtkapital SA. The controller conducted a survey on childless families. In the process, the controller failed to take all… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Jul 15, 2024
€600 ASSOCIACIO CANNABICA DEL MARESME ACANNAM: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on ASSOCIACIO CANNABICA DEL MARESME ACANNAM. The controller had installed video surveillance cameras which, among other… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jul 11, 2024
€5,000 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 5,000 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Jul 10, 2024
€10,000 Clinic owner: Insufficient legal basis for data processing The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the… SPAIN ·AEPD ·Art. 6, 9 Consent Healthcare Controllers Jul 5, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Privacy by Design & Default Personal Data Jul 4, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 24, 2024
€1M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1 million on Fastweb S.p.A. due to unauthorized telemarketing, the unlawful storage of customer data after contract termination, and… ITALY ·Garante ·Art. 5, 6, 7 +13 Direct Marketing Storage Limitation Right to Object Jun 20, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND ·UODO ·Art. 24, 25, 32 +1 Security Privacy by Design & Default Controllers Jun 13, 2024
€100,000 Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data… AUSTRIA ·DSB ·Art. 5, 9, 28 +2 Data Breaches Controllers Processors Jun 6, 2024
€6.4M Eni Plenitude S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6.419.631 on Eni Plenitude S.p.A.. The DPA initiated an investigation against the controller due to 107 notifications and 8 complaints… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Personal Data Jun 6, 2024
€1M CA Autobank S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1 million on CA Autobank S.p.A. A person had filed a complaint with the DPA because a rental car voucher had been refused due to his… ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Processing Agreement Jun 6, 2024
€600,000 GSMA Limited: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 600,000 on GSMA Limited. In 2022, GSMA Limited required employees of its suppliers to register on an online platform and upload proof of… SPAIN ·AEPD ·Art. 6, 9, 14 Personal Data Supervisory Authorities Processing May 31, 2024
€40,000 Member of the European Parliament: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 40,000 on a Member of the European Parliament. The fine was imposed due to their misuse of email addresses, leaked from the voter… GREECE ·HDPA ·Art. 5, 6, 14 Supervisory Authorities Processing Education May 27, 2024
€400,000 Ministry of Interior (Greece): Insufficient technical and organisational measures to ensure information security The Hellenic DPA imposed a fine of EUR 400,000 on the Ministry of Interior for leaking email addresses from the voter registry of Greek expatriates. These personal data, which… HDPA ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Education May 27, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which also recorded the entrance area of the… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance May 14, 2024
€8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers IP Address Apr 30, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Security Encryption Privacy by Design & Default Apr 29, 2024
€100,000 Facile.Energy S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Facile.Energy S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Personal Data Apr 11, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Processing Apr 11, 2024
€525,000 HUBSIDE.STORE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 525,000 on HUBSIDE.STORE. The company had used data from data brokers for commercial acquisition campaigns without ensuring that the data… FRANCE ·CNIL ·Art. 6, 14 Consent Personal Data Supervisory Authorities Apr 4, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 25, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Mar 21, 2024
€79M Enel Energia SpA: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by… Garante Security Supervisory Authorities Human Resources Feb 8, 2024
€800,000 NTT Data Italia S.P.A: Insufficient fulfilment of data breach notification obligations The Italian DPA has imposed a fine of EUR 800,000 on NTT Data Italia S.P.A. The fine is related to the fine imposed on UniCredit (ETid-2227). UniCredit had contracted NTT to carry… ITALY ·Garante ·Art. 28, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 8, 2024
€3M IBERDROLA, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although… SPAIN ·AEPD ·Art. 5, 32 Security Processing Law Enforcement Feb 7, 2024
€5M ENERGYA VM GESTIÓN DE ENERGÍA, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined ENERGYA VM GESTIÓN DE ENERGÍA, S.L. EUR 5 million following an investigation into unlawful personal data processing by Nivalco, a company… SPAIN ·AEPD ·Art. 5 Controllers Processing Personal Data Feb 6, 2024
€3.5M I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3.5 million on I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U. The controller had suffered a cyber attack on its GEA web application resulting… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Feb 5, 2024
€10,000 FRANCE DPA: €10,000 fine The French DPA has imposed a fine of EUR 10,000 on a data controller due to data security vulnerabilities. CNIL ·Unknown Supervisory Authorities Controllers Security Jan 31, 2024
€20,000 Pharmaceutical wholesaler: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a pharmaceutical wholesaler due to violations of several regulations, including a lack of data security and insufficient… FRANCE ·CNIL ·Unknown Controllers Accountability Processors Jan 24, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Encryption Healthcare Controllers Jan 17, 2024
€15,200 Media Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine of EUR 15,200 on a media company. The company failed to react to requests by the DPA. AUSTRIA ·DSB ·Art. 58 Supervisory Authorities Supervision Processing Agreement Jan 2, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Supervisory Authorities Fines Supervision Jan 1, 2024
Private individual: Insufficient legal basis for data processing The DPA of Hamburg has imposed five fines of private individuals for taking or storing photos of individuals without their consent. GERMANY ·HmbBfDI ·Insufficient legal basis for data processing Consent Fines Processing Jan 1, 2024
€2,500 Doctor´s Office: Insufficient technical and organisational measures to ensure information security The DPA of Hessen has imposed a fine of EUR 2,500 on a doctor´s office. The controller hired an office manager who worked partly from home. The manager worked with patient files,… GERMANY ·Art. 5, 6, 9 +1 ·Insufficient technical and organisational measures to ensure information security Controllers Security Healthcare Jan 1, 2024
€1,500 SLOVAKIA DPA: Insufficient cooperation with supervisory authority The Slovak DPA has imposed a fine of EUR 1,500 on an unkown controller. The controller obstructed an inspection of the DPA. Slovak Data Protection Office ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Jan 1, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2024
€12,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 12,000 on a company providing vehicle history check services. The controller refused a data subject's request to rectify personal data… LITHUANIA ·VDAI ·Art. 5, 15, 16 Personal Data Accuracy Controllers Jan 1, 2024
€200 Civic Association: Insufficient legal basis for data processing The Slovak DPA has imposed a fine of EUR 200 on a civic association. The controller violated the principle of lawfulness of processing. SLOVAKIA ·Slovak Data Protection Office ·Insufficient legal basis for data processing Controllers IP Address Supervisory Authorities Jan 1, 2024
Multiple Police Officers: Data Protection Authority of Berlin The DPA of Berlin imposed fined 23 police officers. The police officers misused their access to the police information system for private purposes. GERMANY ·Unknown Supervisory Authorities Public Authority Education Jan 1, 2024
€10,000 Company: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 10,000 on a company. The controller used data for marketing purposes without a legal basis. The company obtained the data through… GERMANY ·Art. 6, 7 ·Insufficient legal basis for data processing Controllers Processing Direct Marketing Jan 1, 2024