Skip to content
Content type · 2,636 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

751–800 of 2,636 sort newestlargest fineoldest
€15,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Vodafone Romania S.A. Personal data such as names, email addresses and customer numbers were repeatedly disclosed due to… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Controllers Jan 20, 2025
€8,000 CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€2,000 DELIVERY SOLUTIONS S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on DELIVERY SOLUTIONS S.A. A security incident led to the unauthorized disclosure of personal data (name, address, telephone… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jan 17, 2025
€200,000 CAJA RURAL DE SALAMANCA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE SALAMANCA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€80,000 CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€12,000 CAJA RURAL DE ONDA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ONDA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€76,000 CAJA RURAL DE GIJÓN, S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE GIJÓN, S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€16,000 CAJA RURAL DEL SUR, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DEL SUR, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€10,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€12,000 CAJA RURAL GRANADA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL GRANADA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€88,000 CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€12,000 CAJA RURAL DE ASTURIAS, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ASTURIAS, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€8,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€8,000 CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 17, 2025
€72,000 CAJA RURAL CENTRAL, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL CENTRAL, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 16, 2025
€6,000 San Pio Hospital in Benevento: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the San Pio Hospital in Benevento. The controller did not ensure that only entitled employees had access to technical… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Controllers Types of Special Categories of Personal Data Jan 16, 2025
€600 BAR GIOIA: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on a BAR GIOIA. The controller installed two surveillance cameras without the necessary information signs, and the cameras were also… ITALY ·Garante ·Art. 5 Controllers Processing Video Surveillance Jan 16, 2025
€400,000 CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Jan 16, 2025
€600 Pro Loco Tourist Association of Cittareale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on the Pro Loco Tourist Association of Cittareale. The controller published personal data of its members on its website without a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Jan 16, 2025
€2,000 Municipality of Cori: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Municipality of Cori. The controller published the names of those receiving food cards intended for people in need on its… ITALY ·Garante ·Art. 6 Controllers Public Authority Education Jan 16, 2025
€100,000 Realmaps S.r.l.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 100,000 on Realmaps S.r.l. The controller collects data on every real estate owner and sells it to customers who use it for direct marketing… ITALY ·Garante ·Art. 5, 6, 7 +12 Retention Period Controllers Processors Jan 16, 2025
€2,000 Alessandro Volta Classical and Scientific High School in Como: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Alessandro Volta Classical and Scientific High School in Como. The controller published the results of the state exam,… ITALY ·Garante ·Art. 5, 6 Controllers Processing Education Jan 16, 2025
€1,500 Macelleria La Costata s.r.I.s: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on Macelleria La Costata s.r.I.s. The controller used video surveillance in its butcher's shop without installing the necessary… ITALY ·Garante ·Art. 5, 6, 13 Controllers Supervisory Authorities Processing Jan 16, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA ·ANSPDCP ·Art. 24, 32 Personal Data Controllers Security Jan 3, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Processors Controllers Personal Data Jan 1, 2025
€40,000 Coolblue B.V: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of €40,000 on Coolblue. The company collected personal data via cookies without users' explicit consent, relying on pre-ticked consent boxes. THE NETHERLANDS ·AP ·Art. 5, 6 Consent Personal Data Processing Dec 23, 2024
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN ·AEPD ·Art. 6, 28 Processors Personal Data Controllers Dec 23, 2024
€100,000 ATRIUM LEX SFC: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 100,000 on the real estate management company ATRIUM LEX SFC. An investor had filed a complaint with the DPA because the controller had… SPAIN ·AEPD ·Art. 13, 32 Controllers Supervisory Authorities Processing Agreement Dec 18, 2024
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND ·UODO ·Art. 30, 35, 38 DPIA Marketing Profiling Dec 18, 2024
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… DPC Notification Obligation Data Breaches Controllers Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2024
€20,000 Physician: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on a physician who had published images of a patient who had undergone cosmetic surgery on a social network without their consent. ITALY ·Garante ·Art. 2, 5, 9 Healthcare Consent Processing Dec 12, 2024
€18,400 Granit Bostad Beritsholm AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 18,400 on the Granit Bostad Beritsholm AB. The controller, a property management company, installed CCTV cameras in an apartment complex… SWEDEN ·IMY ·Art. 6, 13 Controllers Personal Data Supervisory Authorities Dec 11, 2024
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN ·AEPD ·Art. 5, 25, 32 +1 Security Privacy by Design & Default Controllers Dec 10, 2024
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a data controller. The controller had installed a video surveillance system without adequately providing information for data… SPAIN ·AEPD ·Art. 13 Controllers Personal Data Supervisory Authorities Dec 3, 2024
€4.8M Netflix International B.V.: Insufficient fulfilment of information obligations The Dutch DPA has imposed a fine of EUR 4.75 million on Netflix. This fine is based on a complaint filed by the Austrian organization 'noyb'. During its investigation, the DPA… THE NETHERLANDS ·AP ·Art. 5, 12, 13 +1 Personal Data Supervisory Authorities Supervision Nov 26, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN ·AEPD ·Art. 15, 35 Personal Data Controllers Types of Special Categories of Personal Data Nov 22, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD (LU) ·Art. 5, 6, 13 +2 Retention Period Controllers Security Nov 20, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individua had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Nov 19, 2024
€2.4M Posti Jakelu Oy: Insufficient legal basis for data processing The Finnish DPA imposed a fine of EUR 2.4 million on Posti Jakelu Oy following an investigation. It was found that Posti had automatically set up an electronic mailbox for… FINLAND ·Deputy Data Protection Ombudsman ·Art. 6 Consent Supervisory Authorities Processing Agreement Nov 13, 2024
€678,897 Illumia Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints… ITALY ·Garante ·Art. 5, 6, 7 +4 Privacy by Design & Default Security Personal Data Nov 13, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·DPC ·Art. 5, 13, 24 +3 Controllers Security Supervisory Authorities Nov 13, 2024
€500 4T OCIO Y CAFÉ 2009: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on 4T OCIO Y CAFÉ 2009, S.L. for installing a video surveillance system without the express consent of the owners' association of the… SPAIN ·AEPD ·Art. 6 Consent Video Surveillance Monitoring Nov 13, 2024
€5M Foodinho Srl: Non-compliance with general data processing principles The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the… ITALY ·Garante ·Art. 2, 5, 6 +11 Types of Special Categories of Personal Data Personal Data Supervisory Authorities Nov 13, 2024
€2,500 COYARE SLU: Non-compliance with general data processing principles The Spanish DPA fined COYARE SLU EUR 2,500 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the unauthorized… SPAIN ·AEPD ·Art. 5, 32 Processing IP Address Processing Agreement Nov 13, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Data Breaches Processors Controllers Nov 12, 2024
€900,000 Debt collection service provider: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 900,000 on a debt collection service provider. The company had unlawfully stored personal data (amounting to a six-digit number of… GERMANY ·HmbBfDI ·Art. 5, 6 Personal Data Processing Insurance Nov 12, 2024