Skip to content
Content type · 1,843 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

751–800 of 1,843 sort newestlargest fineoldest
Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data… 74/2024 ·Belgium ·APD/GBA Legitimate Interest Direct Marketing Marketing May 16, 2024
€3,000 Polisportiva Mimmo Ferrito s.r.l..: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 3,000 on Polisportiva Mimmo Ferrito s.r.l.. A data subject had filed a complaint with the DPA due to the controller's failure to respond… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Processing Agreement May 9, 2024
€1,600 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a homeowners' association. A person had filed a complaint with the DPA due to the fact that the data controller had published a picture with… SPAIN ·aepd ·Art. 5, 32 Controllers Personal Data IP Address May 9, 2024
€2,000 IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the… ROMANIA ·ANSPDCP ·Art. 32 Security IP Address Controllers May 9, 2024
€10,000 Azzurro Club Hotels S.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on Azzurro Club Hotels S.r.l.. The controller had sent a data subject unsolicited advertising e-mail and failed to respond… ITALY ·Garante ·Art. 6, 12, 15 +1 Personal Data Controllers Direct Marketing May 9, 2024
€75,000 Azienda ospedale università di Padova: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 75,000 on Azienda ospedale università di Padova. During its investigation, the DPA found that employees had accessed patient files… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Inspection Access Rights and Cooperation Obligations IP Address May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Healthcare May 8, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·aepd ·Art. 32, 33 Data Breaches Security Health Data May 8, 2024
€1,200 ARRENDAMIENTOS DEUDORES, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ARRENDAMIENTOS DEUDORES, S.L.. The controller had carried out a credit check on the data subject without any valid legal basis for this. The… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement May 7, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… aepd ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement May 7, 2024
€480 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a homeowners' association. The controller had sent an email to all owners containing a list of the owners' individual monthly heating… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Agreement May 7, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS ·AP ·Art. 5 Cookies Controllers Healthcare May 2, 2024
€1,200 DELPASO CAR HIRE, S.L.U.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on DELPASO CAR HIRE, S.L.U.. A data subject had filed a complaint against the controller with the DPA due to the controller's failure to… SPAIN ·aepd ·Art. 15 Personal Data Controllers Processing Agreement Apr 30, 2024
€8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… UNITED KINGDOM ·ICO ·Art. 5, 32 IP Address Security Controllers Apr 30, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Data Breaches Encryption Security Apr 29, 2024
€10,000 ASSOCIACIO OASIS CULTURAL: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ASSOCIACIO OASIS CULTURAL. A discotheque operated by the controller had published videos of dancing minors on a social media… SPAIN ·aepd ·Art. 6 Social Media Controllers Minors Apr 26, 2024
€10,000 C.I.E.L. S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on C.I.E.L. S.p.A.. An employee working for the controller filed a complaint with the DPA due to the controller's failure to grant… ITALY ·Garante ·Art. 12, 15 Controllers Personal Data Employees Apr 24, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Apr 24, 2024
€30,000 Rossi Carta S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 30,000 on Rossi Carta S.r.l.. An individual had filed a complaint with the DPA after repeatedly receiving unsolicited advertising emails… ITALY ·Garante ·Art. 6, 7, 12 +1 Data Subject Rights Exercise Modalities and Procedures Controllers Personal Data Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Apr 23, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Cookies Fairness & Transparency Direct Marketing Apr 22, 2024
€2,000 S.C. Tensa Art Design S.A..: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on S.C. Tensa Art Design S.A.. The controller had processed the personal data of a data subject for marketing purposes without the… ROMANIA ·ANSPDCP ·Art. 6 Personal Data Direct Marketing Controllers Apr 22, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Fairness & Transparency Cookies Direct Marketing Apr 22, 2024
CROATIA DPA: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed seven fines totaling EUR 16,000 on data controllers for failing to adequately mark video-monitored areas. This lack of marking resulted in… azop ·Art. 13, 27 ·Insufficient fulfilment of information obligations Fines Video Surveillance Controllers Apr 22, 2024
€1,000 DELSA ALQUILERES S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on DELSA ALQUILERES S.L.. The controller had installed video surveillance cameras in a residential complex which, among other… SPAIN ·aepd ·Art. 6, 13 Video Surveillance Controllers Monitoring Apr 12, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN ·aepd ·Art. 5, 32 IP Address Security Insurance Apr 12, 2024
€100,000 Facile.Energy S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Facile.Energy S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of… ITALY ·Garante ·Art. 5, 6, 24 +3 IP Address Controllers Processing Agreement Apr 11, 2024
€1,000 Store owner: Insufficient fulfilment of information obligations The Italian DPA has fined a store owner EUR 1,000. The controller had installed video surveillance cameras in its premises without properly informing data subjects about the… ITALY ·Garante ·Art. 5, 13 Video Surveillance Personal Data Monitoring Apr 11, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 Processing Agreement Controllers IP Address Apr 11, 2024
€25,000 Innova Camara: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 25,000 on Innova Camara. The controller had suffered a cyber attack in which databases were accessed and malicious files (backdoors) were… ITALY ·Garante ·Art. 5 Security Privacy by Design & Default Controllers Apr 11, 2024
€20,000 Istituto Nazionale di Previdenza Sociale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Italian National Institute of Social Security (INPS). The controller had published personal data of participants in a… ITALY ·Garante ·Art. 2, 5, 6 Education Personal Data Public Authority Apr 11, 2024
€175,000 Greek Ministry of Immigration and Asylum: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 175,000 on the Greek Ministry of Immigration and Asylum. The DPA found that the controller had failed to properly carry out a required… GREECE ·HDPA ·Art. 25, 31, 35 DPIA Privacy Impact Assessment Security Apr 2, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN ·aepd ·Art. 5 Video Surveillance Controllers IP Address Mar 25, 2024
€10,000 Stjörnuna ehf: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 10,000 on Stjörnuna ehf. (the operator of a Subway branch). An employee had filed a complaint with the DPA regarding video surveillance… ICELAND ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Mar 24, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·aepd ·Art. 5, 32 Video Surveillance Social Media Monitoring Mar 21, 2024
€500 JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT. The controller had installed a video surveillance system without… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Mar 21, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Mar 15, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A data subject had filed a complaint against the data controller as unauthorized fraudsters… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Mar 15, 2024
€20,000 Banca di Credito Cooperativo Appulo Lucana soc. cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Banca di Credito Cooperativo Appulo Lucana soc. cooperativa. A former employee had requested access to the personal data in… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Human Resources Mar 7, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance IP Address Personal Data Mar 7, 2024
€20,000 Centro Riparazioni Piacentino S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Centro Riparazioni Piacentino S.p.A.. The controller had kept a former employee's email account active despite the… ITALY ·Garante ·Art. 5, 13 Controllers IP Address Personal Data Mar 7, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Mar 5, 2024
€3M Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ): Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 2,995,140 on the Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ). The controller had suffered a data breach which resulted in… GREECE ·HDPA ·Art. 5, 32 Data Breaches Security Privacy by Design & Default Feb 28, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Feb 26, 2024
€2,000 Camera di Commercio Industria Artigianato e Agricoltura: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Camera di Commercio Industria Artigianato e Agricoltura. An individual had filed a complaint against the controller with the DPA… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Education Controllers Feb 22, 2024
€50,000 Azienda Trasporto Passeggeri Emilia-Romagna S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on the transport company azienda Trasporto Passeggeri Emilia-Romagna S.p.A.. The controller provided insufficient information on… ITALY ·Garante ·Art. 5, 6, 7 +4 Right to Object Direct Marketing Data Subject Rights Exercise Modalities and Procedures Feb 22, 2024
€100,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 100,000 on VODAFONE ESPAÑA, S.A.U. for insufficient legal basis for data processing. The data subject had filed a complaint against the… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Feb 13, 2024
€40,000 IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA. A data subject had filed a complaint against the controller with the DPA due to the… SPAIN ·aepd ·Art. 15 Personal Data Controllers Processing Agreement Feb 13, 2024
€4,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.. A data subject had filed a complaint against the controller with the… SPAIN ·aepd ·Art. 15 Personal Data Controllers Insurance Feb 13, 2024
€365,000 CTC EXTERNALIZACIÓN, S.L: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested… SPAIN ·aepd ·Art. 13, 32, 35 DPIA Privacy Impact Assessment Controllers Feb 12, 2024