Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

801–850 of 2,273 sort newestlargest fineoldest
€20,000 Region of Lombardy: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Region of Lombardy. In the context of the sale of company shares held by the region, personal data of employees of the… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Employees Education Oct 26, 2023
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·aepd ·Art. 5, 25, 32 Privacy by Default Privacy by Design Accountability Oct 26, 2023
€1,000 SC Spark Car Sharing SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Spark Car Sharing SRL. An individual had filed a complaint with the DPA because the controller had processed their email… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Direct Marketing Controllers IP Address Oct 25, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·aepd ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Social Media Oct 25, 2023
€3,000 Mensajero SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Mensajero SRL. The controller had suffered a data breach where a link on the controller's website was publicly accessible… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Oct 24, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Oct 23, 2023
€50,000 Oney Servicios Financieros E.F.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on Oney Servicios Financieros E.F.C... The controller had submitted data from the data subject to a credit information system… SPAIN ·aepd ·Art. 5 Personal Data Controllers IP Address Oct 23, 2023
€1,000 DANTE INTERNATIONAL SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on DANTE INTERNATIONAL SA. The controller had sent marketing SMS to a data subject without a valid legal basis. ROMANIA ·ANSPDCP ·Art. 6 Direct Marketing Controllers Personal Data Oct 20, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN ·aepd ·Art. 25, 32 Security Privacy by Design & Default Processing Agreement Oct 20, 2023
€24,000 Insurance company: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an insurance company EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Oct 18, 2023
€600 FESTINA LOTUS S.A.: Insufficient fulfilment of data subjects rights The Spanish Data Protection Authority has imposed a fine of EUR 600 on FESTINA LOTUS S.A. due to the fact that the controller had not properly complied with a data subject's… SPAIN ·aepd ·Art. 17 Personal Data Controllers Supervisory Authorities Oct 18, 2023
€30,000 H&M Hennes & Mauritz GBC AB: Insufficient fulfilment of data subjects rights The Swedish DPA has imposed a fine of EUR 30,000 on H&M for sending out marketing messages, despite the fact that data subjects had exercised their right to objection. Six data… SWEDEN ·Art. 12, 21 ·Insufficient fulfilment of data subjects rights Right to Object Direct Marketing Data Subject Rights Exercise Modalities and Procedures Oct 17, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA has fined a private individual EUR 600 for installing a video surveillance camera that captured parts of a commonly shared garage. The DPA considered this a… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Oct 15, 2023
€70,000 Scionti Selezioni Superiori S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on Scionti Selezioni Superiori S.r.l.. The controller had made unsolicited marketing calls, in some cases to individuals who were… ITALY ·Garante ·Art. 5, 6, 7 +7 Personal Data Controllers Data Subject Rights Exercise Modalities and Procedures Oct 12, 2023
€600,000 GROUPE CANAL +: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on GROUPE CANAL+ for multiple violations of the GDPR. The DPA determined that the data controller failed to demonstrate that it… FRANCE ·CNIL ·Art. 7, 12, 13 +5 Data Breaches IP Address Controllers Oct 12, 2023
€24,000 Link4 Towarzystwo Ubezpieczeń S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Link4 Towarzystwo Ubezpieczeń S. A. EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 8, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·azop ·Art. 5, 6, 12 +2 Personal Data Controllers Insurance Oct 5, 2023
€1,000 Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Cez Vânzare S.A.. The controller had accidentally sent emails containing personal customer data to the wrong recipients. The… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default IP Address Oct 2, 2023
€10M Axpo Italia Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained… ITALY ·Garante ·Art. 5, 24 IP Address Processing Agreement Accuracy Sep 28, 2023
€3,000 Palombaro s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Palombaro s.r.l. EUR 3,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects about… ITALY ·Garante ·Art. 5, 13 Video Surveillance Monitoring Controllers Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Health Data Sep 28, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Healthcare Healthcare Sep 28, 2023
€25,000 RESTART ENERGY ONE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on RESTART ENERGY ONE S.A.. During its investigation, the DPA found that there existed a publicly accessible file on the… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Privacy by Design & Default Sep 26, 2023
€70,000 DIGI SPAIN TELECOM, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on DIGI SPAIN TELECOM, S.L.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… aepd ·Art. 6 ·Insufficient legal basis for data processing Telecommunications Personal Data Consent Sep 26, 2023
€1,040 Self Employed Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,040 on a self employed person. The accused's website did not comply with GDPR requirements for cookies, as it processed data before… CZECH REPUBLIC ·UOOU ·Art. 5, 13 Cookies Personal Data Processing Agreement Sep 26, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·azop ·Art. 6, 13, 32 +1 Notified Body Responsibilities and Operational Obligations Controllers IP Address Sep 26, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Personal Data Sep 25, 2023
€2,000 UAT Comuna Albeni: Insufficient cooperation with supervisory authority The Romanian DPA has fined UAT Comuna Albeni EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Public Sector Sep 25, 2023
€50,000 Athens Urban Transport Organization: Non-compliance with general data processing principles The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with… GREECE ·HDPA ·Art. 5, 25, 35 Privacy by Default DPIA Privacy by Design Sep 25, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN ·aepd ·Art. 9, 13 Health Data Healthcare Personal Data Sep 25, 2023
€12,000 CHATWITH.IO WORLDWIDE, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 12,000 on the website operator CHATWITH.IO WORLDWIDE, S.L. During its investigation, the DPA found that the controller had failed to… SPAIN ·aepd ·Art. 5, 13, 22 Cookies IP Address Controllers Sep 23, 2023
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Sep 19, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has fined NN Asigurări de Viață S.A. EUR 1,000. A person had filed a complaint for receiving advertising messages, although they had objected to receiving… ROMANIA ·ANSPDCP ·Art. 21 Insurance Direct Marketing Personal Data Sep 18, 2023
€10,000 San Severo municipality: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 10,000 on San Severo municipality. The municipality had published a document containing personal data of employees on its website without a… ITALY ·Garante ·Art. 2, 5, 6 Personal Data IP Address Public Authority Sep 14, 2023
€30,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 30,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·azop ·Art. 6, 7, 13 Cookies Personal Data Retention Period Sep 14, 2023
€10,000 Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb for failing to adequately comply with its obligation to comply… ITALY ·Garante ·Art. 12 Personal Data Accuracy Employees Sep 14, 2023
€20,000 Shardana Working Soc. Coop. a r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Shardana Working Soc. Coop. a r.l. EUR 20,000 for failing to respond adequately to requests from employees for access to information regarding their… ITALY ·Garante ·Art. 12, 15 Personal Data Employees Human Resources Sep 14, 2023
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·azop ·Art. 6, 7, 13 Cookies Controllers Retention Period Sep 14, 2023
€90,000 GFB One s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 90,000 on GFB One s.r.l.. An individual had filed a complaint with the DPA because SIM cards were registered in their name, although they… ITALY ·Garante ·Art. 5, 6, 13 +1 Controllers Personal Data Processing Agreement Sep 14, 2023
€42,000 Intesa Sanpaolo Spa: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 15 Insurance Personal Data Supervisory Authorities Sep 14, 2023
€25,000 Zagreb Holding d.o.o.: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed a fine of EUR 25,000 on Zagreb Holding d.o.o., utilities company owned by the city of Zagreb. The DPA had received a complaint from a citizen… CROATIA ·azop ·Art. 13, 25 Controllers Education Personal Data Sep 13, 2023
€23,000 Suomen Yritysrekisteri: Insufficient fulfilment of data subjects rights The Finnish DPA has fined Suomen Yritysrekisteri EUR 23,000. The controller had not sufficiently complied with data subjects' requests for access to their personal data. The… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Sep 11, 2023
€80,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an… SPAIN ·aepd ·Art. 6 Processing Agreement Telecommunications Personal Data Sep 5, 2023
€1,600 Company: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 1,600 on a company providing psychotherapy services. A customer had submitted a request for access to their stored personal data.… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 15 Personal Data Healthcare Processing Agreement Sep 4, 2023
€345M TikTok Limited: Non-compliance with general data processing principles The Irish DPA (DPC), has imposed a fine of EUR 345 million on TikTok Limited. The DPC conducted an investigation primarily focused on the processing of personal data between July… IRELAND ·Art. 5, 12, 13 +2 ·Non-compliance with general data processing principles Social Media IP Address Processing Sep 1, 2023
€ 2,000M AZOP (Croatia) - Decision 14-09-2023 The two companies in question, as controllers, made use of cookies on their websites, but failed to inform data subjects visiting their web pages about the legal basis for… Art. 6, 7, 13 Cookies Fines Personal Data Sep 1, 2023
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 300 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 13 Video Surveillance Personal Data Controllers Sep 1, 2023
€10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… ITALY ·Garante ·Art. 5, 9, 12 +5 Healthcare Recipient Healthcare Aug 31, 2023
€10,000 RCS Mediagroup Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on RCS Mediagroup Spa. A data subject had filed a complaint with the DPA due to the fact that their personal data had been… ITALY ·Garante ·Art. 2, 5, 137 +1 Personal Data IP Address Controllers Aug 31, 2023
€20,000 Bar association: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 on a bar association. Two individuals had filed a complaint with the DPA against the controller because documents relating to a… ITALY ·Garante ·Art. 2, 5 Education Controllers IP Address Aug 31, 2023