Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

801–850 of 2,395 sort newestlargest fineoldest
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Security Encryption Privacy by Design & Default Apr 29, 2024
€16,000 Association: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 16,000 on an association for processing personal data without a sufficient legal basis. FRANCE ·CNIL ·Art. 6 Personal Data Supervisory Authorities Processing Apr 25, 2024
€30,000 Gestore Dei Servizi Energetici - Gse S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA imposed a fine of EUR 30,000 against Gestore Dei Servizi Energetici - Gse S.p.A. for failing to comply with a former employee's request for access to their… ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Employees Apr 24, 2024
€30,000 Rossi Carta S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 30,000 on Rossi Carta S.r.l.. An individual had filed a complaint with the DPA after repeatedly receiving unsolicited advertising emails… ITALY ·Garante ·Art. 6, 7, 12 +1 Personal Data Controllers Supervisory Authorities Apr 24, 2024
€3,000 I.N.P.A.S.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on I.N.P.A.S. (Istituto Nazionale di Previdenza e di Assistenza Sociale). During its investigation, the DPA found that a former… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Processing Public Authority Apr 24, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Apr 24, 2024
€10,000 C.I.E.L. S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on C.I.E.L. S.p.A.. An employee working for the controller filed a complaint with the DPA due to the controller's failure to grant… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Apr 23, 2024
€2,000 S.C. Tensa Art Design S.A..: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on S.C. Tensa Art Design S.A.. The controller had processed the personal data of a data subject for marketing purposes without the… ROMANIA ·ANSPDCP ·Art. 6 Personal Data Consent Controllers Apr 22, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·AZOP ·Art. 6, 7, 13 Fairness & Transparency Controllers Consent Apr 22, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·AZOP ·Art. 6, 7, 13 Consent Controllers Fairness & Transparency Apr 22, 2024
€14M Avast Software s.r.o.: €13,900,000 fine The Czech DPA has fined Avast Software s.r.o. EUR 13.9 million. The company had disclosed the personal data of around 100 million users of its antivirus software to the US company… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Unknown Personal Data Pseudonymization Anonymization Apr 15, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·AEPD ·Art. 6 Consent Personal Data Security Apr 12, 2024
€100,000 Facile.Energy S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Facile.Energy S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Personal Data Apr 11, 2024
€25,000 Innova Camara: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 25,000 on Innova Camara. The controller had suffered a cyber attack in which databases were accessed and malicious files (backdoors) were… ITALY ·Garante ·Art. 5 Security Controllers Personal Data Apr 11, 2024
€20,000 Istituto Nazionale di Previdenza Sociale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Italian National Institute of Social Security (INPS). The controller had published personal data of participants in a… ITALY ·Garante ·Art. 2, 5, 6 Controllers Personal Data Processing Apr 11, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Processing Apr 11, 2024
€1,000 Store owner: Insufficient fulfilment of information obligations The Italian DPA has fined a store owner EUR 1,000. The controller had installed video surveillance cameras in its premises without properly informing data subjects about the… ITALY ·Garante ·Art. 5, 13 Personal Data Controllers Processing Apr 11, 2024
€525,000 HUBSIDE.STORE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 525,000 on HUBSIDE.STORE. The company had used data from data brokers for commercial acquisition campaigns without ensuring that the data… FRANCE ·CNIL ·Art. 6, 14 Consent Personal Data Supervisory Authorities Apr 4, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Mar 21, 2024
€500 JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT. The controller had installed a video surveillance system without… SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Controllers Mar 21, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A data subject had filed a complaint against the data controller as unauthorized fraudsters… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Mar 15, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Mar 15, 2024
€18,000 Toyota Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Toyota Bank Polska S.A. EUR 18,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€326,000 Santander Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 326,000 for failing to report a data breach to the DPA and data subjects in a timely manner. POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by… 2021-0518 ·European Union ·Art. 5, 6, 28 +1 International Transfer Controllers Processors Mar 8, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Mar 7, 2024
€20,000 Centro Riparazioni Piacentino S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Centro Riparazioni Piacentino S.p.A.. The controller had kept a former employee's email account active despite the… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Mar 7, 2024
€20,000 Banca di Credito Cooperativo Appulo Lucana soc. cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Banca di Credito Cooperativo Appulo Lucana soc. cooperativa. A former employee had requested access to the personal data in… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Mar 7, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 5, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Mar 1, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Feb 29, 2024
€3M Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ): Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 2,995,140 on the Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ). The controller had suffered a data breach which resulted in… GREECE ·HDPA ·Art. 5, 32 Security Controllers Personal Data Feb 28, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 26, 2024
€2,000 Camera di Commercio Industria Artigianato e Agricoltura: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Camera di Commercio Industria Artigianato e Agricoltura. An individual had filed a complaint against the controller with the DPA… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Controllers Processing Feb 22, 2024
€40,000 IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA. A data subject had filed a complaint against the controller with the DPA due to the… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Feb 13, 2024
€4,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.. A data subject had filed a complaint against the controller with the… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Feb 13, 2024
€100,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 100,000 on VODAFONE ESPAÑA, S.A.U. for insufficient legal basis for data processing. The data subject had filed a complaint against the… SPAIN ·AEPD ·Art. 6 Controllers Consent Personal Data Feb 13, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Security Personal Data Healthcare Feb 8, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY ·Garante ·Art. 5, 32 Security Controllers Identification Feb 8, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Feb 8, 2024
€1,500 Aylo Social LTD: Insufficient fulfilment of data subjects rights The Cypriot DPA has imposed a fine of EUR 1,500 on Aylo Social LTD for failing to comply with a deletion request. CYPRUS ·Cyprus DPA ·Art. 17 Personal Data Supervisory Authorities Feb 8, 2024
€300,000 Medtronic Italia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Medtronic Italia. The controller had sent emails in an open distribution list to hundreds of individuals using the… ITALY ·Garante ·Art. 5, 9, 12 +2 Personal Data Controllers Healthcare Feb 8, 2024
€2,000 Brivio Limited: Insufficient fulfilment of data subjects rights The Cypriot DPA has imposed a fine of EUR 2,000 on Brivio Limited for failing to respond to a request for information in a timely manner. CYPRUS ·Cyprus DPA ·Art. 12 Personal Data Supervisory Authorities Feb 8, 2024
€2,000 Account Exchange SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Account Exchange SRL for using personal data without the consent of the data subjects. ROMANIA ·ANSPDCP ·Art. 5, 6 Consent Personal Data Processing Feb 7, 2024
€5,000 Wi-Planet sas di Torri Carlo Alberto e c.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Wi-Planet sas di Torri Carlo Alberto e c.. A data subject had filed a complaint with the DPA due to the controller's failure to… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Feb 7, 2024
€5M ENERGYA VM GESTIÓN DE ENERGÍA, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined ENERGYA VM GESTIÓN DE ENERGÍA, S.L. EUR 5 million following an investigation into unlawful personal data processing by Nivalco, a company… SPAIN ·AEPD ·Art. 5 Controllers Processing Personal Data Feb 6, 2024
€3.5M I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3.5 million on I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U. The controller had suffered a cyber attack on its GEA web application resulting… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Feb 5, 2024
€500 Owners' association: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 500 on an owners' association for publishing personal data of an individual in a WhatsApp group without a valid legal basis and for… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 Personal Data Supervisory Authorities Supervision Feb 5, 2024
€5,000 Dentist: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5,000 on a dentist due to a lack of data security and a failure to respect the right of access of a data subject. FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Inspection Access Rights and Cooperation Obligations Jan 31, 2024