Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

801–850 of 3,446 sort newestlargest fineoldest
€1.6M ING BANK N.V., SUCURSAL EN ESPAÑA: Insufficient legal basis for data processing The Spanish data protection authority (AEPD) has imposed a fine on ING BANK N.V., SUCURSAL EN ESPAÑA. As part of the verification process for new banking customers, ING carries… SPAIN ·aepd ·Art. 6 Personal Data Processing Insurance Mar 14, 2025
€20,000 Encore Thermoengineering s.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The… ITALY ·Garante ·Art. 5, 6, 17 Controllers IP Address Employees Mar 13, 2025
€40,000 Interflora Italia S.p.A.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 20,000 on Interflora Italia S.p.A. The controller, who operates an online shop, used customer data for direct marketing purposes without a… ITALY ·Garante ·Art. 5, 6, 12 +2 Right to Object Direct Marketing Marketing Mar 13, 2025
€50,000 Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC): Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 50,000 on the Regional agency for development and services in agriculture (ARSAC). The controller processed geographic data of its employees… ITALY ·Garante ·Art. 5, 6, 13 +3 Fairness & Transparency Education Controllers Mar 13, 2025
€2,000 Municipality of Roccaraso: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on the Municipality of Roccaraso. The controller published personal data of a worker on its public notice board website without a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers IP Address Mar 13, 2025
€2,000 l’Istituto Alberghiero Mediterraneo di Pulsano: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on l’Istituto Alberghiero Mediterraneo di Pulsano. The controller, a school, published a christmas video on the video platform YouTube,… ITALY ·Garante ·Art. 5, 6 Education Controllers Consent Mar 13, 2025
€15,000 G@S Telecomunicazioni di Losito Lucia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 15,000 on G@S Telecomunicazioni di Losito Lucia. The controller processed customer data without sufficient legal basis and additionally… ITALY ·Garante ·Art. 5, 6, 7 +2 Controllers Personal Data Telecommunications Mar 13, 2025
€5,000 Automobilus International S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Automobilus International S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Mar 12, 2025
€1,000 Noy Business Tranzactions SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Noy Business Tranzactions SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Processing Agreement Mar 11, 2025
€13,400 Polskie Radio Szczecin: Insufficient technical and organisational measures to ensure information security The Polish DPA fined Polskie Radio Szczecin (Polish Radio Szczecin) EUR 13,400. Due to the lack of sufficient technical measures, Polskie Radio Szczecin failed to protect the… POLAND ·UODO ·Art. 24, 32 Security Telecommunications IP Address Mar 11, 2025
€10,000 Housing Finance Corporation: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the Housing Finance Corporation. The controller stored client loan data for longer than necessary and did not ensure that the… CYPRUS ·Art. 5, 24 ·Insufficient legal basis for data processing Insurance Controllers Processing Agreement Mar 10, 2025
€338,000 Telenor ASA.: Non-compliance with general data processing principles The Norwegian DPA has imposed a fine of EUR 333,800 on Telenor ASA. During its investigation, the DPA found that the company had not conducted sufficient assessments and… NORWAY ·Datatilsynet ·Art. 24, 37, 38 Supervisory Authorities IP Address Telecommunications Mar 10, 2025
€3,500 Police Officer: Insufficient legal basis for data processing The DPA of Baden-Württemberg has imposed a fine of EUR 3,500 on a police officer. The controller systematically accessed the police database for private purposes, using it to rate… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Processing Data Controller Mar 7, 2025
€2,000 SHOPBAG GROUP ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 2,000 onSHOPBAG GROUP ONLINE SRL. The controller failed to respond to a request made by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers Mar 6, 2025
€20,000 WEBRASOFT SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on WEBRASOFT SRL. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Mar 4, 2025
€10,000 BEKO ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BEKO ROMANIA SA. The controller failed to implement sufficient technical and organisational measures to provide data security,… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Mar 3, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA ·ANSPDCP ·Art. 12, 15 Healthcare Health Data Personal Data Feb 27, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Consent Feb 25, 2025
€600,000 IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including… SPAIN ·aepd ·Art. 5 Healthcare Processing Agreement IP Address Feb 25, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA ·ANSPDCP ·Art. 32 Health Data Security Healthcare Feb 20, 2025
€34,300 Primary Health Care in the Capital Area: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 34,300 on the Primary Health Care in the Capital Area. The controller processed personal and health data in shared medical record… ICELAND ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Healthcare Feb 17, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 Healthcare Health Data Controllers Feb 17, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Agreement Feb 14, 2025
€200,000 ORANGE BANK, S.A. SUCURSAL EN ESPAÑA: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on ORANGE BANK, S.A. SUCURSAL EN ESPAÑA. The AEPD reacted to multiple complaints of private individuals regarding a data… SPAIN ·aepd ·Art. 5 Processors Controllers Security Feb 14, 2025
€120,000 BEEDIGITAL AI, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine against BEEDIGITAL AI, S.A.. A individual had lodged a complaint with the DPA against the controller because they had received advertising from… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle IP Address Professional Secrecy Feb 11, 2025
€3,000 PPC Energie Muntenia SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on PPC Energie Muntenia SA. The controller forwarded customer data to a third company, which then contacted the data subjects for… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Controllers Personal Data Processing Agreement Feb 10, 2025
€3,000 Omniasig Vienna Insurance Group S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Omniasig Vienna Insurance Group S.A. The controller failed to implement sufficient technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance Feb 6, 2025
€500,000 MARINA SALUD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500,000 on MARINA SALUD, S.A. Marina Salud, acting as a processor for a health authority, engaged sub-processors without obtaining the… SPAIN ·aepd ·Art. 28 Processing Agreement Processors Controllers Feb 5, 2025
€1.2M ORANGE ESPAGNE, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200,000 on ORANGE ESPAGNE, S.A.U.. An individual had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6, 25 Telecommunications Security Personal Data Feb 5, 2025
€5,000 FARMEC SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on FARMEC SA. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Controllers Feb 5, 2025
€40,000 Real estate company: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 40,000 on a real estate company for inappropriately monitoring its employees. A software program recorded “periods of inactivity” and… FRANCE ·CNIL ·Art. 5, 6, 12 +3 Monitoring DPIA Audit Logs Feb 4, 2025
€10,000 V&M Contab & Management SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on V&M Contab & Management SRL. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32, 58 Data Breaches Security Controllers Feb 4, 2025
€15,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 25 Data Breaches Security Processing Agreement Feb 3, 2025
€15,000 S.P.E.E.H. HIDROELECTRICA S.A: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on S.P.E.E.H. HIDROELECTRICA S.A. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 25 Data Breaches Security Controllers Jan 31, 2025
€40,000 Orange Romania SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 40,000 on Orange Romania SA. The controller failed to fulfil a request for the erasure of data. The controller also execsevly stored and… ANSPDCP ·Art. 5, 6, 7 +2 ·Non-compliance with general data processing principles IP Address Controllers Personal Data Jan 27, 2025
€5,000 Softehnica S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Softehnica S.R.L. The controller had suffered a ransomware attack, which allowed unauthorized third parties to gain access to… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default Controllers Jan 23, 2025
€9,000 Employment Service under the Ministry of Social Security and Labor of the Republic of Lithuania: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has imposed a fine of EUR 9,000 against the Employment Service under the Ministry of Social Security and Labor of the Republic of Lithuania. Following a data… VDAI ·Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Public Authority Public Sector Jan 21, 2025
€15,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Vodafone Romania S.A. Personal data such as names, email addresses and customer numbers were repeatedly disclosed due to… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Privacy by Design & Default Jan 20, 2025
€12,000 CAJA RURAL GRANADA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL GRANADA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€80,000 CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security Processing Agreement IP Address Jan 17, 2025
€76,000 CAJA RURAL DE GIJÓN, S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE GIJÓN, S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€8,000 CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€12,000 CAJA RURAL DE ONDA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ONDA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€10,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Jan 17, 2025
€200,000 CAJA RURAL DE SALAMANCA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE SALAMANCA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€16,000 CAJA RURAL DEL SUR, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DEL SUR, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Jan 17, 2025
€88,000 CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€8,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€8,000 CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security Insurance Controllers Jan 17, 2025