Content type · 960 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 13 +2 Sep 30, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 9 +1 Sep 30, 2020
€2,000 Sanatatea Press Group S.R.L.: Insufficient technical and organisational measures to ensure information security Sending the personal data collected for the registration for an online course to other participants due to a technical failure. ROMANIA · ·Art. 5, 32 Sep 8, 2020
€11,200 Warsaw University of Life Sciences: Insufficient technical and organisational measures to ensure information security Theft of a private notebook belonging to a university employee who also used this device for business purposes and on which personal data of candidates for study at SGGW was… POLAND · ·Art. 32 Sep 8, 2020
€3,000 Barcelona Airport Security Guard Association ('AVSAB'): Non-compliance with general data processing principles A member of the AVSAB security committee used WhatsApp to send messages to private phone numbers containing personal information about employees. This was a violation of the… SPAIN · ·Art. 5 Sep 7, 2020
€2,000 Istituto Comprensivo Statale Crucoli Torretta: Insufficient technical and organisational measures to ensure information security Publication of personal data of students on the website of the Institute with, inter alia, notes about health and progress in school due to technical failure. ITALY · ·Art. 5, 32 Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY · ·Art. 5, 32 Sep 3, 2020
€500 Apartment building owners association: Insufficient legal basis for data processing Export of a still image from a video surveillance system and posting of the image on the billboard of the building without sufficient legal basis. In addition, violation of the… ROMANIA · ·Art. 5, 6, 12 +3 Sep 1, 2020
€5,000 Basketball Federation of Castilla and Leon: Insufficient legal basis for data processing The Basketball Association transmitted personal data to third parties, which were subsequently published on the Internet without consent of the data subjects. In addition, the… SPAIN · ·Art. 5, 6 Aug 28, 2020
€65,000 Cork University Maternity Hospital: Insufficient technical and organisational measures to ensure information security The „Data Protection Authority of Ireland“ imposed a fine on Cork University Maternity Hospital (CUMH) after the personal data of 78 patients was discovered disposed of in a… IRELAND ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Aug 18, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Aug 12, 2020
€20,100 PrivatBo A.M.B.A.: Insufficient technical and organisational measures to ensure information security The company had distributed USB sticks to tenants in the context of a sale of real estate, which contained not only non-personal information on the real estate objects in question… DENMARK · ·Art. 5, 32 Aug 4, 2020
€5,000 National Institute for Social Security - Department of the Province of Brescia: Insufficient fulfilment of data subjects rights Failure to graint access to personal health data of a data subject according to Art. 15 GDPR. ITALY · ·Art. 15 Aug 4, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA · ·Art. 32 Jul 30, 2020
€5,000 SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security Unauthorised disclosure of the data of five Tarom passengers due to inadequate technical and organisational measures for secure data processing. Among other things, the company… ROMANIA · ·Art. 32 Jul 27, 2020
€70,000 Xfera Moviles S.A.: Non-compliance with general data processing principles A data subject had received a call from another Xfera Móviles customer who stated that the company had charged his bank account with an invoice, disclosing the personal details of… SPAIN · ·Art. 5 Jul 20, 2020
€800,000 Iliad Italia S.p.A.: Non-compliance with general data processing principles The fine relates to data protection infringements concerning the processing of customer data for the activation of SIM cards and the manner in which payment data was recorded. In… ITALY · ·Art. 5, 25 Jul 13, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY · ·Art. 32, 35 Jul 10, 2020
€5,000 Global Business Travel Spain SLU: Insufficient technical and organisational measures to ensure information security The fine was preceded by an employee's access to health data of a person concerned. In the course of its investigations, the Data Protection Authority found that Global Business… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jul 10, 2020
€55,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The company had changed a contract for a mobile phone connection to a new owner, whereby the personal data of a data subject such as his address and telephone numbers were freely… SPAIN · ·Art. 5, 32 Jul 10, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA · ·Art. 32 Jul 9, 2020
€24,000 Iberdrola Clientes: Non-compliance with general data processing principles A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes… SPAIN · ·Art. 5 Jul 2, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Jun 30, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY · ·Art. 32 Jun 22, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA · ·Art. 32 Jun 18, 2020
€288,000 Digi Távközlési Szolgáltató Kft. ('Digi') (electronic communication service provider): Insufficient technical and organisational measures to ensure information security The company had infringed the principles of purpose limitation and storage restriction because its database contained a large amount of customer data which were no longer relevant… HUNGARY · ·Art. 5, 32 Jun 12, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jun 11, 2020
€2,000 Attorney: Insufficient technical and organisational measures to ensure information security In the course of proceedings, an attorney submitted documents whose backs contained personal data of other parties. SPAIN · ·Art. 32 Jun 9, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND · ·Art. 5, 6, 35 May 29, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA · ·Art. 32 May 5, 2020
€134,000 Telenor Norge AS: Insufficient technical and organisational measures to ensure information security Fines for security breaches in a voice mailbox function. NORWAY · ·Art. 32 May 3, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Apr 29, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Apr 23, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE · ·Art. 5, 6 Apr 7, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA · ·Art. 32 Mar 25, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS · ·Art. 9, 32 Mar 24, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN · ·Art. 5 Mar 16, 2020
€9,000 Breiðholt Upper Secondary School: Insufficient technical and organisational measures to ensure information security In violation of Art. 32 GDPR, a teacher had sent an e-mail to his students and their parents with an attachment containing data on their well-being, academic performance and… ICELAND ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Mar 10, 2020
€14,000 Gladsaxe Municipality: Insufficient technical and organisational measures to ensure information security A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city… DENMARK · ·Art. 5, 32 Mar 10, 2020
€7,000 Hørsholm Municipality: Insufficient technical and organisational measures to ensure information security A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and… DENMARK · ·Art. 5, 32 Mar 10, 2020
€20,600 National Center of Addiction Medicine ('SAA'): Insufficient technical and organisational measures to ensure information security Persónuvernd noted that a former employee of the SAA received boxes of allegedly personal belongings that he had left there, but which also contained patient data, including the… ICELAND ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Mar 10, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN · ·Art. 5 Mar 9, 2020
€42,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security According to the AEPD, the company had not been able to demonstrate adequate measures to ensure information security, leading to unauthorized access to personal data of a client. SPAIN · ·Art. 5, 32 Mar 3, 2020
€48,000 Vodafone ONO, S.A.U.: Insufficient technical and organisational measures to ensure information security The decision was taken due to several deficiencies in information security. For example, two people were given the same security access key. SPAIN · ·Art. 32 Feb 28, 2020
Rælingen Municipality: Insufficient technical and organisational measures to ensure information security On February 26, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Rælingen Municipality EUR 73,600 for violations of Art. 5 (1) f) GDPR and Art. 32 GDPR .… NORWAY · ·Art. 5, 32 Feb 26, 2020
€2,560 T.K. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to… BULGARIA · ·Art. 25, 32 Feb 20, 2020
€2,560 L.E. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca EUR 2,557 was imposed on L.E. EOOD for unlawful processing of personal data of data subject I.S. without the knowing and the consent of the data subject and also… BULGARIA · ·Art. 6, 25, 32 Feb 20, 2020
€2,500 Grupo Valsor Y Losan, S.L.: Insufficient technical and organisational measures to ensure information security The controller had disclosed personal data to a third party in a property purchase agreement (breach of principles of integrity and confidentiality of personal data) SPAIN · ·Art. 5 Feb 14, 2020
€30,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The AEPD found that a third party had access to the name, telephone number and address of another customer. SPAIN · ·Art. 5, 32 Feb 14, 2020