Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

851–900 of 3,446 sort newestlargest fineoldest
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€88,000 CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€8,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€2,000 Alessandro Volta Classical and Scientific High School in Como: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Alessandro Volta Classical and Scientific High School in Como. The controller published the results of the state exam,… ITALY ·Garante ·Art. 5, 6 Education Controllers Processing Agreement Jan 16, 2025
€100,000 Realmaps S.r.l.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 100,000 on Realmaps S.r.l. The controller collects data on every real estate owner and sells it to customers who use it for direct marketing… ITALY ·Garante ·Art. 5, 6, 7 +12 Controllers Processors IP Address Jan 16, 2025
€72,000 CAJA RURAL CENTRAL, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL CENTRAL, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 16, 2025
€600 Pro Loco Tourist Association of Cittareale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on the Pro Loco Tourist Association of Cittareale. The controller published personal data of its members on its website without a… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Processing Jan 16, 2025
€2,000 Municipality of Cori: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Municipality of Cori. The controller published the names of those receiving food cards intended for people in need on its… ITALY ·Garante ·Art. 6 Controllers Public Authority IP Address Jan 16, 2025
€600 BAR GIOIA: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on a BAR GIOIA. The controller installed two surveillance cameras without the necessary information signs, and the cameras were also… ITALY ·Garante ·Art. 5 Video Surveillance Monitoring Controllers Jan 16, 2025
€400,000 CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security Processing Agreement Controllers Jan 16, 2025
€1,500 Macelleria La Costata s.r.I.s: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on Macelleria La Costata s.r.I.s. The controller used video surveillance in its butcher's shop without installing the necessary… ITALY ·Garante ·Art. 5, 6, 13 Video Surveillance Controllers Monitoring Jan 16, 2025
€6,000 San Pio Hospital in Benevento: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the San Pio Hospital in Benevento. The controller did not ensure that only entitled employees had access to technical… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Employees Jan 16, 2025
Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Notified Body Responsibilities and Operational Obligations Security Genetic Data Jan 10, 2025
€120,000 National Bank of Greece S.A: Insufficient technical and organisational measures to ensure information security Hellenic Data Protection Authority (HDPA) fined National Bank of Greece S.A €120,000 on 2025-01-10 for: Insufficient technical and organisational measures to ensure information… HDPA ·Art. 5, 15, 25 +3 ·Insufficient technical and organisational measures to ensure information security Security Processing Agreement Supervisory Authorities Jan 10, 2025
€175,000 Credit Institution: Insufficient fulfilment of data subjects rights The DPA of Luxembourg has issued a fine of EUR 175,000 on a Credit Institution. The controller failed to respond to information requests within the timeframe specified in Art. 12… LUXEMBOURG ·CNPD ·Art. 12 Supervisory Authorities Controllers Personal Data Jan 6, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA ·ANSPDCP ·Art. 24, 32 Healthcare Healthcare Security Jan 3, 2025
€357,000 Panek SA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 357,000 on Panek SA. During the reconstruction of its website, the controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 32 Security Controllers Processing Agreement Dec 23, 2024
€15,000 HSSERVICE LIZCON SOLUTIONS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 15,000 on HSSERVICE LIZCON SOLUTIONS, S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€600 ENERGY WINNER, S.L.: Insufficient cooperation with supervisory authority Fine of EUR 600 for failure to provide information to the Spanish DPA within the required timeframe SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€2,000 AUTOMOCIÓN 1972, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 2,000 on AUTOMOCIÓN 1972, S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€9,000 CRIDOLMA BARCELONA S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 9,000 on CRIDOLMA BARCELONA S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN ·aepd ·Art. 6, 28 Insurance Personal Data Controllers Dec 23, 2024
€40,000 Coolblue B.V: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of €40,000 on Coolblue. The company collected personal data via cookies without users' explicit consent, relying on pre-ticked consent boxes. THE NETHERLANDS ·AP ·Art. 5, 6 Cookies Consent Processing Agreement Dec 23, 2024
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Security Dec 20, 2024
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND ·UODO ·Art. 30, 35, 38 Privacy Impact Assessment DPIA Security Dec 18, 2024
€100,000 ATRIUM LEX SFC: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 100,000 on the real estate management company ATRIUM LEX SFC. An investor had filed a complaint with the DPA because the controller had… SPAIN ·aepd ·Art. 13, 32 Controllers Processing Agreement Processing Dec 18, 2024
€950,000 Sambla Group Oy: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 950,000 on Sambla Group Oy. Security vulnerabilities in two of its comparison portals allowed unauthorized persons to access personal… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Insurance Personal Data Dec 17, 2024
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… Notification Obligation Data Breaches Social Media Dec 17, 2024
€200,000 Hospital: Insufficient technical and organisational measures to ensure information security The Belgian DPA has fined a hospital EUR 200,000. The hospital had suffered a ransomware attack through a vulnerability in the server, which paralyzed parts of the computer system… BELGIUM ·APD ·Art. 5, 24, 32 +1 DPIA Security Privacy Impact Assessment Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN ·aepd ·Art. 5 Controllers IP Address Personal Data Dec 16, 2024
€2,000 Torre Annunziata municipality: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on Torre Annunziata municipality for failing to provide the DPA with the contact details of their data protection officer in good… ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Public Sector Dec 14, 2024
€2,000 Maddaloni municipality: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on Maddaloni municipality for failing to provide the DPA with the contact details of their data protection officer in good time. ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Public Sector Dec 14, 2024
€20,000 Physician: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on a physician who had published images of a patient who had undergone cosmetic surgery on a social network without their consent. ITALY ·Garante ·Art. 2, 5, 9 Healthcare Consent Processing Dec 12, 2024
€3.5M CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a… SPAIN ·aepd ·Art. 5, 25 Privacy by Default Privacy by Design Privacy by Design & Default Dec 12, 2024
€18,400 Granit Bostad Beritsholm AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 18,400 on the Granit Bostad Beritsholm AB. The controller, a property management company, installed CCTV cameras in an apartment complex… SWEDEN ·Art. 6, 13 ·Insufficient legal basis for data processing Video Surveillance Controllers Monitoring Dec 11, 2024
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN ·aepd ·Art. 5, 25, 32 +1 Data Breaches Security Insurance Dec 10, 2024
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a data controller. The controller had installed a video surveillance system without adequately providing information for data… SPAIN ·aepd ·Art. 13 Video Surveillance Controllers Monitoring Dec 3, 2024
Lyngby-Taarbæk Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine between EUR 46,900 and EUR 53,600 on the Lyngby-Taarbæk Municipality. The controller failled to implement sufficient security measures resulting… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Public Authority Nov 27, 2024
€4.8M Netflix International B.V.: Insufficient fulfilment of information obligations The Dutch DPA has imposed a fine of EUR 4.75 million on Netflix. This fine is based on a complaint filed by the Austrian organization 'noyb'. During its investigation, the DPA… THE NETHERLANDS ·AP ·Art. 5, 12, 13 +1 Personal Data Telecommunications Processing Nov 26, 2024
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Nov 26, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN ·aepd ·Art. 15, 35 Personal Data Biometric Data Employees Nov 22, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Public Sector IP Address Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN ·aepd ·Art. 15, 35 DPIA Privacy Impact Assessment Employees Nov 22, 2024
€358,000 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted… UODO ·Art. 5, 25, 28 +1 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processing Agreement Nov 20, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period Controllers Nov 20, 2024
€4,700 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4,700 on a subcontractor that was contracted to redesign the website of another company. This fine is linked to ETid-2491. Due to an error… UODO ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processing Agreement Nov 20, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individua had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6 Telecommunications Personal Data Processing Agreement Nov 19, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Video Surveillance Security IP Address Nov 13, 2024
€2,500 COYARE SLU: Non-compliance with general data processing principles The Spanish DPA fined COYARE SLU EUR 2,500 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the unauthorized… SPAIN ·aepd ·Art. 5, 32 IP Address Insurance Processing Agreement Nov 13, 2024