Skip to content
Content type · 865 documents in this view · 3,837 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

851–865 of 865 sort newestlargest fineoldest
€28,100 National Revenue Agency: Insufficient legal basis for data processing The pecuniary sanction of EUR 28, 121 was imposed on the National Revenue Agency for unlawful processing of the personal data of data subject G.B.I. The personal data of G.B.I.… BULGARIA ·CPDP ·Art. 6, 58 Public Authority Personal Data Supervision Sep 3, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Legitimate Interest Public Authority Sep 3, 2019
€18,630 School in Skellefteå: Insufficient legal basis for data processing A school in Skellefteå made a trial to use facial recognition technology. The fine was imposed against the school which had used facial recognition technology to monitor the… SWEDEN ·Art. 5, 9, 35 +1 ·Insufficient legal basis for data processing Types of Special Categories of Personal Data Personal Data Monitoring Aug 20, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Jul 5, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Law Enforcement Jul 2, 2019
€130,000 UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations,… ROMANIA ·ANSPDCP ·Art. 5, 25 Security Personal Data Processing Jun 27, 2019
€2,850 HUNGARY DPA: Insufficient legal basis for data processing The individual requested the deletion of his contact data (including his telephone number), however the controller further processed his contact data for claim enforcement… NAIH ·Art. 5, 6, 17 ·Insufficient legal basis for data processing Legitimate Interest Personal Data Controllers Jun 26, 2019
€350,000 Haga Hospital: Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data… THE NETHERLANDS ·AP ·Art. 32 Security Healthcare Health Data Jun 18, 2019
€61,500 Payment service provider UAB MisterTango: Insufficient fulfilment of data breach notification obligations During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a… LITHUANIA ·VDAI ·Art. 5, 32, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations May 16, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Personal Data Right of Access Apr 29, 2019
€12,950 Sports association: Insufficient legal basis for data processing One sports association published personal data referring to judges who were granted judicial licenses online. However, not only their names were provided, but also their exact… POLAND ·UODO ·Art. 6 Personal Data Controllers Liability Apr 25, 2019
€170,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Public Authority Mar 1, 2019
€50,000 N26: Insufficient legal basis for data processing The fine was imposed against against a bank (according to a newspaper N26) that had processed 'personal data of all former customers' without permission.The Bank has acknowledged… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Security Supervision Mar 1, 2019
€50,000 Unknown Company: Insufficient fulfilment of data subjects rights The data controller had engaged an external company to carry out the duties of access to data according to Art. 15 GDPR. However, the engaged company conducted the correspondence… GERMANY ·Art. 15, 28 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Fairness & Transparency Jan 1, 2019
€3,200 HUNGARY DPA: Insufficient fulfilment of data subjects rights The fine was imposed for (i) not providing a data subject with CCTV recordings, (ii) not retaining recordings for further use by the data subject, and (iii) not informing the data… NAIH ·Art. 12, 13, 15 +1 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Supervision Dec 18, 2018