Content type · 960 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€42,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security The complainant had access to third party data in his personal Vodafone profile. SPAIN · ·Art. 5, 32 Feb 14, 2020
€3,000 Vodafone Romania: Insufficient technical and organisational measures to ensure information security Vodafone Romania had incorrectly processed personal data of an individual in order to process a complaint, which was subsequently sent to a wrong e-mail address. The reason for… ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Feb 11, 2020
€1,450 Accounting firm: Insufficient technical and organisational measures to ensure information security A printed customer list of an accounting firm, which also contained personal data, could be accessed by unauthorized persons. HUNGARY · ·Art. 24, 32 Jan 24, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY · ·Art. 5, 32 Jan 23, 2020
€30,000 Sapienza Università di Roma: Insufficient technical and organisational measures to ensure information security The fine is based on the fact that, according to the data protection authority, the Sapienza Università made available online identification data of two people who had reported… ITALY · ·Art. 5, 32 Jan 23, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY · ·Art. 5, 6, 17 +2 Jan 15, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 13, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·Art. 6, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€2,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security A third party has gained unauthorized access to another person's account. Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC · ·Art. 24, 32 Jan 1, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security Accidental loss of personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€150,000 Aegean Marine Petroleum Network Inc.: Insufficient technical and organisational measures to ensure information security Companies outside the Aegean Marine Petroleum Group had access to its servers containing personal data and copied the contents of the servers, since Aegean Marine Petroleum failed… GREECE · ·Art. 5, 6, 32 Dec 19, 2019
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Dec 18, 2019
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM · ·Art. 6, 12, 13 Dec 17, 2019
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM · ·Art. 32 Dec 17, 2019
€5,000 Shop Macoyn, S.L.: Insufficient technical and organisational measures to ensure information security The company has sent advertising e-mails to several recipients where the e-mail addresses of all other recipients were visible to all recipients, because the recipient addresses… SPAIN · ·Art. 32 Dec 10, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA · ·Art. 5, 25, 32 +1 Dec 10, 2019
€20,000 S CNTAR TAROM SA (Airline): Insufficient technical and organisational measures to ensure information security The Romanian data protection authority imposed a sanction on an airline because it has not taken appropriate measures to ensure that any natural person acting under its… ROMANIA · ·Art. 32 Dec 4, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Dec 3, 2019
€2,500 Royal President S.R.L.: Insufficient fulfilment of data subjects rights Royal President refused a request for access to personal data pursuant to Article 15 of the GDPR and disclosed personal data without the consent of the data subjects. In addition,… ROMANIA · ·Art. 6, 15, 32 Nov 29, 2019
€500 Homeowners Association: Insufficient technical and organisational measures to ensure information security The association used video surveillance systems without proper information according to Art. 13 GDPR and without adequate security measures regarding the persons having access to… ROMANIA · ·Art. 32 Nov 29, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA · ·Art. 32 Nov 28, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA · ·Art. 32 Nov 25, 2019
€60,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security An individual complainant had received an SMS from Xfera Móviles which was to be addressed to a third party and which allowed him to access the account and personal data of this… SPAIN · ·Art. 32 Nov 19, 2019
€60,000 Corporación radiotelevisión espanola: Insufficient technical and organisational measures to ensure information security CORPORACIÓN RADIOTELEVISIÓN ESPAÑOLA and the trade union have reported a security breach to the AEPD after six unencrypted USB sticks containing personal data were lost. The… SPAIN · ·Art. 32 Nov 19, 2019
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS · ·Art. 32 Oct 31, 2019
€100,000 Food company: Insufficient technical and organisational measures to ensure information security The company had set up an applicant portal on its website where interested parties could submit their application documents online. However, the company did not offer an encrypted… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Oct 24, 2019
€15,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security Original fine summary: Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the… ROMANIA · ·Art. 32 Oct 9, 2019
€20,000 Vreau Credit SRL: Insufficient technical and organisational measures to ensure information security Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the platform's staff via… ROMANIA · ·Art. 32, 33 Oct 9, 2019
€660,000 Morele.net: Insufficient technical and organisational measures to ensure information security The Polish data protection authority imposed a fine of over PLN 2.8 million (approx. €644,780) on Morele.net for insufficient organisational and technical safeguards, which led to… POLAND · ·Art. 32 Sep 10, 2019
€511,000 DSK Bank: Insufficient technical and organisational measures to ensure information security Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit… BULGARIA · ·Art. 32 Aug 28, 2019
€2.6M National Revenue Agency: Insufficient technical and organisational measures to ensure information security Leakage of personal data in a hacking attack due to inadequate technical and organisational measures to ensure the protection of information security. It was found that personal… BULGARIA · ·Art. 32 Aug 28, 2019
€4,290 Public area maintenance company: Non-compliance with general data processing principles An ex-employee complained that his employer unlawfully monitored his work by its CCTV. The employer argued that CCTV monitoring was necessary to assess, whether the employee… HUNGARY · ·Art. 5, 6, 13 Aug 2, 2019
€180,000 ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had… FRANCE · ·Art. 32 Jul 25, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA · ·Art. 32 Jul 5, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA · ·Art. 32 Jul 2, 2019
€130,000 UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations,… ROMANIA · ·Art. 5, 25 Jun 27, 2019
€350,000 Haga Hospital: Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data… THE NETHERLANDS · ·Art. 32 Jun 18, 2019
€400,000 SERGIC (Real Estate): Insufficient technical and organisational measures to ensure information security The CNIL based the penalty on two grounds: Lack of basic security measures and excessive data storage. As to the first, sensitive user documents uploaded by rental candidates… FRANCE · ·Art. 5 May 28, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY · ·Art. 32 Apr 29, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY · ·Art. 32 Apr 17, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Apr 12, 2019
€170,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in… NORWAY · ·Art. 5, 32 Mar 1, 2019