Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

901–950 of 2,395 sort newestlargest fineoldest
€3,200 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 3,200 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Nov 16, 2023
€20,000 FORO ASTURIAS: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 20,000 on FORO ASTURIAS. An individual had filed a complaint with the DPA due to the fact that personal data stored by the controller had… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing Nov 16, 2023
€500 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on a private individual. The individual had installed a video surveillance system in a laundromat operated by them without… SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Video Surveillance Nov 16, 2023
€100,000 Autostrade per l’Italia S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Autostrade per l’Italia S.p.A. EUR 100,000 for failing to adequately respond to requests from employees for access to their personal data. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Nov 16, 2023
€10,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on a private individual. The controller had uploaded an individual's personal data, including their name, a picture and their… SPAIN ·AEPD ·Art. 6 Personal Data Consent Controllers Nov 15, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Controllers Nov 13, 2023
€200,000 CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. The controller had included the data subject's personal data in a credit… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Insurance Nov 13, 2023
€20,000 Piraeus Leasing S.M.S.A.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000 on Piraeus Leasing S.M.S.A.. An individual had filed a complaint with the DPA because the controller processed an image on which… GREECE ·HDPA ·Art. 5, 15 Personal Data Controllers Supervisory Authorities Nov 10, 2023
€43,000 Indcap AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 43,000 on Indecap AB. The controller had accidentally sent an email to a large number of its customers containing an Excel document… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 7, 2023
€1,000 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on a homeowners' association. A property owner had filed a complaint with the DPA. The controller had published an enforcement… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing Nov 7, 2023
€5,000 Municipality: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 5,000 on a municipality. The municipality had published a person's personal data on the municipality's website and failed to comply with… GREECE ·HDPA ·Art. 6, 17 Personal Data Public Authority Supervisory Authorities Nov 7, 2023
€200,000 DIGI SPAIN TELECOM, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on DIGI SPAIN TELECOM, S.L.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Telecommunications Nov 6, 2023
€240 Private individual: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 240 on a private individual. The controller had installed video surveillance cameras without properly informing data subjects. SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Nov 6, 2023
€600 Hotel: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 600 on a hotel. The controller had installed video surveillance cameras which, among other things, also covered the public space and… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Nov 3, 2023
€2,000 SINDICATO LIBRE DE TRANSPORTES: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on SINDICATO LIBRE DE TRANSPORTES. A member of the union had shared the data subject's payslip in a WhatsApp group without the data subject's… SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Supervisory Authorities Nov 3, 2023
€3,000 OTP BANK ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA. The controller had accidentally transmitted personal data of an individual to an unauthorized third party.… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 3, 2023
€30,000 APOLLONIA TOPCO, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 30,000 on APOLLONIA TOPCO, S.L.. An individual had filed a complaint with the DPA due to the fact that, in order to receive a refund,… SPAIN ·AEPD ·Art. 5, 38 Retention Period Personal Data Controllers Nov 2, 2023
€48,000 INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P.: Non-compliance with general data processing principles The Spanish DPA has imposed a finea INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P. The controller had suffered a data breach in which personal patient and employee data had… SPAIN ·AEPD ·Art. 5, 32, 34 Data Breaches Security Controllers Nov 2, 2023
€30,000 Voorschoten municipality: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 30,000 on Voorschoten municipality. The municipality had kept information about household waste for longer than necessary and had not… THE NETHERLANDS ·AP ·Art. 5, 6, 14 Personal Data Supervisory Authorities Processing Nov 2, 2023
€180 Private individual: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 180 on a private individual. The controller had installed video surveillance cameras without properly informing data subjects. SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Oct 31, 2023
€10,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on a private individual for publishing intimate images of the data subject on YouTube without their consent. SPAIN ·AEPD ·Art. 6 Consent Personal Data Supervisory Authorities Oct 28, 2023
€500 Homeowners Association: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Oct 27, 2023
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·AEPD ·Art. 5, 25, 32 Privacy by Design & Default Privacy by Default Privacy by Design Oct 26, 2023
€7,000 Ophthalmologic institute: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 7,000 on a ophthalmologic institute. The controller had responded to an online review, disclosing personal data of a patient. SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing Oct 26, 2023
€20,000 Region of Lombardy: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Region of Lombardy. In the context of the sale of company shares held by the region, personal data of employees of the… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Processing Public Authority Oct 26, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·AEPD ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Controllers Oct 25, 2023
€1,000 SC Spark Car Sharing SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Spark Car Sharing SRL. An individual had filed a complaint with the DPA because the controller had processed their email… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Controllers Personal Data Consent Oct 25, 2023
€3,000 Mensajero SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Mensajero SRL. The controller had suffered a data breach where a link on the controller's website was publicly accessible… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 24, 2023
€50,000 Oney Servicios Financieros E.F.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on Oney Servicios Financieros E.F.C... The controller had submitted data from the data subject to a credit information system… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Oct 23, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Oct 23, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN ·AEPD ·Art. 25, 32 Security Privacy by Design & Default Controllers Oct 20, 2023
€1,000 DANTE INTERNATIONAL SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on DANTE INTERNATIONAL SA. The controller had sent marketing SMS to a data subject without a valid legal basis. ROMANIA ·ANSPDCP ·Art. 6 Personal Data Controllers Direct Marketing Oct 20, 2023
€24,000 Insurance company: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an insurance company EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 18, 2023
€600 FESTINA LOTUS S.A.: Insufficient fulfilment of data subjects rights The Spanish Data Protection Authority has imposed a fine of EUR 600 on FESTINA LOTUS S.A. due to the fact that the controller had not properly complied with a data subject's… SPAIN ·AEPD ·Art. 17 Personal Data Controllers Supervisory Authorities Oct 18, 2023
€30,000 H&M Hennes & Mauritz GBC AB: Insufficient fulfilment of data subjects rights The Swedish DPA has imposed a fine of EUR 30,000 on H&M for sending out marketing messages, despite the fact that data subjects had exercised their right to objection. Six data… SWEDEN ·Art. 12, 21 ·Insufficient fulfilment of data subjects rights Right to Object Direct Marketing Personal Data Oct 17, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA has fined a private individual EUR 600 for installing a video surveillance camera that captured parts of a commonly shared garage. The DPA considered this a… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Oct 15, 2023
€600,000 GROUPE CANAL +: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on GROUPE CANAL+ for multiple violations of the GDPR. The DPA determined that the data controller failed to demonstrate that it… FRANCE ·CNIL ·Art. 7, 12, 13 +5 Data Breaches Personal Data Controllers Oct 12, 2023
€70,000 Scionti Selezioni Superiori S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on Scionti Selezioni Superiori S.r.l.. The controller had made unsolicited marketing calls, in some cases to individuals who were… ITALY ·Garante ·Art. 5, 6, 7 +7 Personal Data Right to Object Privacy by Design & Default Oct 12, 2023
€24,000 Link4 Towarzystwo Ubezpieczeń S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Link4 Towarzystwo Ubezpieczeń S. A. EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 8, 2023
DSB-D124.5337 In August 2021, an unprotected Excel file containing the names and PCR test results of several thousand individuals was sent from the compromised email account of the first data… 2023-0.273.912 ·Austria ·Art. 5, 6, 12 +3 Right to be Forgotten Right of Access Personal Data Oct 6, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·AZOP ·Art. 5, 6, 12 +2 Personal Data Legitimate Interest Controllers Oct 5, 2023
€1,000 Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Cez Vânzare S.A.. The controller had accidentally sent emails containing personal customer data to the wrong recipients. The… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 2, 2023
€10M Axpo Italia Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained… ITALY ·Garante ·Art. 5, 24 Controllers Personal Data Processing Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Personal Data Processing Sep 28, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Sep 28, 2023
€3,000 Palombaro s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Palombaro s.r.l. EUR 3,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects about… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Sep 28, 2023
€70,000 DIGI SPAIN TELECOM, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on DIGI SPAIN TELECOM, S.L.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Telecommunications Sep 26, 2023
€1,040 Self Employed Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,040 on a self employed person. The accused's website did not comply with GDPR requirements for cookies, as it processed data before… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 13 Personal Data Supervisory Authorities Consent Sep 26, 2023
€25,000 RESTART ENERGY ONE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on RESTART ENERGY ONE S.A.. During its investigation, the DPA found that there existed a publicly accessible file on the… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Sep 26, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·AZOP ·Art. 6, 13, 32 +1 Personal Data Controllers Encryption Sep 26, 2023