Content type · 240 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 +2 Jul 10, 2025
€15,600 Kinderziekenhuis van de L. Zamenhof Universiteit in Białystok: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 5, 32 Jun 30, 2025
€7,000 Algemeen Ziekenhuis van de Universiteit van Larissa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 5, 14, 15 Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE · ·Art. 5, 12, 13 +3 Jun 24, 2025
€2.7M 23andMe, Inc.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.700.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM · ·Art. 5, 32 Jun 5, 2025
€1.1M Universiteitsapotheek: Niet-naleving van algemene principes voor gegevensverwerking. 1.100.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND · ·Art. 5, 32 May 27, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY · ·Art. 5, 13 May 21, 2025
€7,000 Gezondheidsbeschermingsagentschap van de Metropool van Milaan, Dienst Preventie en Veiligheid op de Werkplek, Noord-Milaan: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 7.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 9 May 21, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY · ·Art. 5, 9 May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Niet-naleving van de algemene principes voor gegevensverwerking. 21.000 euro boete - Italiaanse Autoriteit voor de bescherming van persoonlijke gegevens (Garante). ITALY · ·Art. 5, 13 May 21, 2025
€5,000 Maravet S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 32 May 19, 2025
€6,600 Eigenaar van een apotheek: Niet-naleving van algemene principes voor gegevensverwerking. Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 6, 14, 32 May 9, 2025
€6,600 Eigenaar van een apotheek: Overtreding van de algemene principes van gegevensverwerking. Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 6, 14, 32 May 8, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY · ·Art. 5, 6, 9 Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY · ·Art. 28, 32 Apr 29, 2025
€2,000 Ziekenhuis Tirrenia S.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 12, 15 Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 28, 32 Apr 29, 2025
€40,000 Gemeente Bologna: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 Apr 29, 2025
€7,800 Uitvaartonderneming: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND · ·Art. 5 Apr 15, 2025
€5,000 Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 15 Apr 9, 2025
€3.5M Advanced Computer Software Group Ltd: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.500.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM · ·Art. 32 Mar 26, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA · ·Art. 13, 32, 33 +1 Mar 24, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND · ·Art. 6, 9 Mar 24, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA · ·Art. 12, 15 Feb 27, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA · ·Art. 32 Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA · ·Art. 5, 6, 9 Feb 17, 2025
€34,300 Primary Health Care in the Capital Area: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 34,300 on the Primary Health Care in the Capital Area. The controller processed personal and health data in shared medical record… ICELAND ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Feb 17, 2025
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND · ·Art. 33, 34 Nov 26, 2024
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… Jul 22, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY · ·Art. 5, 25, 32 +1 Jul 4, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND · ·Art. 24, 25, 32 +1 Jun 13, 2024
€500 Comune di Ustica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500 on Comune di Ustica. The municipality had published a document, containing personal data (including health data) of private… ITALY · ·Art. 2, 5, 6 +2 Jun 6, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA · ·Art. 32 May 9, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN · ·Art. 32, 33 May 8, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY · ·Art. 5, 9, 32 Feb 8, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Jan 1, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Jan 1, 2024
€3,300 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,300 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Jan 1, 2024
€3,700 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,700 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Jan 1, 2024
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… CYPRUS ·Art. 5 ·Non-compliance with general data processing principles Dec 7, 2023
€1,000 GREECE DPA: Non-compliance with general data processing principles Unlawful disclosure of health data. ·Art. 5 ·Non-compliance with general data processing principles Oct 11, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY · ·Art. 5, 25, 32 Sep 28, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY · ·Art. 5, 32 Sep 28, 2023
€5,000 Physician: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on a physician for unlawfully disclosing patient data. ITALY · ·Art. 5, 9 Sep 28, 2023
€5,000 Ministero dell'Ambiente e della Sicurezza Energetica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Ministero dell'Ambiente e della Sicurezza Energetica. The controller had published a document on its website that contained… ITALY · ·Art. 2, 5, 6 +1 Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY · ·Art. 5, 9 Sep 28, 2023
€10,000 Phyisician: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 10,000 on a physician. The physician had responded to an online review regarding their practice, disclosing personal health data of a… AUSTRIA · ·Art. 5, 9 Sep 26, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN · ·Art. 9, 13 Sep 25, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY · ·Art. 2, 5, 9 +1 Jun 1, 2023