Content type · 130 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€14M Avast Software s.r.o.: €13,900,000 fine The Czech DPA has fined Avast Software s.r.o. EUR 13.9 million. The company had disclosed the personal data of around 100 million users of its antivirus software to the US company… CZECH REPUBLIC · ·Unknown Apr 15, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY · ·Art. 5, 32 Feb 8, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS · ·Art. 35 Jan 15, 2024
Belgian DPA settles with Mediafin: De Tijd cookie banner must add equal "refuse all" On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The… 159/2023 ·Belgium · Nov 24, 2023
€2,000 UNIQUE HOTEL APARTMENT S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on UNIQUE HOTEL APARTMENT. The controller had copied identification documents for the purposes of guest registration and stored the… SPAIN · ·Art. 5 Oct 18, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA · ·Art. 6, 13, 32 +1 Sep 26, 2023
€25,000 Zagreb Holding d.o.o.: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed a fine of EUR 25,000 on Zagreb Holding d.o.o., utilities company owned by the city of Zagreb. The DPA had received a complaint from a citizen… CROATIA · ·Art. 13, 25 Sep 13, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Aug 28, 2023
DPC (Ireland) - 06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Art. 5, 24, 35 Aug 22, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Jun 28, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA · ·Art. 6, 13, 28 +1 May 4, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA · ·Art. 5, 32 Apr 20, 2023
€1,020 Telecommunications Operator: Non-compliance with general data processing principles The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient identification methodes, resulting in a customer… BULGARIA · ·Art. 5 Mar 16, 2023
€3M CNIL fines VOODOO for cookie and tracker consent failures in mobile games VOODOO ('provider') was a mobile game developer. The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of… France ·Art. 4, 5, 82 Dec 29, 2022
DKK 500,000 Datatilsynet (Denmark) - 2022-63-0003 A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Art. 5, 9, 24 +2 Oct 28, 2022
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Sep 22, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN · ·Art. 6 Sep 16, 2022
€10,000 Bper Banca S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Bper Banca S.p.A.. An individual had filed a complaint with the DPA regarding the failure to fulfill their right to erasure of… ITALY · ·Art. 12 Sep 15, 2022
€48,000 NATURGY ENERGY GROUP, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on NATURGY ENERGY GROUP, S.A.. A person had contacted the energy company pretending to be a relative of a customer. The person requested to… SPAIN · ·Art. 5, 32 Aug 28, 2022
APD/GBA (Belgium) - 117/2022 The data subject was a former customer of the controller (which remained unknown). The data subject received direct marketing from the controller. The data subject objected to the… 117/2022 ·Art. 6, 12, 15 +1 Jul 26, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Jul 19, 2022
Garante per la protezione dei dati personali (Italy) - 9788429 Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Jul 7, 2022
€50 APD/GBA (Belgium) - 85/2022 On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Art. 4, 5, 6 +3 May 25, 2022
€85,000 Otavamedia Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 85,000 on Otavamedia Oy. The DPA had received eleven complaints regarding Otavamedia between 2018 and 2021. Namely, the complaints… FINLAND · ·Art. 5, 12, 15 +2 May 9, 2022
€1.5M DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press… FRANCE · ·Art. 28, 29, 32 Apr 15, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY · ·Art. 5, 32 Mar 4, 2022
BfDI (Germany) - 24-191 II The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Art. 15, 20, 95 Jan 27, 2022
Belgian DPA rules on competence in cross-border cookie consent complaint involving The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium · Jan 21, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Jan 5, 2022
€110,000 UAB Prime Leasing: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000. The DPA conducted the investigation on its own initiative… LITHUANIA · ·Art. 32 Nov 29, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS · ·Art. 32 Nov 12, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY · ·Art. 5, 32 Oct 18, 2021
€78,000 Bank Millennium S.A: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 78,000 on Bank Millennium S.A.. The UODO had become aware of a data protection breach following a complaint against the bank. It… POLAND · ·Art. 33, 34 Oct 14, 2021
DSB (Austria) - 2021-0.698.184 The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered… 2021-0.698.184 ·Art. 6, 51, 57 +1 Oct 8, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK · ·Art. 32 Sep 29, 2021
€6,000 Furnishyourspace S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) imposed a fine of EUR 6,000 on FurnishYourSpace S.L.. The AEPD had received a complaint from the Berlin DPA via the EU Internal Market Information System… SPAIN · ·Art. 5, 6, 12 +2 Aug 30, 2021
€120,000 Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. The reason for this had been a complaint from a person relating to a lack of authentication.… SPAIN · ·Art. 32 Aug 25, 2021
€600 DSB Austria: sharing medical assessment with municipality lacked Art. 9(2) legal basis Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had… Art. 4, 5, 9 +1 Aug 5, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA · ·Art. 9 Aug 5, 2021
€200,000 Regione Lombardia: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on the Region of Lombardy. The region had published on its website the personal data of more than 100,000 students who… ITALY · ·Art. 5, 6 Jul 22, 2021
€3,000 Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal… POLAND · ·Art. 33, 34 Jun 30, 2021
€20,000 UAB VS FITNESS: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) has imposed a fine of EUR 20,000 on UAB VS FITNESS. After receiving a notification from an individual stating that scanning a fingerprint was necessary… LITHUANIA · ·Art. 5, 9, 13 +2 Jun 21, 2021
€1.6M Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has fined Storstockholms Lokaltrafik (Stockholm Local Transport Company) EUR 1,600,000. The controller had equipped ticket inspectors with body-worn cameras, which… SWEDEN ·Art. 5, 6, 13 ·Insufficient legal basis for data processing Jun 21, 2021
€40,000 Aeroporto Guglielmo Marconi di Bologna S.p.a.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY · ·Art. 5, 25, 32 Jun 10, 2021
€40,000 aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY · ·Art. 28, 32 Jun 10, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND · ·Art. 5, 12, 14 +3 Apr 21, 2021
€75,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 27, 2021
€150,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 27, 2021
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 75,000 on Telefónica Móviles España, SAU. The controller had assigned five telephone lines with five numbers to the data subject as… SPAIN · ·Art. 6 Jan 21, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND · ·Art. 33, 34 Jan 5, 2021