Skip to content
Content type · 91 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–91 of 91 sort newestlargest fineoldest
Daycare center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a four-figure fine on a daycare center that had disposed of documents containing personal data of children and their parents in a publicly… GERMANY ·HmbBfDI ·Art. 32 Security Personal Data Education Jan 1, 2023
€525,000 TECHPUMP SOLUTIONS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Techpump Solutions S.L. EUR 525,000. Techpump operates several websites with adult content. The DPA found several violations of data protection law… SPAIN ·AEPD ·Art. 5, 6, 8 +5 Retention Period Personal Data Storage Limitation Oct 31, 2022
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·Datatilsynet (DK) DPIA Controllers Prior Consultation
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN ·AEPD ·Art. 6 Lawful Basis Personal Data Legitimate Interest Sep 16, 2022
€15 Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient A former teacher (the data subject) at a private primary school (the controller) submitted a complaint to the Greek DPA regarding a video surveillance system in the classrooms,… Greece ·Art. 5, 6, 12 +2 Legitimate Interest Personal Data Accountability Sep 9, 2022
€405M Meta Platforms, Inc.: Non-compliance with general data processing principles The Irish DPA (DPC) has imposed a fine of EUR 405,000,000 on Meta Platforms, Inc. (Instagram). Following the investigation, the DPC submitted a draft decision under Art. 60 GDPR… IRELAND ·DPC ·Art. 5, 6, 12 +3 Supervision Supervisory Authorities Processing Sep 5, 2022
Italy Garante: TikTok switch to legitimate interest for personalized ads violates Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Legitimate Interest Direct Marketing Marketing Jul 7, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual. The individual had taken photos of a group of minors as well as police officers without their consent and… SPAIN ·AEPD ·Art. 6 Consent Social Media Minors May 20, 2022
€36,000 City of Reykjavík: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 36,000 on the City of Reykjavík. The city had used the digital education system 'Seesaw' at several schools. The student system… ICELAND ·Persónuvernd ·Art. 5, 6, 32 Retention Period Personal Data Security May 3, 2022
€1,000 Educationest s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Educationest s.r.l. EUR 1,000. The daycare center had sent an email to the families of the children in its care, informing them of the pregnancy and the… ITALY ·Garante ·Art. 5, 6 Consent Processing Education Apr 28, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Storage Limitation Security Apr 7, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
Company: Insufficient legal basis for data processing The DPA of Bremen has imposed a five-digit fine on a company. The company had sent an unredacted social plan to all affected employees in the context of dismissals due to… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Types of Special Categories of Personal Data Employees Jan 1, 2022
Sports photography company: Insufficient legal basis for data processing The DPA of Berlin has imposed a fine on a sports photography company. A sports photographer had published over 16,000 photos of minors who had taken part in a swimming competition… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Consent Processing Minors Jan 1, 2022
€150M Google LLC is a subsidiary owned wholly by Alphabet Inc Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out… SAN-2021-023 ·France ·CNIL Supervision Supervisory Authorities Material scope (GDPR) Dec 31, 2021
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Dec 16, 2021
€1,000 IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,000 on IKEA ROMÂNIA SA. The controller had sent a notification to the DPA about a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Nov 1, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… DPC ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Transparency Information Provision Modalities and Communication Methods Fairness & Transparency Sep 2, 2021
€1,500 MOVE Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data Aug 20, 2021
€200 Private Individual: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on a private individual due to the unlawful disclosure of personal data. The controller had disclosed personal data of… ROMANIA ·ANSPDCP ·Art. 5, 6, 14 Personal Data Controllers Processing Jul 30, 2021
€2.5M Mercadona S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals… SPAIN ·AEPD ·Art. 5, 6, 9 +4 Criminal Data Retention Period Types of Special Categories of Personal Data Jul 26, 2021
€67,900 Region of Syddanmark: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has fined the Region of Syddanmark EUR 67,900 for failing to comply with its obligation as a data controller to implement adequate security measures.… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Controllers Personal Data Jul 16, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Jun 16, 2021
€34,000 Huppuís ehf: Non-compliance with general data processing principles The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 34,000 on Huppuís ehf. A former employee filed a complaint against the controller with the DPA. The reason for this was… ICELAND ·Persónuvernd ·Art. 5, 6, 12 +1 Legitimate Interest Controllers Personal Data Jun 15, 2021
€150,000 Azienda Provinciale per i Servizi Sanitari di Trento: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Provinciale per i Servizi Sanitari di Trento EUR 150,000. The controller had accidentally forwarded 293 medical reports of 175 patients… ITALY ·Garante ·Art. 5, 9 Controllers Healthcare Processing May 27, 2021
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Persónuvernd ·Art. 32 Data Breaches Security Controllers Apr 29, 2021
€750,000 TikTok: Insufficient fulfilment of information obligations The Dutch DPA (AP) has fined the video portal TikTok EUR 750,000 for violating the privacy of young children. The information that Dutch users - mostly young children - received… THE NETHERLANDS ·AP ·Art. 12 Personal Data Supervisory Authorities Supervision Apr 9, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 24 +1 Personal Data Security Public Authority Mar 15, 2021
€12,000 Orthodontic Clinic: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined an orthodontic clinic EUR 12,000. The web form that new patients used to sign up contained mandatory fields for all sorts of patient personal data.… THE NETHERLANDS ·AP ·Art. 32 Encryption Security Personal Data Feb 4, 2021
€38,600 Coop Finnmark SA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Coop Finnmark SA NOK 400,000 (EUR 38,600). The manager of the store in question recorded CCTV footage with a mobile phone and shared the… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Processing Video Surveillance Supervisory Authorities Jan 14, 2021
Physician: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a four-digit fine on a doctor of child and adolescent psychotherapy. The doctor had set up a Whatsgroup with 230 participants to communicate… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Healthcare Supervisory Authorities Jan 1, 2021
€800,000 Carrefour Banque: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine on Carrefour Banque for violation of its obligation to process data fairly (Article 5 (1) GDPR). If a person who subscribed to the Pass card… FRANCE ·CNIL ·Art. 5 Accountability Processing Insurance Nov 18, 2020
32/2020 The complainant, making use of the Greek Ministry of Education and Religion's Order 12773/Δ2/23.01.2015, filed in the name of their son an exemption request from the participation… 32/2020 ·Greece ·HDPA Personal Data Types of Special Categories of Personal Data Retention Period Sep 7, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet (NO) ·Art. 32, 35 DPIA Security Types of Special Categories of Personal Data Jul 10, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·DPC ·Art. 5, 6 Personal Data Processing Public Authority May 17, 2020
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Processors Territorial scope (GDPR) Sep 3, 2019
€18,630 School in Skellefteå: Insufficient legal basis for data processing A school in Skellefteå made a trial to use facial recognition technology. The fine was imposed against the school which had used facial recognition technology to monitor the… SWEDEN ·Art. 5, 9, 35 +1 ·Insufficient legal basis for data processing Types of Special Categories of Personal Data Monitoring Personal Data Aug 20, 2019
€286 Directorate of Social and Child Welfare Institutions of the Ferencvaros District of Budapest: Insufficient fulfilment of data breach notification obligations The employee of the Directorate sent by mistake 9 letters to the wrong recipient, which contained personal data of 18 data subjects (including data of children, criminal data and… HUNGARY ·NAIH ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations May 21, 2019
€170,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Public Authority Mar 1, 2019
Norwegian DPA: Legelisten.no may process healthcare reviews without prior consent Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Norway ·Datatilsynet (NO) Consent Supervisory Authorities Legitimate Interest Nov 8, 2017