Skip to content
Content type · 70 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–70 of 70 sort newestlargest fineoldest
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Data Breaches Integrity and Confidentiality Principle Security Feb 11, 2021
€1,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine of EUR 1,000 on ING Bank N.V. Amsterdam - Bucharest Branch. It was found that the controller had sent files to a contractual partner in… ROMANIA ·ANSPDCP ·Art. 29, 32 Integrity and Confidentiality Principle Professional Secrecy Audit Logs Feb 10, 2021
€1,000 Qualitance QBS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Qualitance QBS SA EUR 1,000 for a violation of Art. 32 GDPR. The company had sent information by email to 295 individuals, disclosing the email… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Security Professional Secrecy Dec 29, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 17, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Garante ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Integrity and Confidentiality Principle Nov 26, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Oct 21, 2020
€3,000 Barcelona Airport Security Guard Association ('AVSAB'): Non-compliance with general data processing principles A member of the AVSAB security committee used WhatsApp to send messages to private phone numbers containing personal information about employees. This was a violation of the… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Controllers Sep 7, 2020
€5,000 Basketball Federation of Castilla and Leon: Insufficient legal basis for data processing The Basketball Association transmitted personal data to third parties, which were subsequently published on the Internet without consent of the data subjects. In addition, the… SPAIN ·aepd ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Professional Secrecy Aug 28, 2020
€70,000 Xfera Moviles S.A.: Non-compliance with general data processing principles A data subject had received a call from another Xfera Móviles customer who stated that the company had charged his bank account with an invoice, disclosing the personal details of… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Jul 20, 2020
€800,000 Iliad Italia S.p.A.: Non-compliance with general data processing principles The fine relates to data protection infringements concerning the processing of customer data for the activation of SIM cards and the manner in which payment data was recorded. In… ITALY ·Garante ·Art. 5, 25 Integrity and Confidentiality Principle Fairness & Transparency Personal Data Jul 13, 2020
€55,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The company had changed a contract for a mobile phone connection to a new owner, whereby the personal data of a data subject such as his address and telephone numbers were freely… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Professional Secrecy Personal Data Jul 10, 2020
€24,000 Iberdrola Clientes: Non-compliance with general data processing principles A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Security Jul 2, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Education Professional Secrecy Mar 16, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Personal Data Mar 9, 2020
€2,500 Grupo Valsor Y Losan, S.L.: Insufficient technical and organisational measures to ensure information security The controller had disclosed personal data to a third party in a property purchase agreement (breach of principles of integrity and confidentiality of personal data) SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Security Feb 14, 2020
CNPD (Portugal) - Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Art. 2, 3, 5 +8 Controllers Personal Data Processing Sep 3, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Anonymization Security Apr 12, 2019
€582 CZECH REPUBLIC DPA: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… UOOU ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Professional Secrecy Feb 28, 2019
€1,165 Credit brokerage: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… CZECH REPUBLIC ·UOOU ·Art. 32 Integrity and Confidentiality Principle Security Insurance Feb 4, 2019
Datatilsynet (Norway) - 15/01355 Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Art. 4, 5, 6 +3 Legitimate Interest Healthcare Personal Data Nov 8, 2017