Skip to content
Content type · 69 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–69 of 69 sort newestlargest fineoldest
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€3,400 Company: Insufficient legal basis for data processing The Czech DPA imposed a fine of EUR 3,400 on a company. The data subject had concluded an energy supply contract with the controller in the past, but then duly terminated it.… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Insufficient legal basis for data processing Processors Controllers Personal Data Jan 1, 2022
DSB Austria: Publishing companies-register data on free ad-funded platform unlawful The data subject was a shareholder and managing director of two companies. The controller operated a free online search platform that allowed users to look up companies registered… 2021-0.698.184 ·Art. 6, 51, 57 +1 Legitimate Interest Personal Data Lawful Basis Oct 8, 2021
€1.5M EDP Energía, S.A.U: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Energía, S.A.U.. The decision follows, in particular, several complaints received for processing personal data… SPAIN ·AEPD ·Art. 13, 25 Personal Data Controllers Supervisory Authorities May 4, 2021
€1.5M EDP Comercializadora, S.A.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing… SPAIN ·AEPD ·Art. 13, 25 Controllers Personal Data Supervisory Authorities May 4, 2021
€200,000 I-DE Redes Eléctricas Inteligentes, S.A.U: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on I-DE Redes Eléctricas Inteligentes, S.A.U. The DPA received complaints from Waitum, S.L. and Servicios Aby 2018, S.L.… SPAIN ·AEPD ·Art. 5, 6 Integrity and Confidentiality Principle Retention Period Controllers Mar 2, 2021
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives Personal Data Supervision Dec 20, 2020
€1,500 Political Party: Insufficient legal basis for data processing Sending of an e-mail to a former party member who had since resigned, with the request to act as an election representative without sufficient legal basis to process the personal… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Public Authority Sep 11, 2020
Datatilsynet (Norway)- 20/02254 The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Datatilsynet (NO) ·Art. 57, 58 Telecommunications Supervision Supervisory Authorities Sep 7, 2020
GBP 130,000 CPS Advisory Limited CPS Advisory Limited (CPSAL) conducted direct marketing calls in relation to personal pensions. The data CPSAL used to conduct the calls had been purchased from third party data… United Kingdom ·ICO ·Art. 55A Supervisory Authorities Direct Marketing Consent Sep 4, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN ·AEPD ·Art. 6 Personal Data Telecommunications Representatives Jun 9, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ÚOOÚ (CZ) ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing May 26, 2020
€290 Representative of a local government: Insufficient legal basis for data processing A local representative took a photo of the director of a company fully owned by the local government depicting the director allegedly tearing off an election poster of the… HUNGARY ·NAIH ·Art. 5, 6, 12 +2 Consent Processing Representatives Mar 4, 2020
The complainant belongs to a political party and is a member of the city council of an Austrian municipality In November, the municipality held a meeting on the "parking space concept", to which a certain group of addressees, including the complainant, was invited. The complainant did… DSB-D123.768/0004-DSB/201 ·Austria ·DSB Public Authority Pseudonymization Anonymization Dec 18, 2019
€1,430 Unknown Company: Non-compliance with general data processing principles The employer restored the mailbox of a director who had left the company a year before and found an email containing a work-related document. The director received no warning that… HUNGARY ·NAIH ·Art. 5, 6, 13 +2 Representatives Processing Employees Dec 11, 2019
€11,760 Commercial representative of telecommunication service provider: Insufficient legal basis for data processing The pecuniary sanction of EUR 11, 760 was imposed on the commercial representative of telecommunications service provider for unlawful processing of the personal data of a data… BULGARIA ·CPDP ·Art. 6 Personal Data Representatives Integrity and Confidentiality Principle Sep 3, 2019
€5,113 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·CPDP ·Art. 6, 25 Personal Data Consent Integrity and Confidentiality Principle Sep 3, 2019
€1,022 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·CPDP ·Art. 6, 25 Personal Data Consent Integrity and Confidentiality Principle Sep 3, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Right of Access Personal Data Apr 29, 2019