Skip to content
Content type · 128 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 128 sort newestlargest fineoldest
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·AEPD ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Controllers Oct 25, 2023
€345M TikTok Limited: Non-compliance with general data processing principles The Irish DPA (DPC), has imposed a fine of EUR 345 million on TikTok Limited. The DPC conducted an investigation primarily focused on the processing of personal data between July… IRELAND ·DPC ·Art. 5, 12, 13 +2 Privacy by Design & Default Processing Personal Data Sep 1, 2023
€10,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on a private individual. The person had published on his Facebook profile a video of another person being clearly drunk without… SPAIN ·AEPD ·Art. 6 Consent Social Media Supervisory Authorities Aug 28, 2023
€20,000 JOLY DIGITAL, S.L.U.: Insufficient legal basis for data processing The Spanish DPA has fined JOLY DIGITAL, S.L.U. EUR 20,000. A person had filed a complaint with the DPA because the controller had published an image they had posted on their… SPAIN ·AEPD ·Art. 6 Controllers Social Media Supervisory Authorities Aug 18, 2023
€10,000 NANDIVALE, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on NANDIVALE, S.L.. The controller had uploaded images on social media of a party at its premises showing minors. The mother of a… SPAIN ·AEPD ·Art. 6 Consent Controllers Social Media Jul 17, 2023
€8,000 Artima S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on Artima S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that employees of… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 15, 2023
€300,000 Rinascente S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing… ITALY ·Garante ·Art. 5, 12, 32 +1 Retention Period DPIA Storage Limitation Jun 8, 2023
€15M TikTok: Non-compliance with general data processing principles The UK DPA (ICO) has fined TikTok EUR 14.5 million. The ICO had found that more than one million British children under the age of 13 were using TikTok without the consent of… UNITED KINGDOM ·ICO ·Art. 5, 12, 13 Fairness & Transparency Personal Data Consent Apr 4, 2023
€50,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.. Several media outlets, including the controller had published an audio… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Apr 3, 2023
€50,000 DIARIO ABC, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on DIARIO ABC, S.L.. Several media outlets, including the controller had published an audio recording of a multiple rape victim's… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 21, 2023
€50,000 UNIDAD EDITORIAL INFORMACION GENERAL S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on UNIDAD EDITORIAL INFORMACION GENERAL S.L.U.. Several media outlets, including the controller had published an audio recording… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 21, 2023
€50,000 LA VANGUARDIA EDICIONES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on LA VANGUARDIA EDICIONES, S.L.. Several media outlets, including the controller had published an audio recording of a multiple… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 21, 2023
€50,000 DISPLAY CONNECTORS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on DISPLAY CONNECTORS, S.L.. Several media outlets, including the controller had published an audio recording of a multiple rape… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 21, 2023
€50,000 EL DIARIO DE PRENSA DIGITAL SL.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on EL DIARIO DE PRENSA DIGITAL SL.. Several media outlets, including the controller had published an audio recording of a multiple… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 21, 2023
€50,000 CONECTA5 TELECINCO, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on CONECTA5 TELECINCO, S.A.U.. Several media outlets, including the controller had published an audio recording of a multiple rape… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 21, 2023
€3,000 CASAL DE L'ESPLUGA DE FRANCOLÍ: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CASAL DE L'ESPLUGA DE FRANCOLÍ. A club managed by the controller had uploaded pictures of a competition showing minors on social media . The… SPAIN ·AEPD ·Art. 6 Controllers Social Media Minors Jan 25, 2023
€390M Meta Platforms Ireland Limited: Non-compliance with general data processing principles The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook… DPC Transparency Supervision Consent Jan 4, 2023
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Consent Personal Data Types of Special Categories of Personal Data Nov 30, 2022
€500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Nov 29, 2022
€265M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Meta Platforms Ireland Limited EUR 265 million. The DPA had launched an investigation against Meta in 2021 after media reports indicated that a dataset… DPC Privacy by Design & Default Security Personal Data Nov 25, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN ·AEPD ·Art. 6 Lawful Basis Personal Data Legitimate Interest Sep 16, 2022
€405M Meta Platforms, Inc.: Non-compliance with general data processing principles The Irish DPA (DPC) has imposed a fine of EUR 405,000,000 on Meta Platforms, Inc. (Instagram). Following the investigation, the DPC submitted a draft decision under Art. 60 GDPR… IRELAND ·DPC ·Art. 5, 6, 12 +3 Supervision Supervisory Authorities Processing Sep 5, 2022
€5,000 Bar owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a bar owner EUR 5,000. The owner had unlawfully shared recordings from the CCTV in the bar via WhatsApp and other social media platforms. SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Social Media Jul 19, 2022
Italy Garante: TikTok switch to legitimate interest for personalized ads violates Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Legitimate Interest Direct Marketing Marketing Jul 7, 2022
€30,000 RADIO TELEVISION MADRID, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on RADIO TELEVISION MADRID, S.A.. Several media outlets, including the controller had published an audio recording of a multiple rape victim's… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jun 23, 2022
€30,000 CORPORACIÓN DE RADIO Y TELEVISIÓN ESPAÑOLA S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CORPORACIÓN DE RADIO Y TELEVISIÓN ESPAÑOLA S.A. Several media outlets, including the controller had published an audio recording of a… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jun 23, 2022
€10,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual EUR 10,000. The individual had created a humiliating and discriminatory video of three siblings based on their skin color, and… SPAIN ·AEPD ·Art. 6 Social Media Human Resources Supervisory Authorities Jun 9, 2022
€50 Belgian DPA: Roularta Media Group violated cookie consent rules On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Belgium ·APD/GBA ·Art. 4, 5, 6 +3 Consent Supervisory Authorities Personal Data May 25, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual. The individual had taken photos of a group of minors as well as police officers without their consent and… SPAIN ·AEPD ·Art. 6 Consent Social Media Minors May 20, 2022
€1,000 LORIS FUEL SHOP SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on the gas station operator LORIS FUEL SHOP SRL. A person had filed a complaint with the DPA because pictures of him were… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data May 12, 2022
€10,000 Nationale Maatschappij der Belgische Spoorwegen: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 10,000 on the Belgian national railroad company (Nationale Maatschappij der Belgische Spoorwegen). A Twitter user who had received an… BELGIUM ·APD/GBA ·Art. 5, 6, 12 +1 Right to Object Personal Data Processing May 4, 2022
€200,000 Amiu S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 200,000 on Amiu S.p.A.. The company operates the waste collection service for the city of Taranto and acted as a processor for this… ITALY ·Garante ·Art. 5, 6, 28 +1 Processors Monitoring Controllers Apr 28, 2022
€150,000 Tarento municipality: Insufficient fulfilment of information obligations The Italian DPA has imposed a fine of EUR 150,000 on Tarento municipality. The company Amiu S.p.A had operated the local waste collection service on behalf of the municipality.… ITALY ·Garante ·Art. 5, 12, 13 +3 Monitoring DPIA Supervisory Authorities Apr 28, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… DPC ·Art. 5, 24 Accountability Supervision Security Mar 15, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Mar 8, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual. The individual had published audiovisual material of a court trial on Twitter without obtaining the… SPAIN ·AEPD ·Art. 6 Consent Social Media Supervisory Authorities Feb 4, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Data Portability Recipient Personal Data Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +3 Anonymization Pseudonymization Marketing Jan 27, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +5 Anonymization Pseudonymization Marketing Jan 27, 2022
APD/GBA · 11/2022 The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·Art. 4, 5, 7 +2 Supervisory Authorities Legitimate Interest Supervision Jan 21, 2022
€2,000 MEETING PUERTO C.B.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on MEETING PUERTO C.B.. The data controller had unlawfully published a picture of the complainant with his partner on Facebook and… SPAIN ·AEPD ·Art. 6 Controllers Social Media Processing Jan 17, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€5,000 Cyprus Judo Federation: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine on the Cyprus Judo Federation. The father of a member had filed a complaint with the DPA because the judo coach of his minor son had published… Cyprus DPA ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Social Media Jan 1, 2022
€60M Facebook Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Facebook Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Social Media Cookies Direct Marketing Dec 31, 2021
€150M Google LLC is a subsidiary owned wholly by Alphabet Inc Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out… SAN-2021-023 ·France ·CNIL Supervision Supervisory Authorities Material scope (GDPR) Dec 31, 2021
€6,000 REAL CLUB NÁUTICO DE RIBADEO: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on REAL CLUB NÁUTICO DE RIBADEO. The controller had uploaded links to court decisions containing personal data of the data… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Social Media Dec 28, 2021
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 6,000 on a private individual. The person had shared a video on Twitter showing images of a sexual assault by a man on a woman. The… SPAIN ·AEPD ·Art. 6 Legitimate Interest Social Media Supervisory Authorities Dec 21, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY ·Garante ·Art. 5, 25, 32 +1 Privacy by Design & Default Security Controllers Dec 16, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021