Skip to content
Content type · 96 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–96 of 96 sort newestlargest fineoldest
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·AZOP ·Art. 6, 7, 13 Personal Data Controllers Consent Sep 14, 2023
€30,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 30,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·AZOP ·Art. 6, 7, 13 Personal Data Controllers Consent Sep 14, 2023
€6,000 ELECTRAWORKS - CEUTA, S.A.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on ELECTRAWORKS - CEUTA, S.A.. The controller had failed to provide sufficient information about the retention periods of personal data. The… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Aug 8, 2023
€100,000 Tiscali Italia SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Tiscali Italia SpA. The controller had sent advertising messages to more than 160,000 customers within four months, even… ITALY ·Garante ·Art. 5, 12, 13 +2 Retention Period Personal Data Storage Limitation Jul 18, 2023
€300,000 Rinascente S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing… ITALY ·Garante ·Art. 5, 12, 32 +1 Retention Period DPIA Storage Limitation Jun 8, 2023
€380,000 Sports betting operator: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 380,000 on a sports betting operator. AZOP had received a complaint from a data subject, stating that the controller had obtained… CROATIA ·AZOP ·Art. 6, 13, 25 +1 Retention Period Controllers Personal Data May 18, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Retention Period Storage Limitation Security Apr 20, 2023
€8,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has fined a company EUR 8, 000. The controller failed ot properly fulfil the data subject's right to access their personal data processed by the company. The… LITHUANIA ·VDAI ·Art. 5, 15 Personal Data Retention Period Storage Limitation Jan 24, 2023
€3,600 Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM: Insufficient legal basis for data processing The Spanish DPA has fined the Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM. The controller processed medical data from Covid-19… SPAIN ·AEPD ·Art. 9, 13 Healthcare Controllers Consent Dec 2, 2022
€600,000 ÉLECTRICITÉ DE FRANCE: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on ÉLECTRICITÉ DE FRANCE (EDF), France's largest electricity supplier. The DPA had received several complaints that individuals… CNIL ·Art. 7, 12, 13 +3 ·Insufficient fulfilment of data subjects rights Right to Object Personal Data Direct Marketing Nov 24, 2022
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE ·CNIL ·Art. 5, 13, 25 +2 Privacy by Default Storage Limitation Retention Period Nov 10, 2022
€180,000 Setúbal municipality: Non-compliance with general data processing principles The Portuguese DPA has imposed a fine of EUR 170,000 on Setúbal municipality. The DPA found data protection violations regarding the collection of personal data from Ukrainian… PORTUGAL ·CNPD (PT) ·Art. 5, 13, 37 Public Authority Retention Period Personal Data Nov 2, 2022
€525,000 TECHPUMP SOLUTIONS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Techpump Solutions S.L. EUR 525,000. Techpump operates several websites with adult content. The DPA found several violations of data protection law… SPAIN ·AEPD ·Art. 5, 6, 8 +5 Retention Period Personal Data Storage Limitation Oct 31, 2022
€2M Alpha Exploration: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2 million on Alpha Exploration. Alpha Exploration operates the social network Clubhouse. In the course of its investigation, the DPA… ITALY ·Garante ·Art. 5, 6, 7 +7 Retention Period DPIA Storage Limitation Oct 6, 2022
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022
€26,000 Policoro municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 26,000 on Policoro municipality. The municipality had installed a video surveillance system without, however, providing sufficient… ITALY ·Garante ·Art. 5, 12, 13 +2 Retention Period Storage Limitation Supervisory Authorities Aug 1, 2022
€1,400 Company: Non-compliance with general data processing principles The DPA of Luxembourg (CNPD) has imposed a fine of EUR 1,400 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this was… LUXEMBOURG ·CNPD (LU) ·Art. 5, 13 Retention Period Storage Limitation Controllers Jun 30, 2022
€134,000 Gyldendal A/S: Non-compliance with general data processing principles The Danish DPA has fined publisher Gyldendal A/S EUR 134,000. During its investigation, the DPA found that the company had kept the data of approximately 685,000 unsubscribed… DENMARK ·Datatilsynet (DK) ·Art. 5 Storage Limitation Processing Telecommunications Jun 22, 2022
€7,000 Asociația de Proprietari Aviației Park: Insufficient legal basis for data processing The Romanian DPA has fined Asociația de Proprietari Aviației Park, operator of a residential facility, EUR 7,000. The controller had processed personal data (surname, first name,… ROMANIA ·ANSPDCP ·Art. 5, 6 Retention Period Storage Limitation Personal Data Jun 20, 2022
€26,000 Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Italy ·Garante ·Art. 5, 12, 13 +3 Public Authority Supervisory Authorities Storage Limitation Jun 9, 2022
€50 Belgian DPA: Roularta Media Group violated cookie consent rules On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Belgium ·APD/GBA ·Art. 4, 5, 6 +3 Consent Supervisory Authorities Personal Data May 25, 2022
€9M Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +7 Retention Period Storage Limitation Right of Access May 18, 2022
€50,000 Palumbo Superyacht Ancona s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Palumbo Superyacht Ancona s.r.l. EUR 50,000. The company had blocked an employee's company email account without permission. The employee had reported… ITALY ·Garante ·Art. 5, 12, 13 +3 Storage Limitation Supervisory Authorities Processing Apr 7, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Storage Limitation Security Apr 7, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Retention Period Storage Limitation Transparency Feb 10, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Data Portability Recipient Right of Access Jan 27, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Garante ·Art. 2, 5, 6 +6 Privacy Shield Retention Period Monitoring Sep 16, 2021
€6,000 Furnishyourspace S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) imposed a fine of EUR 6,000 on FurnishYourSpace S.L.. The AEPD had received a complaint from the Berlin DPA via the EU Internal Market Information System… SPAIN ·AEPD ·Art. 5, 6, 12 +2 Right to Object Personal Data Retention Period Aug 30, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Integrity and Confidentiality Principle Controllers Processors Jul 22, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 +1 Integrity and Confidentiality Principle Retention Period Supervisory Authorities Jul 22, 2021
€1.8M SGAM AG2R LA MONDIALE: Non-compliance with general data processing principles The French DPA (CNIL) has fined private insurer SGAM AG2R LA MONDIALE EUR 1,750,000. The CNIL had carried out an inspection at the AG2R LA MONDIALE group in 2019. On this… FRANCE ·CNIL ·Art. 5, 13, 14 Storage Limitation Retention Period Controllers Jul 20, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Retention Period Personal Data Jun 14, 2021
€7,200 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,200 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD (LU) ·Art. 5, 13, 32 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Storage Limitation Jun 11, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 14 +3 Retention Period Personal Data Storage Limitation Apr 21, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Storage Limitation Apr 8, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet (DK) ·Art. 5 Storage Limitation Fines Personal Data Feb 12, 2021
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Retention Period Storage Limitation Controllers Dec 17, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Healthcare Nov 19, 2020
€12,030 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 12,030 on a legal person. The accused did not comply with the complainant's request to erase their data. The company implemented an… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 12 Personal Data Supervisory Authorities Storage Limitation Oct 14, 2020
€288,000 Digi Távközlési Szolgáltató Kft. ('Digi') (electronic communication service provider): Insufficient technical and organisational measures to ensure information security The company had infringed the principles of purpose limitation and storage restriction because its database contained a large amount of customer data which were no longer relevant… HUNGARY ·NAIH ·Art. 5, 32 Retention Period Security Encryption Jun 12, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Garante ·Art. 5, 6, 17 +2 Integrity and Confidentiality Principle Direct Marketing Right to Object Jan 15, 2020
€8.5M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6, 17 +1 Integrity and Confidentiality Principle Direct Marketing Personal Data Dec 11, 2019
€2,860 Unknown Company: Non-compliance with general data processing principles An employee was on sick leave when his employer checked his desktop, laptop and emails to ensure that his work-related duties were being covered in his absence. The employer then… HUNGARY ·NAIH ·Art. 5, 6, 13 +2 Retention Period Legitimate Interest Storage Limitation Oct 15, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Processors Territorial scope (GDPR) Sep 3, 2019
€10,000 CZECH REPUBLIC DPA: Non-compliance with general data processing principles Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation') and not only kept… ÚOOÚ (CZ) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Storage Limitation Personal Data Mar 21, 2019