Skip to content
Content type · 82 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–82 of 82 sort newestlargest fineoldest
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Controllers Right of Access Personal Data Sep 22, 2022
€26,000 Policoro municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 26,000 on Policoro municipality. The municipality had installed a video surveillance system without, however, providing sufficient… ITALY ·Garante ·Art. 5, 12, 13 +2 Notified Body Responsibilities and Operational Obligations Video Surveillance Public Authority Aug 1, 2022
€1,400 Company: Non-compliance with general data processing principles The DPA of Luxembourg (CNPD) has imposed a fine of EUR 1,400 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this was… LUXEMBOURG ·CNPD ·Art. 5, 13 Retention Period Storage Limitation Controllers Jun 30, 2022
€134,000 Gyldendal A/S: Non-compliance with general data processing principles The Danish DPA has fined publisher Gyldendal A/S EUR 134,000. During its investigation, the DPA found that the company had kept the data of approximately 685,000 unsubscribed… DENMARK ·Datatilsynet ·Art. 5 Storage Limitation IP Address Processing Agreement Jun 22, 2022
€7,000 Asociația de Proprietari Aviației Park: Insufficient legal basis for data processing The Romanian DPA has fined Asociația de Proprietari Aviației Park, operator of a residential facility, EUR 7,000. The controller had processed personal data (surname, first name,… ROMANIA ·ANSPDCP ·Art. 5, 6 Retention Period Video Surveillance Storage Limitation Jun 20, 2022
€26,000 Garante per la protezione dei dati personali (Italy) - 9794895 The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Art. 5, 12, 13 +3 Video Surveillance Storage Limitation Monitoring Jun 9, 2022
€50 APD/GBA (Belgium) - 85/2022 On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Art. 4, 5, 6 +3 Cookies Telecommunications Direct Marketing May 25, 2022
€9M Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +7 Retention Period Fairness & Transparency Storage Limitation May 18, 2022
€50,000 Palumbo Superyacht Ancona s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Palumbo Superyacht Ancona s.r.l. EUR 50,000. The company had blocked an employee's company email account without permission. The employee had reported… ITALY ·Garante ·Art. 5, 12, 13 +3 Storage Limitation IP Address Employees Apr 7, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Storage Limitation Security Apr 7, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Fairness & Transparency Storage Limitation Retention Period Feb 10, 2022
BfDI (Germany) - 24-191 II The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Art. 15, 20, 95 Telecommunications Recipient Data Portability Jan 27, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Monitoring Legitimate Interest Jan 5, 2022
€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Garante ·Art. 2, 5, 6 +6 Audit Logs Fairness & Transparency Processing Agreement Sep 16, 2021
€6,000 Furnishyourspace S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) imposed a fine of EUR 6,000 on FurnishYourSpace S.L.. The AEPD had received a complaint from the Berlin DPA via the EU Internal Market Information System… SPAIN ·aepd ·Art. 5, 6, 12 +2 Right to Object Controllers IP Address Aug 30, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Controllers Processors Integrity and Confidentiality Principle Jul 22, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 +1 Integrity and Confidentiality Principle Fines IP Address Jul 22, 2021
€1.8M SGAM AG2R LA MONDIALE: Non-compliance with general data processing principles The French DPA (CNIL) has fined private insurer SGAM AG2R LA MONDIALE EUR 1,750,000. The CNIL had carried out an inspection at the AG2R LA MONDIALE group in 2019. On this… FRANCE ·CNIL ·Art. 5, 13, 14 Insurance Storage Limitation Retention Period Jul 20, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Personal Data Controllers Jun 14, 2021
€7,200 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,200 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD ·Art. 5, 13, 32 ·Non-compliance with general data processing principles Video Surveillance Storage Limitation Employees Jun 11, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 14 +3 Retention Period Storage Limitation Personal Data Apr 21, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Storage Limitation Retention Period IP Address Apr 8, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet ·Art. 5 Fines Administrative Fines on Union Institutions, Bodies, Offices and Agencies Storage Limitation Feb 12, 2021
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Healthcare Retention Period Storage Limitation Dec 17, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Fairness & Transparency Health Data Nov 19, 2020
€12,030 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 12,030 on a legal person. The accused did not comply with the complainant's request to erase their data. The company implemented an… CZECH REPUBLIC ·UOOU ·Art. 6, 12 Storage Limitation Personal Data Processing Agreement Oct 14, 2020
€288,000 Digi Távközlési Szolgáltató Kft. ('Digi') (electronic communication service provider): Insufficient technical and organisational measures to ensure information security The company had infringed the principles of purpose limitation and storage restriction because its database contained a large amount of customer data which were no longer relevant… HUNGARY ·NAIH ·Art. 5, 32 Encryption Storage Limitation Security Jun 12, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Garante ·Art. 5, 6, 17 +2 Integrity and Confidentiality Principle Telecommunications Direct Marketing Jan 15, 2020
€8.5M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6, 17 +1 Fines Integrity and Confidentiality Principle Personal Data Dec 11, 2019
€2,860 Unknown Company: Non-compliance with general data processing principles An employee was on sick leave when his employer checked his desktop, laptop and emails to ensure that his work-related duties were being covered in his absence. The employer then… HUNGARY ·NAIH ·Art. 5, 6, 13 +2 Monitoring Human Resources Legitimate Interest Oct 15, 2019
CNPD (Portugal) - Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Art. 2, 3, 5 +8 Controllers Personal Data Processing Sep 3, 2019
€10,000 CZECH REPUBLIC DPA: Non-compliance with general data processing principles Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation') and not only kept… UOOU ·Art. 5 ·Non-compliance with general data processing principles Retention Period Storage Limitation Personal Data Mar 21, 2019