Content type · 960 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€50,000 N26: Insufficient legal basis for data processing The fine was imposed against against a bank (according to a newspaper N26) that had processed 'personal data of all former customers' without permission.The Bank has acknowledged… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Mar 1, 2019
€582 CZECH REPUBLIC DPA: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Feb 28, 2019
€5,000 Lands Authority: Insufficient technical and organisational measures to ensure information security As a result of the lack of appropriate security measures on the Lands Authority website, over 10 gigabytes of personal data became easily accessible to the public via a simple… MALTA ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Feb 18, 2019
€1,165 Credit brokerage: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… CZECH REPUBLIC · ·Art. 32 Feb 4, 2019
€30,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security Disclosure of customer personal data (i.a. purchase history) via an SMS to another customer. The initial fine of EUR 50.000 was reduced to EUR 30.000. SPAIN · ·Art. 5, 32 Jan 1, 2019
€48,000 VODAFONE ONO, S.A.U.: Insufficient technical and organisational measures to ensure information security Customers could access personal data of other customers in the customer area. The initial fine of EUR 60.000 was reduced to EUR 48.000. SPAIN · ·Art. 32 Jan 1, 2019
€20,000 Hamburger Verkehrsverbund GmbH (HVV GmbH): Insufficient fulfilment of data breach notification obligations On July 6, 2018, HVV GmbH was informed by a customer about a security gap on the website www.hvv.de, which was caused by an update on February 5, 2018 and concerned the so-called… GERMANY ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Jan 1, 2019
€80,000 GERMANY DPA: Insufficient technical and organisational measures to ensure information security In a digital publication, health data was accidentally published due to inadequate internal control mechanisms. Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2019
€20,000 Knuddels.de: Insufficient technical and organisational measures to ensure information security After a hacker attack in July personal data of approx. 330.000 users, including passwords and email addresses had been revealed. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Nov 21, 2018
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL · ·Art. 5, 32 Jul 17, 2018