Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

951–1000 of 2,273 sort newestlargest fineoldest
€50,000 FUSIONA SOLUCIONES ENERGÉTICAS, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 50,000 on FUSIONA SOLUCIONES ENERGÉTICAS, S.A.. The controller had submitted data from the data subject to a credit information system… SPAIN ·aepd ·Art. 6 Personal Data Controllers Processing Agreement May 17, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY ·Garante ·Art. 5, 6, 32 Healthcare Security Healthcare May 17, 2023
€60,000 Website operator: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on a website operator. The controller had published unauthorized personal data on the website www.trovanumeri.com, which it had… ITALY ·Garante ·Art. 5, 6, 12 +6 IP Address Controllers Personal Data May 17, 2023
€5,000 Compania Națională Poșta Română S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on the Romanian Post (Compania Națională Poșta Română S.A.). During its investigation, the DPA found that the controller had… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Personal Data Processing May 16, 2023
€6,700 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,700 on a municipality. The controller had reported a data breach to the DPA. During its investigation, the DPA found that the controller… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Privacy by Design & Default May 16, 2023
€1,200M Meta Platforms Ireland Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had… Art. 46 Notified Body Competence Challenges and Dispute Resolution Privacy Shield Processing Agreement May 12, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€11,000 Libra Internet Bank SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 11,000 on Libra Internet Bank SA. An individual had filed a complaint against the bank due to the bank's failure to fully comply with… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Data Subject Rights Exercise Modalities and Procedures Supervisory Authorities May 11, 2023
€5.2M Clearview AI: Insufficient cooperation with supervisory authority The French DPA has fined Clearview AI EUR 5.2 million. The DPA had imposed a fine of EUR 20 million on the company in 2022 for unlawfully collecting personal data. In addition to… FRANCE ·CNIL ·Insufficient cooperation with supervisory authority Personal Data Supervisory Authorities Supervision May 10, 2023
€2,200 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,200 on a municipality. The controller had reported a data breach to the DPA. An employee had unauthorizedly copied a document containing… POLAND ·UODO ·Art. 5, 25, 32 Data Breaches Security Public Authority May 5, 2023
€1,200 FUNDACIÓ PRIVADA UNIVERSITARIA EADA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on FUNDACIÓ PRIVADA UNIVERSITARIA EADA. An individual who had participated in a training event filed a complaint against the educational… SPAIN ·aepd ·Art. 6 Education IP Address Direct Marketing May 5, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·azop ·Art. 6, 13, 28 +1 Security Controllers Personal Data May 4, 2023
€3,810 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 3,810 on a legal person. The accused unlawfully processed the personal data of an unspecified number of creditors to purchase their claims… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Personal Data Processing Processing Agreement May 4, 2023
€200,000 GSMA LTD.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 200,000 against GSMA LTD.. An individual had filed a complaint with the DPA because they had to transfer special categories of personal… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Security May 3, 2023
€5,000 BANQUETES SANTA ANA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,000 on BANQUETES SANTA ANA, S.L.. The controller had asked a couple celebrating their wedding at its premises to provide the personal… SPAIN ·aepd ·Art. 5 IP Address Controllers Personal Data May 3, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default May 2, 2023
€176,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 176,000 on Roma Capitale. The city had provided data of women who had abortions to the company in charge of the funeral, which included the… ITALY ·Garante ·Art. 2, 5, 9 +3 Personal Data IP Address Processing Agreement Apr 27, 2023
€240,000 Benetton Group S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 240,000 on Benetton Group S.r.l.. The controller had stored a large amount of customer data indefinitely. The DPA also found that the… ITALY ·Garante ·Art. 5, 32 IP Address Controllers Privacy by Design & Default Apr 27, 2023
€239,000 Ama S.p.a.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 239,000 on Ama S.p.a.. Ama is in charge of the administration of certain cemeteries in Rome. The city of Rome had provided data of women who… ITALY ·Garante ·Art. 2, 28, 29 +1 Personal Data Education Processing Agreement Apr 27, 2023
€4,000 Università degli studi di Cassino e del Lazio Meridionale: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR on Università degli studi di Cassino e del Lazio Meridionale. A professor at the university had filed a complaint against the university… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Education Processing Agreement Apr 27, 2023
€17,600 Skåne region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has fined Skåne region EUR 17,600. An employee of the region had lost an unencrypted USB stick containing the social security numbers and sensitive personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Personal Data Apr 26, 2023
€70,000 DIGI SPAIN TELECOM, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on DIGI SPAIN TELECOM, S.L.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… aepd ·Art. 6 ·Insufficient legal basis for data processing Telecommunications Personal Data Consent Apr 25, 2023
€1,000 Tensa Art Design SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Tensa Art Design SA. The controller failed to comply with a data subject's right to object. ROMANIA ·ANSPDCP ·Art. 12 Right to Object Data Subject Rights Exercise Modalities and Procedures Personal Data Apr 24, 2023
€70,000 Telefónica Móviles España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on Telefónica Móviles España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Apr 24, 2023
€5,400 Disciplinary officer: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 5,400 on a disciplinary officer of the Polish Bar Association after an unencrypted USB stick containing personal data was lost. POLAND ·UODO ·Art. 5, 25, 32 Encryption Security Personal Data Apr 20, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Data Breaches Storage Limitation Security Apr 20, 2023
€3,000 Partidul Uniunea Salvați România: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on the party 'Partidul Uniunea Salvați România'. The controller had published personal data of persons with different degrees of… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Agreement Apr 19, 2023
€600 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 600 on a legal person. The order was issued based on the carried out inspection. The accused did not provide information on its website… CZECH REPUBLIC ·UOOU ·Art. 12 Personal Data Processing Processing Agreement Apr 17, 2023
€676,956 Sorgenia S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 676,956 against Sorgenia S.p.a.. The DPA had received several complaints from data subjects regarding unauthorized telemarketing. During… ITALY ·Garante ·Art. 5, 12, 25 Security Controllers Processing Agreement Apr 14, 2023
€15,000 Citynews S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Citynews S.p.A. EUR 15,000. The controller had published an article in a newspaper reporting on the arrest of an individual, including health data of the… ITALY ·Garante ·Art. 5, 9 Healthcare Health Data Personal Data Apr 14, 2023
€237,800 Green Network S.p.A.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 237,800 against Green Network S.p.A.. The DPA had received several complaints from data subjects regarding unauthorized telemarketing.… ITALY ·Garante ·Art. 5, 25 Security Privacy by Design & Default Controllers Apr 14, 2023
€13,000 Azienda socio sanitaria locale n. 3 di Nuoro: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 13,000 on Azienda socio sanitaria locale n. 3 di Nuoro. An individual had filed a complaint with the DPA because the health authority had… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Personal Data Controllers Apr 13, 2023
€500,000 Mas s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500,000 on Mas s.r.l.. As part of its investigation, the DPA found that the controller had acquired illegally created lists containing… ITALY ·Garante ·Art. 5, 6, 7 +4 Direct Marketing IP Address Controllers Apr 13, 2023
€112,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Apr 13, 2023
€7.6M TIM S.p.A.: Insufficient legal basis for data processing The Italian DPA has fined TIM S.p.A. EUR 7,631,175. The DPA had received numerous complaints about the telecommunications provider, mainly for unauthorized telemarketing… ITALY ·Garante ·Art. 5, 6, 7 +5 Telecommunications Direct Marketing Personal Data Apr 13, 2023
€200,000 Mas s.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 200,000 on Mas s.r.l.s.. During its investigation, the DPA found that the controller had acquired illegally created lists containing… ITALY ·Garante ·Art. 5, 6, 7 +4 IP Address Personal Data Direct Marketing Apr 13, 2023
€3,000 REGENCY COMPANY SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on REGENCY COMPANY SRL. The controller had installed video surveillance cameras in its premises for the purpose of monitoring… ROMANIA ·ANSPDCP ·Art. 5, 6 Video Surveillance Monitoring Audit Logs Apr 7, 2023
€770 Secretary of the Central Election Commission Konstantin Ninov: Insufficient legal basis for data processing The Bulgarian DPA has imposed a fine of EUR 770 on Konstantin Ninov, a secretary of the central election commission. The controller forwarded personal data, including voter lists,… BULGARIA ·KZLD ·Art. 6 Personal Data Controllers Education Apr 6, 2023
€3,000 Tensa Art Design SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on Tensa Art Design SRL. An individual had filed a complaint for receiving promotional messages despite having filed an objection… ROMANIA ·ANSPDCP ·Art. 21 Right to Object Direct Marketing Personal Data Apr 4, 2023
€84,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. During its investigation, the DPA found that the controller had registered alleged debts of a former… SPAIN ·aepd ·Art. 6, 15 Controllers Personal Data Insurance Apr 4, 2023
€15M TikTok: Non-compliance with general data processing principles The UK DPA (ICO) has fined TikTok EUR 14.5 million. The ICO had found that more than one million British children under the age of 13 were using TikTok without the consent of… UNITED KINGDOM ·ICO ·Art. 5, 12, 13 Social Media Fairness & Transparency Minors Apr 4, 2023
€1,800 LISMARTSA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on LISMARTSA, S.L.. The controller had sent an email containing personal data of 74 people to all recipients. The DPA considered this to be a… SPAIN ·aepd ·Art. 5 IP Address Controllers Personal Data Mar 30, 2023
€450 Private individual: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 450 on an private individual. The individual had published personal data of numerous people on a social network without their consent. ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Consent Processing Agreement Mar 27, 2023
€70,000 Orange Espagne S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on Orange Espagne S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Agreement Mar 23, 2023
€40,000 La Risorsa Umana.it s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on La Risorsa Umana.it s.r.l. An employee of the controller had filed a complaint against the controller. During its… ITALY ·Garante ·Art. 5, 13, 28 Controllers IP Address Personal Data Mar 23, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Recipient Mar 23, 2023
€5,000 Tehnoplus Industry SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 5,000 on Tehnoplus Industry SRL. An employee of the company had filed a complaint with the DPA because the controller had installed a… ROMANIA ·ANSPDCP ·Art. 5, 6 Audit Logs IP Address Controllers Mar 23, 2023
€70,000 CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. The data subject had received a message from a debt collection company on behalf… SPAIN ·aepd ·Art. 6 Personal Data Insurance Processing Agreement Mar 21, 2023
€10,000 NGENIERÍA Y TELECOM JAÉN, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on INGENIERÍA Y TELECOM JAÉN, S.L.. The controller had extented the data subject's contract without their consent. SPAIN ·aepd ·Art. 6 Telecommunications Controllers Personal Data Mar 17, 2023