Skip to content
Content type · 1,114 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

951–1000 of 1,114 sort newestlargest fineoldest
€30,000 ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 30,000 on the ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε. organization. A data subject who had suffered a car accident on the organization's premises filed a… GREECE ·HDPA ·Art. 12, 15 Personal Data Supervisory Authorities Monitoring Feb 15, 2022
€1,600 RECLAMADOR, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine RECLAMADOR, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the controller continued… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Feb 14, 2022
€2M Amazon Road Transport Spain S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Amazon Road Transport Spain S.L. EUR 2,000,000. The AEPD had received a complaint from a trade union against the company. Amazon Road required… AEPD ·Art. 6, 10 ·Insufficient legal basis for data processing Criminal Data Processing Processing Agreement Feb 11, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Personal Data Security Supervisory Authorities Feb 10, 2022
€1,500 Studio Colli Aniene Verderocca S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,500 on Studio Colli Aniene Verderocca S.r.l.. A data subject had filed a complaint with the DPA for unsolicited telephone advertising.… ITALY ·Garante ·Art. 12, 14, 15 +2 Personal Data Direct Marketing Supervisory Authorities Feb 10, 2022
€5,000 Arte del vivere S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Arte del vivere S.r.l.. A data subject filed a complaint with the DPA as his personal data had been published on the website… ITALY ·Garante ·Art. 12, 17, 157 Personal Data Controllers Supervisory Authorities Feb 10, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Storage Limitation Retention Period Fairness & Transparency Feb 10, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Personal Data Supervisory Authorities Feb 10, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Processing Feb 10, 2022
€300,000 SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS. in the amount of EUR 300,000. The data subject had received marketing emails from the controller… SPAIN ·AEPD ·Art. 6, 17, 28 Personal Data Controllers Supervisory Authorities Feb 4, 2022
€2,000 ASESORES DE SEGURIDAD PRIVADA, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on ASESORES DE SEGURIDAD PRIVADA, S.L.. The DPA criticized that the controller did not sufficiently inform the data subject about… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Feb 2, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +8 Fairness & Transparency Marketing Transparency Feb 2, 2022
€700,000 Orange Espagne S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Orange Espagne S.A.U. EUR 700,000. Two Orange Espagne customers had filed complaints with the DPA. In the course of its investigation, the DPA found that… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€70,000 ORANGE ESPAÑA VIRTUAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined ORANGE ESPAÑA VIRTUAL, S.L. EUR 70,000. Two Orange España Virtual customers had filed complaints with the DPA. In the course of its investigation, the… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€3.9M Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found… SPAIN ·AEPD ·Art. 5 Security Personal Data Processing Feb 1, 2022
€200,000 XFERA MÓVILES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined XFERA MÓVILES, S.A. EUR 200,000. Two Xfera customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Insurance Processing Agreement Feb 1, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches Anonymization Security Jan 27, 2022
€2,000 Private club 'Ruian': Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 2,000 on the private club 'Ruian'. The controller had installed video surveillance cameras which, among other things, also… ITALY ·Garante ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jan 27, 2022
€40,000 T.S.M. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on T.S.M. s.r.l.. A data subject had filed a complaint with the DPA against the company for failing to comply with their requests… ITALY ·Garante ·Art. 13, 15, 21 +2 Personal Data Supervisory Authorities Processing Jan 27, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
€117,000 Santander Bank Polska S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 118,000 for failing to notify data subjects of a data breach. A former employee of the bank managed to gain unauthorized… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Personal Data Jan 19, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Encryption Security Pseudonymization Jan 19, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Encryption Security Jan 19, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS ·AP ·Art. 12 Personal Data Controllers Supervisory Authorities Jan 14, 2022
€7,500 Azienda Sanitaria Locale Frosinone: Insufficient fulfilment of information obligations The Italian DPA has fined Azienda Sanitaria Locale Frosinone EUR 7,500. In the course of its investigation against the medical facility, the Garante found that their privacy… ITALY ·Garante ·Art. 5, 12, 13 Supervisory Authorities Processing Processing Agreement Jan 13, 2022
€1,000 A.S.L. Napoli 1 Centro: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 1,000 on A.S.L. Napoli 1 Centro. An employee at the health authority had filed a complaint with the DPA against the… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing IP Address Jan 13, 2022
€14,000 Azienda sanitaria unica regionale Marche: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 14,000 on Azienda sanitaria unica regionale Marche. The DPA launched an investigation against the health department following media… ITALY ·Garante ·Art. 5, 32, 35 Security Personal Data Supervisory Authorities Jan 13, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processors Jan 1, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 1, 2022
€1,400 Dentist: Non-compliance with general data processing principles The Hungarian DPA has fined a dentist EUR 1,300. The controller had installed several surveillance cameras in their practice, which permanently recorded employees and patients.… HUNGARY ·NAIH ·Non-compliance with general data processing principles Video Surveillance Monitoring Healthcare Jan 1, 2022
€2,700 Covid-19 test center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them… GERMANY ·HmbBfDI ·Art. 32 Encryption Security Personal Data Jan 1, 2022
€7,500 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 7,500 on DW Dynamic Works LIMITED. The controller operated as a processor for the Cypriot Ministry of Denfese. The minsitry had suffered… CYPRUS ·Cyprus DPA ·Art. 32 Security Controllers Processors Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Cyprus DPA ·Art. 24, 28 Controllers Processors Processing Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Five fines for failing to comply with orders issued by the DPA. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Jan 1, 2022
Physician: Insufficient legal basis for data processing The DPA of Bremen imposed a fine on a physician for transmitting patient's data to a billing office without their consent. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Processing Agreement Healthcare Jan 1, 2022
€90M Google LLC: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 90,000,000 on GOOGLE LLC. The CNIL received several complaints regarding the manner in which cookies could be… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Processing Agreement Dec 31, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Personal Data Dec 28, 2021
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Controllers Processing Dec 26, 2021
€5,000 HUBSIDE IBÉRICA S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 HUBSIDE IBÉRICA S.L.. A data subject had filed a complaint with the DPA against the controller for charging her several… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Dec 22, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY ·Garante ·Art. 5, 6, 9 Healthcare Personal Data Controllers Dec 17, 2021
€1,000 Università Telematica Internazionale Uninettuno: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,000 on Università Telematica Internazionale Uninettuno. A professor had filed a complaint with the DPA against the educational… ITALY ·Garante ·Art. 5 Retention Period Personal Data Processing Dec 16, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Garante ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2021
Enel Energia S.p.A: Insufficient legal basis for data processing Originial fine summary: The Italian DPA has fined Enel Energia S.p.A EUR 26.5 million for numerous breaches of the GDPR. Following a complex preliminary investigation launched… ITALY ·Garante ·Art. 5, 6, 12 +7 Direct Marketing Personal Data Controllers Dec 16, 2021
€20,000 FCA Italy s.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined FCA Italy s.p.a. EUR 20,000. A former customer of the controller had asked the controller to provide him with the transcripts of telephone conversations… Garante ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Dec 16, 2021
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·DPC ·Art. 12, 13, 15 Personal Data Right of Access Controllers Dec 9, 2021
€10,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA has imposed a fine of EUR 10,000 against a company. The data subject had repeatedly received mail with advertising content from a company, although he had objected… APD/GBA ·Art. 12, 14, 15 +2 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Direct Marketing Dec 8, 2021
€2.8M Dutch Minister of Finance: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the Minister of Finance EUR 2,75 million. In the context of childcare benefit applications, tax offices had processed data on the dual nationality of… THE NETHERLANDS ·AP ·Art. 5, 6, 8 Personal Data Processing Education Nov 25, 2021
€200,000 Aimon Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 200,000 on Aimon Srl. Two data subjects had complained about unsolicited SMS advertising from B&T S.p.A. to the DPA. In the course of the… ITALY ·Garante ·Art. 5, 6, 12 +1 Direct Marketing Personal Data Supervisory Authorities Nov 25, 2021
€27,200 YAY ehf.: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Persónuvernd ·Art. 5, 6, 28 +1 Retention Period Personal Data Fairness & Transparency Nov 23, 2021