Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1001–1050 of 3,651 sort newestlargest fineoldest
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a data controller. The controller had installed a video surveillance system without adequately providing information for data… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Dec 3, 2024
Lyngby-Taarbæk Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine between EUR 46,900 and EUR 53,600 on the Lyngby-Taarbæk Municipality. The controller failled to implement sufficient security measures resulting… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Public Authority Nov 27, 2024
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Nov 26, 2024
€4.8M Netflix International B.V.: Insufficient fulfilment of information obligations The Dutch DPA has imposed a fine of EUR 4.75 million on Netflix. This fine is based on a complaint filed by the Austrian organization 'noyb'. During its investigation, the DPA… THE NETHERLANDS ·AP ·Art. 5, 12, 13 +1 Telecommunications Personal Data Processing Nov 26, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Public Sector Public Authority Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN ·aepd ·Art. 15, 35 Personal Data Employees Biometric Data Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN ·aepd ·Art. 15, 35 DPIA Privacy Impact Assessment Employees Nov 22, 2024
€358,000 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted… UODO ·Art. 5, 25, 28 +1 ·Insufficient technical and organisational measures to ensure information security Encryption Security Controllers Nov 20, 2024
€4,700 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4,700 on a subcontractor that was contracted to redesign the website of another company. This fine is linked to ETid-2491. Due to an error… UODO ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Privacy by Design & Default Nov 20, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period Controllers Nov 20, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individua had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Nov 19, 2024
€2.4M Posti Jakelu Oy: Insufficient legal basis for data processing The Finnish DPA imposed a fine of EUR 2.4 million on Posti Jakelu Oy following an investigation. It was found that Posti had automatically set up an electronic mailbox for… FINLAND ·Deputy Data Protection Ombudsman ·Art. 6 Consent Processing Agreement Processing Nov 13, 2024
€5M Foodinho Srl: Non-compliance with general data processing principles The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the… ITALY ·Garante ·Art. 2, 5, 6 +11 IP Address Employees Personal Data Nov 13, 2024
€2,500 COYARE SLU: Non-compliance with general data processing principles The Spanish DPA fined COYARE SLU EUR 2,500 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the unauthorized… SPAIN ·aepd ·Art. 5, 32 IP Address Insurance Processing Agreement Nov 13, 2024
€678,897 Illumia Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints… ITALY ·Garante ·Art. 5, 6, 7 +4 Security Privacy by Design & Default Processing Agreement Nov 13, 2024
€500 4T OCIO Y CAFÉ 2009: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on 4T OCIO Y CAFÉ 2009, S.L. for installing a video surveillance system without the express consent of the owners' association of the… SPAIN ·aepd ·Art. 6 Video Surveillance Monitoring Consent Nov 13, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Video Surveillance IP Address Security Nov 13, 2024
€900,000 Debt collection service provider: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 900,000 on a debt collection service provider. The company had unlawfully stored personal data (amounting to a six-digit number of… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Insurance Personal Data Processing Nov 12, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Nov 12, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN ·aepd ·Art. 5, 32 Security IP Address Controllers Nov 11, 2024
€2,000 KAFFA KOFFEE ORGANISATION, S.L.: Non-compliance with general data processing principles The Spanish DPA fined KAFFA KOFFEE ORGANISATION, S.L. EUR 2,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Processing Nov 7, 2024
€1,000 MINAS DE VALDECASTILLO, S.A..: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on MINAS DE VALDECASTILLO, S.A.. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers IP Address Nov 6, 2024
€1,000 Blackcab Systems SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Blackcab Systems SRL. A individual lodged a complaint with the DPA, alleging that the controller had failed to properly respond… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 4, 2024
€15M OpenAI OpCo LLC: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15 million on OpenAI in connection with the operation of the generative AI chatbot “ChatGPT”. The DPA found that OpenAI had violated… ITALY ·Garante ·Art. 5, 6, 12 +4 Fairness & Transparency IP Address Transparency Nov 2, 2024
€12,000 NEGOCIOS R&R 2020 S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined NEGOCIOS R&R 2020 S.L. EUR 12,000 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€4,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined GESTIÓN DE VENTAS IBERIA S.L. EUR 4000 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€900 RIVENDELL TECHNOLOGY, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 900 on RIVENDELL TECHNOLOGY, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€15,000 Untold SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Untold SRL. During its investigation, the DPA found that the controller had failed to properly comply with a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Processing Oct 30, 2024
€5,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA fined Vodafone Romania S.A. EUR 5,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Telecommunications Security IP Address Oct 28, 2024
€310M LinkedIn: Insufficient legal basis for data processing The Irish DPA (DPC) has fined LinkedIn EUR 310 million. This decision is related to an investigation following a complaint in 2018 from the French NGO 'La Quadrature Du Net'. In… Art. 60 Social Media Processing Agreement Direct Marketing Oct 24, 2024
€10,000 Profi Rom Food SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 10,000 on Profi Rom Food SRL. During its investigation, the DPA found that the controller had forwarded copies of several employees' ID… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Employees Processing Agreement Oct 23, 2024
€180,000 IBERCAJA BANCO, S.A.: Insufficient legal basis for data processing The Spanish DPA has fined IBERCAJA BANCO, S.A. for unlawfully accessing a customer’s credit file after the termination of their contractual relationship. The DPA concluded that… SPAIN ·aepd ·Art. 6 Insurance Processing Agreement IP Address Oct 22, 2024
€20,800 Grue municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA fined Grue municipality EUR 20,800 following the municipality's notification of a data breach. The municipality reported that personal data of students had been… NORWAY ·Datatilsynet ·Art. 24, 32 Data Breaches Security Public Authority Oct 21, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individual had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Oct 18, 2024
€9,000 Vilnius District Municipality Administration: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has imposed a fine of EUR 1,000 on the Vilnius District Municipality Administration. The Municipality Administration had been hacked. The attack resulted in… LITHUANIA ·VDAI ·Art. 5, 32, 34 Public Authority Security Public Sector Oct 18, 2024
€5,800 POLAND DPA: Insufficient involvement of data protection officer The Polish DPA has imposed a fine of EUR 5,800 on a data controller. The controller failed to appoint a data protection officer and to provide the DPA with the contact details in… UODO ·Art. 37 ·Insufficient involvement of data protection officer Controllers Supervisory Authorities Processing Agreement Oct 18, 2024
€1,000 KUR KLINIKUM, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1000 on KUR KLINIKUM, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 17, 2024
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Your Consulting SRL. The controller had suffered a data breach involving the unauthorized disclosure of personal data. During… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Oct 16, 2024
€5,000 Company: Lack of appointment of data protection officer The Austrian DPA has imposed a fine on a company. The controller appointed a DPO who had a conflict of interest, meaning the person was not suitable for the role. AUSTRIA ·dsb ·Art. 38 Notified Body Responsibilities and Operational Obligations Supervisory Authorities Controllers Oct 16, 2024
Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·APD/GBA Cookies Direct Marketing Telecommunications Oct 11, 2024
€5,000 ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. The controller, a law firm, published the names and photos of its… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement Oct 4, 2024
€900 Private individual: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 900 on a private individual for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 4, 2024
€600 VOLTIUM CONSULTORES 2020: Insufficient cooperation with supervisory authority The Spanish DPA has fined VOLTIUM CONSULTORES 2020 EUR 600 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 4, 2024
€91M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 91 million on Meta Platforms Ireland Limited (MPIL). The DPC had initiated an investigation after MPIL reported that user passwords… Encryption Data Breaches Security Sep 27, 2024
€904,000 Police Service of Northern Ireland: Insufficient technical and organisational measures to ensure information security The ICO fined the Police Service of Northern Ireland £750,000 (EUR 904,000) after accidentally publishing personal data of 9,483 police officers and staff on the internet. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Personal Data Public Sector Sep 26, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers Prior Consultation IP Address Sep 26, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers IP Address Processors Sep 26, 2024
€4,000 CI & DI Food s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA imposed a fine of EUR 4,000 against CI & DI Food s.r.l. for failing to comply with a former employee's request for access to their personal data. ITALY ·Garante ·Art. 12, 15 Personal Data Employees Supervisory Authorities Sep 26, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·aepd ·Art. 5 Telecommunications IP Address Security Sep 26, 2024