Skip to content
Content type · 1,013 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1001–1013 of 1,013 sort newestlargest fineoldest
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Garante ·Art. 32 Controllers Processors Security Apr 17, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Anonymization Apr 12, 2019
€50,000 N26: Insufficient legal basis for data processing The fine was imposed against against a bank (according to a newspaper N26) that had processed 'personal data of all former customers' without permission.The Bank has acknowledged… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Security Insurance Mar 1, 2019
€170,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Public Authority Mar 1, 2019
€582 CZECH REPUBLIC DPA: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… ÚOOÚ (CZ) ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Feb 28, 2019
€5,000 Lands Authority: Insufficient technical and organisational measures to ensure information security As a result of the lack of appropriate security measures on the Lands Authority website, over 10 gigabytes of personal data became easily accessible to the public via a simple… MALTA ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Personal Data Feb 18, 2019
€1,165 Credit brokerage: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Feb 4, 2019
€48,000 VODAFONE ONO, S.A.U.: Insufficient technical and organisational measures to ensure information security Customers could access personal data of other customers in the customer area. The initial fine of EUR 60.000 was reduced to EUR 48.000. SPAIN ·AEPD ·Art. 32 Security Personal Data Telecommunications Jan 1, 2019
€20,000 Hamburger Verkehrsverbund GmbH (HVV GmbH): Insufficient fulfilment of data breach notification obligations On July 6, 2018, HVV GmbH was informed by a customer about a security gap on the website www.hvv.de, which was caused by an update on February 5, 2018 and concerned the so-called… GERMANY ·HmbBfDI ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2019
€30,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security Disclosure of customer personal data (i.a. purchase history) via an SMS to another customer. The initial fine of EUR 50.000 was reduced to EUR 30.000. SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Telecommunications Jan 1, 2019
€80,000 GERMANY DPA: Insufficient technical and organisational measures to ensure information security ⇄ In a digital publication, health data was accidentally published due to inadequate internal control mechanisms. Art. 32 ·Insufficient technical and organisational measures to ensure information security Supervisory Authorities Security Healthcare Jan 1, 2019
€20,000 Knuddels.de: Insufficient technical and organisational measures to ensure information security After a hacker attack in July personal data of approx. 330.000 users, including passwords and email addresses had been revealed. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Telecommunications Nov 21, 2018
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL ·CNPD (PT) ·Art. 5, 32 Security Healthcare Health Data Jul 17, 2018