Skip to content
Content type · 1,282 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1001–1050 of 1,282 sort newestlargest fineoldest
€20,000 Dentist: Insufficient legal basis for data processing The Italian DPA (Garante) has fined a dentist EUR 20,000. A data subject filed a complaint with the DPA against the dentist for refusing to treat him after the data subject had… ITALY ·Garante ·Art. 5 Healthcare Healthcare Personal Data Jun 10, 2021
€40,000 Aeroporto Guglielmo Marconi di Bologna S.p.a.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 5, 25, 32 Security Encryption Professional Secrecy Jun 10, 2021
€34,800 Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 34,800 on the directorate of the Östra Skaraborg Rescue Service. The DPA had received information that several fire stations in Östra… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Video Surveillance Monitoring Audit Logs Jun 9, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·Art. 5, 6, 9 +2 ·Non-compliance with general data processing principles Data Breaches Integrity and Confidentiality Principle Professional Secrecy Jun 7, 2021
€19,600 Radiotelevisión del principado de Asturias: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 26,000 on Radiotelevisión del principado de Asturias. The fine consists of EUR 20,000 due to a violation of Art. 5 (1) c) GDPR and… SPAIN ·aepd ·Art. 5, 12 Video Surveillance Monitoring Audit Logs Jun 7, 2021
€49,200 Moss municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the… NORWAY ·Datatilsynet ·Art. 32 Data Breaches Security Healthcare Jun 4, 2021
€15,000 PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ: Non-compliance with general data processing principles The Hellenic DPA has fined PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ EUR 15,000 due to the illegal installation and operation of a video surveillance system. The controller had installed a video… GREECE ·HDPA ·Art. 5 Video Surveillance Accountability Fairness & Transparency Jun 3, 2021
€450,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen) EUR 450,000. The UWV had not properly secured the… THE NETHERLANDS ·AP ·Art. 32 Security Insurance Healthcare May 31, 2021
€2,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 2,000 on a private individual for the unauthorized use of video surveillance cameras, which also recorded parts of public space… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring May 27, 2021
€150,000 Azienda Provinciale per i Servizi Sanitari di Trento: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Provinciale per i Servizi Sanitari di Trento EUR 150,000. The controller had accidentally forwarded 293 medical reports of 175 patients… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare IP Address May 27, 2021
€120,000 Azienda Usl della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Usl della Romagna EUR 120,000. The local health authority of Romagna had accidentally transmitted a patient's report regarding an… ITALY ·Garante ·Art. 5, 9 Healthcare IP Address Processing Agreement May 27, 2021
€4,000 Alava Norte, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Alava Norte, S.L. EUR 4,000. The controller had installed three 360° video surveillance cameras on the facade of one of its buildings to secure… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers May 25, 2021
€6,000 Desolasol Restauración, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Desolasol Restauración S.L. EUR 6,000. The data subject had submitted a consumer complaint form to the restaurant because he was unable to… SPAIN ·aepd ·Art. 5 Personal Data IP Address Controllers May 25, 2021
€3,000 Homeowners Association: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·aepd ·Art. 5, 12 Video Surveillance Monitoring IP Address May 21, 2021
€39,000 Municipality of Oslo: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,000 on the Municipality of Oslo. On a website of the controller a subpoena from the public prosecutor's office… NORWAY ·Datatilsynet ·Art. 5, 6 Health Data Healthcare Public Authority May 20, 2021
€500 Owners Association of Iasi Municipality: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has imposed a fine of EUR 500 on Asociație de Proprietari din municipiul Iași (Owners Association of Iasi Municipality). The controller did not provide… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers May 19, 2021
€10,000 Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato: Insufficient legal basis for data processing The Hellenic DPA has fined the Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato EUR 10,000. The controller had… GREECE ·HDPA ·Art. 6, 12, 17 Personal Data Controllers Education May 17, 2021
€200 Website operator: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on the operator of the website declaratieppr.ro. During the Covid19 pandemic, visitors to the site were able to fill out a… ROMANIA ·ANSPDCP ·Art. 5, 6, 13 +1 IP Address Personal Data Controllers May 14, 2021
€30,000 Allianz Compañia de Seguros y Reaseguros, S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Allianz Compañia de Seguros y Reaseguros, S.A. EUR 30,000. The controller had sent an invoice to the data subject although no contractual… SPAIN ·aepd ·Art. 6 Insurance Controllers Processing Agreement May 14, 2021
€2.9M Iren Mercato S.p.A.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Iren Mercato S.p.A. EUR 2,856,169 for failing to verify that all transfers of data of recipients of promotional activities were covered by consent.… ITALY ·Garante ·Art. 5, 6, 7 IP Address Controllers Direct Marketing May 13, 2021
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Social Media Employees May 13, 2021
€20,000 Synlab Med srl: Non-compliance with general data processing principles The Italian DPA has fined Synlab Med srl EUR 20,000. The company conducted Covid-19 tests for various regional health authorities. In this context, the company had inadvertently… ITALY ·Garante ·Art. 2, 5, 9 Healthcare IP Address Processing Agreement May 13, 2021
€5,000 A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ: Non-compliance with general data processing principles The Hellenic DPA has fined A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ EUR 5,000. The controller had not responded to requests for information and deletion from the data subject.… GREECE ·HDPA ·Art. 5, 12, 15 +1 Personal Data IP Address Controllers May 12, 2021
€2,400 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,400 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Employees Accountability May 12, 2021
€2,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,600 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Video Surveillance Employees Monitoring May 12, 2021
€1,900 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,900 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Accountability IP Address May 12, 2021
€1,000 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,000 on a company. The controller had installed a video surveillance system with the purposes of the protection of… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Video Surveillance Accountability IP Address May 12, 2021
€2,000 Santa Ninfa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Santa Ninfa municipality. The municipality had published a resolution on its website that contained personal information… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Public Authority Education Apr 29, 2021
€570 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 570 on a company. In the course of his professional activities, a data subject had made a telephone call to a company on… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers IP Address Accountability Apr 27, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·aepd ·Art. 5, 6, 14 Integrity and Confidentiality Principle Fairness & Transparency Personal Data Apr 23, 2021
€1,500 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed a surveillance camera on his property, which recorded, among other… SPAIN ·aepd ·Art. 5 Audit Logs Monitoring IP Address Apr 22, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Recipient Security Apr 22, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 14 +3 Retention Period Storage Limitation Personal Data Apr 21, 2021
€15,000 Fondazione Policlinico Tor Vergata di Roma: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Fondazione Policlinico Tor Vergata di Roma. In February 2020, a data subject filed a complaint with Garante alleging… ITALY ·Garante ·Art. 5, 13, 25 +1 Healthcare Personal Data Processing Agreement Apr 21, 2021
€2,800 Website operator: Non-compliance with general data processing principles The Hungarian DPA (NAIH) has imposed a fine of EUR 2,800 on a website operator. The controller had failed to prove the lawfulness of its processing of personal data upon request… HUNGARY ·NAIH ·Art. 5, 24 Accountability Controllers IP Address Apr 20, 2021
€1,500 Pub owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the owner of a pub EUR 1,500 due to the unauthorized use of two video surveillance cameras covering parts of the public space. SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Apr 19, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Personal Data Security Apr 15, 2021
€5,000 S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined S.C. Tip Top Food Industry S.R.L. EUR 5,000. The controller had installed several video cameras in the food areas and changing rooms to… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Video Surveillance IP Address Employees Apr 15, 2021
€3,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller resides on the 1st floor of an apartment building, where he is the owner of… SPAIN ·aepd ·Art. 5, 13 Audit Logs IP Address Controllers Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·aepd ·Art. 6 Controllers IP Address Processing Agreement Apr 13, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Apr 8, 2021
€60,000 Kutxabank, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request… SPAIN ·aepd ·Art. 17 Right to be Forgotten Personal Data Data Subject Rights Exercise Modalities and Procedures Apr 8, 2021
€4,000 Comune di Castellanza: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the municipality of Castellanza. The municipality had uploaded documents containing personal data of the data subject… ITALY ·Garante ·Art. 5, 6 Personal Data Education IP Address Mar 25, 2021
€4.5M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Fastweb S.p.A. EUR 4,500,000 for aggressive telemarketing. Following a complex preliminary investigation launched after hundreds of reports and… ITALY ·Garante ·Art. 5, 6, 7 +8 IP Address Direct Marketing Telecommunications Mar 25, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Health Data Mar 23, 2021
€1,000 Laboratorio Octogón, S.L.: Non-compliance with general data processing principles Usage of CCTV camera systems that were also monitoring public space (breach of principle of data minimization). SPAIN ·aepd ·Art. 5 Video Surveillance Audit Logs Monitoring Mar 23, 2021
€3,000 Asesoría Alpi-Clúa S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 3,000 on Asesoría Alpi-Clúa S.L.. A client had requested documents from the controller to submit them to the tax authorities. The… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Controllers Mar 18, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet ·Art. 5, 6, 24 +1 Data Breaches Security Education Mar 15, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data Education Controllers Mar 15, 2021
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY ·Datatilsynet ·Art. 24, 32, 35 DPIA Data Breaches Privacy Impact Assessment Mar 15, 2021