Skip to content
Content type · 1,114 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1001–1050 of 1,114 sort newestlargest fineoldest
€800 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 800 on a legal person. The accused did not respond to the complainant's repeated requests for copies of the telephone recordings. CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Supervisory Authorities Insurance Nov 19, 2021
€1,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,000 on a legal person. For at least two months, the accused incorrectly included 50 entities in the published list of processors, even… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Supervisory Authorities Processors Nov 1, 2021
€500,000 Address Broker: Insufficient fulfilment of data subjects rights The Austrian DPA has imposed a fine of EUR 500,000 on an address broker. The controller provided a form for data subjects to exercise their rights. The controller regularly did… AUSTRIA ·DSB ·Art. 12 Personal Data Controllers Supervisory Authorities Sep 28, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet (NO) ·Art. 5, 28, 32 +1 Processors Controllers International Transfer Sep 27, 2021
€900,000 Vattenfall Europe Sales GmbH: Insufficient data processing agreement The DPA from Hamburg has imposed a fine of EUR 900,000 on Vattenfall Europe Sales GmbH. The fine is related to data matching, which the controller had carried out in the period… GERMANY ·HmbBfDI ·Art. 12, 13 Controllers Fairness & Transparency Personal Data Sep 24, 2021
€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Garante ·Art. 2, 5, 6 +6 Storage Limitation Retention Period Privacy Shield Sep 16, 2021
€3.3M Sky Italia S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has fined Sky Italia S.r.l. EUR 3,296,326 for illegal telemarketing. The DPA's decision followed a complex investigation launched after dozens of reports… ITALY ·Garante ·Art. 5, 6, 7 +5 Direct Marketing Right to Object Personal Data Sep 16, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Integrity and Confidentiality Principle Controllers Processors Jul 22, 2021
€50,000 Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 50,000 on Caixabank S.A.. A data subject had filed a complaint with the DPA because he had received commercial advertising from… SPAIN ·AEPD ·Art. 6 Direct Marketing Personal Data Right to Object Jul 8, 2021
€4,200 Marbella Resorts S.L.: Insufficient data processing agreement The Spanish DPA (AEPD) has imposed a fine of EUR 7,000 on Marbella Resorts S.L.. In the case at hand, the data subject had booked a room in the hotel complex of the controller. On… SPAIN ·AEPD ·Art. 28 Controllers Personal Data Processors Jul 6, 2021
€8,500 Magazine publisher: Insufficient legal basis for data processing The Finnish DPA has imposed a fine of EUR 8,500 on a magazine publisher. The DPA received four complaints against the magazine publisher for unsolicited telephone advertising.The… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 7, 12 +3 Direct Marketing Right to Object Consent Jun 24, 2021
€40,000 aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 28, 32 Encryption Security Controllers Jun 10, 2021
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused did not respond to the complainant's repeated requests to provide access to personal data and to… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Right of Access Personal Data Supervisory Authorities Jun 9, 2021
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused did not respond to the subject's request to disclose what information the accused was processing about… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jun 9, 2021
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUr 2,000 on a legal person. The accused did not respond to the subject's request to disclose what information the accused was processing about… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jun 9, 2021
€2,000 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on an unknown controller. The accused did not respond to the subject's request to disclose what information the accused was… ÚOOÚ (CZ) ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers Jun 9, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jun 7, 2021
€25,000 Region Sörmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Sörmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·IMY ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Encryption Personal Data Jun 7, 2021
€50,000 Region Stockholm: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13, 14 Supervisory Authorities Personal Data Security Jun 7, 2021
€2,000 Banca Comercială Română S.A.: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined Banca Comercială Română S.A. EUR 2,000. A data subject had initiated a complaint with the DPA because the controller had used his personal… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing May 19, 2021
€800 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 800 on a legal person. The accused did not respond to its former employee's request to delete their former work email and even told the… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Supervisory Authorities Processing Agreement May 14, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Security Controllers Apr 22, 2021
€200 Self Employed Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 200 on a self employed person. The accused obtained scans of identity cards from foreign subjects who booked accommodation there and kept… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 12 +4 Personal Data Consent Processing Mar 10, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Cyprus DPA ·Art. 12, 15, 31 +1 Right of Access Personal Data Supervisory Authorities Mar 3, 2021
Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Encryption Controllers Processing Mar 3, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Supervisory Authorities Feb 23, 2021
€350,000 Roma Capitale: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined the city of Rome EUR 350,000 for failing to take adequate technical and organizational measures regarding the data of citizens who had obtained… ITALY ·Garante ·Art. 5, 6, 28 +1 Security Supervisory Authorities Privacy by Design & Default Feb 11, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Controllers Personal Data Feb 11, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Integrity and Confidentiality Principle Privacy by Design & Default Security Feb 11, 2021
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Supervisory Authorities Feb 2, 2021
€80 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 80 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Supervisory Authorities Feb 1, 2021
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Types of Special Categories of Personal Data Jan 27, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Jan 27, 2021
€150,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Personal Data Jan 27, 2021
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 75,000 on Telefónica Móviles España, SAU. The controller had assigned five telephone lines with five numbers to the data subject as… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Jan 21, 2021
€26,710 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Supervisory Authorities Marketing Direct Marketing Jan 20, 2021
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Supervisory Authorities Marketing Direct Marketing Jan 20, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent unsolicited commercial communications to the complainant and failed to respond to their repeated… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jan 19, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Processors Controllers Processing Jan 14, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out four credit checks on the data… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Consent Jan 4, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles Supervisory Authorities Controllers Processors Jan 1, 2021
Physician: Insufficient legal basis for data processing The DPA of Brandenburg imposed a fine on a physician. The father of a minor patient had filed a complaint with the DPA because the physician had transmitted numerous data on his… GERMANY ·Art. 6, 9 ·Insufficient legal basis for data processing Consent Healthcare Processing Jan 1, 2021
€100 SLOVAKIA DPA: €100 fine Unlawful video surveillance in a garden community. Slovak Data Protection Office ·Unknown Supervisory Authorities Video Surveillance Monitoring Jan 1, 2021
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 28, 2020
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives Personal Data Supervision Dec 20, 2020
€26,710 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Supervisory Authorities Marketing Direct Marketing Dec 18, 2020
€8,100 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,100 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Supervisory Authorities Marketing Direct Marketing Dec 18, 2020
€200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 200 on a legal person. The accused sent the data subject, despite his objection and therefore his disagreement with further processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Direct Marketing Dec 18, 2020
€9,420 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Supervisory Authorities Marketing Direct Marketing Dec 18, 2020