Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1051–1100 of 2,273 sort newestlargest fineoldest
€12,800 Political Party: Insufficient legal basis for data processing The Bulgarian DPA has imposed a fine of EUR 12,800 on a political party. In preparation for an upcoming election, the controller submitted a list of supporters to the Central… BULGARIA ·KZLD ·Art. 6 Controllers Personal Data Processing Agreement Jan 26, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 32, 75 Health Data Healthcare Recipient Jan 26, 2023
€5,000 Azienda ULSS n.5 Polesana: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 5,000 on Azienda ULSS n.5 Polesana. The healthcare facility had mistakenly sent a patient medical record to the wrong patient. The DPA… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Security Jan 26, 2023
€4,100 Company: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 4,100 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Jan 25, 2023
€8,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has fined a company EUR 8, 000. The controller failed ot properly fulfil the data subject's right to access their personal data processed by the company. The… LITHUANIA ·VDAI ·Art. 5, 15 Personal Data Data Subject Rights Exercise Modalities and Procedures Storage Limitation Jan 24, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·Art. 5, 32 ·Non-compliance with general data processing principles Security Healthcare Healthcare Jan 23, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Security Education Jan 19, 2023
€56,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. An individual had filed a complaint with the DPA because the controller had disclosed their personal… SPAIN ·aepd ·Art. 5, 32 Personal Data Controllers IP Address Jan 19, 2023
€6,400 Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,400 on the Szczecin-Centrum District Court. The court had reported a data breach to the DPA involving the loss of three data carriers.… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Data Breaches Security Jan 19, 2023
€5.5M WhatsApp Ireland Ltd.: Insufficient legal basis for data processing The Irish DPA (DPC) has fined WhatsApp Ireland Ltd. EUR 5.5 million. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of an… Art. 6, 12, 13 ·Insufficient legal basis for data processing Notified Body Competence Challenges and Dispute Resolution Fairness & Transparency Processing Agreement Jan 19, 2023
€1,000 Dante Internațional SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dante Internațional SA. A data subject had filed a complaint with the DPA against the controller due to the fact that the… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Controllers Processing Agreement Jan 18, 2023
€2,000 Private investigator: Insufficient fulfilment of information obligations The Spanish DPA has fined a private investigator EUR 2,000. An individual who had hired the investigator filed a complaint with the DPA. They stated that the controller had failed… SPAIN ·aepd ·Art. 13 Personal Data Controllers Supervisory Authorities Jan 18, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Jan 17, 2023
€1,020 Telecommunications Operator: Non-compliance with general data processing principles The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient technical and organisational measures to ensure… BULGARIA ·KZLD ·Art. 5, 6 Telecommunications Security Controllers Jan 17, 2023
€50,000 DPC (Ireland) - 05/SIU/2018 This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Video Surveillance Monitoring Legitimate Interest Jan 16, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jan 16, 2023
€40,000 Thomas International Systems, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Thomas International Systems, S.A.. Thomas International performs psychological tests on behalf of other companies. Thomas International had… SPAIN ·aepd ·Art. 9 Personal Data Insurance Controllers Jan 16, 2023
€56,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an… SPAIN ·aepd ·Art. 6 Insurance Processing Agreement Personal Data Jan 16, 2023
€3,000 SERVICIOS INTEGRALES DEL HOGAR TENERIFE, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on a SERVICIOS INTEGRALES DEL HOGAR TENERIFE, S.L.. A former employee had filed a complaint with the DPA due to the controller's unauthorized… SPAIN ·aepd ·Art. 6 Controllers Personal Data Employees Jan 12, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€2,500 Azienda Sanitaria Locale di Brindisi: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,500 on Azienda Sanitaria Locale di Brindisi. A data subject had filed a complaint with the DPA due to the health authority's failure to… ITALY ·Garante ·Art. 12, 15 Personal Data Healthcare Supervisory Authorities Jan 11, 2023
€6,000 Praktiškas UAB: Insufficient legal basis for data processing The Lithuanian DPA has fined Praktiškas UAB, the operator of SportGates sports clubs, EUR 6,000. The controller had processed biometric data of customers in the context of their… LITHUANIA ·VDAI ·Art. 5, 9, 13 +2 DPIA Consent Controllers Jan 9, 2023
€390M Meta Platforms Ireland Limited: Non-compliance with general data processing principles The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook… Social Media Notified Body Competence Challenges and Dispute Resolution Fairness & Transparency Jan 4, 2023
€3,000 Apă Canal Ilfov SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Apă Canal Ilfov SA. The controller sent an e-mail with personal data to several recipients in an open distribution list. This… ROMANIA ·ANSPDCP ·Art. 32 IP Address Controllers Security Jan 4, 2023
€500 Homeowners Association: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 500 on a homeowners' association. The controller had publicly posted a list with the first and last names of all members of the… ROMANIA ·ANSPDCP ·Art. 5 Controllers IP Address Personal Data Jan 3, 2023
€3,000 Transport Workers' Union of Aragon: Non-compliance with general data processing principles The Spanish DPA has fined the Transport Workers' Union of Aragon EUR 3,000. The union had published a document with personal data (surname, first name and identity card number) of… SPAIN ·aepd ·Art. 5, 32 Security IP Address Personal Data Jan 3, 2023
€24,000 FACTOR ENERGÍA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on a FACTOR ENERGÍA, S.A.. A data subject had filed a complaint with the DPA because they had received advertising messages from the controller… SPAIN ·aepd ·Art. 6 Controllers IP Address Personal Data Jan 2, 2023
Operator of a dating platform: Insufficient technical and organisational measures to ensure information security The DPA of Bremen has imposed a fine on the operator of an online dating platform. The controller had not provided an email verification procedure for registration on its dating… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 1, 2023
Daycare center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a four-figure fine on a daycare center that had disposed of documents containing personal data of children and their parents in a publicly… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Education Jan 1, 2023
€28,000 Political party: €28,000 fine The Austrian DPA has imposed a fine of EUR 50,700 on a political party. The controller had sent two emails in an open distribution list. This allowed the recipients to view the… AUSTRIA ·dsb ·Unknown Political Opinions Personal Data Education Jan 1, 2023
€16,600 Company: €16,600 fine The DPA of Niedersachsen has imposed a fine of EUR 16,600 on a company in the real estate industry for failing to conclude a joint controllership agreement. In addition, the… GERMANY ·Art. 6, 12, 26 ·Unknown Joint Controllers Controllers IP Address Jan 1, 2023
Real estate agency: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on a real estate agency. The controller had repeatedly sent advertising messages to a former prospect and tried to contact them by… GERMANY ·Insufficient legal basis for data processing Personal Data Controllers Fines Jan 1, 2023
€2,500 MALTA DPA: Insufficient fulfilment of data subjects rights Multiple data protection shortcomings Art. 5, 12, 13 +4 ·Insufficient fulfilment of data subjects rights Personal Data IP Address Processing Agreement Jan 1, 2023
Fishing club: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on a fishing club due to the fact that lists of members' personal data such as first and last names, full addresses with… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Processing Agreement Jan 1, 2023
€3,000 Breikot Management Ltd: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 3,000 on Breikot Management Ltd. The DPA found that the company had violated the principle of minimization by processing excessive… CYPRUS ·Art. 5, 6 ·Non-compliance with general data processing principles IP Address Personal Data Processing Jan 1, 2023
€8,000 Cypriot Ministry of the Interior: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on the Cypriot Ministry of the Interior. The Ministry of Interior had unlawfully transmitted personal data of employees to the… CYPRUS ·Art. 5 ·Non-compliance with general data processing principles Personal Data IP Address Public Authority Jan 1, 2023
€2,000 Private individual: Insufficient legal basis for data processing The DPA of Baden-Wuerttemberg has imposed a fine of EUR 2,000 on a clinic employee. The employee had unlawfully accessed a patient administration system in order to find out more… GERMANY ·Art. 6, 9 ·Insufficient legal basis for data processing Healthcare Personal Data Processing Jan 1, 2023
Private individual: Non-compliance with general data processing principles The DPA of Hamburg has imposed a mid-four-figure fine on a private individual for improper use of the personal data of an opponent in a video game. The case occurred on the live… GERMANY ·Non-compliance with general data processing principles Personal Data IP Address Processing Jan 1, 2023
Private individual: Insufficient legal basis for data processing The DPA in Baden-Wuerttemberg imposed a fine on a private individual for installing a motion tracker on the data subject's car without their consent. GERMANY ·Insufficient legal basis for data processing Personal Data Processing Consent Jan 1, 2023
€25,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hessen has fined a company EUR 25,000. A person had filed a complaint for receiving advertising messages, although they had objected to receiving advertising messages GERMANY ·Art. 21 ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Processing Agreement Jan 1, 2023
Pizza delivery service: Non-compliance with general data processing principles The DPA of Baden-Wuerttemberg has imposed a four-digit fine on a pizza delivery service. The controller had disposed of receipts containing customers' personal data at a public… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Controllers IP Address Personal Data Jan 1, 2023
Clinic: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a clinic for transmitting an unredacted treatment report on the psychiatric treatment of the data subject to an accident insurance fund… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Insurance Healthcare Personal Data Jan 1, 2023
€9,000 Magdeburg University Hospital: Insufficient fulfilment of data breach notification obligations The DPA of Sachsen-Anhalt has imposed a fine of EUR 9,000 on Magdeburg University Hospital. The clinic had failed to report to the DPA a data breach involving a former employee… GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2023
€8,000 Bank of Cyprus Public Company Ltd.: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on Bank of Cyprus Public Company Ltd.. The controller had stored inaccurate data about a data subject in its system. Art. 5 ·Non-compliance with general data processing principles Accuracy Controllers Personal Data Jan 1, 2023
€15,000 A&G Couriers Limited T/A Fastway Couriers (Ireland): Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined A&G Couriers Limited T/A Fastway Couriers (Ireland) EUR 15,000. During a changeover of its IT systems, the controller had suffered a cyberattack in… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Right of Access Processing Agreement Dec 30, 2022
€6,300 Company: Insufficient cooperation with supervisory authority The Polish DPA has fined a company EUR 6,300 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Personal Data Dec 30, 2022
€3M CNIL fines VOODOO for cookie and tracker consent failures in mobile games VOODOO ('provider') was a mobile game developer. The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of… France ·Art. 4, 5, 82 Cookies Telecommunications Direct Marketing Dec 29, 2022
€2,000 Homeowners Association: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a homeowners' association. An individual who did cleaning work in the residential complex had filed a complaint with the DPA… SPAIN ·aepd ·Art. 6, 15 Personal Data Controllers Right of Access Dec 28, 2022
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Personal Data Dec 28, 2022
€100,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 100,00 on Vodafone España, S.A.U. due data processing without a sufficient legal basis. A data subject stated that a prepaid line of… SPAIN ·aepd ·Art. 6 Personal Data Processing Agreement Telecommunications Dec 28, 2022