Skip to content
Content type · 2,636 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1051–1100 of 2,636 sort newestlargest fineoldest
€40,000 Azienda socio sanitaria territoriale di Lodi CF: Non-compliance with general data processing principles The Italian DPA has imposed a fine of ERU 40,000 on the health authority Azienda socio sanitaria territoriale di Lodi CF. Employees of the health authority had accessed the file… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Processing Supervisory Authorities Oct 12, 2023
€1,000 GREECE DPA: Non-compliance with general data processing principles Unlawful disclosure of health data. HDPA ·Art. 5 ·Non-compliance with general data processing principles Processing Supervisory Authorities Health Data Oct 11, 2023
€5,300 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 5,300 on a private individual. An individual had rented a room from the controller and filed a complaint due to the fact that the… SPAIN ·AEPD ·Art. 6, 13 Controllers Consent Supervisory Authorities Oct 11, 2023
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 300. The individual had installed video surveillance cameras on their property which covered, among other things, the public… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Oct 11, 2023
€15,000 ILUNION SEGURIDAD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on ILUNION SEGURIDAD, S.A. The controller had sent labor communications by e-mail without using the blind copy option, revealing… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing Insurance Oct 10, 2023
€1,500 NORDETIA CLINICS MÓSTOLES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,500 on NORDETIA CLINICS MÓSTOLES S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing Supervisory Authorities Oct 10, 2023
€4,000 Private individual: Non-compliance with general data processing principles The Spanish DPA has fined a private individual EUR 4,000 for installing a video surveillance camera that captured parts of a commonly shared garage. The DPA considered this a… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Oct 9, 2023
€500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 500. The individual had installed video surveillance cameras on their property which covered, among other things, the public… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Oct 9, 2023
DSB-D124.5337 In August 2021, an unprotected Excel file containing the names and PCR test results of several thousand individuals was sent from the compromised email account of the first data… 2023-0.273.912 ·Austria ·Art. 5, 6, 12 +3 Right to be Forgotten Right of Access Personal Data Oct 6, 2023
€500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Oct 5, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·AZOP ·Art. 5, 6, 12 +2 Personal Data Legitimate Interest Controllers Oct 5, 2023
€70,000 Schockholm School borard: Non-compliance with general data processing principles The Swedish DPA has fined the Stockholm School Board EUR 70,000 for excessive video surveillance in a school. A school had installed extensive video surveillance due to past… SWEDEN ·IMY ·Art. 5, 6, 13 Supervisory Authorities Processing Video Surveillance Oct 3, 2023
€1,000 Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Cez Vânzare S.A.. The controller had accidentally sent emails containing personal customer data to the wrong recipients. The… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 2, 2023
€5,000 Physician: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on a physician for unlawfully disclosing patient data. ITALY ·Garante ·Art. 5, 9 Healthcare Processing Health Data Sep 28, 2023
€10M Axpo Italia Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained… ITALY ·Garante ·Art. 5, 24 Controllers Personal Data Processing Sep 28, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY ·Garante ·Art. 5, 32 Processing Health Data Healthcare Sep 28, 2023
€3,000 Palombaro s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Palombaro s.r.l. EUR 3,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects about… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Personal Data Processing Sep 28, 2023
€5,000 Ministero dell'Ambiente e della Sicurezza Energetica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Ministero dell'Ambiente e della Sicurezza Energetica. The controller had published a document on its website that contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Controllers Sep 28, 2023
€420 CHINA CENTER LLEIDA: Insufficient fulfilment of information obligations The Spanish DPA has fined CHINA CENTER LLEIDA due to a lack of sufficient data processing information in relation to video surveillance in their premises. The original fine of EUR… SPAIN ·AEPD ·Art. 13 Supervisory Authorities Monitoring Video Surveillance Sep 27, 2023
€10,000 Phyisician: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 10,000 on a physician. The physician had responded to an online review regarding their practice, disclosing personal health data of a… AUSTRIA ·DSB ·Art. 5, 9 Healthcare Types of Special Categories of Personal Data Processing Sep 26, 2023
€70,000 DIGI SPAIN TELECOM, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on DIGI SPAIN TELECOM, S.L.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Telecommunications Sep 26, 2023
€25,000 RESTART ENERGY ONE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on RESTART ENERGY ONE S.A.. During its investigation, the DPA found that there existed a publicly accessible file on the… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Sep 26, 2023
€30,000 EUROPA PRESS DE CATALUNYA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 30,000 on EUROPA PRESS DE CATALUNYA, S.A.. Several media outlets, including the controller had published an audio recording of a multiple… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Sep 26, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·AZOP ·Art. 6, 13, 32 +1 Encryption Controllers Personal Data Sep 26, 2023
€50,000 Athens Urban Transport Organization: Non-compliance with general data processing principles The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with… GREECE ·HDPA ·Art. 5, 25, 35 Privacy by Design & Default Privacy by Default Privacy by Design Sep 25, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Sep 25, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN ·AEPD ·Art. 9, 13 Personal Data Healthcare Controllers Sep 25, 2023
€2,000 UAT Comuna Albeni: Insufficient cooperation with supervisory authority The Romanian DPA has fined UAT Comuna Albeni EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Sep 25, 2023
€12,000 CHATWITH.IO WORLDWIDE, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 12,000 on the website operator CHATWITH.IO WORLDWIDE, S.L. During its investigation, the DPA found that the controller had failed to… SPAIN ·AEPD ·Art. 5, 13, 22 Personal Data Controllers Supervisory Authorities Sep 23, 2023
€2,500 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA of Luxembourg has imposed a fine of EUR 2,500 on a controller. The controller had used location systems on his service vehicles and construction machinery. During its… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers Sep 21, 2023
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered neighbour… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Sep 21, 2023
€4,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 4,000 on a private individual. An individual had rented a room from the controller and filed a complaint against them due to the fact… SPAIN ·AEPD ·Art. 6 Controllers Consent Video Surveillance Sep 21, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Sep 19, 2023
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Sep 19, 2023
€200,000 SAF LOGISTICS: Non-compliance with general data processing principles The French DPA has fined SAF LOGISTICS EUR 200,000. An employee reported to the DPA that the controller had collected data on the private lives of its employees. During its… FRANCE ·CNIL ·Art. 5, 9, 10 +1 Criminal Data Controllers Supervisory Authorities Sep 18, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has fined NN Asigurări de Viață S.A. EUR 1,000. A person had filed a complaint for receiving advertising messages, although they had objected to receiving… ROMANIA ·ANSPDCP ·Art. 21 Direct Marketing Personal Data Processing Sep 18, 2023
€90,000 GFB One s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 90,000 on GFB One s.r.l.. An individual had filed a complaint with the DPA because SIM cards were registered in their name, although they… ITALY ·Garante ·Art. 5, 6, 13 +1 Personal Data Controllers Supervisory Authorities Sep 14, 2023
€30,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 30,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·AZOP ·Art. 6, 7, 13 Personal Data Controllers Consent Sep 14, 2023
€10,000 Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb for failing to adequately comply with its obligation to comply… ITALY ·Garante ·Art. 12 Personal Data Supervisory Authorities Accuracy Sep 14, 2023
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·AZOP ·Art. 6, 7, 13 Personal Data Controllers Consent Sep 14, 2023
€10,000 San Severo municipality: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 10,000 on San Severo municipality. The municipality had published a document containing personal data of employees on its website without a… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Public Authority Sep 14, 2023
€5,000 Nimbus s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Nimbus s.r.l.. The controller had introduced a biometric attendance system at the workplace without adequately informing the… ITALY ·Garante ·Art. 5, 9, 13 Controllers Consent Supervisory Authorities Sep 14, 2023
€25,000 Zagreb Holding d.o.o.: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed a fine of EUR 25,000 on Zagreb Holding d.o.o., utilities company owned by the city of Zagreb. The DPA had received a complaint from a citizen… CROATIA ·AZOP ·Art. 13, 25 Controllers Personal Data Privacy by Design & Default Sep 13, 2023
€70,000 SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.. A customer had filed a complaint with the DPA due to the fact that the controller… SPAIN ·AEPD ·Art. 6 Controllers Consent Supervisory Authorities Sep 7, 2023
€10,300 University of Iceland: Insufficient fulfilment of information obligations The Icelandic DPA has fined the University of Iceland EUR 10,300. The university had not sufficiently informerd about the existence of video surveillance cameras on university… Persónuvernd ·Art. 5, 12, 13 ·Insufficient fulfilment of information obligations Supervisory Authorities Processing Video Surveillance Sep 6, 2023
€80,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Sep 5, 2023
€ 2,000M Decision 14-09-2023 The two companies in question, as controllers, made use of cookies on their websites, but failed to inform data subjects visiting their web pages about the legal basis for… Croatia ·AZOP ·Art. 6, 7, 13 Personal Data Consent Fines Sep 1, 2023
€345M TikTok Limited: Non-compliance with general data processing principles The Irish DPA (DPC), has imposed a fine of EUR 345 million on TikTok Limited. The DPC conducted an investigation primarily focused on the processing of personal data between July… IRELAND ·DPC ·Art. 5, 12, 13 +2 Privacy by Design & Default Processing Personal Data Sep 1, 2023
€10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… ITALY ·Garante ·Art. 5, 9, 12 +5 Recipient Personal Data Controllers Aug 31, 2023