Skip to content
Content type · 1,535 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1101–1150 of 1,535 sort newestlargest fineoldest
€3.9M Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Security Feb 1, 2022
€700,000 Orange Espagne S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Orange Espagne S.A.U. EUR 700,000. Two Orange Espagne customers had filed complaints with the DPA. In the course of its investigation, the DPA found that… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Personal Data Feb 1, 2022
€70,000 ORANGE ESPAÑA VIRTUAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined ORANGE ESPAÑA VIRTUAL, S.L. EUR 70,000. Two Orange España Virtual customers had filed complaints with the DPA. In the course of its investigation, the… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Personal Data Feb 1, 2022
€900,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined TELEFÓNICA MÓVILES ESPAÑA, S.A.U. EUR 900,000. Four Telefónica customers had filed complaints with the DPA. In the course of its investigation, the DPA… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€200,000 XFERA MÓVILES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined XFERA MÓVILES, S.A. EUR 200,000. Two Xfera customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches DPIA Security Jan 27, 2022
€3.2M OTE Group: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 3.2 million on Cosmote subsidiary OTE Group. Among other things, OTE Group had contributed to Cosmote's security infrastructure. Cosmote… GREECE ·HDPA ·Art. 32 Data Breaches Notification Obligation Security Jan 27, 2022
€2,000 Private club 'Ruian': Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 2,000 on the private club 'Ruian'. The controller had installed video surveillance cameras which, among other things, also… ITALY ·Garante ·Art. 5, 13 Video Surveillance Controllers IP Address Jan 27, 2022
€40,000 T.S.M. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on T.S.M. s.r.l.. A data subject had filed a complaint with the DPA against the company for failing to comply with their requests… ITALY ·Garante ·Art. 13, 15, 21 +2 Personal Data Processing Agreement Supervisory Authorities Jan 27, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·Art. 5, 24, 28 +2 ·Insufficient technical and organisational measures to ensure information security Data Breaches Controllers Security Jan 26, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Encryption Data Breaches Security Jan 19, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Encryption Data Breaches Security Jan 19, 2022
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,500 on a private individual. The person had installed video cameras in the apartment building where he lives, which recorded, among… SPAIN ·aepd ·Art. 5 IP Address Processing Agreement Processing Jan 17, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS ·AP ·Art. 12 Personal Data Controllers Data Controller Jan 14, 2022
€2,400 PHARMA TALENTS, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's… SPAIN ·aepd ·Art. 5, 32 Security Healthcare Personal Data Jan 14, 2022
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jan 13, 2022
€1,000 A.S.L. Napoli 1 Centro: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 1,000 on A.S.L. Napoli 1 Centro. An employee at the health authority had filed a complaint with the DPA against the… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Healthcare IP Address Jan 13, 2022
€14,000 Azienda sanitaria unica regionale Marche: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 14,000 on Azienda sanitaria unica regionale Marche. The DPA launched an investigation against the health department following media… ITALY ·Garante ·Art. 5, 32, 35 Security Healthcare Privacy by Design & Default Jan 13, 2022
€3,000 Property Owner Community: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Jan 11, 2022
€5,000 Cyprus Judo Federation: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine on the Cyprus Judo Federation. The father of a member had filed a complaint with the DPA because the judo coach of his minor son had published… Art. 31 ·Insufficient cooperation with supervisory authority Social Media Supervisory Authorities Supervision Jan 1, 2022
Logistics company: Insufficient technical and organisational measures to ensure information security A logistics company had disposed of delivery lists in a public waste paper container. The lists contained a large amount of detailed information, such as the first and last names… GERMANY ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security IP Address Jan 1, 2022
€16,400 Covid-19 test center: Insufficient legal basis for data processing The DPA of Hessen has fined a Covid-19 test center EUR 16,400. The controller had sent an e-mail containing personal data to several recipients in an open distribution list. The… GERMANY ·Art. 6, 33 ·Insufficient legal basis for data processing Data Breaches Healthcare IP Address Jan 1, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Encryption Security Jan 1, 2022
€80,700 Beauty salon: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 80,700 on a beauty salon. The controller had installed video cameras in all its premises, which permanently recorded customers and… HUNGARY ·NAIH ·Insufficient legal basis for data processing Video Surveillance Controllers Direct Marketing Jan 1, 2022
€250,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has failed to implement appropriate technical and organizational measures to protect personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Jan 1, 2022
€1,300 Website operator: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,300 on a website operator. An individual had filed a complaint with the DPA against the controller due to the fact that the… HUNGARY ·NAIH ·Art. 5, 12, 31 Personal Data Controllers Supervisory Authorities Jan 1, 2022
€5,000 Cyprus Electricity Authority: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Personal Data Jan 1, 2022
€800 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes in order to obtain information about a colleague. GERMANY ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2022
€12,800 Political party: Insufficient legal basis for data processing The Bulgarian DPA has imposed a fine of EUR 12,800 on a political party. Several individuals had filed a complaint with the DPA because their personal data had been added to voter… BULGARIA ·KZLD ·Art. 6 Personal Data Consent Processing Jan 1, 2022
GERMANY DPA: Insufficient legal basis for data processing The DPA of Thüringen has imposed a fine on a controller. The controller had installed a video surveillance camera in the public entrance area of an apartment building without a… Art. 6 ·Insufficient legal basis for data processing Video Surveillance Controllers Monitoring Jan 1, 2022
€1,400 Dentist: Non-compliance with general data processing principles The Hungarian DPA has fined a dentist EUR 1,300. The controller had installed several surveillance cameras in their practice, which permanently recorded employees and patients.… HUNGARY ·NAIH ·Non-compliance with general data processing principles Video Surveillance Healthcare Monitoring Jan 1, 2022
€50,000 Company: Insufficient fulfilment of data subjects rights The DPA of Niedersachsen has imposed a fine of EUR 50,000 on a company. The company sent out a newsletter by e-mail that could not be unsubscribed from due to technical… GERMANY ·Art. 15, 21 ·Insufficient fulfilment of data subjects rights Right to Object Personal Data Supervisory Authorities Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a five-figure fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Direct Marketing Consent Personal Data Jan 1, 2022
Debt collection company: Insufficient legal basis for data processing The DPA from Baden-Württemberg has imposed a fine on a debt collection company. The debt collection company had received investor information from an employee of an insolvent… GERMANY ·Art. 6, 14 ·Insufficient legal basis for data processing Insurance Personal Data Processing Agreement Jan 1, 2022
€300 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes in order to obtain information about their ex-partner's new partner. GERMANY ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Art. 24, 28 ·Insufficient data processing agreement Controllers Insurance Processing Agreement Jan 1, 2022
€2,700 Credit institution: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 2,700 on a credit institution. Several individuals had filed a complaint with the DPA due to the fact that the controller had… HUNGARY ·NAIH ·Art. 5, 6 Controllers Processing Agreement Consent Jan 1, 2022
€7,380 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes over a period of three years. GERMANY ·Insufficient legal basis for data processing Scientific Research Processing Human Resources Jan 1, 2022
€2,700 Covid-19 test center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Healthcare Security Jan 1, 2022
€1,600 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA imposed a fine of EUR 1,600 on a physician. A patient had filed a complaint against the controller with the DPA. The patient had asked the doctor to send all… HUNGARY ·NAIH ·Art. 5, 12, 13 Healthcare Health Data Healthcare Jan 1, 2022
€17,000 Bank of Cyprus Public Company Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Processing Agreement Jan 1, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jan 1, 2022
€150M CNIL rejects Google's stay request and ne bis in idem challenge in cookie consent case Google LLC is a subsidiary owned wholly by Alphabet Inc. Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and… France ·Art. 56 Cookies Telecommunications Material scope (GDPR) Dec 31, 2021
€75,000 Greek Ministry of Tourism: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 75,000 on the Greek Ministry of Tourism. A data breach had occurred at the authority. According to the DPA, an attempt by a citizen to… GREECE ·HDPA ·Art. 13, 32, 33 +1 Data Breaches Notification Obligation Public Sector Dec 29, 2021
€300,000 FREE MOBILE: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has imposed a fine of EUR 300,000 on FREEE MOBILE. The CNIL had received numerous complaints regarding the company's failure to comply with data subjects'… FRANCE ·CNIL ·Art. 12, 15, 21 +2 Right to Object Data Subject Rights Exercise Modalities and Procedures Telecommunications Dec 28, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Insurance Dec 28, 2021
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Healthcare Health Data Dec 26, 2021
€5,000 Sfam España General s.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Sfam España General s.l.. A data subject had filed a complaint with the DPA against the controller for charging her… SPAIN ·aepd ·Art. 6 Controllers Personal Data Insurance Dec 22, 2021
€5,000 HUBSIDE IBÉRICA S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 HUBSIDE IBÉRICA S.L.. A data subject had filed a complaint with the DPA against the controller for charging her several… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Dec 22, 2021