Skip to content
Content type · 3,589 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1101–1150 of 3,589 sort newestlargest fineoldest
€3.2M Apoteket AB.: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 3.2 million on Apoteket AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused… SWEDEN ·IMY ·Art. 32 Security Controllers Personal Data Aug 29, 2024
€698,000 Apohem AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 698,000 on Apohem AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused personal data… SWEDEN ·IMY ·Art. 32 Security Controllers Personal Data Aug 29, 2024
€50,000 SANTANDER CONSUMER FINANCE, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 50,000 on SANTANDER CONSUMER FINANCE, S.A.. The fine followed a complaint from an individual who received advertising from the company,… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Direct Marketing Aug 22, 2024
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Notification Obligation Data Breaches Personal Data Aug 20, 2024
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 20, 2024
€1.5M The Austrian DPA has imposed a fine of EUR 1,500,000 on a company, that is part of a group The controller installed video surveillance devices that did not comply with the GDPR, resulting in the company being fined. Company: €1,500,000 fine ·AUSTRIA ·DSB Monitoring Video Surveillance Controllers Aug 16, 2024
€1.5M IKEA: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 1,500,000 on IKEA. The controller used excessive video surveillance, including in public spaces and the checkout area. Additionally, the… AUSTRIA ·DSB ·Art. 5, 6 Controllers Processing Video Surveillance Aug 16, 2024
€26,800 Municipality of Vejen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 26,800 on the municipality of Vejen. The municipality had suffered a security incident involving the theft of three unencrypted computers… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Public Authority Encryption Education Aug 14, 2024
€270,000 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA. An individual who provided services to the controller filed a complaint with the DPA due to the fact… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Aug 12, 2024
€1,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual EUR 1,000. The controller had uploaded images from their video surveillance camera to Instagram showing, amongst others, a minor and… SPAIN ·AEPD ·Art. 6 Controllers Social Media Video Surveillance Aug 6, 2024
€10,000 LOCAL VERTICALS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has fined LOCAL VERTICALS, S.L. EUR 10,000. An individual filed a complaint with the DPA because they could not access the privacy policy during the registration… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Aug 6, 2024
€1,000 BEST ELAN ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has fined BEST ELAN ONLINE SRL EUR 1,000 for failing to provide information requested by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Aug 6, 2024
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual for installing video surveillance cameras without a valid legal basis. SPAIN ·AEPD ·Art. 6 Video Surveillance Monitoring Processing Agreement Aug 6, 2024
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… AP Personal Data Privacy Shield International Transfer Jul 22, 2024
€6,900 Municipality of Korou: Insufficient involvement of data protection officer The French DPA has imposed a fine of EUR 6,900 on the municipality of Korou for failing to appoint a data protection officer. FRANCE ·CNIL ·Art. 31, 37 Public Authority Supervisory Authorities Jul 22, 2024
€200,000 Vodafone España, S.A.U.: Insufficient cooperation with supervisory authority The Spanish DPA has fined Vodafone España, S.A.U. EUR 200,000 for failing to provide information requested by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Telecommunications Jul 18, 2024
€600 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on a private individual. The individual had shared personal data of a data subject in a Facebook group without their consent. The original fine… SPAIN ·AEPD ·Art. 6 Personal Data Consent Social Media Jul 18, 2024
€80,000 Selectra S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access… ITALY ·Garante ·Art. 5, 13, 88 +1 Storage Limitation Retention Period Controllers Jul 17, 2024
€5M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5 million on Hera Comm S.p.A. The investigation was launched following numerous complaints. The energy supplier had failed to take… ITALY ·Garante ·Art. 5, 12, 15 +3 Controllers Personal Data Supervisory Authorities Jul 17, 2024
€600 DIGIMAN ALICANTE S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on DIGIMAN ALICANTE S.L.. The data controller had installed a video surveillance system without adequately providing information for data… SPAIN ·AEPD ·Art. 13 Controllers Personal Data Supervisory Authorities Jul 17, 2024
€30,000 Pere Sihtkapital SA: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 30,000 on Pere Sihtkapital SA. The controller conducted a survey on childless families. In the process, the controller failed to take all… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Jul 15, 2024
€600 ASSOCIACIO CANNABICA DEL MARESME ACANNAM: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on ASSOCIACIO CANNABICA DEL MARESME ACANNAM. The controller had installed video surveillance cameras which, among other… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jul 11, 2024
€5,000 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 5,000 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Jul 10, 2024
€300 WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.. The controller had sent postal advertising to a private individual without their consent by… SPAIN ·AEPD ·Art. 6 Consent Controllers Direct Marketing Jul 10, 2024
€10,000 Clinic owner: Insufficient legal basis for data processing The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the… SPAIN ·AEPD ·Art. 6, 9 Consent Healthcare Controllers Jul 5, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Personal Data Privacy by Design & Default Jul 4, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which also recorded parts of a neighbouring… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Jul 4, 2024
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA ·VDAI ·Art. 5, 12 Transparency Accountability Controllers Jul 2, 2024
€50,000 METRO SA: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 50,000 on METRO SA. A former employee had sent text messages to the private mobile phone of a customer who had a user account in the… GREECE ·HDPA ·Art. 15, 17, 24 +2 Security Personal Data Controllers Jun 27, 2024
€600 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a Homeowners' association. The association had installed video surveillance cameras which, among other things, also covered the public space.… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jun 26, 2024
€80,000 AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A. y SEUR GEOPOST, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A. y SEUR GEOPOST, S.L.. The controller had suffered a security incident which, according to… SPAIN ·AEPD ·Art. 32 Security Controllers Personal Data Jun 26, 2024
€4,000 ALTERNATIVA CORELLANA INDEPENDIENTE: Insufficient cooperation with supervisory authority The Spanish DPA has fined ALTERNATIVA CORELLANA INDEPENDIENTE EUR 4,000 for failing to provide information requested by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Jun 26, 2024
€1,000 Rețele Electrice Dobrogea SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Rețele Electrice Dobrogea SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 25, 2024
€150,000 BANCO CETELEM, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO CETELEM, S.A.. A person had filed a complaint against the controller with the DPA due to the fact that debits had been made from their… SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Insurance Jun 25, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera in their garage area, which however also recorded… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Jun 25, 2024
€3,000 Rețele Electrice Muntenia SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Rețele Electrice Muntenia SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 25, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 24, 2024
€4,000 Medical association: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,000 on the medical association 'Ordine dei Medici Chirurghi e degli Odontoiatri'. A patient had filed a complaint with the DPA. During… ITALY ·Garante ·Art. 12, 13, 15 Personal Data Controllers Supervisory Authorities Jun 20, 2024
€20,000 Municipality of Nepi: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 on the municipality of Nepi. The controller had published a document containing the ranking list of a pre-selection test for a… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Controllers Supervisory Authorities Jun 20, 2024
€1M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1 million on Fastweb S.p.A. due to unauthorized telemarketing, the unlawful storage of customer data after contract termination, and… ITALY ·Garante ·Art. 5, 6, 7 +13 Storage Limitation Direct Marketing Right to Object Jun 20, 2024
€10,000 TS Food Processing s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on TS Food Processing s.r.l.. A data subject (former emplyee) had filed a complaint with the DPA due to the controller's failure… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Jun 20, 2024
€42,000 CUI ZSQ FOOD, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CUI ZSQ FOOD, S.L.. An employee had filed a complaint with the DPA as video recordings of the company's surveillance system in which they… SPAIN ·AEPD ·Art. 5 Processing Employees Monitoring Jun 20, 2024
€600 Club Balonmano Gijón: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Club Balonmano Gijón. The sports club had published pictures of minors without the consent of parents. The original fine of EUR 1,000 was… SPAIN ·AEPD ·Art. 6 Consent Minors Supervisory Authorities Jun 17, 2024
€3,000 20 AÑOS DE MÚSICA A.I.E.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on 20 AÑOS DE MÚSICA A.I.E.. A person had filed a complaint with the DPA due to the fact that in order for minors to attend concerts organized… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jun 17, 2024
€3,000 DQG NORTE A.I.E: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on DQG NORTE A.I.E.. A person had filed a complaint with the DPA due to the fact that in order for minors to attend concerts organized by the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jun 13, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND ·UODO ·Art. 24, 25, 32 +1 Security Privacy by Design & Default Controllers Jun 13, 2024
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A data subject had filed a complaint with the DPA because the controller had proposed to a credit… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Jun 12, 2024
€5,000 Bakery: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 5,000 on a bakery. The DPA found that the controller had violated its information obligations and the principle of data minimization in… FRANCE ·CNIL ·Non-compliance with general data processing principles Retention Period Video Surveillance Controllers Jun 10, 2024
€160,000 ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A person had filed a complaint with the DPA because their ex-partner had been given… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Jun 10, 2024
€100,000 NATURGY IBERIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 100,000 on NATURGY IBERIA, S.A.. A customer had filed a complaint with the DPA because an amendment had been made to their electricity… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Consent Jun 10, 2024