Skip to content
Content type · 1,282 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1151–1200 of 1,282 sort newestlargest fineoldest
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. In connection with the delivery of magazine subscriptions, the company did not provide the data subject with… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data IP Address Processing Sep 25, 2020
€3,000 Grupo Carolizan: Non-compliance with general data processing principles Operation of CCTV camera systems in an arcade area in front of a building, i.e. also covering public space. This violated the principles of data minimization, as the surveillance… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Sep 17, 2020
€10,000 Property owners community: Non-compliance with general data processing principles Publication of a document containing personal data (information about identity of the data subject as well as about debts) on a community notice billboard. SPAIN ·aepd ·Art. 5 Personal Data IP Address Processing Sep 16, 2020
€8,000 Private Person: Non-compliance with general data processing principles Operation of a CCTV camera that also monitored public space outside the premises of the data controller. GREECE ·HDPA ·Art. 5 Video Surveillance Controllers Processing Sep 11, 2020
€2,000 Sanatatea Press Group S.R.L.: Insufficient technical and organisational measures to ensure information security Sending the personal data collected for the registration for an online course to other participants due to a technical failure. ROMANIA ·ANSPDCP ·Art. 5, 32 Security Telecommunications Personal Data Sep 8, 2020
€3,000 Barcelona Airport Security Guard Association ('AVSAB'): Non-compliance with general data processing principles A member of the AVSAB security committee used WhatsApp to send messages to private phone numbers containing personal information about employees. This was a violation of the… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Controllers Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Security Education Sep 3, 2020
€5,000 Basketball Federation of Castilla and Leon: Insufficient legal basis for data processing The Basketball Association transmitted personal data to third parties, which were subsequently published on the Internet without consent of the data subjects. In addition, the… SPAIN ·aepd ·Art. 5, 6 Integrity and Confidentiality Principle Professional Secrecy Personal Data Aug 28, 2020
€50,000 Bankia S.A.: Non-compliance with general data processing principles The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this… SPAIN ·aepd ·Art. 5 Personal Data Insurance IP Address Aug 28, 2020
€5,000 Party of the Socialists of Catalonia: Non-compliance with general data processing principles The Socialist Party of Catalonia has used the personal data provided by a professional doctor to send a letter to the complainant's relative asking for political support. This… SPAIN ·aepd ·Art. 5 Personal Data IP Address Education Aug 17, 2020
€3,000 GROW BEATS SL: Insufficient fulfilment of information obligations The company had published a cookie policy on its website, which on the one hand contained no information about the purpose of the use of cookies and on the other hand no… SPAIN ·aepd ·Art. 12, 13, 14 Cookies IP Address Law Enforcement Aug 6, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Installation of CCTV surveillance cameras that were also monitoring the public space and without proper information. SPAIN ·aepd ·Art. 5, 12, 13 Video Surveillance Monitoring Audit Logs Aug 5, 2020
€250,000 Spartoo: Non-compliance with general data processing principles A fine of EUR 250000 was imposed on the online retailer Spartoo. The reason for this was that the company, which has its headquarters in France but supplies a large number of… FRANCE ·CNIL ·Art. 5, 13, 14 IP Address Personal Data Encryption Aug 5, 2020
€3,000 Community of San Giorgio Jonico: Insufficient legal basis for data processing Publication of personal data on the municipal website with regard to legal proceedings. ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Jul 29, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK ·Datatilsynet ·Art. 5 Retention Period Personal Data IP Address Jul 28, 2020
€3,000 Communal political association: Insufficient legal basis for data processing A local political association has sent out election advertisements to the residents of the municipality for the local elections in 2018. For this purpose, the association used the… BELGIUM ·APD ·Art. 5, 6, 14 Education IP Address Public Authority Jul 28, 2020
€55,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing Telefónica Móviles España has processed the personal data of a data subject, such as first and last name and bank details, in order to activate three telephone lines that were… SPAIN ·aepd ·Art. 5, 6 Personal Data IP Address Telecommunications Jul 23, 2020
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The company had carried out the number porting of his telephone line from his current company without his consent. Personal data was transferred from the former telephone operator… SPAIN ·aepd ·Art. 5, 6 Personal Data IP Address Consent Jul 23, 2020
€70,000 Xfera Moviles S.A.: Non-compliance with general data processing principles A data subject had received a call from another Xfera Móviles customer who stated that the company had charged his bank account with an invoice, disclosing the personal details of… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Jul 20, 2020
€24,000 Banco Bilbao Vizcaya Argentaria, SA: Insufficient legal basis for data processing BBVA had no legitimate basis for processing the data of the data subject and had therefore infringed Article 6(1) of the GDPR, since the company processed solvency and credit… SPAIN ·aepd ·Art. 5, 6 Insurance IP Address Personal Data Jul 20, 2020
€40,000 Iberia Lae SA Operadora Unipersonal: Insufficient cooperation with supervisory authority The company did not grant the data subject access to telephone records. The applicant's request for access did not receive a reply, despite the prior order of the AEPD. SPAIN ·aepd ·Art. 58 Right of Access Right of Access Procedures Personal Data Jul 20, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide evidence that the data subject had consented to the scanning or copying of their ID card… CZECH REPUBLIC ·UOOU ·Art. 5, 6, 7 +3 Personal Data IP Address Consent Jul 14, 2020
€600,000 Google Belgium SA: Insufficient fulfilment of data subjects rights The Belgian data protection authority has fined Google Belgium SA, a subsidiary of Google, 600,000 euros. The reasons for the fine were the rejection of an application by a data… APD ·Art. 5, 6, 12 +1 ·Insufficient fulfilment of data subjects rights Right to be Forgotten Fairness & Transparency Personal Data Jul 14, 2020
€800,000 Iliad Italia S.p.A.: Non-compliance with general data processing principles The fine relates to data protection infringements concerning the processing of customer data for the activation of SIM cards and the manner in which payment data was recorded. In… ITALY ·Garante ·Art. 5, 25 Integrity and Confidentiality Principle Fairness & Transparency Direct Marketing Jul 13, 2020
€55,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The company had changed a contract for a mobile phone connection to a new owner, whereby the personal data of a data subject such as his address and telephone numbers were freely… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Professional Secrecy Personal Data Jul 10, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet ·Art. 32, 35 DPIA Privacy Impact Assessment Health Data Jul 10, 2020
€12,000 Vodafone España, SAU: Non-compliance with general data processing principles Fines for violation of Art. 5 (1) d) GDPR for changing the customer's master data into the name of a third party, the ex-spouse of the customer. SPAIN ·aepd ·Art. 5 Fines IP Address Telecommunications Jul 10, 2020
€1,500 Auto Desguaces Iglesias S.L.: Non-compliance with general data processing principles The company had installed surveillance cameras that recorded the public road and therefore violated the principle of data minimization. SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Jul 10, 2020
€5,000 School Fitness Holiday & Franchising S.L.: Non-compliance with general data processing principles Breach of transparency principle. No further information available at the moment. SPAIN ·aepd ·Art. 5 Education Fairness & Transparency Transparency Jul 10, 2020
€24,000 Iberdrola Clientes: Non-compliance with general data processing principles A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Security Professional Secrecy Jul 2, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Insurance Healthcare Security Jun 30, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK ·Datatilsynet ·Art. 5, 6, 33 +1 Data Breaches Personal Data Education Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE ·HDPA ·Art. 5 Personal Data Education IP Address Jun 29, 2020
€2,000 Comunidad de propietarios demelza beach: Non-compliance with general data processing principles Illegal use of CCTV cameras due to coverage of public space and recording of passing pedestrians. Furthermore, insufficient fulfilment of information obligations. SPAIN ·aepd ·Art. 5, 6, 13 +1 Video Surveillance IP Address Processing Jun 22, 2020
€2,000 Café Bar: Non-compliance with general data processing principles Illegal use of CCTV cameras (recording of third parties) and insufficient fulfilment of information obligations. SPAIN ·aepd ·Art. 5, 6, 13 +1 Video Surveillance IP Address Healthcare Jun 16, 2020
€1,900 Housing Association: Non-compliance with general data processing principles Unlawful usage of surveillance cameras. In the decision, the data protection authority stressed that sound recordings have additional privacy implications, especially in a… SWEDEN ·Art. 5, 6 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jun 16, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 16, 2020
€288,000 Digi Távközlési Szolgáltató Kft. ('Digi') (electronic communication service provider): Insufficient technical and organisational measures to ensure information security The company had infringed the principles of purpose limitation and storage restriction because its database contained a large amount of customer data which were no longer relevant… HUNGARY ·NAIH ·Art. 5, 32 Encryption Storage Limitation Retention Period Jun 12, 2020
€1,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Jun 9, 2020
€2,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Jun 9, 2020
€5,000 Municipal employee: Insufficient legal basis for data processing In the context of a municipal election in 2018, the data controller had sent election advertisements to a group of employees of the same municipal administration, unlawfully using… BELGIUM ·APD ·Art. 5, 6 Controllers Education IP Address Jun 8, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6, 35 Video Surveillance DPIA Privacy Impact Assessment May 29, 2020
€16,000 Kymen Vesi Oy: Non-compliance with general data processing principles Fine for failure to carry out a data protection impact assessment ('DPIA') for the processing of location data of employees with a vehicle information system FINLAND ·Deputy Data Protection Ombudsman ·Art. 35 DPIA Privacy Impact Assessment Employees May 22, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE ·HDPA ·Art. 5, 6 Video Surveillance Monitoring IP Address Apr 7, 2020
€6,000 Amalfi Servicios de Restauracion S.L.: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·aepd ·Art. 5, 13, 14 Video Surveillance Monitoring IP Address Mar 16, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Education Personal Data Mar 16, 2020
€2,000 Homeowners Association: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·aepd ·Art. 5, 13, 14 Video Surveillance Monitoring IP Address Mar 12, 2020
€7,000 Hørsholm Municipality: Insufficient technical and organisational measures to ensure information security A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and… DENMARK ·Datatilsynet ·Art. 5, 32 Security Personal Data Public Authority Mar 10, 2020
€14,000 Gladsaxe Municipality: Insufficient technical and organisational measures to ensure information security A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city… DENMARK ·Datatilsynet ·Art. 5, 32 Encryption Security Personal Data Mar 10, 2020
€20,600 National Center of Addiction Medicine ('SAA'): Insufficient technical and organisational measures to ensure information security Persónuvernd noted that a former employee of the SAA received boxes of allegedly personal belongings that he had left there, but which also contained patient data, including the… ICELAND ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Health Data Security Mar 10, 2020