Content type · 1,282 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. In connection with the delivery of magazine subscriptions, the company did not provide the data subject with… CZECH REPUBLIC · ·Art. 15 Sep 25, 2020
€3,000 Grupo Carolizan: Non-compliance with general data processing principles Operation of CCTV camera systems in an arcade area in front of a building, i.e. also covering public space. This violated the principles of data minimization, as the surveillance… SPAIN · ·Art. 5 Sep 17, 2020
€10,000 Property owners community: Non-compliance with general data processing principles Publication of a document containing personal data (information about identity of the data subject as well as about debts) on a community notice billboard. SPAIN · ·Art. 5 Sep 16, 2020
€8,000 Private Person: Non-compliance with general data processing principles Operation of a CCTV camera that also monitored public space outside the premises of the data controller. GREECE · ·Art. 5 Sep 11, 2020
€2,000 Sanatatea Press Group S.R.L.: Insufficient technical and organisational measures to ensure information security Sending the personal data collected for the registration for an online course to other participants due to a technical failure. ROMANIA · ·Art. 5, 32 Sep 8, 2020
€3,000 Barcelona Airport Security Guard Association ('AVSAB'): Non-compliance with general data processing principles A member of the AVSAB security committee used WhatsApp to send messages to private phone numbers containing personal information about employees. This was a violation of the… SPAIN · ·Art. 5 Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY · ·Art. 5, 32 Sep 3, 2020
€5,000 Basketball Federation of Castilla and Leon: Insufficient legal basis for data processing The Basketball Association transmitted personal data to third parties, which were subsequently published on the Internet without consent of the data subjects. In addition, the… SPAIN · ·Art. 5, 6 Aug 28, 2020
€50,000 Bankia S.A.: Non-compliance with general data processing principles The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this… SPAIN · ·Art. 5 Aug 28, 2020
€5,000 Party of the Socialists of Catalonia: Non-compliance with general data processing principles The Socialist Party of Catalonia has used the personal data provided by a professional doctor to send a letter to the complainant's relative asking for political support. This… SPAIN · ·Art. 5 Aug 17, 2020
€3,000 GROW BEATS SL: Insufficient fulfilment of information obligations The company had published a cookie policy on its website, which on the one hand contained no information about the purpose of the use of cookies and on the other hand no… SPAIN · ·Art. 12, 13, 14 Aug 6, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Installation of CCTV surveillance cameras that were also monitoring the public space and without proper information. SPAIN · ·Art. 5, 12, 13 Aug 5, 2020
€250,000 Spartoo: Non-compliance with general data processing principles A fine of EUR 250000 was imposed on the online retailer Spartoo. The reason for this was that the company, which has its headquarters in France but supplies a large number of… FRANCE · ·Art. 5, 13, 14 Aug 5, 2020
€3,000 Community of San Giorgio Jonico: Insufficient legal basis for data processing Publication of personal data on the municipal website with regard to legal proceedings. ITALY · ·Art. 5, 6 Jul 29, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK · ·Art. 5 Jul 28, 2020
€3,000 Communal political association: Insufficient legal basis for data processing A local political association has sent out election advertisements to the residents of the municipality for the local elections in 2018. For this purpose, the association used the… BELGIUM · ·Art. 5, 6, 14 Jul 28, 2020
€55,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing Telefónica Móviles España has processed the personal data of a data subject, such as first and last name and bank details, in order to activate three telephone lines that were… SPAIN · ·Art. 5, 6 Jul 23, 2020
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The company had carried out the number porting of his telephone line from his current company without his consent. Personal data was transferred from the former telephone operator… SPAIN · ·Art. 5, 6 Jul 23, 2020
€70,000 Xfera Moviles S.A.: Non-compliance with general data processing principles A data subject had received a call from another Xfera Móviles customer who stated that the company had charged his bank account with an invoice, disclosing the personal details of… SPAIN · ·Art. 5 Jul 20, 2020
€24,000 Banco Bilbao Vizcaya Argentaria, SA: Insufficient legal basis for data processing BBVA had no legitimate basis for processing the data of the data subject and had therefore infringed Article 6(1) of the GDPR, since the company processed solvency and credit… SPAIN · ·Art. 5, 6 Jul 20, 2020
€40,000 Iberia Lae SA Operadora Unipersonal: Insufficient cooperation with supervisory authority The company did not grant the data subject access to telephone records. The applicant's request for access did not receive a reply, despite the prior order of the AEPD. SPAIN · ·Art. 58 Jul 20, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide evidence that the data subject had consented to the scanning or copying of their ID card… CZECH REPUBLIC · ·Art. 5, 6, 7 +3 Jul 14, 2020
€600,000 Google Belgium SA: Insufficient fulfilment of data subjects rights The Belgian data protection authority has fined Google Belgium SA, a subsidiary of Google, 600,000 euros. The reasons for the fine were the rejection of an application by a data… ·Art. 5, 6, 12 +1 ·Insufficient fulfilment of data subjects rights Jul 14, 2020
€800,000 Iliad Italia S.p.A.: Non-compliance with general data processing principles The fine relates to data protection infringements concerning the processing of customer data for the activation of SIM cards and the manner in which payment data was recorded. In… ITALY · ·Art. 5, 25 Jul 13, 2020
€55,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The company had changed a contract for a mobile phone connection to a new owner, whereby the personal data of a data subject such as his address and telephone numbers were freely… SPAIN · ·Art. 5, 32 Jul 10, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY · ·Art. 32, 35 Jul 10, 2020
€12,000 Vodafone España, SAU: Non-compliance with general data processing principles Fines for violation of Art. 5 (1) d) GDPR for changing the customer's master data into the name of a third party, the ex-spouse of the customer. SPAIN · ·Art. 5 Jul 10, 2020
€1,500 Auto Desguaces Iglesias S.L.: Non-compliance with general data processing principles The company had installed surveillance cameras that recorded the public road and therefore violated the principle of data minimization. SPAIN · ·Art. 5 Jul 10, 2020
€5,000 School Fitness Holiday & Franchising S.L.: Non-compliance with general data processing principles Breach of transparency principle. No further information available at the moment. SPAIN · ·Art. 5 Jul 10, 2020
€24,000 Iberdrola Clientes: Non-compliance with general data processing principles A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes… SPAIN · ·Art. 5 Jul 2, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Jun 30, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK · ·Art. 5, 6, 33 +1 Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE · ·Art. 5 Jun 29, 2020
€2,000 Comunidad de propietarios demelza beach: Non-compliance with general data processing principles Illegal use of CCTV cameras due to coverage of public space and recording of passing pedestrians. Furthermore, insufficient fulfilment of information obligations. SPAIN · ·Art. 5, 6, 13 +1 Jun 22, 2020
€2,000 Café Bar: Non-compliance with general data processing principles Illegal use of CCTV cameras (recording of third parties) and insufficient fulfilment of information obligations. SPAIN · ·Art. 5, 6, 13 +1 Jun 16, 2020
€1,900 Housing Association: Non-compliance with general data processing principles Unlawful usage of surveillance cameras. In the decision, the data protection authority stressed that sound recordings have additional privacy implications, especially in a… SWEDEN ·Art. 5, 6 ·Non-compliance with general data processing principles Jun 16, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS · ·Art. 33 Jun 16, 2020
€288,000 Digi Távközlési Szolgáltató Kft. ('Digi') (electronic communication service provider): Insufficient technical and organisational measures to ensure information security The company had infringed the principles of purpose limitation and storage restriction because its database contained a large amount of customer data which were no longer relevant… HUNGARY · ·Art. 5, 32 Jun 12, 2020
€1,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN · ·Art. 5 Jun 9, 2020
€2,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN · ·Art. 5 Jun 9, 2020
€5,000 Municipal employee: Insufficient legal basis for data processing In the context of a municipal election in 2018, the data controller had sent election advertisements to a group of employees of the same municipal administration, unlawfully using… BELGIUM · ·Art. 5, 6 Jun 8, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND · ·Art. 5, 6, 35 May 29, 2020
€16,000 Kymen Vesi Oy: Non-compliance with general data processing principles Fine for failure to carry out a data protection impact assessment ('DPIA') for the processing of location data of employees with a vehicle information system FINLAND · ·Art. 35 May 22, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE · ·Art. 5, 6 Apr 7, 2020
€6,000 Amalfi Servicios de Restauracion S.L.: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN · ·Art. 5, 13, 14 Mar 16, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN · ·Art. 5 Mar 16, 2020
€2,000 Homeowners Association: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN · ·Art. 5, 13, 14 Mar 12, 2020
€7,000 Hørsholm Municipality: Insufficient technical and organisational measures to ensure information security A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and… DENMARK · ·Art. 5, 32 Mar 10, 2020
€14,000 Gladsaxe Municipality: Insufficient technical and organisational measures to ensure information security A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city… DENMARK · ·Art. 5, 32 Mar 10, 2020
€20,600 National Center of Addiction Medicine ('SAA'): Insufficient technical and organisational measures to ensure information security Persónuvernd noted that a former employee of the SAA received boxes of allegedly personal belongings that he had left there, but which also contained patient data, including the… ICELAND ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Mar 10, 2020