Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1201–1250 of 3,808 sort newestlargest fineoldest
€900 Private individual: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 900 on a private individual for failing to prove compliance with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 4, 2024
€5,000 ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. The controller, a law firm, published the names and photos of its… SPAIN ·AEPD ·Art. 6 Controllers Insurance Processing Agreement Oct 4, 2024
€91M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 91 million on Meta Platforms Ireland Limited (MPIL). The DPC had initiated an investigation after MPIL reported that user passwords… DPC Encryption Data Breaches Security Sep 27, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·AEPD ·Art. 5 Controllers Security Personal Data Sep 26, 2024
€904,000 Police Service of Northern Ireland: Insufficient technical and organisational measures to ensure information security The ICO fined the Police Service of Northern Ireland £750,000 (EUR 904,000) after accidentally publishing personal data of 9,483 police officers and staff on the internet. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Personal Data Security Education Sep 26, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers Consent Processing Sep 26, 2024
€4,000 CI & DI Food s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA imposed a fine of EUR 4,000 against CI & DI Food s.r.l. for failing to comply with a former employee's request for access to their personal data. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Employees Sep 26, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers Consent Processing Sep 26, 2024
€1,400 Attorney: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 1,400 on an attorney. An individual had filed a complaint with the DPA because the controller did not adequately respond to their… GREECE ·HDPA ·Art. 12, 31 Personal Data Controllers Supervisory Authorities Sep 23, 2024
€2,000 PPC ENERGIE MUNTENIA S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on PPC ENERGIE MUNTENIA S.A. for failing to respond to a data subject's request for the deletion of their personal data in a… ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Supervisory Authorities Supervision Sep 23, 2024
€600 SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L. €600 on 2024-09-23 for: Insufficient cooperation with supervisory authority. Spain ·AEPD ·Art. 58 Supervisory Authorities Supervision Sep 23, 2024
€3,000 Constanța South Container Terminal SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Constanța South Container Terminal SRL. The controller had suffered a data breach in which personal data of employees had been… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 17, 2024
€1,000 SC Class IT Outsourcing SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on SC Class IT Outsourcing SRL for failing to respond to a data subject's request for the deletion of their personal data in a… ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Supervisory Authorities Supervision Sep 16, 2024
€3,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on Vodafone România SA for failing to respond to a data subject's request for access and deletion of their personal data in a… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Supervisory Authorities Supervision Sep 16, 2024
€35,700 Company: €35,700 fine The Croatian DPA (AZOP) has imposed fines totaling EUR 35,700 on nine companies for failing to adequately indicate their video surveillance areas and for failing to provide all… CROATIA ·AZOP ·Unknown Fines Video Surveillance Monitoring Sep 13, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·AZOP ·Art. 5, 6, 12 +4 Data Breaches Storage Limitation Retention Period Sep 13, 2024
€45,000 Croatian DPA fines two hotels €45,000 for unlawful cookie processing The Croatian DPA (AZOP) has imposed a fine of EUR 45,000 on two hotels for unlawfully processing personal data through the use of cookies. CROATIA ·AZOP ·Unknown Supervisory Authorities Cookies Personal Data Sep 13, 2024
€842,062 Sky Italia S.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Sky Italia EUR 842,062 for unlawful telemarketing. The investigation revealed that Sky contacted individuals without proper consent, including those… ITALY ·Garante ·Art. 5, 6, 130 Consent Processing Direct Marketing Sep 12, 2024
€5,000 Top Quality Corporation s.r.l.s.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Top Quality Corporation s.r.l.s. A data subject (former emplyee) had filed a complaint with the DPA due to the controller's… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Sep 12, 2024
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE ·CNIL ·Art. 5, 66 Identification Supervisory Authorities Processing Sep 12, 2024
€400 Private individual: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 400 on a private individual. The individual had installed video surveillance cameras, which however also recorded parts of neighboring… ITALY ·Garante ·Art. 5, 6 Processing Video Surveillance Monitoring Sep 12, 2024
€600 KVIKU SPAIN, S.L: Insufficient cooperation with supervisory authority The Spanish DPA has fined KVIKU SPAIN, S.L. EUR 600 for failing to provide information requested by the DPA. AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Sep 11, 2024
€25,000 Belgian DPA finds MediaHuis violated GDPR fairness over cookie banner design A data subject visited four website operated by MediaHuis, namely: Gazet van Antwerpen; De Standaard; Het Nieuwsblad; Het Belang van Limburg. On each website there was a cookie… Belgium ·APD/GBA ·Art. 5, 6, 7 Supervisory Authorities Direct Marketing Legitimate Interest Sep 6, 2024
€20,900 Eidskog municipality: Insufficient legal basis for data processing The Norwegian DPA imposed a fine of EUR 20,900 on Eidskog municipality for giving two former employees access to a whistleblower’s report without redacting sensitive health and… NORWAY ·Datatilsynet (NO) ·Art. 6 Public Authority Supervisory Authorities Healthcare Sep 6, 2024
€3,000 PLAY FUL KIDS, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 3,000 on PLAY FUL KIDS, S.L. due to an incident that occurred during a children's birthday party on the premises of the controller involving… SPAIN ·AEPD ·Art. 6 Controllers Processing Agreement Minors Sep 5, 2024
€3,000 Senira Limited: Insufficient cooperation with supervisory authority The Cypriot DPA fined Senira Limited EUR 3,000 for failing to sufficiently cooperate with the DPA. CYPRUS ·Cyprus DPA ·Art. 31 Supervisory Authorities Supervision Processing Agreement Sep 4, 2024
€12,700 University of Agder: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the University of Agder (UiA) EUR 12,700. An employee of UiA had discovered that documents containing personal data of employees, students and external… NORWAY ·Datatilsynet (NO) ·Art. 24, 32 Security Personal Data Education Sep 4, 2024
€19,800 National Prosecutor's Office: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 19,800 on the National Prosecutor's Office. During a press conference, the public prosecutor's office disclosed an individual's personal… POLAND ·UODO ·Art. 6, 9, 33 +1 Data Breaches Personal Data Types of Special Categories of Personal Data Sep 2, 2024
€4,500 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA has fined a data controller EUR 4,500 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Aug 30, 2024
€698,000 Apohem AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 698,000 on Apohem AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused personal data… SWEDEN ·IMY ·Art. 32 Security Controllers Personal Data Aug 29, 2024
€3.2M Apoteket AB.: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 3.2 million on Apoteket AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused… SWEDEN ·IMY ·Art. 32 Security Controllers Personal Data Aug 29, 2024
€50,000 SANTANDER CONSUMER FINANCE, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 50,000 on SANTANDER CONSUMER FINANCE, S.A.. The fine followed a complaint from an individual who received advertising from the company,… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Direct Marketing Aug 22, 2024
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Notification Obligation Data Breaches Personal Data Aug 20, 2024
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 20, 2024
€1.5M The Austrian DPA has imposed a fine of EUR 1,500,000 on a company, that is part of a group The controller installed video surveillance devices that did not comply with the GDPR, resulting in the company being fined. Company: €1,500,000 fine ·AUSTRIA ·DSB Monitoring Video Surveillance Controllers Aug 16, 2024
€1.5M IKEA: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 1,500,000 on IKEA. The controller used excessive video surveillance, including in public spaces and the checkout area. Additionally, the… AUSTRIA ·DSB ·Art. 5, 6 Controllers Processing Video Surveillance Aug 16, 2024
€26,800 Municipality of Vejen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 26,800 on the municipality of Vejen. The municipality had suffered a security incident involving the theft of three unencrypted computers… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Public Authority Encryption Education Aug 14, 2024
€270,000 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA. An individual who provided services to the controller filed a complaint with the DPA due to the fact… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Aug 12, 2024
€10,000 LOCAL VERTICALS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has fined LOCAL VERTICALS, S.L. EUR 10,000. An individual filed a complaint with the DPA because they could not access the privacy policy during the registration… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Aug 6, 2024
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual for installing video surveillance cameras without a valid legal basis. SPAIN ·AEPD ·Art. 6 Video Surveillance Monitoring Processing Agreement Aug 6, 2024
€1,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual EUR 1,000. The controller had uploaded images from their video surveillance camera to Instagram showing, amongst others, a minor and… SPAIN ·AEPD ·Art. 6 Controllers Social Media Video Surveillance Aug 6, 2024
€1,000 BEST ELAN ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has fined BEST ELAN ONLINE SRL EUR 1,000 for failing to provide information requested by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Aug 6, 2024
€6,900 Municipality of Korou: Insufficient involvement of data protection officer The French DPA has imposed a fine of EUR 6,900 on the municipality of Korou for failing to appoint a data protection officer. FRANCE ·CNIL ·Art. 31, 37 Public Authority Supervisory Authorities Jul 22, 2024
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… AP Personal Data Privacy Shield International Transfer Jul 22, 2024
€600 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on a private individual. The individual had shared personal data of a data subject in a Facebook group without their consent. The original fine… SPAIN ·AEPD ·Art. 6 Personal Data Consent Social Media Jul 18, 2024
€200,000 Vodafone España, S.A.U.: Insufficient cooperation with supervisory authority The Spanish DPA has fined Vodafone España, S.A.U. EUR 200,000 for failing to provide information requested by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Telecommunications Jul 18, 2024
€80,000 Selectra S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access… ITALY ·Garante ·Art. 5, 13, 88 +1 Storage Limitation Retention Period Controllers Jul 17, 2024
€600 DIGIMAN ALICANTE S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on DIGIMAN ALICANTE S.L.. The data controller had installed a video surveillance system without adequately providing information for data… SPAIN ·AEPD ·Art. 13 Controllers Personal Data Supervisory Authorities Jul 17, 2024
€5M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5 million on Hera Comm S.p.A. The investigation was launched following numerous complaints. The energy supplier had failed to take… ITALY ·Garante ·Art. 5, 12, 15 +3 Controllers Personal Data Supervisory Authorities Jul 17, 2024
€30,000 Pere Sihtkapital SA: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 30,000 on Pere Sihtkapital SA. The controller conducted a survey on childless families. In the process, the controller failed to take all… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Jul 15, 2024