Skip to content
Content type · 3,594 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1201–1250 of 3,594 sort newestlargest fineoldest
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… AEPD ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data May 7, 2024
€480 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a homeowners' association. The controller had sent an email to all owners containing a list of the owners' individual monthly heating… SPAIN ·AEPD ·Art. 5 Controllers Processing Supervisory Authorities May 7, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS ·AP ·Art. 5 Personal Data Controllers Processing May 2, 2024
€210 Association: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an association EUR 210 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 30, 2024
€8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers IP Address Apr 30, 2024
€1,200 DELPASO CAR HIRE, S.L.U.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on DELPASO CAR HIRE, S.L.U.. A data subject had filed a complaint against the controller with the DPA due to the controller's failure to… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Apr 30, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Encryption Security Privacy by Design & Default Apr 29, 2024
€10,000 ASSOCIACIO OASIS CULTURAL: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ASSOCIACIO OASIS CULTURAL. A discotheque operated by the controller had published videos of dancing minors on a social media… SPAIN ·AEPD ·Art. 6 Controllers Social Media Minors Apr 26, 2024
€16,000 Association: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 16,000 on an association for processing personal data without a sufficient legal basis. FRANCE ·CNIL ·Art. 6 Personal Data Supervisory Authorities Processing Apr 25, 2024
€3,000 I.N.P.A.S.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on I.N.P.A.S. (Istituto Nazionale di Previdenza e di Assistenza Sociale). During its investigation, the DPA found that a former… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Processing Public Authority Apr 24, 2024
€30,000 Gestore Dei Servizi Energetici - Gse S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA imposed a fine of EUR 30,000 against Gestore Dei Servizi Energetici - Gse S.p.A. for failing to comply with a former employee's request for access to their… ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Employees Apr 24, 2024
€10,000 C.I.E.L. S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on C.I.E.L. S.p.A.. An employee working for the controller filed a complaint with the DPA due to the controller's failure to grant… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Apr 24, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Apr 24, 2024
€30,000 Rossi Carta S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 30,000 on Rossi Carta S.r.l.. An individual had filed a complaint with the DPA after repeatedly receiving unsolicited advertising emails… ITALY ·Garante ·Art. 6, 7, 12 +1 Personal Data Controllers Supervisory Authorities Apr 24, 2024
€5,000 Dly S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Dly S.r.l.. The company had installed video surveillance systems in its premises, however, their specific use was not authorized. ITALY ·Garante ·Art. 5, 88, 114 Monitoring Processing Video Surveillance Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Apr 23, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·AZOP ·Art. 6, 7, 13 Fairness & Transparency Controllers Consent Apr 22, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·AZOP ·Art. 6, 7, 13 Consent Fairness & Transparency Controllers Apr 22, 2024
CROATIA DPA: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed seven fines totaling EUR 16,000 on data controllers for failing to adequately mark video-monitored areas. This lack of marking resulted in… AZOP ·Art. 13, 27 ·Insufficient fulfilment of information obligations Supervisory Authorities Controllers Processing Apr 22, 2024
€2,000 S.C. Tensa Art Design S.A..: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on S.C. Tensa Art Design S.A.. The controller had processed the personal data of a data subject for marketing purposes without the… ROMANIA ·ANSPDCP ·Art. 6 Personal Data Consent Controllers Apr 22, 2024
€1,000 CONSULTORÍA PERITACIONES ALMERIENSES, S.L: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on CONSULTORÍA PERITACIONES ALMERIENSES, S.L for failing to comply with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Insurance Apr 19, 2024
€400 Private individual: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 400 on a private individual for failing to prove compliance with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Apr 15, 2024
€14M Avast Software s.r.o.: €13,900,000 fine The Czech DPA has fined Avast Software s.r.o. EUR 13.9 million. The company had disclosed the personal data of around 100 million users of its antivirus software to the US company… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Unknown Personal Data Anonymization Pseudonymization Apr 15, 2024
€600 Website operator: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 600 on a website operator for failing to ensure that the privacy policy on a website complied with the requirements of Art. 13 GDPR. SPAIN ·AEPD ·Art. 13 Supervisory Authorities Apr 12, 2024
€1,000 DELSA ALQUILERES S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on DELSA ALQUILERES S.L.. The controller had installed video surveillance cameras in a residential complex which, among other… SPAIN ·AEPD ·Art. 6, 13 Controllers Supervisory Authorities Video Surveillance Apr 12, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which, among other things, also recorded public… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Apr 12, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·AEPD ·Art. 6 Consent Personal Data Security Apr 12, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Insurance Apr 12, 2024
€6,000 Libero Consorzio comunale di Enna: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 6,000 on Libero Consorzio comunale di Enna for failing to appoint a data protection officer ITALY ·Garante ·Art. 37, 38 Supervisory Authorities Public Authority Apr 11, 2024
€20,000 Istituto Nazionale di Previdenza Sociale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Italian National Institute of Social Security (INPS). The controller had published personal data of participants in a… ITALY ·Garante ·Art. 2, 5, 6 Controllers Personal Data Processing Apr 11, 2024
€1,000 Store owner: Insufficient fulfilment of information obligations The Italian DPA has fined a store owner EUR 1,000. The controller had installed video surveillance cameras in its premises without properly informing data subjects about the… ITALY ·Garante ·Art. 5, 13 Personal Data Controllers Processing Apr 11, 2024
€25,000 Innova Camara: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 25,000 on Innova Camara. The controller had suffered a cyber attack in which databases were accessed and malicious files (backdoors) were… ITALY ·Garante ·Art. 5 Security Controllers Personal Data Apr 11, 2024
€100,000 Facile.Energy S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Facile.Energy S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Personal Data Apr 11, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Processing Apr 11, 2024
€112,000 VODAFONE ESPAÑA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on VODAFONE ESPAÑA, S.A.U.. A person had lodged a complaint with the DPA because they had received their telephone bill which, however, had been… SPAIN ·AEPD ·Art. 5 Processing Telecommunications Supervisory Authorities Apr 5, 2024
€525,000 HUBSIDE.STORE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 525,000 on HUBSIDE.STORE. The company had used data from data brokers for commercial acquisition campaigns without ensuring that the data… FRANCE ·CNIL ·Art. 6, 14 Consent Personal Data Supervisory Authorities Apr 4, 2024
€175,000 Greek Ministry of Immigration and Asylum: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 175,000 on the Greek Ministry of Immigration and Asylum. The DPA found that the controller had failed to properly carry out a required… GREECE ·HDPA ·Art. 25, 31, 35 DPIA Controllers Security Apr 2, 2024
€27,000 20 MINUTOS EDITORA, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine 20 MINUTOS EDITORA, S.L. for failing to prove compliance with an order issued by the DPA. The original fine of EUR 45,000 was reduced to EUR… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Telecommunications Mar 25, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 25, 2024
€10,000 Stjörnuna ehf: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 10,000 on Stjörnuna ehf. (the operator of a Subway branch). An employee had filed a complaint with the DPA regarding video surveillance… ICELAND ·Persónuvernd ·Art. 5, 6, 12 +1 Controllers Supervisory Authorities Processing Mar 24, 2024
€10,000 Azienda sanitaria locale Roma 3: Insufficient fulfilment of data breach notification obligations The Italian DPA has fined Azienda sanitaria locale Roma 3 EUR 10,000 for failing to report a data breach to the DPA in a timely manner and to properly document the data breach. ITALY ·Garante ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 21, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Mar 21, 2024
€500 JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT. The controller had installed a video surveillance system without… SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Controllers Mar 21, 2024
€1,000 CLÍNICA PARÍS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on CLÍNICA PARÍS, S.L for failing to prove compliance with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Healthcare Mar 20, 2024
€500 CORPORACIÓN DUAL GRUPO LC, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined CORPORACIÓN DUAL GRUPO LC, S.L. EUR 500 for failing to provide information requested by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Mar 15, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Mar 15, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A data subject had filed a complaint against the data controller as unauthorized fraudsters… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Mar 15, 2024
€326,000 Santander Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 326,000 for failing to report a data breach to the DPA and data subjects in a timely manner. POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€18,000 Toyota Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Toyota Bank Polska S.A. EUR 18,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€20,000 Banca di Credito Cooperativo Appulo Lucana soc. cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Banca di Credito Cooperativo Appulo Lucana soc. cooperativa. A former employee had requested access to the personal data in… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Mar 7, 2024