Skip to content
Content type · 1,282 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1251–1282 of 1,282 sort newestlargest fineoldest
€47,000 ClickQuickNow: Non-compliance with general data processing principles The UODO imposed a fine of EUR 47000 for obstructing the exercise of the right of withdrawal for the processing of personal data. The company has not taken appropriate technical… POLAND ·UODO ·Art. 5 Right to be Forgotten Personal Data IP Address Oct 16, 2019
€2,860 Unknown Company: Non-compliance with general data processing principles An employee was on sick leave when his employer checked his desktop, laptop and emails to ensure that his work-related duties were being covered in his absence. The employer then… HUNGARY ·NAIH ·Art. 5, 6, 13 +2 Monitoring Human Resources Employees Oct 15, 2019
€200,000 Telecommunication Service Provider: Non-compliance with general data processing principles A large number of customers were subject to telemarketing calls, although they had declared an opt-out for this. This was ignored due to technical errors. GREECE ·HDPA ·Art. 5, 25 Telecommunications Direct Marketing IP Address Oct 7, 2019
€200,000 Telecommunication Service Provider: Non-compliance with general data processing principles Inappropriate technical measures resulted in the data of 8,000 customers not being deleted upon request. GREECE ·HDPA ·Art. 21, 25 Telecommunications IP Address Processing Agreement Oct 7, 2019
€10,000 Merchant: Non-compliance with general data processing principles The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's… BELGIUM ·APD ·Art. 5 IP Address Personal Data Right of Access Sep 17, 2019
€511,000 DSK Bank: Insufficient technical and organisational measures to ensure information security Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit… BULGARIA ·KZLD ·Art. 32 Personal Data Insurance Security Aug 28, 2019
€1,715 Government Office Managing the Real Estate Register: Non-compliance with general data processing principles The owners of a real estate complained that the government office posted its decision on the change in the person of the lessee (which concluded a lease agreement with real estate… HUNGARY ·NAIH ·Art. 5, 14 Personal Data Education IP Address Aug 8, 2019
€4,290 Public area maintenance company: Non-compliance with general data processing principles An ex-employee complained that his employer unlawfully monitored his work by its CCTV. The employer argued that CCTV monitoring was necessary to assess, whether the employee… HUNGARY ·NAIH ·Art. 5, 6, 13 Monitoring Video Surveillance Audit Logs Aug 2, 2019
€150,000 PWC Business Solutions: Insufficient legal basis for data processing The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to… GREECE ·HDPA ·Art. 5, 6, 13 +1 Legitimate Interest Fairness & Transparency Controllers Jul 30, 2019
€8,575 Budapest Environs Regional Court: Insufficient legal basis for data processing The chairman of the Budapest Environs Regional Court organised a meeting for court officials, during which he stated that he quit from the Hungarian Association of Judges and… HUNGARY ·NAIH ·Art. 5, 6 Education Processing IP Address Jul 17, 2019
€92,146 Organizer of SZIGET festival and VOLT festival: Insufficient legal basis for data processing The NAIH found that there were inappropriate legal bases is use and that the controller did not comply with the principle of purpose limitation. Also, information on the data… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers IP Address Personal Data May 23, 2019
€286 Directorate of Social and Child Welfare Institutions of the Ferencvaros District of Budapest: Insufficient fulfilment of data breach notification obligations The employee of the Directorate sent by mistake 9 letters to the wrong recipient, which contained personal data of 18 data subjects (including data of children, criminal data and… HUNGARY ·NAIH ·Art. 33 Notification Obligation Data Breaches Recipient May 21, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet ·Art. 32 Security Education Right of Access Apr 29, 2019
€34,375 Hungarian political party: Insufficient fulfilment of data breach notification obligations NAIH imposed a fine of HUF 11,000,000 (EUR 34,375) on an undisclosed Hungarian political party for failing to notify the NAIH and relevant individuals about a data breach, and… HUNGARY ·NAIH ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Apr 5, 2019
€10,000 CZECH REPUBLIC DPA: Non-compliance with general data processing principles Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation') and not only kept… UOOU ·Art. 5 ·Non-compliance with general data processing principles Retention Period Storage Limitation Personal Data Mar 21, 2019
€3,200 Unnamed financial institution: Insufficient fulfilment of data subjects rights The fine was imposed in relation to a data subject's request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting… HUNGARY ·NAIH ·Art. 5, 6, 13 +1 Retention Period Legitimate Interest Personal Data Mar 4, 2019
€170,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in… NORWAY ·Datatilsynet ·Art. 5, 32 Security Education Public Authority Mar 1, 2019
€1,560 Debt collector: Non-compliance with general data processing principles A data subject requested information about and erasure of the data processed, which the debt collector refused stating that it could not identify the subject. For identification… HUNGARY ·NAIH ·Art. 5 Personal Data Fairness & Transparency Controllers Feb 20, 2019
€1,560 Bank: Non-compliance with general data processing principles A bank mistakenly sent SMS messages about a subject's credit card debt to the telephone number of another person. After receiving an incorrect telephone number from the client at… HUNGARY ·NAIH ·Art. 5 Personal Data Insurance IP Address Feb 8, 2019
€2,500 Private person: Insufficient legal basis for data processing The fine was impossed against a private person who sent several e-mails between July and September 2018, in which he used personal e-mail addresses visible to all recipients, from… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Recipient Criminal Data IP Address Feb 5, 2019
€388 Employer: Insufficient legal basis for data processing A former employee of a company requested the deletion of information relating to him/her which was published on the Facebook website of the employer and which was still available… CZECH REPUBLIC ·UOOU ·Art. 6 Social Media IP Address Processing Jan 10, 2019
€2,000 Restaurant: Non-compliance with general data processing principles Video surveillance cameras have been used in violation of principle of data minimisation (monitoring also of customer areas in restaurants). GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring Retention Period Jan 1, 2019
€50,000 Unknown Company: Insufficient fulfilment of data subjects rights The data controller had engaged an external company to carry out the duties of access to data according to Art. 15 GDPR. However, the engaged company conducted the correspondence… GERMANY ·Art. 15, 28 ·Insufficient fulfilment of data subjects rights Controllers Fairness & Transparency IP Address Jan 1, 2019
€48,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The claimant's bank account was charged by the company with two invoices for the services he had contracted, however, displaying personal data of another customer. The initial… SPAIN ·aepd ·Art. 5 Personal Data IP Address Telecommunications Jan 1, 2019
€36,000 VODAFONE ONO, S.A.U.: Non-compliance with general data processing principles The company sent a marketing email to a large number of recipients (clients) without using the blind copy feature. The initial fine of EUR 60.000 was reduced to EUR 36.000. SPAIN ·aepd ·Art. 5 IP Address Direct Marketing Telecommunications Jan 1, 2019
€20,000 Hamburger Verkehrsverbund GmbH (HVV GmbH): Insufficient fulfilment of data breach notification obligations On July 6, 2018, HVV GmbH was informed by a customer about a security gap on the website www.hvv.de, which was caused by an update on February 5, 2018 and concerned the so-called… GERMANY ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2019
€160,000 Taxa 4x35: Non-compliance with general data processing principles The Danish DPA reported the taxi company to the police and recommended a fine (of 1.2M DKK) for non-adherence to the data-minimization principle. While the company deleted the… DENMARK ·Datatilsynet ·Art. 5 Administrative Fines on Union Institutions, Bodies, Offices and Agencies Fines IP Address Jan 1, 2019
€3,600 AMADOR RECREATIVOS, S.L: Non-compliance with general data processing principles Surveillance of the public space by video surveillance cameras against violation of the principles of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period Monitoring Jan 1, 2019
€294,000 GERMANY DPA: Non-compliance with general data processing principles A company was fined EUR 294 000 for 'unnecessarily long' storage and retention of personnel files and for 'excessive' data collection in the personnel selection process, during… Art. 5 ·Non-compliance with general data processing principles Healthcare Health Data IP Address Jan 1, 2019
€9,000 Employer: Non-compliance with general data processing principles Video surveillance cameras have not only been used to protect property, but have also monitored employees (violation of principle of data minimisation). SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring Retention Period Jan 1, 2019
€20,000 Employer: Non-compliance with general data processing principles Video surveillance cameras have not only been used to protect property, but have also monitored employees (violation of principle of data minimisation). SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring Retention Period Jan 1, 2019
€1,800 Kebab restaurant: Insufficient legal basis for data processing CCTV was unlawfully used. Sufficient information about the video surveillance was missing. In addition, the storage period of 14 days was too long and therefore against the… AUSTRIA ·dsb ·Art. 5, 13, 14 Video Surveillance Monitoring IP Address Jan 1, 2018