Skip to content
Content type · 1,535 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1301–1350 of 1,535 sort newestlargest fineoldest
€18,000 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA of Luxembourg has imposed a fine of EUR 18,000 on a company. According to the DPA, the controller firstly failed to involve the data protection officer in all matters… CNPD ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Personal Data May 31, 2021
€120,000 Azienda Usl della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Usl della Romagna EUR 120,000. The local health authority of Romagna had accidentally transmitted a patient's report regarding an… ITALY ·Garante ·Art. 5, 9 Healthcare IP Address Processing Agreement May 27, 2021
€900 Managing Director of a company: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on the managing director of a company. A data subject filed a complaint with the AEPD against the controller with whom he… SPAIN ·aepd ·Art. 13 Personal Data Controllers Processing Agreement May 25, 2021
€4,000 Alava Norte, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Alava Norte, S.L. EUR 4,000. The controller had installed three 360° video surveillance cameras on the facade of one of its buildings to secure… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers May 25, 2021
€100,000 Vodafone España, SAU: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Vodafone España, S.A.U.. A data subject had filed a complaint with the Spanish DPA against the telecommunications… SPAIN ·aepd ·Art. 28 Telecommunications Processors Controllers May 25, 2021
€45,000 Telefónica de España, S.A.U: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 75,000 on Telefonica de España, S.A.U.. A data subject had filed a complaint with the AEPD against the telecommunications company.… SPAIN ·aepd ·Art. 6 Controllers Telecommunications Personal Data May 21, 2021
€10,000 Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato: Insufficient legal basis for data processing The Hellenic DPA has fined the Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato EUR 10,000. The controller had… GREECE ·HDPA ·Art. 6, 12, 17 Personal Data Controllers Education May 17, 2021
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Social Media Health Data May 13, 2021
€2.9M Iren Mercato S.p.A.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Iren Mercato S.p.A. EUR 2,856,169 for failing to verify that all transfers of data of recipients of promotional activities were covered by consent.… ITALY ·Garante ·Art. 5, 6, 7 IP Address Processing Agreement Direct Marketing May 13, 2021
€5,000 KARIERA A.E.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 5,000 on ΚARIERA A.E.. A data subject had filed a complaint with the DPA against the controller due to the fact that the controller… GREECE ·HDPA ·Art. 17, 21, 25 Personal Data Controllers Processing Agreement May 12, 2021
€2,400 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,400 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Employees Monitoring May 12, 2021
€1,900 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,900 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance IP Address Accountability May 12, 2021
€3,000 Solram T Y R S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on Solram T Y R S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·aepd ·Art. 17 Personal Data Controllers Processing Agreement May 12, 2021
€1,000 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,000 on a company. The controller had installed a video surveillance system with the purposes of the protection of… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Video Surveillance Accountability IP Address May 12, 2021
€2,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,600 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Video Surveillance Employees IP Address May 12, 2021
€1.5M EDP Comercializadora, S.A.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing… SPAIN ·aepd ·Art. 13, 25 Controllers Personal Data Processing Agreement May 4, 2021
€1.5M EDP Energía, S.A.U: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Energía, S.A.U.. The decision follows, in particular, several complaints received for processing personal data… SPAIN ·aepd ·Art. 13, 25 Controllers Personal Data Processing Agreement May 4, 2021
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement Apr 29, 2021
€5,050 PNP S.A.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Polish DPA (UODO) for investigative purposes. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Apr 27, 2021
€15,000 Anytime Fitness Iberia S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on Anytime Fitness Iberia S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact… SPAIN ·aepd ·Art. 17, 21 Personal Data Controllers Processing Agreement Apr 27, 2021
€3,000 Pagamastarde S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Pagamastarde S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·aepd ·Art. 17, 21 Controllers Personal Data Processing Agreement Apr 27, 2021
€100,000 Financial company: Insufficient technical and organisational measures to ensure information security The Belgian DPA (APD) has imposed a fine of EUR 100,000 on a financial company. A data subject had filed two complaints with the APD against the company. They were based on 20… BELGIUM ·APD ·Art. 5, 32 Personal Data Security Controllers Apr 26, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·aepd ·Art. 5, 6, 14 Integrity and Confidentiality Principle Fairness & Transparency Personal Data Apr 23, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Recipient Security Apr 22, 2021
€1,500 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed a surveillance camera on his property, which recorded, among other… SPAIN ·aepd ·Art. 5 Audit Logs Monitoring IP Address Apr 22, 2021
€15,000 Fondazione Policlinico Tor Vergata di Roma: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Fondazione Policlinico Tor Vergata di Roma. In February 2020, a data subject filed a complaint with Garante alleging… ITALY ·Garante ·Art. 5, 13, 25 +1 Healthcare Personal Data Controllers Apr 21, 2021
€2,800 Website operator: Non-compliance with general data processing principles The Hungarian DPA (NAIH) has imposed a fine of EUR 2,800 on a website operator. The controller had failed to prove the lawfulness of its processing of personal data upon request… HUNGARY ·NAIH ·Art. 5, 24 Accountability Controllers IP Address Apr 20, 2021
€2,000 Società triveneta di chirurgia: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Società triveneta di chirurgia. A physician had shown slides of a clinical case at a congress, which were subsequently… ITALY ·Garante ·Art. 5, 6, 9 Healthcare Personal Data Healthcare Apr 15, 2021
€12,000 Istituto Nazionale Previdenza Sociale (INPS): Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 12,000 on the Italian National Institute for Social Security (Istituto Nazionale della Previdenza Sociale). That fine was based… ITALY ·Garante ·Art. 5, 12, 15 Personal Data Education Public Authority Apr 15, 2021
€3,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller resides on the 1st floor of an apartment building, where he is the owner of… SPAIN ·aepd ·Art. 5, 13 Audit Logs IP Address Controllers Apr 15, 2021
€5,000 S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined S.C. Tip Top Food Industry S.R.L. EUR 5,000. The controller had installed several video cameras in the food areas and changing rooms to… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Video Surveillance Employees IP Address Apr 15, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Personal Data Apr 15, 2021
€5,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on… ITALY ·Garante ·Art. 5, 6, 9 Healthcare Healthcare Personal Data Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·aepd ·Art. 6 Controllers IP Address Processing Agreement Apr 13, 2021
€3,400 Miljø- og Kvalitetsledelse AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 3,400 on Miljø- og Kvalitetsledelse AS. At one of the carwashes operated by the controller, incidents of vandalism had… NORWAY ·Datatilsynet ·Art. 5, 6 Controllers Monitoring Processing Agreement Apr 9, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Apr 8, 2021
€60,000 Kutxabank, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request… SPAIN ·aepd ·Art. 17 Right to be Forgotten Data Subject Rights Exercise Modalities and Procedures Personal Data Apr 8, 2021
€2,400 Promotech Digital S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined Promotech Digital S.L. EUR 2,400 for repeatedly sending the data subject advertising SMS, even though he never subscribed or agreed to receive… SPAIN ·aepd ·Art. 21 Direct Marketing Personal Data Controllers Apr 6, 2021
€3,000 Electrotecnica Bastida S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Electrotecnica Bastida S.L. EUR 3,000. Police officers had found 29 envelopes addressed to the controllers' respective employees on a vacant lot… SPAIN ·aepd ·Art. 32 Security Controllers Privacy by Design & Default Apr 5, 2021
€10,000 Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security The Romania DPA (ANSPDCP) has fined Telekom Romania Mobile Communications S.A. EUR 10,000 for failing to implement adequate security measures to ensure the security of personal… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Security Mar 30, 2021
€30,000 OneDirect Srl: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 30,000 on OneDirect Srl. A data subject had filed two complaints with the DPA after receiving advertisements by e-mail from the… ITALY ·Garante ·Art. 6, 7, 30 +1 Right to Object Controllers Personal Data Mar 25, 2021
€1,425 Operator of a care facility: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,425 on the operator of a care facility. The operator had installed a total of 25 cameras in all rooms of the facility, with… HUNGARY ·NAIH ·Art. 5, 6, 13 Video Surveillance Healthcare Monitoring Mar 25, 2021
€20,000 GEDI News Network Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on GEDI News Network Spa. A data subject filed a complaint with the Italian DPA against the controller regarding an… ITALY ·Garante ·Art. 12 Personal Data Controllers Telecommunications Mar 25, 2021
€7,000 TECNOMEDICAL S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 7,000 on TECNOMEDICAL S.r.l.. A data subject filed a complaint with the DPA after the controller failed to properly respond to… ITALY ·Garante ·Art. 12, 15 Personal Data Health Data Healthcare Mar 25, 2021
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY ·NAIH ·Art. 32, 33, 34 Encryption Integrity and Confidentiality Principle Healthcare Mar 24, 2021
€19,900 Basaren Drift AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 19,900 on Basaren Drift AS. The controller had installed video cameras in its premises which recorded both its employees… NORWAY ·Datatilsynet ·Art. 5, 6, 13 Video Surveillance Controllers Monitoring Mar 21, 2021
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 60,000 on Vodafone Spain. The data subject had been a customer of the controller several years ago. After receiving payment reminders… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Mar 16, 2021
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY ·Datatilsynet ·Art. 24, 32, 35 DPIA Data Breaches Privacy Impact Assessment Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet ·Art. 5, 6, 24 +1 Data Breaches Education Security Mar 15, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data Accuracy IP Address Mar 15, 2021