Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1301–1350 of 2,273 sort newestlargest fineoldest
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Fairness & Transparency Health Data Audit Logs Jul 7, 2022
€1,800 FINCAS ARENYS SL: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on FINCAS ARENYS SL. An individual had filed a complaint with the DPA. The individual had contacted the real estate company in order to rent a… SPAIN ·aepd ·Art. 13 Personal Data Processing Processing Agreement Jul 7, 2022
€2,120 University Hospital of the Medical University of Warsaw: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 2,120 on the University Hospital of the Medical University of Warsaw. The university hospital had suffered a data breach in which a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jul 6, 2022
€56,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Vodafone España, S.A.U. due to insufficient legal basis for data processing. The data subject stated that, unauthorized third parties had… SPAIN ·aepd ·Art. 6 IP Address Controllers Processing Agreement Jul 6, 2022
€12,450 Głównego Geodetę Kraju: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 12,450 on the public cartography institute Głównego Geodetę Kraju. The institute had suffered a data breach in which numerous land… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jul 6, 2022
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jul 5, 2022
€1,400 Company: Non-compliance with general data processing principles The DPA of Luxembourg (CNPD) has imposed a fine of EUR 1,400 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this was… LUXEMBOURG ·CNPD ·Art. 5, 13 Storage Limitation Retention Period Controllers Jun 30, 2022
€5,000 Federazione Italiana Sommelier, Albergatori e Ristoratori: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Federazione Italiana Sommelier, Albergatori e Ristoratori. The federation had sent a protocol containing personal data of a… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Cloud Computing Jun 30, 2022
€2,000 Continental Automotive Romania SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Continental Automotive Romania SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Video Surveillance Security Jun 30, 2022
Persónuvernd (Iceland) - 2020061979 The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Art. 38, 39 Supervisory Authorities Notified Body Responsibilities and Operational Obligations Notified Body Independence Jun 29, 2022
€1,000 Company: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,000 on a company. The company had requested various personal data from customers for appointment bookings. The DPA found that… SPAIN ·aepd ·Art. 13 Personal Data Controllers Processing Agreement Jun 28, 2022
€2,000 Parliamentary election candidate: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 2,000 on a parliamentary election candidate. A data subject had filed a complaint with the DPA because of receiving unsolicited election… GREECE ·HDPA ·Art. 11, 12 Personal Data Direct Marketing Consent Jun 24, 2022
€1M TotalEnergies Electricité et Gaz France: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 1,000,000 on TotalEnergies Electricité et Gaz France. As part of its investigation, the DPA found that the controller had violated its… CNIL ·Art. 14, 15, 21 ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Controllers Jun 23, 2022
€2,000 WIND Ελλάς Τηλεπικοινωνίες ΑΕΒΕ: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined WIND Ελλάς Τηλεπικοινωνίες ΑΕΒΕ EUR 2,000. A customer of the company had sent an email requesting access to the footage recorded by the store's cameras… GREECE ·HDPA ·Art. 15 Personal Data Controllers Telecommunications Jun 20, 2022
€7,000 Asociația de Proprietari Aviației Park: Insufficient legal basis for data processing The Romanian DPA has fined Asociația de Proprietari Aviației Park, operator of a residential facility, EUR 7,000. The controller had processed personal data (surname, first name,… ROMANIA ·ANSPDCP ·Art. 5, 6 Retention Period Storage Limitation Video Surveillance Jun 20, 2022
€1,000 SC Interactions Marketing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on SC Interactions Marketing SRL. The controller had sent advertising messages by e-mail to several people on behalf of another… ROMANIA ·ANSPDCP ·Art. 32 IP Address Controllers Direct Marketing Jun 20, 2022
€2,000 Federazione Italiana Nuoto: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) fined Federazione Italiana Nuoto EUR 2,000 for failing to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Processing Agreement Jun 16, 2022
€20,000 Deutsche Bank S.p.A.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Insurance Personal Data Supervisory Authorities Jun 16, 2022
€70,000 Unicredit S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Unicredit S.p.A. EUR 70,000. An employee had filed a complaint with the DPA claiming that their right to access their personal data had not been… ITALY ·Garante ·Art. 12, 15 Right of Access Right of Access Procedures Personal Data Jun 16, 2022
€3,000 S.C. Wine Point S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on S.C. Wine Point S.R.L.. A data subject had filed a complaint with the DPA for having received an advertising e-mail from the… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Professional Secrecy Security Jun 15, 2022
€26,000 Garante per la protezione dei dati personali (Italy) - 9794895 The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Art. 5, 12, 13 +3 Video Surveillance Monitoring Storage Limitation Jun 9, 2022
Austrian DPA: Court's publication of full divorce settlement in land register violates The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·DSB Controllers Material scope (GDPR) Integrity and Confidentiality Principle Jun 9, 2022
€10,000 Cribis Credit Management s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Cribis Credit Management s.r.l. EUR 10,000. The company had inadvertently sent an e-mail about late payments on a subscription to the head of the data… ITALY ·Garante ·Art. 5, 6 Personal Data Insurance IP Address Jun 9, 2022
€1,500 Wens Experience SRL: Insufficient data processing agreement The Romanian DPA has imposed a fine of EUR 1,500 on Wens Experience SRL. In the course of its investigation, the DPA found that Wens Experience, in the course of acting as a… ROMANIA ·ANSPDCP ·Art. 28 Controllers Processors Processing Agreement Jun 8, 2022
€3,500 Esselmann Technika Pojazdowa Sp. z o.o. Sp. k.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Esselmann Technika Pojazdowa Sp. z o.o. Sp. k. EUR 3,500. The controller had suffered a data breach during which a certificate of employment containing… POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 6, 2022
€360 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 360 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jun 3, 2022
€2,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland România SCS. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. An employee who… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Jun 3, 2022
€3,000 LODEJU, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on the restaurant operator LODEJU, S.L.. The controller had installed video surveillance cameras in its premises which,… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jun 3, 2022
€2,100 Stołeczny Ośrodek dla Osób Nietrzeźwych: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 2,100 on 'Stołeczny Ośrodek dla Osób Nietrzeźwych', a center for people suffering from alcoholism. During its investigation, the DPA found… POLAND ·UODO ·Art. 5, 6 Video Surveillance Healthcare Monitoring May 31, 2022
€2,000 Turkish City: Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Turkish City' EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the… ITALY ·Garante ·Art. 13 Video Surveillance Monitoring Controllers May 26, 2022
€4,000 Università Agraria di Nettuno: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the Università Agraria di Nettuno. A former employee of the university had filed a complaint with the DPA due to the fact that… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Education Processing May 26, 2022
€46,000 Azienda Sanitaria Locale Roma: Insufficient legal basis for data processing The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Healthcare Health Data May 26, 2022
€16,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 16,000 on the Region of Tuscany. The region had published documents on its website containing information on professionals from the… ITALY ·Garante ·Art. 2, 5, 6 Education Public Authority Processing Agreement May 26, 2022
€70,000 Azienda sanitaria universitaria Friuli Centrale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 70,000 on the healthcare facility Azienda sanitaria universitaria Friuli Centrale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare May 26, 2022
€2,000 Store owner: Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Turkish City' EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the… ITALY ·Garante ·Art. 5, 13 Video Surveillance Monitoring Controllers May 26, 2022
€50,000 Azienda sanitaria universitaria Friuli Occidentale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare May 26, 2022
€100,000 Intesa Sanpaolo S.p.A: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 100,000 on Intesa Sanpaolo S.p.A.. The bank had unlawfully disclosed data of the data subject to unauthorized third parties (the father… ITALY ·Garante ·Art. 5, 6 Personal Data Insurance Processing Agreement May 26, 2022
€10,000 Afragola municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on Afragola municipality. A former employee of the municipality had filed a complaint with the DPA because the municipality had… ITALY ·Garante ·Art. 2, 5, 12 Personal Data IP Address Public Authority May 26, 2022
€50,000 Roularta Media Group: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 50,000 on Roularta Media Group. As part of its investigation, the DPA found that the cookie management on two websites operated by… BELGIUM ·APD ·Art. 5, 6, 7 +4 Cookies Personal Data Consent May 25, 2022
€50 APD/GBA (Belgium) - 85/2022 On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Art. 4, 5, 6 +3 Cookies Telecommunications Direct Marketing May 25, 2022
€5,000 MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on MED LIFE S.A.. The company had disposed of documents containing sensitive patient data in a publicly accessible garbage can. An… ROMANIA ·ANSPDCP ·Art. 32 Health Data Healthcare Security May 24, 2022
€42,000 Alquiler Seguro SA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 42,000 on Alquiler Seguro SA. The company had advertised a job for which the data subject had applied. As part of the application… SPAIN ·aepd ·Art. 6 Personal Data Processing Agreement Processing May 24, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual operating three websites EUR 2,000. During its investigation, the DPA found that all three websites lacked a field for giving… SPAIN ·aepd ·Art. 6 Personal Data Controllers Processing May 20, 2022
€5,000 Kredyt Inkaso Investments RO S.A: Insufficient legal basis for data processing The Romanian DPA has fined Kredyt Inkaso Investments RO S.A. EUR 5,000. A data subject had filed a complaint with the DPA against the controller for having disclosed their… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +1 Data Breaches Personal Data Insurance May 18, 2022
€10M Google LLC: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 10 million on GOOGLE LLC. Two data subjects had complained to the DPA that Google had disclosed their personal data to third… SPAIN ·aepd ·Art. 6, 17 Right to be Forgotten Data Subject Rights Exercise Modalities and Procedures Personal Data May 18, 2022
€9M Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +7 Fairness & Transparency Retention Period Privacy Impact Assessment May 18, 2022
€4,000 INSEKT FOOD S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on INSEKT FOOD S.L.. A data subject hat filed a complain with the DPA against the controller due to the fact that the… SPAIN ·aepd ·Art. 6 Integrity and Confidentiality Principle Personal Data Data Breaches May 17, 2022
€8,000 TIGERS MARKET, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 8,000 on TIGERS MARKET, S.L.. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·aepd ·Art. 21, 23, 48 Direct Marketing Personal Data Controllers May 17, 2022
€1,500 MAYR MELNHOF PACKAGING ROMANIA S.R.L.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,500 on MAYR MELNHOF PACKAGING ROMANIA S.R.L.. The controller had installed video surveillance cameras in the premises for the purpose… ANSPDCP ·Art. 5, 6 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address May 17, 2022
HDPA (Greece) - 21/2023 Following a complaint lodged by the applicant against two telecommunications providers for violation of communication security and privacy and his right to the protection of his… 21/2023 Telecommunications Personal Data Supervisory Authorities May 17, 2022