Skip to content
Content type · 2,403 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1301–1350 of 2,403 sort newestlargest fineoldest
€1,000 SC Das Sense Society SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Das Sense Society SRL EUR 1,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Nov 9, 2022
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide access to information about the purpose of the processing, the storage period, the… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Controllers Supervisory Authorities Nov 9, 2022
€5,000 SC Prestige Media PHG SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on SC Prestige Media PHG SRL. The controller had published 23 documents containing information on the termination of employment… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Personal Data Processing Nov 8, 2022
€2,000 Romanian Post: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on the Romanian Post. The Post suffered a data breach where staff lost several mailings containing pension statements, employment… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Data Breaches Nov 7, 2022
€70,000 UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC (UPS). A person had filed a complaint with the DPA because UPS had delivered a… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Nov 3, 2022
€75,000 Burwebs S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Burwebs S.L. EUR 75,000. Burwebs operates websites with adult content. During its investigation, the DPA found that Burwebs did not process users' data… SPAIN ·AEPD ·Art. 5, 12, 13 +3 Accountability Personal Data Processing Nov 3, 2022
€180,000 Setúbal municipality: Non-compliance with general data processing principles The Portuguese DPA has imposed a fine of EUR 170,000 on Setúbal municipality. The DPA found data protection violations regarding the collection of personal data from Ukrainian… PORTUGAL ·CNPD (PT) ·Art. 5, 13, 37 Public Authority Storage Limitation Retention Period Nov 2, 2022
€1,700 Mayor: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1,700 on the mayor of Dobrzyniewo Duże municipality. The mayor had reported a data breach to the DPA pursuant to Art. 33 GDPR. An… POLAND ·UODO ·Art. 5, 25, 32 Data Breaches Privacy by Design & Default Security Nov 2, 2022
€2,000 Rapido Finance, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on Rapido Finance, S.L.. The data subject had received a message from a company on behalf of Rapid Finance requesting payment of… SPAIN ·AEPD ·Art. 6 Personal Data Insurance Supervisory Authorities Nov 2, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD (PT) ·Art. 5, 9, 12 +5 Privacy Shield Controllers Processors Nov 2, 2022
€25,000 CAIXABANK S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 25,000 on CAIXABANK S.A.. The data subject had repeatedly and unsuccessfully requested that their address on file with the bank be… SPAIN ·AEPD ·Art. 16 Personal Data Supervisory Authorities Insurance Nov 2, 2022
€5,000 CÍTRICOS TANTA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 5,000 on CÍTRICOS TANTA, S.L.. The controller had entered personal data of an employee in the Social Security General Employee Register… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Security Nov 2, 2022
€70,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A customer of the bank had filed a complaint with the DPA. The customer had in the past,… SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Processing Oct 31, 2022
€525,000 TECHPUMP SOLUTIONS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Techpump Solutions S.L. EUR 525,000. Techpump operates several websites with adult content. The DPA found several violations of data protection law… SPAIN ·AEPD ·Art. 5, 6, 8 +5 Storage Limitation Retention Period Personal Data Oct 31, 2022
€56,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA for having unsuccessfully requested a copy of their phone contract from… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Oct 31, 2022
DKK 500,000 Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Denmark ·Datatilsynet (DK) ·Art. 5, 9, 24 +2 Integrity and Confidentiality Principle Supervisory Authorities Encryption
€6,400 AIO E-COMMERCE, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on AIO E-COMMERCE, S.L.. The controller had suffered a data breach resulting in personal data such as bank details being siphoned off and… SPAIN ·AEPD ·Art. 5 Retention Period Security Controllers Oct 26, 2022
€10,000 ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP. The law firm had collected personal data from website users without obtaining their… SPAIN ·AEPD ·Art. 6, 13 Personal Data Controllers Consent Oct 26, 2022
€8,000 ADSL HOUSE, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 8,000 on ADSL HOUSE, S.L.. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·AEPD ·Art. 21, 23, 48 Direct Marketing Personal Data Controllers Oct 24, 2022
€10,000 Italian Archery Federation (FITARCO): Insufficient legal basis for data processing The Italian DPA (Garante) has fined the Italian Archery Federation (FITARCO) EUR 10,000. A member of the federation had filed a complaint with the DPA due to the fact that the… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Processing Supervisory Authorities Oct 20, 2022
€12,000 Comune di Salento: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on Comune di Salento. An individual had lodged a complaint with the DPA for being recorded by a CCTV camera, which proved that he… ITALY ·Garante ·Art. 5, 6, 12 +3 Personal Data Processing Supervisory Authorities Oct 20, 2022
€900 Istituto di Istruzione Superiore G. Renda di Polistena, Reggio Calabria: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 900 on the educational institution 'Istituto di Istruzione Superiore G. Renda di Polistena, Reggio Calabria'. A former employee of the… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Oct 20, 2022
€9,000 Azienda Ospedaliero-Universitaria Careggi di Firenze: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 9,000 on Azienda Ospedaliero-Universitaria Careggi di Firenze. The controller had mistakenly sent a patient medical record to the wrong… ITALY ·Garante ·Art. 5, 9, 32 Security Controllers Personal Data Oct 20, 2022
€1.4M Douglas Italia S.p.a.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1.4 million on Douglas Italia S.p.a. for various GDPR violations. In the course of its investigation, the DPA initially found that… ITALY ·Garante ·Art. 5, 6, 7 +4 Personal Data Accountability Consent Oct 20, 2022
€5M Interserve Group Limited: Insufficient technical and organisational measures to ensure information security The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Interserve… UNITED KINGDOM ·ICO ·Art. 5, 32 Data Breaches Security Controllers Oct 19, 2022
€5,000 RESTEXPERIENCE, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined RESTEXPERIENCE, S.L. EUR 5,000. The controller had accidentally sent an email containing tax information of 36 individuals to 11 unauthorized… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Controllers Oct 19, 2022
€2,000 SC Materiale Constructii Online SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Materiale Constructii Online SRL EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Oct 18, 2022
€150 Private individual: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 150 on a private individual. The individual had made unauthorized use of another person's personal data without their consent. ROMANIA ·ANSPDCP ·Art. 6 Consent Personal Data Processing Oct 18, 2022
€35,000 OES GLOBAL ENERGY S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 35,000 on OES GLOBAL ENERGY S.L.. A customer of the controller had filed a complaint with the DPA after receiving an e-mail from the… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Controllers Security Oct 17, 2022
€20M Clearview Al Inc.: Insufficient fulfilment of data subjects rights The French DPA has fined Clearview Al Inc. EUR 20,000,000. The company holds a database of more than 20 billion facial images (including those of french residents and nationals)… FRANCE ·CNIL ·Art. 6, 12, 15 +2 Personal Data Types of Special Categories of Personal Data Supervisory Authorities Oct 17, 2022
€12,000 SEAN SERIOS S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 12,000 on SEAN SERIOS S.L. The controller had published the results of a selection procedure on a website. This included, among other… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Education Oct 14, 2022
€24,000 CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A data subject filed a complaint with the DPA. The data subject had taken… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Oct 9, 2022
€900 Private individual: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on a private individual. The individual unauthorizedly sent e-mails with personal data to several recipients in an open distribution list. This… SPAIN ·AEPD ·Art. 5, 32 Security Personal Data Supervisory Authorities Oct 9, 2022
€64,000 EVERIS SPAIN S.L: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of… AEPD ·Art. 5, 32 ·Non-compliance with general data processing principles Integrity and Confidentiality Principle Security Personal Data Oct 9, 2022
€10,000 Poste Italiane S.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) fined Poste Italiane S.p.a. EUR 10,000 for failing to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12 Personal Data Supervisory Authorities Oct 6, 2022
€10,000 Codess Sociale, Soc. Coop. sociale.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Codess Sociale, Soc. Coop. sociale. A former voluntary member had filed a complaint with the DPA. The data subject states that… ITALY ·Garante ·Art. 12, 17 Personal Data Controllers Supervisory Authorities Oct 6, 2022
€3,000 Associazione Rescue Drones Network ODV: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 3,000 on Associazione Rescue Drones Network ODV. A founding member of the association had filed a complaint with the DPA. The member… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Oct 6, 2022
€2M Alpha Exploration: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2 million on Alpha Exploration. Alpha Exploration operates the social network Clubhouse. In the course of its investigation, the DPA… ITALY ·Garante ·Art. 5, 6, 7 +7 Storage Limitation Retention Period DPIA Oct 6, 2022
€15,000 Servizio Idrico Integrato S.c.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Servizio Idrico Integrato S.c.p.a. EUR 15,000. The controller had operated a website where personal data was being processed without using an SSL form.… ITALY ·Garante ·Art. 5, 32 Security Controllers Personal Data Oct 6, 2022
€1.5M Easylife Ltd.: Insufficient legal basis for data processing The UK DPA has imposed a fine of EUR 1,547,000 on Easylife Ltd. Easylife is a retailer that sells household items as well as services and products under its health, motor,… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +1 Personal Data Healthcare Types of Special Categories of Personal Data Oct 4, 2022
€6,000 Club Náutico el Estacio: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on Club Náutico el Estacio. A data subject filed a complaint against the controller with the AEPD. The complaint is based on… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Security Oct 4, 2022
€150 Website operator: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 150 on a website operator. The controller had published unauthorized personal data such as telephone number, ID number and series,… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Oct 3, 2022
€900 LfD (Lower Saxony) - Fine EUR 900,000 against bank A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to… Germany ·Art. 6 Legitimate Interest Lawful Basis Personal Data
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·Datatilsynet (DK) DPIA Controllers Prior Consultation
Danish DPA reprimands Region Syddanmark for inadequate processor audit procedures The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Denmark ·Datatilsynet (DK) Processors Controllers Supervisory Authorities
€180 Y OTRO MAS C.B.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on Y OTRO MAS C.B.. The controller had installed a video surveillance system in a residential complex. During its investigation, the DPA found… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Sep 28, 2022
€26,700 TV2 Média Csoport Zrt.: Non-compliance with general data processing principles The Hungarian DPA has fined TV2 Média Csoport Zrt. EUR 26,700. In the course of its investigation, the DPA found that the controller had operated two websites without providing… HUNGARY ·NAIH ·Art. 5, 6, 12 +1 Personal Data Consent Controllers Sep 26, 2022
€1,200 Health insurance provider: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This… HUNGARY ·NAIH ·Art. 5, 12, 31 Personal Data Insurance Supervisory Authorities Sep 25, 2022
€3,000 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Sep 23, 2022
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022