Skip to content
Content type · 1,535 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1401–1450 of 1,535 sort newestlargest fineoldest
Medical clinic: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on a medical clinic. The clinic had installed 21 cameras in its premises for the purpose of protection against crime and property damage.… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Healthcare Monitoring Jan 1, 2021
Private individual: Non-compliance with general data processing principles The Austrian DPA has fined a private individual. The individual had installed a video surveillance system which, among other things, also recorded the public space and stored the… AUSTRIA ·dsb ·Art. 5 Video Surveillance Monitoring IP Address Jan 1, 2021
€1,800 Police officer: Insufficient legal basis for data processing A police officer repeatedly had accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
Company: Data Protection Authority of Brandenburg The DPA of Brandenburg has imposed a fine on a company. An individual had filed a complaint with the DPA based on the fact that the company produced a video recording in which the… GERMANY ·Unknown Supervisory Authorities Processing Agreement Law Enforcement Jan 1, 2021
€400 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes. The officer had purchased a notebook for private use on an Internet platform. Since the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Scientific Research Processing Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully accessed data in a police database. For this reason, the DPA of Brandenburg imposed a fine for a violation of § 32 (1) BbgDSG. The Brandenburg Data… GERMANY ·Insufficient legal basis for data processing Public Authority Processing Agreement Education Jan 1, 2021
GERMANY DPA: Insufficient technical and organisational measures to ensure information security The camera images of a store were distributed without the knowledge and intention of the controller due to a faulty configuration. The distribution involved recordings of… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processing Agreement Jan 1, 2021
€50,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 50,000 on a company for several violations of the GDPR. The controller is a company that carries out parking ticket controls. The… APD ·Art. 5, 12, 14 +2 ·Insufficient fulfilment of data subjects rights Personal Data IP Address Controllers Dec 23, 2020
€15,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 15,000 on a company due to insufficient fulfilment of data subject rights. The controller is a debt collection agency which was… APD ·Art. 5, 6, 12 +2 ·Insufficient fulfilment of data subjects rights Personal Data Data Subject Rights Exercise Modalities and Procedures Controllers Dec 23, 2020
€6,000 Iberdrola Clientes, SAU: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) fined Iberdrola Clientes, SAU EUR 6,000. The data subject had received promotional calls from two different telephone numbers of the controller although the… SPAIN ·aepd ·Art. 21, 23, 48 Personal Data Controllers Direct Marketing Dec 22, 2020
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives IP Address Telecommunications Dec 20, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data IP Address Dec 17, 2020
€6,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well… FRANCE ·CNIL ·Art. 32, 33 Healthcare Healthcare Security Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Personal Data Public Authority Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Garante ·Art. 12 Education Personal Data Controllers Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Health Data Healthcare Dec 17, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 17, 2020
€55,400 Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) imposed a fine of HUF 20,500,000 (EUR 55,400) on Robinson Tours Idegenforgalmi és Szolgáltató Kft. (Robinson Tours Ltd.) The travel agent's reservation… HUNGARY ·NAIH ·Art. 25, 32, 34 Data Breaches Security Processing Agreement Dec 16, 2020
€1,940 HUNGARY DPA: Insufficient fulfilment of information obligations The Hungarian DPA (NAIH) imposed a fine of HUF 700,000 (EUR 1,940) against a construction company. The controller had installed a video surveillance system at a construction site… NAIH ·Art. 5, 13 ·Insufficient fulfilment of information obligations Video Surveillance Monitoring Controllers Dec 16, 2020
€450,000 Twitter International Company: Insufficient fulfilment of data breach notification obligations The Irish DPA (DPC) fined Twitter International Company EUR 450,000 for violating Art. 33 (1) GDPR and Art. 33 (5) GDPR for failing to notify the DPA in a timely manner of a data… IRELAND ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Social Media Dec 15, 2020
€29,500 Uppsalahem AB: Insufficient legal basis for data processing The Swedish DPA (Integritetsskyddsmyndigheten) fined the housing company Uppsalahem AB SEK 300,000 (EUR 29,500). The housing company had installed surveillance cameras in an… SWEDEN ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Legitimate Interest Monitoring Dec 15, 2020
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Right of Access Right of Access Procedures Supervisory Authorities Dec 11, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Healthcare Dec 11, 2020
€2,850 Smart Cities Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the Polish DPA (UODO). The controller failed to provide personal data and other information requested by UODO for investigative… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Dec 9, 2020
€3,000 Comercio Online Levante, S.L.: Insufficient technical and organisational measures to ensure information security A woman filed a complaint with the Spanish DPA (AEPD) against Comercio Online Levante, S.L. due to the fact that she was shown the personal data of another user when trying to… SPAIN ·aepd ·Art. 5, 32 Controllers Personal Data Security Dec 2, 2020
€6,000 Servicio de Alojamientos Responsables, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine in the amount of EUR 6,000 against the controller for unauthorized conclusion of a contract in the name of the data subject without his/her… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Dec 2, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of Eur 2,000 on a legal person. The accused failed to comply with the request to erase the auction notice with the personal data and failed to… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Processing Agreement Supervisory Authorities Nov 30, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Garante ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Integrity and Confidentiality Principle Nov 26, 2020
€3,000 Charly Mike s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Charly Mike s.r.l.. The controller is the hotel operator of the Hotel Olimpo in Alberobello. Garante received a complaint… ITALY ·Garante ·Art. 5, 13 Video Surveillance Monitoring Controllers Nov 26, 2020
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·aepd ·Art. 6, 13, 14 Recipient IP Address Personal Data Nov 25, 2020
€1,500 Private Individual: Insufficient legal basis for data processing The Belgian DPA (APD) imposed a fine against private individuals. The controllers installed video cameras on their private property, two of which were positioned in a way that… BELGIUM ·APD ·Art. 6, 25 Controllers Processing Processing Agreement Nov 25, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Privacy by Design & Default Personal Data Nov 24, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Telecommunications Processing Agreement Nov 23, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Right of Access Procedures Healthcare Nov 19, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY ·Garante ·Art. 5, 6, 7 +7 IP Address Telecommunications Security Nov 12, 2020
€20,000 Xfera Moviles S.A.: Insufficient legal basis for data processing Xfera Móviles had failed to cooperate with the AEPD in the investigation of privacy violations. Xfera Móviles had neither responded to the request for information nor provided any… SPAIN ·aepd ·Art. 31 Telecommunications Processing Supervisory Authorities Nov 6, 2020
€20M Marriott International, Inc: Insufficient technical and organisational measures to ensure information security Original Summary: The ICO issued a notice of its intention to fine Marriott International Inc due to a cyber incident which was notified to the ICO by Marriott in November 2018. A… UNITED KINGDOM ·ICO ·Art. 32 Fines Security Healthcare Oct 30, 2020
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY ·Garante ·Art. 5, 13 Video Surveillance Controllers Employees Oct 29, 2020
€200 Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles IP Address Encryption Controllers Oct 24, 2020
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Security Oct 22, 2020
€900 Café Restaurante B.B.B: Non-compliance with general data processing principles The cafe used CCTV cameras which also captured the public space outside resulting in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Oct 9, 2020
€5,000 Caja Rural San José de Nules S. Cooperativa de Crédito: Non-compliance with general data processing principles The company published information with the names and surnames of its employees, which led to the disclosure of the data subject's financial situation. SPAIN ·aepd ·Art. 5 Personal Data IP Address Employees Oct 9, 2020
€35M H&M Hennes & Mauritz Online Shop A.B. & Co. KG: Insufficient legal basis for data processing The fashion company with seat in Hamburg operates a service center in Nuremberg. Here, according to the findings of the Hamburg data protection officer, since at least 2014… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Religious Beliefs Employees Human Resources Oct 1, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Telecommunications Cookies Supervisory Authorities Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Security Education Sep 3, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The complainant, through her attorney, requested access to her personal data. The accused failed to respond, even… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Supervisory Authorities Insurance Aug 31, 2020
€48 Police Officer: Insufficient legal basis for data processing Acess to personal data in a police database for private research activities. ESTONIA ·AKI ·Art. 5, 6 Scientific Research Personal Data Processing Aug 17, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Data Breaches Security Aug 12, 2020
€3,000 GROW BEATS SL: Insufficient fulfilment of information obligations The company had published a cookie policy on its website, which on the one hand contained no information about the purpose of the use of cookies and on the other hand no… SPAIN ·aepd ·Art. 12, 13, 14 Cookies IP Address Law Enforcement Aug 6, 2020
€5,000 Operator of CCTV of a residential building: Insufficient legal basis for data processing The operator of video cameras on a residential property had installed cameras there to monitor the shared area of two blocks of flats. The data controller argued that the owners… BELGIUM ·APD ·Art. 6, 7 Video Surveillance Controllers Consent Jul 14, 2020