Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1401–1450 of 2,273 sort newestlargest fineoldest
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data Healthcare DPIA Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 DPIA Health Data Audit Logs Apr 4, 2022
€7,500 Company: Insufficient fulfilment of data subjects rights The Belgian DPA has imposed a fine of EUR 7,500 on a company. A former managing director had filed a complaint against the company with the DPA. In the context of being dismissed,… BELGIUM ·APD ·Art. 5, 6, 15 +4 Personal Data IP Address Employees Apr 1, 2022
€720,000 Klarna Bank AB: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 720,000 on Klarna Bank AB. Klarna is a financial company that processes a large number of personal data in various ways. As part of its… SWEDEN ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Personal Data Processing Agreement IP Address Mar 28, 2022
€2,000 Condor SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Mar 28, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK ·Datatilsynet ·Art. 36 DPIA Privacy Impact Assessment Healthcare Mar 25, 2022
€2,000 Kaufland Romania SCS: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland Romania SCS. A data subject had filed a complaint with the DPA concerning the controller's failure to comply with… ANSPDCP ·Art. 15 ·Insufficient fulfilment of data subjects rights Video Surveillance Monitoring Controllers Mar 25, 2022
€10,000 Brav s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Brav s.r.l.. The operator of the online platform had reported a data breach to the DPA pursuant to Art. 33 GDPR. Unauthorized… ITALY ·Garante ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Security Mar 24, 2022
€490 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 490 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Mar 23, 2022
€4,000 English School Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email… Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 22, 2022
€5,000 English School staff union (ESSA): Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 21, 2022
€2,000 Operatorul Briza Land S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has fined Operatorul Briza Land S.R.L. EUR 2,000. The controller failed to properly respond to a request for information. ROMANIA ·ANSPDCP ·Art. 15 Controllers Personal Data Supervisory Authorities Mar 10, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Encryption Data Breaches Notification Obligation Mar 10, 2022
€8,000 Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo: Insufficient legal basis for data processing The Italian DPA (Garante) has fined the Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo EUR 8,000. A former employee of the environmental agency had filed a complaint… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Processing Employees Mar 10, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Garante ·Art. 2, 5, 6 +3 Healthcare Controllers Personal Data Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare Health Data Mar 10, 2022
€2,000 Foreign language school: Insufficient fulfilment of data subjects rights The Hellenic DPA imposed a fine of EUR 2,000 on an employer (owner of a private foreign language school). An employee, who works as a language teacher in the school, had filed a… GREECE ·HDPA ·Art. 5, 13 Right to Object Education Controllers Mar 9, 2022
€2,000 Employer: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 2,000 on an employer. An employee had filed a complaint due to the employer's failure to comply with the employee's right to object. The… GREECE ·HDPA ·Art. 5, 13 Right to Object Monitoring Audit Logs Mar 9, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·azop ·Art. 15 Video Surveillance Personal Data Accuracy Mar 8, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·azop ·Art. 32 Data Breaches Integrity and Confidentiality Principle Controllers Mar 8, 2022
€7,000 Hörpu tónlistar- og ráðstefnuhúss ohf.: Non-compliance with general data processing principles The Icelandic DPA has fined Hörpu tónlistar- og ráðstefnuhúss ohf. EUR 7,000. The DPA had received a complaint regarding the concert hall's collection of ID number and date of… ICELAND ·Art. 5, 6 ·Non-compliance with general data processing principles IP Address Personal Data Processing Agreement Mar 8, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Security Access Controls Mar 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Controllers Personal Data Mar 3, 2022
€13,500 Company: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 13,500 on a company. An individual had filed a complaint with the DPA, stating that the company had published personal data such as their… HUNGARY ·NAIH ·Art. 5, 6, 12 +1 Personal Data Consent Processing Agreement Mar 2, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Public Authority Public Sector Feb 24, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA ·ANSPDCP ·Art. 12, 13, 21 Personal Data Video Surveillance Controllers Feb 22, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Insurance Feb 22, 2022
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a private individual. The data subject had filed a complaint against the data controller for publishing images of herself… SPAIN ·aepd ·Art. 6 Controllers Personal Data Data Controller Feb 16, 2022
€30,000 ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 30,000 on the ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε. organization. A data subject who had suffered a car accident on the organization's premises filed a… GREECE ·HDPA ·Art. 12, 15 Video Surveillance Personal Data Monitoring Feb 15, 2022
€1,600 RECLAMADOR, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine RECLAMADOR, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the controller continued… SPAIN ·aepd ·Art. 17, 21 Personal Data Controllers Processing Agreement Feb 14, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Education Public Authority Feb 10, 2022
€5,000 Arte del vivere S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Arte del vivere S.r.l.. A data subject filed a complaint with the DPA as his personal data had been published on the website… ITALY ·Garante ·Art. 12, 17, 157 Personal Data Controllers IP Address Feb 10, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Fairness & Transparency IP Address Retention Period Feb 10, 2022
€1,500 Studio Colli Aniene Verderocca S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,500 on Studio Colli Aniene Verderocca S.r.l.. A data subject had filed a complaint with the DPA for unsolicited telephone advertising.… ITALY ·Garante ·Art. 12, 14, 15 +2 Personal Data Direct Marketing Processing Agreement Feb 10, 2022
€10,000 Costampress S.p.A.: Insufficient legal basis for data processing The company had left the e-mail account of the data subject active even after the termination of his employment and did not provide sufficient information about this. ITALY ·Garante ·Art. 5, 12, 13 Personal Data Processing Employees Feb 10, 2022
€2,000 Comune di Guidizzolo: Insufficient legal basis for data processing The community published information about a court case on its website, including personal data such as the name and professional information of a data subject. ITALY ·Garante ·Art. 2, 5, 6 Personal Data Education Processing Feb 10, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Education Public Authority Personal Data Feb 10, 2022
€634,000 Budapest Bank Zrt.: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has fined Budapest Bank Zrt. EUR 634,000. NAIH reports that the bank used an artificial intelligence-driven software solution to automate the evaluation… HUNGARY ·NAIH ·Art. 5, 6, 12 +5 Right to Object Legitimate Interest Data Subject Rights Exercise Modalities and Procedures Feb 8, 2022
€300,000 SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS. in the amount of EUR 300,000. The data subject had received marketing emails from the controller… SPAIN ·aepd ·Art. 6, 17, 28 Insurance Personal Data Controllers Feb 4, 2022
€10,000 Εκδοτικού Οίκου Δίας: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the publisher Εκδοτικού Οίκου Δίας. A public figure had filed a complaint with the DPA. The publisher had published incorrect… CYPRUS ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Telecommunications Processing Feb 4, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM ·APD ·Art. 5, 6, 9 +8 IP Address Fairness & Transparency Direct Marketing Feb 2, 2022
€2,000 ASESORES DE SEGURIDAD PRIVADA, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on ASESORES DE SEGURIDAD PRIVADA, S.L.. The DPA criticized that the controller did not sufficiently inform the data subject about… SPAIN ·aepd ·Art. 13 Personal Data Controllers Insurance Feb 2, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet ·Art. 5, 6, 32 Data Breaches Education Security Feb 2, 2022
€70,000 ORANGE ESPAÑA VIRTUAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined ORANGE ESPAÑA VIRTUAL, S.L. EUR 70,000. Two Orange España Virtual customers had filed complaints with the DPA. In the course of its investigation, the… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€900,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined TELEFÓNICA MÓVILES ESPAÑA, S.A.U. EUR 900,000. Four Telefónica customers had filed complaints with the DPA. In the course of its investigation, the DPA… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€3.9M Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Security Feb 1, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Controllers Processing Agreement Feb 1, 2022
€700,000 Orange Espagne S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Orange Espagne S.A.U. EUR 700,000. Two Orange Espagne customers had filed complaints with the DPA. In the course of its investigation, the DPA found that… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€200,000 XFERA MÓVILES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined XFERA MÓVILES, S.A. EUR 200,000. Two Xfera customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters… SPAIN ·aepd ·Art. 5 IP Address Processing Agreement Telecommunications Feb 1, 2022
€5,000 Cyrana España General S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Cyrana España General S.L. EUR 5,000. The controller had sent an invoice to the data subject although no contractual relationship existed. SPAIN ·aepd ·Art. 6 Controllers IP Address Processing Agreement Jan 31, 2022