Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1401–1450 of 2,403 sort newestlargest fineoldest
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Aug 3, 2022
€42,000 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. The company had repeatedly sent advertising messages to a data subject, although the data subject had… SPAIN ·AEPD ·Art. 6 Personal Data Direct Marketing Insurance Aug 2, 2022
€30,200 Krokatjønnvegen 15 AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined Krokatjønnvegen 15 AS EUR 30,200. The controller had carried out credit checks on two data subject without any contractual basis for… NORWAY ·Datatilsynet (NO) ·Art. 6 Personal Data Controllers Supervisory Authorities Aug 2, 2022
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Aug 1, 2022
€3,000 ESTUDIOS EUROPEOS DE POSTGRADO Y EMPRESA, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3,000 on ESTUDIOS EUROPEOS DE POSTGRADO Y EMPRESA, S.L.. An employee had filed a complaint with the DPA. The employee stated that she had… SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Jul 29, 2022
€15,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A former customer had received e-mails containing electronic bills even after they had terminated their contract with the company resulting in a processing of personal data… SPAIN ·AEPD ·Art. 6 Personal Data Telecommunications Processing Jul 26, 2022
Belgian DPA: Legitimate interest can justify direct marketing to recent former customers The data subject was a former customer of the controller (which remained unknown). The data subject received direct marketing from the controller. The data subject objected to the… 117/2022 ·Belgium ·APD/GBA Direct Marketing Legitimate Interest Marketing Jul 26, 2022
€40,000 ESVETEL, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on ESVETEL, S.L.. The data subject had received an advertising call from the controller made on behalf of Vodafone España,… SPAIN ·AEPD ·Art. 28, 48 Personal Data Controllers Supervisory Authorities Jul 22, 2022
€10,000 Company: Non-compliance with general data processing principles The DPA of Luxembourg (CNPD) has imposed a fine of EUR 10,000 on a company. The company had installed a video surveillance system for the purpose of protecting company property… LUXEMBOURG ·CNPD (LU) ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jul 22, 2022
€285,000 Telecommunications company: Insufficient technical and organisational measures to ensure information security The Croatian DPA has fined a telecommunications company EUR 285,000. The company had suffered a data breach. Attackers had managed to access data from about 100,000 data subjects.… CROATIA ·AZOP ·Art. 25, 32 Security Personal Data Telecommunications Jul 21, 2022
€10,000 Stay over s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Stay Over s.r.l. EUR 10,000. A former employee had filed a complaint with the DPA. The company had failed to respond to a request for access to personal… ITALY ·Garante ·Art. 5, 12, 13 +2 Right of Access Personal Data Supervisory Authorities Jul 21, 2022
€2,000 Global Service s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Global Service s.r.l. EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Jul 21, 2022
€20,000 Acqua Novara.VCO S.p.a.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on Acqua Novara.VCO S.p.a.. The fine is related to the fine against Clio S.r.l.. Clio provides and manages a whistleblowing… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Supervisory Authorities Processing Jul 21, 2022
€5,000 Ginosa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Ginosa municipality. The fine is related to the fine against Clio S.r.l.. Clio provides and manages a whistleblowing reporting… ITALY ·Garante ·Art. 2, 5, 6 +1 Supervisory Authorities Personal Data Public Authority Jul 21, 2022
€4,000 Car dealership: Insufficient fulfilment of information obligations The Croatian DPA has fined a car dealership EUR 4,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects about… CROATIA ·AZOP ·Art. 27 Personal Data Controllers Processing Jul 21, 2022
€3,000 Azienda Socio Sanitaria Territoriale Rhodense: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Socio Sanitaria Territoriale Rhodense EUR 3,000. The healthcare facility had reported the loss of a patient's medical record. The file contained… ITALY ·Garante ·Art. 5, 32 Security Personal Data Privacy by Design & Default Jul 21, 2022
€20,000 DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A.: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A. in the amount of EUR 20,000. An individual had filed a complaint with the DPA for receiving… HDPA ·Art. 5, 6, 12 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Processing Jul 19, 2022
€4,000 Bookstore employee: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Agency has imposed a fine of EUR 4,000 on an employee of a bookstore. An individual had filed a complaint with the DPA because he had received an… SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Recipient Jul 19, 2022
Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022) During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Belgium ·APD/GBA Health Data Healthcare Types of Special Categories of Personal Data Jul 19, 2022
€56,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 56,000 on BANKINTER, S.A.. The controller had inadvertently sent a report on the data subject's investment portfolio to a third party.… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Jul 18, 2022
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jul 15, 2022
€3,600 ECOZONO Y CULTURA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ECOZONO Y CULTURA, S.L.. Econzo, through a service provider, had collected data from data subjects who agreed to disclose the data for survey… SPAIN ·AEPD ·Art. 6 Personal Data Direct Marketing Supervisory Authorities Jul 15, 2022
€132,000 DKV Seguros y Reaseguros, S.A.E.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DKV Seguros y Reaseguros, S.A.E.. An individual had filed a complaint with the DPA after receiving multiple e-mails from the controller… SPAIN ·AEPD ·Art. 5, 32, 33 Data Breaches Security Controllers Jul 13, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000,000 on Clearview AI Inc. The non-profit organization 'Homos Digitalis' had filed a complaint with the DPA on behalf of the data… HDPA Personal Data Fairness & Transparency Transparency Jul 13, 2022
€202,000 Manx Care Ltd: Non-compliance with general data processing principles The DPA of Isle of Man has imposed a fine of EUR 202,000 on Manx Care Ltd. Manx Care had emailed an unsecured attachment containing a patient's confidential health information to… ISLE OF MAN ·Art. 5, 24, 25 +3 ·Non-compliance with general data processing principles Data Breaches Retention Period Privacy by Design & Default Jul 13, 2022
€800 SMART ELECTRIC SOLUTIONS, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 800 on SMART ELECTRIC SOLUTIONS, S.L.. The company had installed video surveillance cameras which, among other things, also… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jul 12, 2022
€6,000 FREE SUN ENERGY S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on FREE SUN ENERGY S.L.. A customer of the company had filed a complaint with the DPA because instead of receiving their invoice, they had… SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Supervisory Authorities Jul 12, 2022
€1,500 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,500 on a physician. A patient had asked the doctor to send her complete medical records, such as imaging records as well as consent… HUNGARY ·NAIH ·Art. 5, 12, 13 Personal Data Consent Supervisory Authorities Jul 8, 2022
€20,000 Intesa Sanpaolo Vita S.p.a.: Non-compliance with general data processing principles The Italian DPA has fined Intesa Sanpaolo Vita S.p.a. EUR 20,000. The data subject, who had taken out a life insurance policy with the controller, had filed a complaint with the… ITALY ·Garante ·Art. 5 Personal Data Controllers Processing Jul 7, 2022
€4,000 E Software Concept SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on E Software Concept SRL. The company had uploaded certain documents on its website that were publicly accessible. Among other… ROMANIA ·ANSPDCP ·Art. 32, 58 Recipient Security Personal Data Jul 7, 2022
€1,800 FINCAS ARENYS SL: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on FINCAS ARENYS SL. An individual had filed a complaint with the DPA. The individual had contacted the real estate company in order to rent a… SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Processing Jul 7, 2022
€175,000 UBEEQO INTERNATIONAL: Non-compliance with general data processing principles The French DPA (CNIL) has fined the company UBEEQO INTERNATIONAL EUR 175,000. The vehicle rental company had collected geolocation data on rented vehicles at every 500 meters. The… FRANCE ·CNIL ·Art. 5, 12 Retention Period Personal Data Supervisory Authorities Jul 7, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Data Breaches Personal Data Fairness & Transparency Jul 7, 2022
Italy Garante: TikTok switch to legitimate interest for personalized ads violates Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Legitimate Interest Direct Marketing Marketing Jul 7, 2022
€12,450 Głównego Geodetę Kraju: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 12,450 on the public cartography institute Głównego Geodetę Kraju. The institute had suffered a data breach in which numerous land… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 6, 2022
€56,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Vodafone España, S.A.U. due to insufficient legal basis for data processing. The data subject stated that, unauthorized third parties had… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Jul 6, 2022
€2,120 University Hospital of the Medical University of Warsaw: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 2,120 on the University Hospital of the Medical University of Warsaw. The university hospital had suffered a data breach in which a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 6, 2022
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jul 5, 2022
€1,400 Company: Non-compliance with general data processing principles The DPA of Luxembourg (CNPD) has imposed a fine of EUR 1,400 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this was… LUXEMBOURG ·CNPD (LU) ·Art. 5, 13 Storage Limitation Retention Period Controllers Jun 30, 2022
€5,000 Federazione Italiana Sommelier, Albergatori e Ristoratori: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Federazione Italiana Sommelier, Albergatori e Ristoratori. The federation had sent a protocol containing personal data of a… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Cloud Computing Jun 30, 2022
€2,000 Continental Automotive Romania SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Continental Automotive Romania SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jun 30, 2022
Icelandic DPA: genetic research company violated DPO independence under Art. 38(3) GDPR The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Iceland ·Persónuvernd Supervisory Authorities Prior Consultation Controllers Jun 29, 2022
€1,000 Company: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,000 on a company. The company had requested various personal data from customers for appointment bookings. The DPA found that… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Jun 28, 2022
€2,000 Parliamentary election candidate: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 2,000 on a parliamentary election candidate. A data subject had filed a complaint with the DPA because of receiving unsolicited election… GREECE ·HDPA ·Art. 11, 12 Personal Data Supervisory Authorities Direct Marketing Jun 24, 2022
€1M TotalEnergies Electricité et Gaz France: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 1,000,000 on TotalEnergies Electricité et Gaz France. As part of its investigation, the DPA found that the controller had violated its… CNIL ·Art. 14, 15, 21 ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Controllers Jun 23, 2022
€2,000 WIND Ελλάς Τηλεπικοινωνίες ΑΕΒΕ: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined WIND Ελλάς Τηλεπικοινωνίες ΑΕΒΕ EUR 2,000. A customer of the company had sent an email requesting access to the footage recorded by the store's cameras… GREECE ·HDPA ·Art. 15 Personal Data Controllers Supervisory Authorities Jun 20, 2022
€7,000 Asociația de Proprietari Aviației Park: Insufficient legal basis for data processing The Romanian DPA has fined Asociația de Proprietari Aviației Park, operator of a residential facility, EUR 7,000. The controller had processed personal data (surname, first name,… ROMANIA ·ANSPDCP ·Art. 5, 6 Storage Limitation Retention Period Personal Data Jun 20, 2022
€1,000 SC Interactions Marketing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on SC Interactions Marketing SRL. The controller had sent advertising messages by e-mail to several people on behalf of another… ROMANIA ·ANSPDCP ·Art. 32 Controllers Personal Data Security Jun 20, 2022
€70,000 Unicredit S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Unicredit S.p.A. EUR 70,000. An employee had filed a complaint with the DPA claiming that their right to access their personal data had not been… ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Supervisory Authorities Jun 16, 2022
€20,000 Deutsche Bank S.p.A.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Insurance Jun 16, 2022