Skip to content
Content type · 202 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 202 sort newestlargest fineoldest
€8,000 Comune di Vicchio: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 8,000 on Comune di Vicchio. The municipality processed biometric data of employees for the purpose of registering their attendance.… ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Biometric Data Special Categories of Data Dec 15, 2022
€6,000 Comune di Bracciano: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Comune di Bracciano. A former employee had filed a complaint with the DPA due to the fact, that the municipality had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Health Data IP Address Dec 15, 2022
€230,000 Viking Line Oy Abp: Non-compliance with general data processing principles The Finnish DPA has imposed a fine of EUR 230,000 on Viking Line Oy Abp. A former employee had filed a complaint with the DPA. During its investigation, the DPA found that the… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Healthcare Health Data Personal Data Dec 9, 2022
€6,000 A.R.N.A.S. Civico: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on A.R.N.A.S. Civico. Two employees of the controller had filed a complaint with the DPA. During its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +1 Health Data Healthcare Employees Dec 1, 2022
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Social Media Health Data Insurance Nov 30, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Healthcare Health Data Nov 24, 2022
€20,000 Sportitalia: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Sportitalia. The controller processed biometric data (fingerprints) of employees for the purpose of registering their… ITALY ·Garante ·Art. 5, 9, 13 +1 Employees Special Categories of Data IP Address Nov 10, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD ·Art. 5, 9, 12 +5 DPIA Privacy Shield Privacy Impact Assessment Nov 2, 2022
DKK 500,000 Datatilsynet (Denmark) - 2022-63-0003 A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Art. 5, 9, 24 +2 Data Breaches Security Encryption Oct 28, 2022
€5,000 Fondazione Teatro Regio di Torino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Fondazione Teatro Regio di Torino. A foundation member had filed a complaint with the DPA due to the fact, that the foundation… ITALY ·Garante ·Art. 2, 5, 6 Health Data Healthcare Processing Oct 20, 2022
€5M Interserve Group Limited: Insufficient technical and organisational measures to ensure information security The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Interserve… UNITED KINGDOM ·ICO ·Art. 5, 32 Data Breaches Security IP Address Oct 19, 2022
€20M Clearview Al Inc.: Insufficient fulfilment of data subjects rights The French DPA has fined Clearview Al Inc. EUR 20,000,000. The company holds a database of more than 20 billion facial images (including those of french residents and nationals)… FRANCE ·CNIL ·Art. 6, 12, 15 +2 Personal Data Biometric Data Special Categories of Data Oct 17, 2022
€1.5M Easylife Ltd.: Insufficient legal basis for data processing The UK DPA has imposed a fine of EUR 1,547,000 on Easylife Ltd. Easylife is a retailer that sells household items as well as services and products under its health, motor,… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +1 Healthcare Direct Marketing Health Data Oct 4, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Security Health Data Aug 11, 2022
€9,600 LAST LAP, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on LAST LAP, S.L.. Last Lap organizes the San Silvestre road running race. Race participants were required to show their vaccination certificate… SPAIN ·aepd ·Art. 6, 9 Health Data Healthcare IP Address Aug 1, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Lawful Basis Controllers Jul 19, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000,000 on Clearview AI Inc. The non-profit organization 'Homos Digitalis' had filed a complaint with the DPA on behalf of the data… HDPA Fairness & Transparency Personal Data IP Address Jul 13, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Audit Logs Data Breaches Health Data Jul 7, 2022
€50,000 Azienda sanitaria universitaria Friuli Occidentale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Health Data Healthcare Healthcare May 26, 2022
€70,000 Azienda sanitaria universitaria Friuli Centrale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 70,000 on the healthcare facility Azienda sanitaria universitaria Friuli Centrale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare May 26, 2022
€9M Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +7 Fairness & Transparency Retention Period Privacy Impact Assessment May 18, 2022
€1,500 Direzione Didattica Statale 1° Circolo-Eboli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on the school 'Direzione Didattica Statale 1° Circolo-Eboli'. The educational institution had sent a document containing the names… ITALY ·Garante ·Art. 2, 5, 6 +1 Education Health Data Healthcare Apr 28, 2022
€2,500 'Isabella Gonzaga' high school: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the 'Isabella Gonzaga' high school. The school had published a document, which also contained personal health data of some… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Health Data Education Apr 28, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data DPIA Healthcare Apr 4, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM ·APD ·Art. 5, 6, 9 Health Data Healthcare Archiving Apr 4, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data DPIA Healthcare Apr 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Controllers Personal Data Mar 3, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Fairness & Transparency Storage Limitation IP Address Feb 10, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD ·Art. 5, 6, 9 +5 Religious Beliefs Social Media Fairness & Transparency Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD ·Art. 5, 6, 9 +3 Religious Beliefs Social Media Fairness & Transparency Jan 27, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Healthcare Integrity and Confidentiality Principle Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Data Breaches Jan 26, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Legitimate Interest Personal Data Jan 5, 2022
Company: Insufficient legal basis for data processing The DPA of Bremen has imposed a five-digit fine on a company. The company had sent an unredacted social plan to all affected employees in the context of dismissals due to… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Employees Personal Data Special Categories of Data Jan 1, 2022
€65,000 MALTA DPA: Non-compliance with general data processing principles The controller has violated numerous GDPR regulations, involving special categories of personal data of numerous individuals. Art. 5, 6, 9 +3 ·Non-compliance with general data processing principles IP Address Personal Data Controllers Jan 1, 2022
€1.3M Lisbon City Council: Insufficient legal basis for data processing The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since… PORTUGAL ·CNPD ·Art. 5, 6, 9 +2 Religious Beliefs DPIA Fines Dec 21, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY ·Garante ·Art. 5, 6, 9 Health Data Healthcare Personal Data Dec 17, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY ·Datatilsynet ·Art. 6, 9 IP Address Direct Marketing Fines Dec 13, 2021
€60,000 Irish Teacher Council: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 60,000 on the Irish Teaching Council. The Council notified the DPA of a data breach under Art. 33 of the GDPR. Accordingly, two employees… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data Dec 2, 2021
€20,000 DAVISER SERVICIOS, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 on DAVISER SERVICIOS, S.L.. The company had been processing biometric data (fingerprints) of employees for access to… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Agreement Nov 30, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY ·Datatilsynet ·Art. 5, 32 Encryption Access Controls Security Oct 18, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Notification Obligation Integrity and Confidentiality Principle Sep 29, 2021
€2,000 Istituto Comprensivo - IC Cosenza III “V. Negroni”: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo - IC Cosenza III “V. Negroni”. The educational institution had published a document, which also contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Education Health Data Healthcare Sep 21, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet ·Art. 32 Data Breaches Security Health Data Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Notification Obligation Healthcare Sep 17, 2021
€10,000 Favrskov municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Encryption Notification Obligation Sep 16, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet ·Art. 32 Security Healthcare Health Data Sep 8, 2021
€600 DSB Austria: sharing medical assessment with municipality lacked Art. 9(2) legal basis Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had… Art. 4, 5, 9 +1 Personal Data Healthcare Health Data Aug 5, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·dsb ·Art. 9 Personal Data Legitimate Interest Healthcare Aug 5, 2021
€2.5M Mercadona S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals… SPAIN ·aepd ·Art. 5, 6, 9 +4 Criminal Data Privacy Impact Assessment IP Address Jul 26, 2021