Skip to content
Content type · 240 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 240 sort newestlargest fineoldest
€15,000 Thin Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Thin Srl. The authority took action following a complaint from a GP who alleged that the company had breached data protection… ITALY ·Garante ·Art. 5, 9, 13 Healthcare Health Data Processing Agreement Jun 1, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY ·Garante ·Art. 5, 6, 32 Healthcare Security Healthcare May 17, 2023
€15,000 Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Health Data Education Apr 27, 2023
€15,000 Citynews S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Citynews S.p.A. EUR 15,000. The controller had published an article in a newspaper reporting on the arrest of an individual, including health data of the… ITALY ·Garante ·Art. 5, 9 Health Data Healthcare Personal Data Apr 14, 2023
€3,000 Comune di Cogollo del Cengio: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on Comune di Cogollo del Cengio. A former employee had filed a complaint with the DPA due to the fact, that the municipality had… ITALY ·Garante ·Art. 2, 5, 6 +1 Health Data Healthcare IP Address Apr 13, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 9, 32 Health Data Healthcare Recipient Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Data Breaches Integrity and Confidentiality Principle Security Mar 23, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Health Data Mar 23, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Healthcare Recipient Healthcare Mar 16, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Recipient Health Data Healthcare Mar 16, 2023
€50,000 Azienda sanitaria locale di Bari: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda sanitaria locale di Bari. The healthcare facility had published reviews of former patients on the Internet and provided… ITALY ·Garante ·Art. 5, 9, 25 Healthcare Health Data Healthcare Mar 2, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA ·ANSPDCP ·Art. 6, 9 Health Data Healthcare Healthcare Jan 31, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA ·ANSPDCP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 31, 2023
€5,000 Azienda ULSS n.5 Polesana: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 5,000 on Azienda ULSS n.5 Polesana. The healthcare facility had mistakenly sent a patient medical record to the wrong patient. The DPA… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Security Jan 26, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 32, 75 Healthcare Health Data Recipient Jan 26, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·Art. 5, 32 ·Non-compliance with general data processing principles Security Healthcare Health Data Jan 23, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Healthcare Jan 17, 2023
€50,000 DPC (Ireland) - 05/SIU/2018 This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Video Surveillance Legitimate Interest Monitoring Jan 16, 2023
€6,000 Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Health Data Healthcare Education Jan 11, 2023
€3,600 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records containing patient data in a public waste disposal site. GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Health Data Healthcare Security Jan 1, 2023
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on six private individuals. The individuals, who worked in a hospital, had accessed the medical records of a colleague who… GERMANY ·Insufficient legal basis for data processing Healthcare Health Data Healthcare Jan 1, 2023
Physician: Non-compliance with general data processing principles The DPA of Bavaria has imposed a fine in the four figure range on a physician. The physician had responded to an online review regarding their practice, disclosing personal health… GERMANY ·Non-compliance with general data processing principles Healthcare Health Data IP Address Jan 1, 2023
€122,000 Company: Insufficient legal basis for data processing The Finnish DPA has imposed a fine of EUR 122,000 on a company with products that process health data, such as heart rate, etc. The DPA had received several complaints regarding… FINLAND ·Deputy Data Protection Ombudsman ·Art. 9 Health Data Healthcare Consent Dec 27, 2022
€6,000 Comune di Bracciano: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Comune di Bracciano. A former employee had filed a complaint with the DPA due to the fact, that the municipality had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Health Data Healthcare IP Address Dec 15, 2022
€120,000 Eurosanità S.P.A.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 120,000 on Eurosanità S.P.A.. The controller operates various healthcare facilities. An individual had filed a complaint with the DPA for… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Healthcare Health Data Dec 15, 2022
€3,000 Scuola Statale Secondaria di I^ grado 'Bianco-Pascol': Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the school 'Scuola Statale Secondaria di I^ grado 'Bianco-Pascoli', di Fasano (BR)'. The educational institution had published a… ITALY ·Garante ·Art. 2, 5, 6 +2 Education Healthcare Health Data Dec 15, 2022
€55,000 Azienda Universitaria Giuliano Isontina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Health Data DPIA Healthcare Dec 15, 2022
€55,000 Azienda Universitaria Friuli Centrale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Centrale. The health authority has created patient profiles using algorithms and personal patient… ITALY ·Garante ·Art. 2, 5, 9 +2 Health Data DPIA Healthcare Dec 15, 2022
€16,000 HOSPITAL RECOLETAS PONFERRADA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on the healthcare facility HOSPITAL RECOLETAS PONFERRADA, S.L.. A patient had filed a complaint with the DPA. The patient had filled out a… SPAIN ·aepd ·Art. 6, 15 Healthcare Healthcare Health Data Dec 15, 2022
€55,000 Azienda Universitaria Friuli Occidentale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Occidentale. The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 DPIA Health Data Healthcare Dec 15, 2022
€230,000 Viking Line Oy Abp: Non-compliance with general data processing principles The Finnish DPA has imposed a fine of EUR 230,000 on Viking Line Oy Abp. A former employee had filed a complaint with the DPA. During its investigation, the DPA found that the… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Health Data Healthcare Personal Data Dec 9, 2022
€3,600 Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM: Insufficient legal basis for data processing The Spanish DPA has fined the Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM. The controller processed medical data from Covid-19… SPAIN ·aepd ·Art. 9, 13 Healthcare Health Data Storage Limitation Dec 2, 2022
€6,000 A.R.N.A.S. Civico: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on A.R.N.A.S. Civico. Two employees of the controller had filed a complaint with the DPA. During its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Health Data Employees Dec 1, 2022
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Health Data Insurance Social Media Nov 30, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Healthcare Health Data Nov 24, 2022
€40,000 Azienda Usl Valle d'Aosta: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Usl Valle d'Aosta EUR 40,000. An employee and patient of the health department had filed a complaint with the DPA because a colleague who had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare Nov 10, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD ·Art. 5, 9, 12 +5 DPIA Privacy Shield Processing Agreement Nov 2, 2022
€5,000 Fondazione Teatro Regio di Torino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Fondazione Teatro Regio di Torino. A foundation member had filed a complaint with the DPA due to the fact, that the foundation… ITALY ·Garante ·Art. 2, 5, 6 Healthcare Health Data Processing Agreement Oct 20, 2022
€7,000 I.S.P.R.O.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the oncology health care facility I.S.P.R.O.. An individual had mistakenly received medical records from another… ITALY ·Garante ·Art. 5, 9 Healthcare Health Data Healthcare Oct 20, 2022
€9,000 Azienda Ospedaliero-Universitaria Careggi di Firenze: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 9,000 on Azienda Ospedaliero-Universitaria Careggi di Firenze. The controller had mistakenly sent a patient medical record to the wrong… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Healthcare Oct 20, 2022
€100,000 Veneto region: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 100,000 on the Veneto Region. The DPA had received a complaint from dozens of medical and nursing staff. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 Health Data Healthcare Education Oct 6, 2022
€1.5M Easylife Ltd.: Insufficient legal basis for data processing The UK DPA has imposed a fine of EUR 1,547,000 on Easylife Ltd. Easylife is a retailer that sells household items as well as services and products under its health, motor,… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +1 Healthcare Direct Marketing Health Data Oct 4, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Security Health Data Aug 11, 2022
€9,600 LAST LAP, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on LAST LAP, S.L.. Last Lap organizes the San Silvestre road running race. Race participants were required to show their vaccination certificate… SPAIN ·aepd ·Art. 6, 9 Healthcare Health Data IP Address Aug 1, 2022
€3,000 Azienda Socio Sanitaria Territoriale Rhodense: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Socio Sanitaria Territoriale Rhodense EUR 3,000. The healthcare facility had reported the loss of a patient's medical record. The file contained… ITALY ·Garante ·Art. 5, 32 Healthcare Health Data Healthcare Jul 21, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Lawful Basis Controllers Jul 19, 2022
€1,500 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,500 on a physician. A patient had asked the doctor to send her complete medical records, such as imaging records as well as consent… HUNGARY ·NAIH ·Art. 5, 12, 13 Healthcare Health Data Healthcare Jul 8, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Fairness & Transparency Audit Logs Data Breaches Jul 7, 2022
€70,000 Azienda sanitaria universitaria Friuli Centrale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 70,000 on the healthcare facility Azienda sanitaria universitaria Friuli Centrale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare May 26, 2022
€50,000 Azienda sanitaria universitaria Friuli Occidentale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare May 26, 2022