Skip to content
Content type · 261 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 261 sort newestlargest fineoldest
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… AP Personal Data Privacy Shield International Transfer Jul 22, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Privacy by Design & Default Personal Data Jul 4, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND ·UODO ·Art. 24, 25, 32 +1 Security Privacy by Design & Default Controllers Jun 13, 2024
€500 Comune di Ustica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500 on Comune di Ustica. The municipality had published a document, containing personal data (including health data) of private… ITALY ·Garante ·Art. 2, 5, 6 +2 Public Authority Types of Special Categories of Personal Data Healthcare Jun 6, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Healthcare May 9, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·AEPD ·Art. 32, 33 Data Breaches Security Personal Data May 8, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Security Personal Data Healthcare Feb 8, 2024
€3,300 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,300 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Controllers Types of Special Categories of Personal Data Jan 1, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Supervisory Authorities Fines Supervision Jan 1, 2024
€3,700 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,700 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Controllers Types of Special Categories of Personal Data Jan 1, 2024
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… CYPRUS ·Cyprus DPA ·Art. 5 Personal Data Processing Health Data Dec 7, 2023
€1,000 GREECE DPA: Non-compliance with general data processing principles Unlawful disclosure of health data. HDPA ·Art. 5 ·Non-compliance with general data processing principles Processing Supervisory Authorities Health Data Oct 11, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY ·Garante ·Art. 5, 32 Processing Health Data Healthcare Sep 28, 2023
€5,000 Ministero dell'Ambiente e della Sicurezza Energetica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Ministero dell'Ambiente e della Sicurezza Energetica. The controller had published a document on its website that contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Controllers Sep 28, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Sep 28, 2023
€5,000 Physician: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on a physician for unlawfully disclosing patient data. ITALY ·Garante ·Art. 5, 9 Healthcare Processing Health Data Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Personal Data Processing Sep 28, 2023
€10,000 Phyisician: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 10,000 on a physician. The physician had responded to an online review regarding their practice, disclosing personal health data of a… AUSTRIA ·DSB ·Art. 5, 9 Healthcare Types of Special Categories of Personal Data Processing Sep 26, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN ·AEPD ·Art. 9, 13 Personal Data Healthcare Controllers Sep 25, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY ·Garante ·Art. 2, 5, 9 +1 Healthcare Personal Data Controllers Jun 1, 2023
€15,000 Thin Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Thin Srl. The authority took action following a complaint from a GP who alleged that the company had breached data protection… ITALY ·Garante ·Art. 5, 9, 13 Healthcare Personal Data International Transfer Jun 1, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY ·Garante ·Art. 5, 6, 32 Security Controllers Personal Data May 17, 2023
€15,000 Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Apr 27, 2023
€15,000 Citynews S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Citynews S.p.A. EUR 15,000. The controller had published an article in a newspaper reporting on the arrest of an individual, including health data of the… ITALY ·Garante ·Art. 5, 9 Personal Data Types of Special Categories of Personal Data Controllers Apr 14, 2023
€3,000 Comune di Cogollo del Cengio: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on Comune di Cogollo del Cengio. A former employee had filed a complaint with the DPA due to the fact, that the municipality had… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Apr 13, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Security Data Breaches Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Integrity and Confidentiality Principle Data Breaches Privacy by Design & Default Mar 23, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 9, 32 Security Personal Data Healthcare Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€50,000 Azienda sanitaria locale di Bari: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda sanitaria locale di Bari. The healthcare facility had published reviews of former patients on the Internet and provided… ITALY ·Garante ·Art. 5, 9, 25 Healthcare Processing Health Data Mar 2, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Consent Controllers Jan 31, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA ·ANSPDCP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 31, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 32, 75 Security Personal Data Controllers Jan 26, 2023
€5,000 Azienda ULSS n.5 Polesana: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 5,000 on Azienda ULSS n.5 Polesana. The healthcare facility had mistakenly sent a patient medical record to the wrong patient. The DPA… ITALY ·Garante ·Art. 5, 9, 32 Security Healthcare Personal Data Jan 26, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·DPC ·Art. 5, 32 Security Controllers Personal Data Jan 23, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·IMY ·Art. 32 Security Personal Data Privacy by Design & Default Jan 17, 2023
€50,000 DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Legitimate Interest Controllers Personal Data Jan 16, 2023
€6,000 Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Jan 11, 2023
€3,600 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records containing patient data in a public waste disposal site. GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Jan 1, 2023
Physician: Non-compliance with general data processing principles The DPA of Bavaria has imposed a fine in the four figure range on a physician. The physician had responded to an online review regarding their practice, disclosing personal health… GERMANY ·Non-compliance with general data processing principles Health Data Healthcare Types of Special Categories of Personal Data Jan 1, 2023
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on six private individuals. The individuals, who worked in a hospital, had accessed the medical records of a colleague who… GERMANY ·Insufficient legal basis for data processing Health Data Healthcare Human Resources Jan 1, 2023
€122,000 Company: Insufficient legal basis for data processing The Finnish DPA has imposed a fine of EUR 122,000 on a company with products that process health data, such as heart rate, etc. The DPA had received several complaints regarding… FINLAND ·Deputy Data Protection Ombudsman ·Art. 9 Healthcare Consent Types of Special Categories of Personal Data Dec 27, 2022
€16,000 HOSPITAL RECOLETAS PONFERRADA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on the healthcare facility HOSPITAL RECOLETAS PONFERRADA, S.L.. A patient had filed a complaint with the DPA. The patient had filled out a… SPAIN ·AEPD ·Art. 6, 15 Personal Data Consent Controllers Dec 15, 2022
€55,000 Azienda Universitaria Giuliano Isontina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Healthcare DPIA Marketing Dec 15, 2022
€55,000 Azienda Universitaria Friuli Centrale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Centrale. The health authority has created patient profiles using algorithms and personal patient… ITALY ·Garante ·Art. 2, 5, 9 +2 Healthcare DPIA Profiling Dec 15, 2022
€3,000 Scuola Statale Secondaria di I^ grado 'Bianco-Pascol': Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the school 'Scuola Statale Secondaria di I^ grado 'Bianco-Pascoli', di Fasano (BR)'. The educational institution had published a… ITALY ·Garante ·Art. 2, 5, 6 +2 Healthcare Types of Special Categories of Personal Data Supervisory Authorities Dec 15, 2022
€6,000 Comune di Bracciano: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Comune di Bracciano. A former employee had filed a complaint with the DPA due to the fact, that the municipality had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Dec 15, 2022
€55,000 Azienda Universitaria Friuli Occidentale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Occidentale. The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Healthcare DPIA Marketing Dec 15, 2022