Content type · 332 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€10,000 ASSOCIACIO OASIS CULTURAL: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ASSOCIACIO OASIS CULTURAL. A discotheque operated by the controller had published videos of dancing minors on a social media… SPAIN · ·Art. 6 Apr 26, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN · ·Art. 5 Mar 25, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY · ·Art. 5, 13, 114 Mar 7, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY · ·Art. 5, 9, 32 Feb 8, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND · ·Art. 5, 6, 9 +3 Jan 17, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Jan 1, 2024
€16,000 Hotel: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 16,000 on a hotel for processing ID card data without a legal basis. GERMANY ·Insufficient legal basis for data processing Jan 1, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Jan 1, 2024
€2,000 Mushtaq Rubina Kebabish: Insufficient fulfilment of information obligations The Italian DPA has fined Mushtaq Rubina Kebabish EUR 2,000. The controller had operated video surveillance cameras in one of their premises without properly informing about the… ITALY · ·Art. 5, 13 Dec 7, 2023
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… CYPRUS ·Art. 5 ·Non-compliance with general data processing principles Dec 7, 2023
€10,000 Pharmacy owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,000 on a pharmacy owner. The controller had disposed of a large number of personal documents, including medical information of data… SPAIN · ·Art. 5, 32 Nov 24, 2023
€72,000 Eurocollege Oxford English Institute S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 72,000 on Eurocollege Oxford English Institute S.L. The data subject stated that they had signed a training contract with the affiliated… SPAIN · ·Art. 5, 6, 9 Nov 17, 2023
€18,000 Cluster S.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 18,000 on Cluster S-r.l. A data subject had complained to the DPA because their son's health-related data and their own personal data had… ITALY · ·Art. 5, 32 Nov 16, 2023
€600 Hotel: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 600 on a hotel. The controller had installed video surveillance cameras which, among other things, also covered the public space and… SPAIN · ·Art. 5, 13 Nov 3, 2023
€2,000 UNIQUE HOTEL APARTMENT S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on UNIQUE HOTEL APARTMENT. The controller had copied identification documents for the purposes of guest registration and stored the… SPAIN · ·Art. 5 Oct 18, 2023
€40,000 Azienda socio sanitaria territoriale di Lodi CF: Non-compliance with general data processing principles The Italian DPA has imposed a fine of ERU 40,000 on the health authority Azienda socio sanitaria territoriale di Lodi CF. Employees of the health authority had accessed the file… ITALY · ·Art. 5, 9, 32 Oct 12, 2023
€3,000 Palombaro s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Palombaro s.r.l. EUR 3,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects about… ITALY · ·Art. 5, 13 Sep 28, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY · ·Art. 5, 32 Sep 28, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY · ·Art. 5, 25, 32 Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY · ·Art. 5, 9 Sep 28, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA · ·Art. 6, 13, 32 +1 Sep 26, 2023
€10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… ITALY · ·Art. 5, 9, 12 +5 Aug 31, 2023
€2,000 Med Life SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Med Life SA. The controller had refused to disclose certain video recordings of the reception of a hospital to the data… ROMANIA · ·Art. 12, 15 Aug 3, 2023
€15,000 RCL CRUISES LTD: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on RCL CRUISES LTD. An individual had filed a complaint with the DPA. The individual, after requesting information about a cruise… SPAIN · ·Art. 5, 32 Jul 7, 2023
€5,000 Ristorante Francesco srl: Non-compliance with general data processing principles The Italian DPA has fined Ristorante Francesco srl EUR 5,000. The controller had operated video surveillance cameras in its premises without the required authorization.… ITALY · ·Art. 5, 13, 114 Jul 6, 2023
€500 EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L. EUR 500. The controller had installed video surveillance cameras which, among other things, also… SPAIN · ·Art. 5 Jul 4, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY · ·Art. 2, 5, 9 +1 Jun 1, 2023
€10,000 Camedi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Camedi s.r.l. Medical Center. A person had filed a complaint with the DPA because they had received invoices as well as… ITALY · ·Art. 5, 9, 32 Jun 1, 2023
€15,000 Thin Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Thin Srl. The authority took action following a complaint from a GP who alleged that the company had breached data protection… ITALY · ·Art. 5, 9, 13 Jun 1, 2023
€300 CBHNOS S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CBHNOS S.L.. The controller had installed video surveillance cameras which, among other things, also covered a public road. The DPA… SPAIN · ·Art. 5 May 29, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY · ·Art. 5, 6, 32 May 17, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY · ·Art. 5, 9, 32 Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY · ·Art. 5, 25, 32 +1 Mar 23, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY · ·Art. 5, 32 Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA · ·Art. 32 Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA · ·Art. 32 Mar 16, 2023
€220,000 Argon Medical Devices: Insufficient fulfilment of data breach notification obligations The Norwegian DPA has fined Argon Medical Devices EUR 220,000. The controller failed to notify the DPA of a data breach that involved personal data of all its European employees… NORWAY · ·Art. 33 Mar 8, 2023
€50,000 Azienda sanitaria locale di Bari: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda sanitaria locale di Bari. The healthcare facility had published reviews of former patients on the Internet and provided… ITALY · ·Art. 5, 9, 25 Mar 2, 2023
€80,500 I&S Limited Kft: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 80,500 on the spa operator, 'I&S Limited Kft'. During its investigation, the DPA found that the controller had installed video… HUNGARY · ·Art. 5, 6, 9 +3 Feb 6, 2023
€600 HOTEL VILLA SORO, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on HOTEL VILLA SORO, S.L.. The controller had installed a video surveillance system without providing the required information according to Art.… SPAIN · ·Art. 13 Feb 3, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA · ·Art. 33 Jan 31, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA · ·Art. 6, 9 Jan 31, 2023
€5,000 Azienda ULSS n.5 Polesana: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 5,000 on Azienda ULSS n.5 Polesana. The healthcare facility had mistakenly sent a patient medical record to the wrong patient. The DPA… ITALY · ·Art. 5, 9, 32 Jan 26, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY · ·Art. 5, 32, 75 Jan 26, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·Art. 5, 32 ·Non-compliance with general data processing principles Jan 23, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 17, 2023
€2,000 Private individual: Insufficient legal basis for data processing The DPA of Baden-Wuerttemberg has imposed a fine of EUR 2,000 on a clinic employee. The employee had unlawfully accessed a patient administration system in order to find out more… GERMANY ·Art. 6, 9 ·Insufficient legal basis for data processing Jan 1, 2023
Pizza delivery service: Non-compliance with general data processing principles The DPA of Baden-Wuerttemberg has imposed a four-digit fine on a pizza delivery service. The controller had disposed of receipts containing customers' personal data at a public… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2023
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on six private individuals. The individuals, who worked in a hospital, had accessed the medical records of a colleague who… GERMANY ·Insufficient legal basis for data processing Jan 1, 2023
€9,000 Magdeburg University Hospital: Insufficient fulfilment of data breach notification obligations The DPA of Sachsen-Anhalt has imposed a fine of EUR 9,000 on Magdeburg University Hospital. The clinic had failed to report to the DPA a data breach involving a former employee… GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Jan 1, 2023