Skip to content
Content type · 332 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 332 sort newestlargest fineoldest
€10,000 ASSOCIACIO OASIS CULTURAL: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ASSOCIACIO OASIS CULTURAL. A discotheque operated by the controller had published videos of dancing minors on a social media… SPAIN ·aepd ·Art. 6 Social Media Controllers Minors Apr 26, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN ·aepd ·Art. 5 Video Surveillance Controllers IP Address Mar 25, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance Personal Data Controllers Mar 7, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Recipient Feb 8, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Healthcare Healthcare Encryption Jan 17, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Fines Supervisory Authorities Processing Agreement Jan 1, 2024
€16,000 Hotel: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 16,000 on a hotel for processing ID card data without a legal basis. GERMANY ·Insufficient legal basis for data processing Processing Processing Agreement Supervisory Authorities Jan 1, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jan 1, 2024
€2,000 Mushtaq Rubina Kebabish: Insufficient fulfilment of information obligations The Italian DPA has fined Mushtaq Rubina Kebabish EUR 2,000. The controller had operated video surveillance cameras in one of their premises without properly informing about the… ITALY ·Garante ·Art. 5, 13 Video Surveillance Personal Data Controllers Dec 7, 2023
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… CYPRUS ·Art. 5 ·Non-compliance with general data processing principles Health Data Healthcare Healthcare Dec 7, 2023
€10,000 Pharmacy owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,000 on a pharmacy owner. The controller had disposed of a large number of personal documents, including medical information of data… SPAIN ·aepd ·Art. 5, 32 Healthcare Healthcare IP Address Nov 24, 2023
€72,000 Eurocollege Oxford English Institute S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 72,000 on Eurocollege Oxford English Institute S.L. The data subject stated that they had signed a training contract with the affiliated… SPAIN ·aepd ·Art. 5, 6, 9 Healthcare Personal Data IP Address Nov 17, 2023
€18,000 Cluster S.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 18,000 on Cluster S-r.l. A data subject had complained to the DPA because their son's health-related data and their own personal data had… ITALY ·Garante ·Art. 5, 32 Healthcare Anonymization Personal Data Nov 16, 2023
€600 Hotel: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 600 on a hotel. The controller had installed video surveillance cameras which, among other things, also covered the public space and… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers IP Address Nov 3, 2023
€2,000 UNIQUE HOTEL APARTMENT S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on UNIQUE HOTEL APARTMENT. The controller had copied identification documents for the purposes of guest registration and stored the… SPAIN ·aepd ·Art. 5 Controllers IP Address Processing Agreement Oct 18, 2023
€40,000 Azienda socio sanitaria territoriale di Lodi CF: Non-compliance with general data processing principles The Italian DPA has imposed a fine of ERU 40,000 on the health authority Azienda socio sanitaria territoriale di Lodi CF. Employees of the health authority had accessed the file… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Healthcare IP Address Oct 12, 2023
€3,000 Palombaro s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Palombaro s.r.l. EUR 3,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects about… ITALY ·Garante ·Art. 5, 13 Video Surveillance Monitoring Controllers Sep 28, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Sep 28, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Healthcare Healthcare Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Health Data Sep 28, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·azop ·Art. 6, 13, 32 +1 Notified Body Responsibilities and Operational Obligations Controllers IP Address Sep 26, 2023
€10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… ITALY ·Garante ·Art. 5, 9, 12 +5 Healthcare Recipient Healthcare Aug 31, 2023
€2,000 Med Life SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Med Life SA. The controller had refused to disclose certain video recordings of the reception of a hospital to the data… ROMANIA ·ANSPDCP ·Art. 12, 15 Healthcare Healthcare Personal Data Aug 3, 2023
€15,000 RCL CRUISES LTD: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on RCL CRUISES LTD. An individual had filed a complaint with the DPA. The individual, after requesting information about a cruise… SPAIN ·aepd ·Art. 5, 32 Controllers Processing Agreement IP Address Jul 7, 2023
€5,000 Ristorante Francesco srl: Non-compliance with general data processing principles The Italian DPA has fined Ristorante Francesco srl EUR 5,000. The controller had operated video surveillance cameras in its premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance Monitoring Personal Data Jul 6, 2023
€500 EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L. EUR 500. The controller had installed video surveillance cameras which, among other things, also… SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring Controllers Jul 4, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY ·Garante ·Art. 2, 5, 9 +1 Health Data Healthcare Healthcare Jun 1, 2023
€10,000 Camedi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Camedi s.r.l. Medical Center. A person had filed a complaint with the DPA because they had received invoices as well as… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Healthcare Processing Agreement Jun 1, 2023
€15,000 Thin Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Thin Srl. The authority took action following a complaint from a GP who alleged that the company had breached data protection… ITALY ·Garante ·Art. 5, 9, 13 Health Data Healthcare Processing Agreement Jun 1, 2023
€300 CBHNOS S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CBHNOS S.L.. The controller had installed video surveillance cameras which, among other things, also covered a public road. The DPA… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers May 29, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY ·Garante ·Art. 5, 6, 32 Security Healthcare Healthcare May 17, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 9, 32 Health Data Healthcare Healthcare Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Data Breaches Integrity and Confidentiality Principle Security Mar 23, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Healthcare Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Healthcare Recipient Health Data Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Healthcare Recipient Health Data Mar 16, 2023
€220,000 Argon Medical Devices: Insufficient fulfilment of data breach notification obligations The Norwegian DPA has fined Argon Medical Devices EUR 220,000. The controller failed to notify the DPA of a data breach that involved personal data of all its European employees… NORWAY ·Datatilsynet ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Mar 8, 2023
€50,000 Azienda sanitaria locale di Bari: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda sanitaria locale di Bari. The healthcare facility had published reviews of former patients on the Internet and provided… ITALY ·Garante ·Art. 5, 9, 25 Health Data Healthcare Healthcare Mar 2, 2023
€80,500 I&S Limited Kft: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 80,500 on the spa operator, 'I&S Limited Kft'. During its investigation, the DPA found that the controller had installed video… HUNGARY ·NAIH ·Art. 5, 6, 9 +3 Video Surveillance Monitoring IP Address Feb 6, 2023
€600 HOTEL VILLA SORO, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on HOTEL VILLA SORO, S.L.. The controller had installed a video surveillance system without providing the required information according to Art.… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Feb 3, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA ·ANSPDCP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 31, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Health Data Healthcare Jan 31, 2023
€5,000 Azienda ULSS n.5 Polesana: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 5,000 on Azienda ULSS n.5 Polesana. The healthcare facility had mistakenly sent a patient medical record to the wrong patient. The DPA… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Healthcare Jan 26, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 32, 75 Health Data Healthcare Recipient Jan 26, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·Art. 5, 32 ·Non-compliance with general data processing principles Security Healthcare Health Data Jan 23, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Jan 17, 2023
€2,000 Private individual: Insufficient legal basis for data processing The DPA of Baden-Wuerttemberg has imposed a fine of EUR 2,000 on a clinic employee. The employee had unlawfully accessed a patient administration system in order to find out more… GERMANY ·Art. 6, 9 ·Insufficient legal basis for data processing Healthcare Personal Data Processing Jan 1, 2023
Pizza delivery service: Non-compliance with general data processing principles The DPA of Baden-Wuerttemberg has imposed a four-digit fine on a pizza delivery service. The controller had disposed of receipts containing customers' personal data at a public… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Controllers Personal Data IP Address Jan 1, 2023
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on six private individuals. The individuals, who worked in a hospital, had accessed the medical records of a colleague who… GERMANY ·Insufficient legal basis for data processing Healthcare Health Data Healthcare Jan 1, 2023
€9,000 Magdeburg University Hospital: Insufficient fulfilment of data breach notification obligations The DPA of Sachsen-Anhalt has imposed a fine of EUR 9,000 on Magdeburg University Hospital. The clinic had failed to report to the DPA a data breach involving a former employee… GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 1, 2023