Skip to content
Content type · 179 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 179 sort newestlargest fineoldest
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Dec 9, 2022
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Consent Personal Data Types of Special Categories of Personal Data Nov 30, 2022
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE ·CNIL ·Art. 5, 13, 25 +2 Privacy by Default Storage Limitation Retention Period Nov 10, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD (PT) ·Art. 5, 9, 12 +5 Privacy Shield Controllers DPIA Nov 2, 2022
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·Datatilsynet (DK) DPIA Controllers Prior Consultation
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The private individual had installed three video surveillance cameras on his property which, among other… SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Monitoring Sep 13, 2022
€2,500 Company: Insufficient technical and organisational measures to ensure information security The Belgian DPA has imposed a fine of EUR 2,500 on a company. The company operates a digital management platform where suppliers and customers can communicate and upload… BELGIUM ·APD/GBA ·Art. 5, 24, 32 Security Personal Data Privacy by Design & Default Aug 23, 2022
€500 CINCON S.C.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on CINCON S.C.. The company had failed to provide the information required by Art. 13 GDPR on a form through which potential… SPAIN ·AEPD ·Art. 13 Supervisory Authorities Human Resources Jul 22, 2022
Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022) During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Belgium ·APD/GBA Health Data Healthcare Types of Special Categories of Personal Data Jul 19, 2022
€3,600 ECOZONO Y CULTURA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ECOZONO Y CULTURA, S.L.. Econzo, through a service provider, had collected data from data subjects who agreed to disclose the data for survey… SPAIN ·AEPD ·Art. 6 Personal Data Direct Marketing Supervisory Authorities Jul 15, 2022
€175,000 UBEEQO INTERNATIONAL: Non-compliance with general data processing principles The French DPA (CNIL) has fined the company UBEEQO INTERNATIONAL EUR 175,000. The vehicle rental company had collected geolocation data on rented vehicles at every 500 meters. The… FRANCE ·CNIL ·Art. 5, 12 Retention Period Personal Data Supervisory Authorities Jul 7, 2022
€12,450 Głównego Geodetę Kraju: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 12,450 on the public cartography institute Głównego Geodetę Kraju. The institute had suffered a data breach in which numerous land… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 6, 2022
SA Rossel & Cie: Insufficient legal basis for data processing Original fine summary: The Belgian DPA has imposed a fine of EUR 50,000 on the media company SA Rossel & Cie. During its investigation, the DPA found GDPR violations on three… BELGIUM ·APD/GBA ·Art. 6, 7, 12 +2 Consent Supervisory Authorities Processing Jun 16, 2022
€10,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual EUR 10,000. The individual had created a humiliating and discriminatory video of three siblings based on their skin color, and… SPAIN ·AEPD ·Art. 6 Social Media Human Resources Supervisory Authorities Jun 9, 2022
€1,500 Wens Experience SRL: Insufficient data processing agreement The Romanian DPA has imposed a fine of EUR 1,500 on Wens Experience SRL. In the course of its investigation, the DPA found that Wens Experience, in the course of acting as a… ROMANIA ·ANSPDCP ·Art. 28 Processors Controllers Supervisory Authorities Jun 8, 2022
€50,000 Roularta Media Group: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 50,000 on Roularta Media Group. As part of its investigation, the DPA found that the cookie management on two websites operated by… BELGIUM ·APD/GBA ·Art. 5, 6, 7 +4 Consent Personal Data Supervisory Authorities May 25, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual operating three websites EUR 2,000. During its investigation, the DPA found that all three websites lacked a field for giving… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent May 20, 2022
€4,000 INSEKT FOOD S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on INSEKT FOOD S.L.. A data subject hat filed a complain with the DPA against the controller due to the fact that the… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Integrity and Confidentiality Principle May 17, 2022
€1,000 LORIS FUEL SHOP SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on the gas station operator LORIS FUEL SHOP SRL. A person had filed a complaint with the DPA because pictures of him were… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data May 12, 2022
€6,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a homeowners' association. An apartment owner who had been a resident for 15 years had filed a complaint with the DPA due… SPAIN ·AEPD ·Art. 5, 13 Retention Period Personal Data Supervisory Authorities May 11, 2022
€10,000 Nationale Maatschappij der Belgische Spoorwegen: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 10,000 on the Belgian national railroad company (Nationale Maatschappij der Belgische Spoorwegen). A Twitter user who had received an… BELGIUM ·APD/GBA ·Art. 5, 6, 12 +1 Right to Object Personal Data Processing May 4, 2022
€5,000 MISTORE CANARIAS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on MISTORE CANARIAS, S.L.. A person who had made a purchase from the company had filed a complaint against the company with… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent May 3, 2022
€50,000 Istituto Nazionale Assicurazione Infortuni sul Lavoro: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Istituto Nazionale Assicurazione Infortuni sul Lavoro (Public Accident Insurance for workers) EUR 50,000. As part of its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +2 Security Personal Data Data Breaches Apr 28, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Integrity and Confidentiality Principle Personal Data Controllers Apr 7, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Personal Data Processing Apr 7, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Mar 8, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·AZOP ·Art. 15 Personal Data Supervisory Authorities Controllers Mar 8, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Personal Data Supervisory Authorities Feb 24, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Personal Data Supervisory Authorities Security Feb 10, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Personal Data Supervisory Authorities Feb 10, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 32 Security Personal Data Public Authority Feb 2, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +8 Marketing Fairness & Transparency Transparency Feb 2, 2022
€8M REWE International AG: €8,000,000 fine The Austrian DPA has imposed a fine of EUR 8 million on REWE International AG. Just in the summer of 2021, the subsidiary 'Unser Ö-Bonus Club GmbH' received a fine of EUR 2… AUSTRIA ·DSB ·Unknown Human Resources Supervisory Authorities Jan 14, 2022
Medical care center: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a medical care center for having scanned a customer's ID card against their will and stored the copy. Once the customer complained, they… GERMANY ·Insufficient legal basis for data processing Personal Data Right to Object Healthcare Jan 1, 2022
€7,380 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes over a period of three years. GERMANY ·Insufficient legal basis for data processing Scientific Research Human Resources Processing Jan 1, 2022
Company: Insufficient fulfilment of information obligations The DPA of Bremen has imposed a three-digit fine on a company. The company offered its applicants an online application procedure on its website without informing users about the… GERMANY ·Art. 12, 13 ·Insufficient fulfilment of information obligations Personal Data Supervisory Authorities Human Resources Jan 1, 2022
Data protection officer: Insufficient legal basis for data processing The DPA of Thüringen has imposed a three-digit fine on the data protection officer of a company. The controller had posted a photo in a WhatsApp group of the company which showed… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Controllers Personal Data Consent Jan 1, 2022
€90M Google LLC: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 90,000,000 on GOOGLE LLC. The CNIL received several complaints regarding the manner in which cookies could be… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Supervisory Authorities Dec 31, 2021
€60M Facebook Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Facebook Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Social Media Cookies Direct Marketing Dec 31, 2021
€150M Google LLC is a subsidiary owned wholly by Alphabet Inc Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out… SAN-2021-023 ·France ·CNIL Supervision Supervisory Authorities Material scope (GDPR) Dec 31, 2021
€60M Google Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Google Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Telecommunications Dec 31, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY ·Garante ·Art. 5, 32 Security Personal Data Privacy by Design & Default Dec 2, 2021
€400,000 Régie autonome des transports parisiens: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine of EUR 400,000 on RATP (the operator of the public transport system in Paris). In May 2020, a trade union filed a complaint with the CNIL… FRANCE ·CNIL ·Art. 5, 32 Retention Period Accountability Security Nov 4, 2021
€5,000 Ciechi Ardizzone Gioeni di Catania: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Ciechi Ardizzone Gioeni di Catania residential home for blind people. A visitor to the residence filed a complaint… ITALY ·Garante ·Art. 5, 12, 13 +1 Integrity and Confidentiality Principle Retention Period Monitoring Sep 16, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Personal Data Supervisory Authorities Sep 8, 2021
€2.5M Mercadona S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals… SPAIN ·AEPD ·Art. 5, 6, 9 +4 Criminal Data Retention Period Types of Special Categories of Personal Data Jul 26, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… Garante ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles Privacy by Design & Default DPIA Controllers Jul 22, 2021
€80,700 Medicals Nordic I/S: Non-compliance with general data processing principles The Danish DPA (Datatilsynet) has fined Medicals Nordic I/S EUR 80,700. In January 2021, the DPA became aware that Medicals Nordic was using WhatsApp to transmit confidential… DENMARK ·Datatilsynet (DK) ·Non-compliance with general data processing principles Healthcare Health Data Human Resources Jul 9, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jun 7, 2021