Skip to content
Content type · 240 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 240 sort newestlargest fineoldest
€2,500 Company: Insufficient technical and organisational measures to ensure information security The Belgian DPA has imposed a fine of EUR 2,500 on a company. The company operates a digital management platform where suppliers and customers can communicate and upload… BELGIUM ·APD ·Art. 5, 24, 32 Security Processing Agreement Privacy by Design & Default Aug 23, 2022
€500 CINCON S.C.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on CINCON S.C.. The company had failed to provide the information required by Art. 13 GDPR on a form through which potential… SPAIN ·aepd ·Art. 13 Processing Agreement Human Resources Law Enforcement Jul 22, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Controllers Lawful Basis Jul 19, 2022
€3,600 ECOZONO Y CULTURA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ECOZONO Y CULTURA, S.L.. Econzo, through a service provider, had collected data from data subjects who agreed to disclose the data for survey… SPAIN ·aepd ·Art. 6 Direct Marketing Processing Agreement Personal Data Jul 15, 2022
€175,000 UBEEQO INTERNATIONAL: Non-compliance with general data processing principles The French DPA (CNIL) has fined the company UBEEQO INTERNATIONAL EUR 175,000. The vehicle rental company had collected geolocation data on rented vehicles at every 500 meters. The… FRANCE ·CNIL ·Art. 5, 12 IP Address Processing Agreement Personal Data Jul 7, 2022
€12,450 Głównego Geodetę Kraju: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 12,450 on the public cartography institute Głównego Geodetę Kraju. The institute had suffered a data breach in which numerous land… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jul 6, 2022
SA Rossel & Cie: Insufficient legal basis for data processing Original fine summary: The Belgian DPA has imposed a fine of EUR 50,000 on the media company SA Rossel & Cie. During its investigation, the DPA found GDPR violations on three… BELGIUM ·APD ·Art. 6, 7, 12 +2 Cookies Processing Agreement Telecommunications Jun 16, 2022
€10,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual EUR 10,000. The individual had created a humiliating and discriminatory video of three siblings based on their skin color, and… SPAIN ·aepd ·Art. 6 Social Media Processing Agreement Processing Jun 9, 2022
€1,500 Wens Experience SRL: Insufficient data processing agreement The Romanian DPA has imposed a fine of EUR 1,500 on Wens Experience SRL. In the course of its investigation, the DPA found that Wens Experience, in the course of acting as a… ROMANIA ·ANSPDCP ·Art. 28 Processors Controllers Processing Agreement Jun 8, 2022
€50,000 Roularta Media Group: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 50,000 on Roularta Media Group. As part of its investigation, the DPA found that the cookie management on two websites operated by… BELGIUM ·APD ·Art. 5, 6, 7 +4 Cookies Consent Personal Data May 25, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual operating three websites EUR 2,000. During its investigation, the DPA found that all three websites lacked a field for giving… SPAIN ·aepd ·Art. 6 Personal Data Controllers Processing May 20, 2022
€4,000 INSEKT FOOD S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on INSEKT FOOD S.L.. A data subject hat filed a complain with the DPA against the controller due to the fact that the… SPAIN ·aepd ·Art. 6 Integrity and Confidentiality Principle Personal Data Data Breaches May 17, 2022
€1,000 LORIS FUEL SHOP SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on the gas station operator LORIS FUEL SHOP SRL. A person had filed a complaint with the DPA because pictures of him were… ROMANIA ·ANSPDCP ·Art. 29, 32 Video Surveillance Integrity and Confidentiality Principle Security May 12, 2022
€6,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a homeowners' association. An apartment owner who had been a resident for 15 years had filed a complaint with the DPA due… SPAIN ·aepd ·Art. 5, 13 Personal Data IP Address Processing Agreement May 11, 2022
€10,000 Nationale Maatschappij der Belgische Spoorwegen: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 10,000 on the Belgian national railroad company (Nationale Maatschappij der Belgische Spoorwegen). A Twitter user who had received an… BELGIUM ·APD ·Art. 5, 6, 12 +1 Social Media Right to Object Data Subject Rights Exercise Modalities and Procedures May 4, 2022
€5,000 MISTORE CANARIAS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on MISTORE CANARIAS, S.L.. A person who had made a purchase from the company had filed a complaint against the company with… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement May 3, 2022
€50,000 Istituto Nazionale Assicurazione Infortuni sul Lavoro: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Istituto Nazionale Assicurazione Infortuni sul Lavoro (Public Accident Insurance for workers) EUR 50,000. As part of its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +2 Data Breaches Security Insurance Apr 28, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Privacy Impact Assessment Healthcare Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Video Surveillance Integrity and Confidentiality Principle IP Address Apr 7, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·azop ·Art. 32 Data Breaches Integrity and Confidentiality Principle Controllers Mar 8, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·azop ·Art. 15 Video Surveillance Accuracy Personal Data Mar 8, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Public Authority Education Feb 24, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Education Personal Data Feb 10, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Education Personal Data Public Authority Feb 10, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet ·Art. 5, 6, 32 Data Breaches Security Education Feb 2, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM ·APD ·Art. 5, 6, 9 +8 IP Address Fairness & Transparency Direct Marketing Feb 2, 2022
€8M REWE International AG: €8,000,000 fine The Austrian DPA has imposed a fine of EUR 8 million on REWE International AG. Just in the summer of 2021, the subsidiary 'Unser Ö-Bonus Club GmbH' received a fine of EUR 2… AUSTRIA ·dsb ·Unknown Processing Agreement Supervisory Authorities Human Resources Jan 14, 2022
Medical care center: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a medical care center for having scanned a customer's ID card against their will and stored the copy. Once the customer complained, they… GERMANY ·Insufficient legal basis for data processing Healthcare Healthcare Personal Data Jan 1, 2022
Company: Insufficient fulfilment of information obligations The DPA of Bremen has imposed a three-digit fine on a company. The company offered its applicants an online application procedure on its website without informing users about the… GERMANY ·Art. 12, 13 ·Insufficient fulfilment of information obligations Personal Data Processing Processing Agreement Jan 1, 2022
Data protection officer: Insufficient legal basis for data processing The DPA of Thüringen has imposed a three-digit fine on the data protection officer of a company. The controller had posted a photo in a WhatsApp group of the company which showed… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing Agreement Jan 1, 2022
€7,380 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes over a period of three years. GERMANY ·Insufficient legal basis for data processing Scientific Research Processing Human Resources Jan 1, 2022
€150M CNIL rejects Google's stay request and ne bis in idem challenge in cookie consent case Google LLC is a subsidiary owned wholly by Alphabet Inc. Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and… France ·Art. 56 Cookies Telecommunications Material scope (GDPR) Dec 31, 2021
€60M Google Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Google Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Telecommunications Dec 31, 2021
€60M Facebook Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Facebook Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Social Media Direct Marketing Cookies Dec 31, 2021
€90M Google LLC: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 90,000,000 on GOOGLE LLC. The CNIL received several complaints regarding the manner in which cookies could be… FRANCE ·CNIL ·Art. 82 Direct Marketing Cookies Processing Agreement Dec 31, 2021
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Security Public Authority Dec 16, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY ·Garante ·Art. 5, 32 Security Fines Privacy by Design & Default Dec 2, 2021
€27,200 YAY ehf.: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 28 +1 ·Non-compliance with general data processing principles Fairness & Transparency Personal Data IP Address Nov 23, 2021
€51,000 Icelandic Ministry of Industry and Innovation: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 7 +4 ·Non-compliance with general data processing principles Fairness & Transparency Personal Data IP Address Nov 23, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Access Controls Security Nov 12, 2021
€400,000 Régie autonome des transports parisiens: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine of EUR 400,000 on RATP (the operator of the public transport system in Paris). In May 2020, a trade union filed a complaint with the CNIL… FRANCE ·CNIL ·Art. 5, 32 IP Address Accountability Processing Agreement Nov 4, 2021
€2,000 COOPERA RC SERVICES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 2,000 on COOPERA RC SERVICES. The controller had not provided sufficient contact details through which data subjects could… SPAIN ·aepd ·Art. 13 Controllers Telecommunications Personal Data Nov 2, 2021
€5,000 S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security IP Address Nov 1, 2021
€2,000 OTTO s.r.l.: Insufficient fulfilment of information obligations The Italian DPA (Garante) has imposed a fine of EUR 2,000 on OTTO s.r.l.. During an administrative inspection of a store managed by OTTO, the police found that a video… ITALY ·Garante ·Art. 13 Video Surveillance Monitoring Controllers Oct 28, 2021
€2,000 Anfiteatro Flavio s.r.l.: Insufficient fulfilment of information obligations The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Anfiteatro Flavio s.r.l.. During an administrative inspection of a hotel managed by Anfiteatro Flavio, the police… ITALY ·Garante ·Art. 13 Video Surveillance Monitoring Controllers Oct 28, 2021
€78,000 Bank Millennium S.A: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 78,000 on Bank Millennium S.A.. The UODO had become aware of a data protection breach following a complaint against the bank. It… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 14, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Notification Obligation Integrity and Confidentiality Principle Sep 29, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet ·Art. 5, 28, 32 +1 Processors Processing Agreement Controllers Sep 27, 2021
€75,600 ST. OLAVS HOSPITAL HF: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had… NORWAY ·Datatilsynet ·Art. 32 Healthcare Healthcare Access Controls Sep 20, 2021
€3.3M Sky Italia S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has fined Sky Italia S.r.l. EUR 3,296,326 for illegal telemarketing. The DPA's decision followed a complex investigation launched after dozens of reports… ITALY ·Garante ·Art. 5, 6, 7 +5 Processing Agreement Direct Marketing Right to Object Sep 16, 2021