Skip to content
Content type · 394 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 394 sort newestlargest fineoldest
€5,000 Banca Transilvania S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on Banca Transilvania S.A. The controller forwarded client data to an insurance company without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Insurance Processing Agreement Controllers Apr 3, 2025
€600 Owner of a Law Firm: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on the owner of a law firm. The controller disclosed personal information in an external email because they did not implement sufficient technical… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Apr 3, 2025
€1.6M ING BANK N.V., SUCURSAL EN ESPAÑA: Insufficient legal basis for data processing The Spanish data protection authority (AEPD) has imposed a fine on ING BANK N.V., SUCURSAL EN ESPAÑA. As part of the verification process for new banking customers, ING carries… SPAIN ·aepd ·Art. 6 Personal Data Processing Insurance Mar 14, 2025
€10,000 Housing Finance Corporation: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the Housing Finance Corporation. The controller stored client loan data for longer than necessary and did not ensure that the… CYPRUS ·Art. 5, 24 ·Insufficient legal basis for data processing Controllers Insurance Processing Agreement Mar 10, 2025
€200,000 ORANGE BANK, S.A. SUCURSAL EN ESPAÑA: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on ORANGE BANK, S.A. SUCURSAL EN ESPAÑA. The AEPD reacted to multiple complaints of private individuals regarding a data… SPAIN ·aepd ·Art. 5 Processors Controllers Security Feb 14, 2025
€3,000 Omniasig Vienna Insurance Group S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Omniasig Vienna Insurance Group S.A. The controller failed to implement sufficient technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance Feb 6, 2025
€10,000 V&M Contab & Management SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on V&M Contab & Management SRL. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32, 58 Data Breaches Security Controllers Feb 4, 2025
€15,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 25 Data Breaches Security Controllers Feb 3, 2025
€80,000 CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security IP Address Processing Agreement Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€88,000 CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€76,000 CAJA RURAL DE GIJÓN, S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE GIJÓN, S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€12,000 CAJA RURAL DE ONDA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ONDA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€8,000 CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€12,000 CAJA RURAL GRANADA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL GRANADA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Processing Agreement IP Address Jan 17, 2025
€8,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Insurance Controllers Jan 17, 2025
€16,000 CAJA RURAL DEL SUR, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DEL SUR, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€200,000 CAJA RURAL DE SALAMANCA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE SALAMANCA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Jan 17, 2025
€8,000 CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security Processing Agreement Insurance Jan 17, 2025
€10,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€12,000 CAJA RURAL DE ASTURIAS, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ASTURIAS, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€400,000 CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security Processing Agreement IP Address Jan 16, 2025
€72,000 CAJA RURAL CENTRAL, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL CENTRAL, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 16, 2025
€120,000 National Bank of Greece S.A: Insufficient technical and organisational measures to ensure information security Hellenic Data Protection Authority (HDPA) fined National Bank of Greece S.A €120,000 on 2025-01-10 for: Insufficient technical and organisational measures to ensure information… HDPA ·Art. 5, 15, 25 +3 ·Insufficient technical and organisational measures to ensure information security Security Processing Agreement Supervisory Authorities Jan 10, 2025
€175,000 Credit Institution: Insufficient fulfilment of data subjects rights The DPA of Luxembourg has issued a fine of EUR 175,000 on a Credit Institution. The controller failed to respond to information requests within the timeframe specified in Art. 12… LUXEMBOURG ·CNPD ·Art. 12 Supervisory Authorities Controllers Personal Data Jan 6, 2025
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN ·aepd ·Art. 6, 28 Insurance Controllers Processors Dec 23, 2024
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND ·UODO ·Art. 30, 35, 38 Privacy Impact Assessment DPIA Insurance Dec 18, 2024
€950,000 Sambla Group Oy: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 950,000 on Sambla Group Oy. Security vulnerabilities in two of its comparison portals allowed unauthorized persons to access personal… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Insurance Personal Data Dec 17, 2024
€3.5M CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a… SPAIN ·aepd ·Art. 5, 25 Privacy by Default Privacy by Design Privacy by Design & Default Dec 12, 2024
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN ·aepd ·Art. 5, 25, 32 +1 Data Breaches Insurance Security Dec 10, 2024
€2,500 COYARE SLU: Non-compliance with general data processing principles The Spanish DPA fined COYARE SLU EUR 2,500 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the unauthorized… SPAIN ·aepd ·Art. 5, 32 IP Address Insurance Processing Agreement Nov 13, 2024
€900,000 Debt collection service provider: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 900,000 on a debt collection service provider. The company had unlawfully stored personal data (amounting to a six-digit number of… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Insurance Processing Nov 12, 2024
€180,000 IBERCAJA BANCO, S.A.: Insufficient legal basis for data processing The Spanish DPA has fined IBERCAJA BANCO, S.A. for unlawfully accessing a customer’s credit file after the termination of their contractual relationship. The DPA concluded that… SPAIN ·aepd ·Art. 6 IP Address Insurance Processing Agreement Oct 22, 2024
€5,000 ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. The controller, a law firm, published the names and photos of its… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement Oct 4, 2024
€1,400 Attorney: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 1,400 on an attorney. An individual had filed a complaint with the DPA because the controller did not adequately respond to their… GREECE ·HDPA ·Art. 12, 31 Controllers Personal Data Supervisory Authorities Sep 23, 2024
€600 KVIKU SPAIN, S.L: Insufficient cooperation with supervisory authority The Spanish DPA has fined KVIKU SPAIN, S.L. EUR 600 for failing to provide information requested by the DPA. aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Sep 11, 2024
€3,000 Senira Limited: Insufficient cooperation with supervisory authority The Cypriot DPA fined Senira Limited EUR 3,000 for failing to sufficiently cooperate with the DPA. CYPRUS ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Sep 4, 2024
€50,000 SANTANDER CONSUMER FINANCE, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 50,000 on SANTANDER CONSUMER FINANCE, S.A.. The fine followed a complaint from an individual who received advertising from the company,… SPAIN ·aepd ·Art. 6 Controllers Insurance Personal Data Aug 22, 2024
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Recipient Aug 20, 2024
€150,000 BANCO CETELEM, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO CETELEM, S.A.. A person had filed a complaint against the controller with the DPA due to the fact that debits had been made from their… SPAIN ·aepd ·Art. 6, 17 Controllers IP Address Personal Data Jun 25, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Insurance Jun 24, 2024
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A data subject had filed a complaint with the DPA because the controller had proposed to a credit… SPAIN ·aepd ·Art. 5 Personal Data Controllers IP Address Jun 12, 2024
€160,000 ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A person had filed a complaint with the DPA because their ex-partner had been given… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Insurance Jun 10, 2024
€6,000 Ambitious People Group B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 6,000 on the recruitment company Ambitious People Group B.V. . The controller had not deleted the data of data subjects after they had… THE NETHERLANDS ·AP ·Art. 12, 17 Controllers Personal Data Data Controller Jun 4, 2024
€70,000 CAIXABANK S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK S.A.. A person had filed a complaint with the DPA because an employee of the controller had accidentally disclosed… SPAIN ·aepd ·Art. 5, 32 IP Address Personal Data Processing Agreement May 28, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… aepd ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement May 7, 2024
€1,200 ARRENDAMIENTOS DEUDORES, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ARRENDAMIENTOS DEUDORES, S.L.. The controller had carried out a credit check on the data subject without any valid legal basis for this. The… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement May 7, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Apr 23, 2024
€1,000 CONSULTORÍA PERITACIONES ALMERIENSES, S.L: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on CONSULTORÍA PERITACIONES ALMERIENSES, S.L for failing to comply with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Apr 19, 2024