Skip to content
Content type · 136 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–136 of 136 sort newestlargest fineoldest
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·DPC ·Art. 12, 13, 15 Right of Access Personal Data Controllers Dec 9, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€2,000 Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Valoris Center S.R.L.. The controller notified the DPA of a data breach pursuant to Art. 33 GDPR. A call center… ROMANIA ·ANSPDCP ·Art. 29, 32 Data Breaches Security Right of Access Nov 26, 2021
€2,900 Vodafone România SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,900 on VODAFONE România S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 3, 32 Data Breaches Security Personal Data Nov 14, 2021
€150,000 TIM S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has fined mobile operator TIM S.p.A. EUR 150,000 for denying a data subject access to his phone data needed to defend himself in a criminal case. Since… ITALY ·Garante ·Art. 15 Right of Access Personal Data Supervisory Authorities Nov 11, 2021
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused did not respond to the complainant's repeated requests to provide access to personal data and to… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Right of Access Personal Data Supervisory Authorities Jun 9, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 23, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Cyprus DPA ·Art. 12, 15, 31 +1 Right of Access Personal Data Supervisory Authorities Mar 3, 2021
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Dec 11, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Healthcare Nov 19, 2020
€1,000 American College of Greece: Insufficient fulfilment of information obligations The Hellenic DPA (HDPA) imposed a fine of EUR 1,000 against the American College of Greece for violations of the right of access and the right to erasure of personal data. HDPA ·Art. 12 ·Insufficient fulfilment of information obligations Personal Data Supervisory Authorities Right to be Forgotten Oct 29, 2020
€54,800 Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak: Insufficient fulfilment of data subjects rights The data controller denied the data subject access to the video material recorded by CCTV in a local store, with which the data subject wanted to prove that he or she had not… HUNGARY ·NAIH ·Art. 12, 15, 18 +1 Right of Access Personal Data Controllers Oct 23, 2020
€20,050 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 20,050 on a legal person. The accused processes hundreds of thousands of personal data on the website about self-employed persons without… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 12 +2 Right of Access Personal Data Processing Sep 30, 2020
€10,000 Cavauto S.R.L.: Insufficient legal basis for data processing Access to personal data of a former employee (containing his browser history) on his work computer. ITALY ·Garante ·Art. 5, 6, 7 Personal Data Processing Right of Access Aug 10, 2020
€3,000 GTL S.R.L.: Insufficient fulfilment of data subjects rights ⇄ Failure to graint access to personal data of a data subject according to Art. 15 GDPR. ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Supervisory Authorities Aug 6, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. Following the delivery of the goods with the invoice, the accused did not respond to the request of the OA for… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Right of Access Personal Data Supervisory Authorities Aug 3, 2020
HDPA 23/2020: Complaint against HEDNO S.A. for denial of employment certificate The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Greece ·Art. 4, 5, 12 +6 Right of Access Personal Data Processors Jul 30, 2020
€40,000 Iberia Lae SA Operadora Unipersonal: Insufficient cooperation with supervisory authority The company did not grant the data subject access to telephone records. The applicant's request for access did not receive a reply, despite the prior order of the AEPD. SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Jul 20, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Jul 9, 2020
€15,000 Mapei S.p.A.: Insufficient fulfilment of data subjects rights Mapei failed to respond to the request for access to personal data of the data subject. In addition, Mapei had left the e-mail account of the person concerned active even after… ITALY ·Garante ·Art. 5, 12, 13 +1 Right of Access Personal Data Supervisory Authorities Jul 2, 2020
€13,500 Department of Home Affairs: Insufficient fulfilment of data subjects rights Fines for failure to comply with the right of access to personal data under Articles 12 and 15 GDPR. The Isle of Man has declared the GDPR - although it is not an EU state - to be… ISLE OF MAN ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Inspection Access Rights and Cooperation Obligations Jun 25, 2020
€5,800 Unknown Company: Insufficient fulfilment of data subjects rights The data controller has not complied with its obligation regarding the right of access to video recordings and was also unable to demonstrate that his data processing activities… HUNGARY ·NAIH ·Art. 6, 15 Right of Access Controllers Processing Mar 19, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 18, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA ·AZOP ·Art. 15 Right of Access Personal Data Supervisory Authorities Mar 13, 2020
€42,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security According to the AEPD, the company had not been able to demonstrate adequate measures to ensure information security, leading to unauthorized access to personal data of a client. SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Right of Access Mar 3, 2020
€5,000 Public Power Corporation S.A.: Insufficient fulfilment of data subjects rights The Decision clarified that data subjects have a right of access to the processing of their personal data and that they must also be provided with a copy of the personal data… GREECE ·HDPA ·Art. 15 Right of Access Personal Data Processing Feb 21, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Cyprus DPA ·Art. 32 Right of Access Security Personal Data Jan 13, 2020
€2,500 Royal President S.R.L.: Insufficient fulfilment of data subjects rights Royal President refused a request for access to personal data pursuant to Article 15 of the GDPR and disclosed personal data without the consent of the data subjects. In addition,… ROMANIA ·ANSPDCP ·Art. 6, 15, 32 Right of Access Personal Data Security Nov 29, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Nov 25, 2019
€10,000 Merchant: Non-compliance with general data processing principles The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's… BELGIUM ·APD/GBA ·Art. 5 Identification Personal Data Processing Sep 17, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Processors Territorial scope (GDPR) Sep 3, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Right of Access Personal Data Apr 29, 2019
€1,900 HUNGARY DPA: Insufficient fulfilment of data subjects rights The data controller did not fulfil the data subject's access request. NAIH ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Right of Access Personal Data Apr 5, 2019
€500 Employer: Insufficient fulfilment of data subjects rights An employee sent a request to his employer for access to personal data concerning him. The request was not answered in time and not in a complete way. BULGARIA ·CPDP ·Art. 15 Right of Access Personal Data Employees Feb 22, 2019