Skip to content
Content type · 151 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 151 sort newestlargest fineoldest
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Controllers Personal Data Right of Access Sep 22, 2022
€530 Sułkowice Cultural Center: Insufficient data processing agreement The Polish DPA has imposed a fine of EUR 530 on the Sułkowice Cultural Center. During its investigation, the DPA found that the controller had transferred the processing of… POLAND ·UODO ·Art. 28 Controllers Processors Processing Agreement Sep 7, 2022
€5,000 EDYTE SA: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 5,000 on EDYTE SA. EDYTE, as a processor, had unlawfully disclosed personal data to third parties without the authorization of the data… GREECE ·HDPA ·Art. 29 Controllers Processors Personal Data Sep 6, 2022
€10,000 Clio S.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on Clio S.r.l.. Clio provides and manages a whistleblowing reporting application for various private and public entities. As part… ITALY ·Garante ·Art. 2, 5, 6 +1 Processors Controllers Processing Agreement Jul 21, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Lawful Basis Controllers Jul 19, 2022
€1,500 Wens Experience SRL: Insufficient data processing agreement The Romanian DPA has imposed a fine of EUR 1,500 on Wens Experience SRL. In the course of its investigation, the DPA found that Wens Experience, in the course of acting as a… ROMANIA ·ANSPDCP ·Art. 28 Controllers Processors Processing Agreement Jun 8, 2022
€200,000 Amiu S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 200,000 on Amiu S.p.A.. The company operates the waste collection service for the city of Taranto and acted as a processor for this… ITALY ·Garante ·Art. 5, 6, 28 +1 Video Surveillance Audit Logs Monitoring Apr 28, 2022
€20,000 Nos s.r.l.s.: Insufficient legal basis for data processing The Italian DPA fined Nos s.r.l.s. in the amount EUR 20,000. Nos acted as a processor for Vodafone and did advertising for the telecommunications company. For this purpose, Nos… ITALY ·Garante ·Art. 5, 6, 7 +2 Personal Data Processors Direct Marketing Apr 28, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY ·Garante ·Art. 28 Processing Agreement IP Address Data Processor Apr 7, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·azop ·Art. 32 Data Breaches Integrity and Confidentiality Principle Controllers Mar 8, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·Art. 5, 24, 28 +2 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jan 26, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Encryption Data Breaches Security Jan 19, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Data Breaches Encryption Security Jan 19, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processing Personal Data Jan 5, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Processors Controllers Jan 1, 2022
€5,000 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on DW Dynamic Works LIMITED. The controller operated as a processor for Hermes Airport Ltd.. Hermes had suffered a cyberattack… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Privacy by Design & Default Jan 1, 2022
€7,500 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 7,500 on DW Dynamic Works LIMITED. The controller operated as a processor for the Cypriot Ministry of Denfese. The minsitry had suffered… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Privacy by Design & Default Jan 1, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Art. 24, 28 ·Insufficient data processing agreement Controllers Processors Processing Agreement Jan 1, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Data Breaches Security Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Public Sector Privacy by Design & Default Jan 1, 2022
€3,400 Company: Insufficient legal basis for data processing The Czech DPA imposed a fine of EUR 3,400 on a company. The data subject had concluded an energy supply contract with the controller in the past, but then duly terminated it.… CZECH REPUBLIC ·UOOU ·Insufficient legal basis for data processing Controllers Processors Processing Agreement Jan 1, 2022
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Privacy by Design & Default Dec 28, 2021
€1,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,000 on a legal person. For at least two months, the accused incorrectly included 50 entities in the published list of processors, even… CZECH REPUBLIC ·UOOU ·Art. 12 Personal Data Processing Agreement Processors Nov 1, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet ·Art. 5, 28, 32 +1 Processors Controllers Processing Agreement Sep 27, 2021
€900,000 Vattenfall Europe Sales GmbH: Insufficient data processing agreement The DPA from Hamburg has imposed a fine of EUR 900,000 on Vattenfall Europe Sales GmbH. The fine is related to data matching, which the controller had carried out in the period… GERMANY ·Art. 12, 13 ·Insufficient data processing agreement Processing Agreement Fairness & Transparency Controllers Sep 24, 2021
€3.3M Sky Italia S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has fined Sky Italia S.r.l. EUR 3,296,326 for illegal telemarketing. The DPA's decision followed a complex investigation launched after dozens of reports… ITALY ·Garante ·Art. 5, 6, 7 +5 Right to Object Direct Marketing Processing Agreement Sep 16, 2021
€1,800 Agency: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on an agency. The controller had disposed of documents containing personal data of its clients in the garbage. The AEPD considered this… SPAIN ·aepd ·Art. 32 Security Processors Controllers Aug 23, 2021
€400,000 Monsanto Company: Insufficient fulfilment of information obligations The French DPA (CNIL) has fined MONSANTO EUR 400,000. In May 2019, several media revealed that MONSANTO was in possession of a file containing the personal data of more than 200… FRANCE ·CNIL ·Art. 14, 28 Social Media Fairness & Transparency Right to Object Jul 26, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Controllers Processors Fines Jul 22, 2021
€4,200 Marbella Resorts S.L.: Insufficient data processing agreement The Spanish DPA (AEPD) has imposed a fine of EUR 7,000 on Marbella Resorts S.L.. In the case at hand, the data subject had booked a room in the hotel complex of the controller. On… SPAIN ·aepd ·Art. 28 Processing Agreement Controllers Personal Data Jul 6, 2021
Insurance company: Insufficient fulfilment of information obligations The DPA has ex officio, without prior notice, conducted a direct supervision over an insurance company based in Zagreb. Upon inspection of its business facility for carrying out… CROATIA ·azop ·Art. 13, 14 Video Surveillance Insurance Monitoring Jul 5, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·azop ·Art. 32 Processors Controllers Data Breaches Jul 5, 2021
€100,000 Vodafone España, SAU: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Vodafone España, S.A.U.. A data subject had filed a complaint with the Spanish DPA against the telecommunications… SPAIN ·aepd ·Art. 28 Telecommunications Processors Controllers May 25, 2021
€1,500 Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A.,… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Processors Controllers Apr 19, 2021
Security company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A data controller using the services of the security company reported the breach of personal data to the DPA, arising after an employee of the security company recorded the video… CROATIA ·azop ·Art. 32 Security Controllers Processors Feb 22, 2021
€60,000 Roma Servizi per La Mobilita S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined Roma Servizi per La Mobilita S.r.l. EUR 60,000 for failing to take adequate technical and organizational measures regarding the data of citizens… ITALY ·Garante ·Art. 32 Security Controllers Processors Feb 11, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Controllers Processors Processing Agreement Jan 14, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles DPIA Accountability Controllers Jan 1, 2021
€3,000 Avata Hispania, S.L.: Insufficient legal basis for data processing Infringement of Art. 28 (3) g) GDPR, since personal data were further processed after the controller had terminated the contractual relationship with the processor. SPAIN ·aepd ·Art. 5, 6, 28 Controllers Processors IP Address Oct 3, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 13 +2 Healthcare Processors Healthcare Sep 30, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 9 +1 Healthcare Security Controllers Sep 30, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. Proceedings were initiated following an inspection carried out in response to a complaint. The accused processed and… CZECH REPUBLIC ·UOOU ·Art. 5, 13, 28 +1 Processors Controllers Cookies Sep 25, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Telecommunications Cookies Supervision Sep 7, 2020
HDPA (Greece) - 23/2020 The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Art. 4, 5, 12 +6 Personal Data Controllers Human Resources Jul 30, 2020
€200,000 Merlini s.r.l.: Insufficient legal basis for data processing The company had carried out telemarketing activities on behalf of Wind Tre S.p.A. through a third party provider as data processor without sufficient legal basis fpr data… ITALY ·Garante ·Art. 5, 6, 7 +2 Processors Controllers Processing Jul 13, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·Art. 26 ·Insufficient data processing agreement Processing Agreement IP Address Data Processor Jan 1, 2020
€9,380 Major of Aleksandrów Kujawski: Insufficient data processing agreement No data processing agreement has been concluded with the company whose servers contained the resources of the Public Information Bulletin (BIP) of the Municipal Office in… POLAND ·UODO ·Art. 28 Processing Agreement IP Address Education Oct 18, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Garante ·Art. 32 Controllers Data Breaches Processors Apr 17, 2019