Content type · 472 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY · ·Art. 5, 6, 9 Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 28, 32 Apr 29, 2025
€7,800 Uitvaartonderneming: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND · ·Art. 5 Apr 15, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND · ·Art. 5 Apr 15, 2025
€5,000 Gynaecologist: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 5,000 on a gynaecologist. The controller failed to completely fullfill an information request by a patient. GREECE · ·Art. 15 Apr 9, 2025
€5,000 Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 15 Apr 9, 2025
€20,000 Hospital: Non-compliance with general data processing principles Data Protection Commissioner of Malta fined Hospital €20,000 on 2025-04-02 for: Non-compliance with general data processing principles. Malta ·Art. 5, 6, 14 +2 ·Non-compliance with general data processing principles Apr 2, 2025
€3.5M Advanced Computer Software Group Ltd: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.500.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM · ·Art. 32 Mar 26, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM · ·Art. 32 Mar 26, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND · ·Art. 6, 9 Mar 24, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA · ·Art. 32 Mar 24, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€40,000 Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 5, 6, 12 +3 Mar 24, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA · ·Art. 13, 32, 33 +1 Mar 24, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€500 GALENICUM HEALTH, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500 on GALENICUM HEALTH, S.L.U. The controller uses video surveillance that partially captures images of a public road, which infringes… SPAIN · ·Art. 5 Mar 20, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA · ·Art. 12, 15 Feb 27, 2025
€600,000 IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including… SPAIN · ·Art. 5 Feb 25, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA · ·Art. 32 Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA · ·Art. 5, 6, 9 Feb 17, 2025
€34,300 Primary Health Care in the Capital Area: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 34,300 on the Primary Health Care in the Capital Area. The controller processed personal and health data in shared medical record… ICELAND ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Feb 17, 2025
€500,000 MARINA SALUD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500,000 on MARINA SALUD, S.A. Marina Salud, acting as a processor for a health authority, engaged sub-processors without obtaining the… SPAIN · ·Art. 28 Feb 5, 2025
Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected… ESTONIA · ·Insufficient technical and organisational measures to ensure information security Jan 10, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA · ·Art. 24, 32 Jan 3, 2025
€200,000 Hospital: Insufficient technical and organisational measures to ensure information security The Belgian DPA has fined a hospital EUR 200,000. The hospital had suffered a ransomware attack through a vulnerability in the server, which paralyzed parts of the computer system… BELGIUM · ·Art. 5, 24, 32 +1 Dec 17, 2024
€20,000 Physician: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on a physician who had published images of a patient who had undergone cosmetic surgery on a social network without their consent. ITALY · ·Art. 2, 5, 9 Dec 12, 2024
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND · ·Art. 33, 34 Nov 26, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK · ·Insufficient technical and organisational measures to ensure information security Nov 12, 2024
€1,000 KUR KLINIKUM, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1000 on KUR KLINIKUM, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN · ·Art. 58 Oct 17, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA · ·Art. 5, 6, 12 +4 Sep 13, 2024
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE · ·Art. 5, 66 Sep 12, 2024
€20,900 Eidskog municipality: Insufficient legal basis for data processing The Norwegian DPA imposed a fine of EUR 20,900 on Eidskog municipality for giving two former employees access to a whistleblower’s report without redacting sensitive health and… NORWAY · ·Art. 6 Sep 6, 2024
€698,000 Apohem AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 698,000 on Apohem AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Aug 29, 2024
€3.2M Apoteket AB.: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 3.2 million on Apoteket AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Aug 29, 2024
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… Jul 22, 2024
€10,000 Clinic owner: Insufficient legal basis for data processing The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the… SPAIN · ·Art. 6, 9 Jul 5, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY · ·Art. 5, 25, 32 +1 Jul 4, 2024
€4,000 Medical association: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,000 on the medical association 'Ordine dei Medici Chirurghi e degli Odontoiatri'. A patient had filed a complaint with the DPA. During… ITALY · ·Art. 12, 13, 15 Jun 20, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND · ·Art. 24, 25, 32 +1 Jun 13, 2024
€100,000 Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data… AUSTRIA · ·Art. 5, 9, 28 +2 Jun 6, 2024
€500 Comune di Ustica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500 on Comune di Ustica. The municipality had published a document, containing personal data (including health data) of private… ITALY · ·Art. 2, 5, 6 +2 Jun 6, 2024
€8,400 Azienda Sanitaria Locale TO4: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,400 on Azienda Sanitaria Locale TO4. The controller had sent an email containing information on medical treatment plans to several… ITALY · ·Art. 5, 9 May 23, 2024
€4,500 Azienda Socio-sanitaria Territoriale Rhodense: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,500 on Azienda Socio-sanitaria Territoriale Rhodense. An individual had filed a complaint with the DPA because the controller had not… ITALY · ·Art. 5, 12, 16 May 23, 2024
€336,000 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 336,000 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During… POLAND · ·Art. 5, 32 May 20, 2024
€75,000 Azienda ospedale università di Padova: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 75,000 on Azienda ospedale università di Padova. During its investigation, the DPA found that employees had accessed patient files… ITALY · ·Art. 5, 9, 25 +1 May 9, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA · ·Art. 32 May 9, 2024
€3,000 Medical association: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the… ITALY · ·Art. 2, 5, 6 May 9, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN · ·Art. 32, 33 May 8, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA · ·Art. 32 May 8, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS · ·Art. 5 May 2, 2024