Content type · 1,535 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€600,000 Google Belgium SA: Insufficient fulfilment of data subjects rights The Belgian data protection authority has fined Google Belgium SA, a subsidiary of Google, 600,000 euros. The reasons for the fine were the rejection of an application by a data… ·Art. 5, 6, 12 +1 ·Insufficient fulfilment of data subjects rights Jul 14, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide evidence that the data subject had consented to the scanning or copying of their ID card… CZECH REPUBLIC · ·Art. 5, 6, 7 +3 Jul 14, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY · ·Art. 32, 35 Jul 10, 2020
€1,500 Auto Desguaces Iglesias S.L.: Non-compliance with general data processing principles The company had installed surveillance cameras that recorded the public road and therefore violated the principle of data minimization. SPAIN · ·Art. 5 Jul 10, 2020
€3,400 East Power Sp. z o.o.: Insufficient cooperation with supervisory authority After three subpoenas to East Power, in which the latter failed to provide sufficient explanations on a direct marketing complaint, the data protection authority found that East… POLAND · ·Art. 31, 58 Jul 10, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA · ·Art. 32 Jul 9, 2020
€15,000 Mapei S.p.A.: Insufficient fulfilment of data subjects rights Mapei failed to respond to the request for access to personal data of the data subject. In addition, Mapei had left the e-mail account of the person concerned active even after… ITALY · ·Art. 5, 12, 13 +1 Jul 2, 2020
€6,000 National Police Brigade: Insufficient legal basis for data processing Making copies of a company's business records in the context of investigations which contained data from third parties and for which there was no legal basis for processing. SPAIN · ·Art. 5, 6 Jun 19, 2020
€4,010 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 4,010 on a legal person. The order was issued based on the carried out inspection. The accused failed to respond to numerous requests to… CZECH REPUBLIC · ·Art. 17 Jun 11, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jun 11, 2020
€1,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN · ·Art. 5 Jun 9, 2020
€2,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN · ·Art. 5 Jun 9, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN · ·Art. 6 Jun 9, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND · ·Art. 5, 6, 35 May 29, 2020
€100,000 Posti Group Oyj: Insufficient fulfilment of data subjects rights The decision relates to complaints alleging that data subjects received direct marketing from the company although they had requested that their postal data be deleted.… FINLAND · ·Art. 12, 13, 14 +1 May 22, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM · ·Art. 31, 37, 58 Apr 28, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Apr 23, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE · ·Art. 5, 6 Apr 7, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA · ·Art. 32 Mar 25, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN · ·Art. 58 Mar 18, 2020
€4,000 Private Person: Insufficient legal basis for data processing On a beach, a private person secretly photographed female bathers. The incident was reported to the AEPD by the local police. SPAIN · ·Art. 5, 6 Mar 16, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA · ·Art. 15 Mar 13, 2020
€6,000 Casa Gracio Operation: Non-compliance with general data processing principles The company used CCTV cameras in the premises of a hotel which also captured the public roads outside the hotel resulting in a violation of the so called principle of data… SPAIN · ·Art. 5 Feb 25, 2020
€75,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine preceded the complaint by the data subject, who argued that Vodafone España had signed a contract for the transfer of a telephone subscription with a third party without… SPAIN · ·Art. 5, 6 Feb 3, 2020
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine was preceded by a complaint from the data subject, who argued that he had received an e-mail from Vodafone España, which contained the billing of a telephone line that… SPAIN · ·Art. 5, 6 Feb 3, 2020
€4,000 Comune di Colledara: Insufficient legal basis for data processing Publication of documents relating to a public tender with personal data on a website ITALY · ·Art. 5, 6 Jan 30, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY · ·Art. 5, 32 Jan 23, 2020
€3,600 Zhang Bordeta 2006, S.L. (Store and Restaurant): Non-compliance with general data processing principles The store and restaurant owner installed a video surveillance system which, among others, also took pictures of the sidewalk and thus of the public space, which violates the… SPAIN · ·Art. 5 Jan 14, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 13, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
Police officer: Insufficient legal basis for data processing Several cases in which police officers have accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Jan 1, 2020
€300 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·Art. 6, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
€400 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·Art. 26 ·Insufficient data processing agreement Jan 1, 2020
€150,000 Aegean Marine Petroleum Network Inc.: Insufficient technical and organisational measures to ensure information security Companies outside the Aegean Marine Petroleum Group had access to its servers containing personal data and copied the contents of the servers, since Aegean Marine Petroleum failed… GREECE · ·Art. 5, 6, 32 Dec 19, 2019
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Dec 18, 2019
€2,000 Nursing Care Organisation: Insufficient fulfilment of data subjects rights The company failed to act on requests from the data subject to get access to his data and to have his data erased. BELGIUM · ·Art. 12, 15, 17 Dec 17, 2019
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM · ·Art. 32 Dec 17, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company has excessively processed the personal data of his employees through the video cameras installed in the offices and in the places where there are cabinets where the… ROMANIA · ·Art. 5, 6, 7 Dec 13, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Dec 3, 2019
€75,000 Curenergía Comercializador de último recurso: Insufficient legal basis for data processing An individual filed a complaint against the company alleging that the company had used its personal data as a former customer, such as first and last name, VAT identification… SPAIN · ·Art. 6 Nov 28, 2019