Skip to content
Content type · 1,535 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1451–1500 of 1,535 sort newestlargest fineoldest
€600,000 Google Belgium SA: Insufficient fulfilment of data subjects rights The Belgian data protection authority has fined Google Belgium SA, a subsidiary of Google, 600,000 euros. The reasons for the fine were the rejection of an application by a data… APD ·Art. 5, 6, 12 +1 ·Insufficient fulfilment of data subjects rights Right to be Forgotten Fairness & Transparency Personal Data Jul 14, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide evidence that the data subject had consented to the scanning or copying of their ID card… CZECH REPUBLIC ·UOOU ·Art. 5, 6, 7 +3 IP Address Personal Data Consent Jul 14, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet ·Art. 32, 35 DPIA Privacy Impact Assessment Health Data Jul 10, 2020
€1,500 Auto Desguaces Iglesias S.L.: Non-compliance with general data processing principles The company had installed surveillance cameras that recorded the public road and therefore violated the principle of data minimization. SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Jul 10, 2020
€3,400 East Power Sp. z o.o.: Insufficient cooperation with supervisory authority After three subpoenas to East Power, in which the latter failed to provide sufficient explanations on a direct marketing complaint, the data protection authority found that East… POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Law Enforcement Jul 10, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA ·ANSPDCP ·Art. 32 Right of Access Security Social Media Jul 9, 2020
€15,000 Mapei S.p.A.: Insufficient fulfilment of data subjects rights Mapei failed to respond to the request for access to personal data of the data subject. In addition, Mapei had left the e-mail account of the person concerned active even after… ITALY ·Garante ·Art. 5, 12, 13 +1 Right of Access Personal Data Supervisory Authorities Jul 2, 2020
€6,000 National Police Brigade: Insufficient legal basis for data processing Making copies of a company's business records in the context of investigations which contained data from third parties and for which there was no legal basis for processing. SPAIN ·aepd ·Art. 5, 6 Public Authority Education Processing Jun 19, 2020
€4,010 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 4,010 on a legal person. The order was issued based on the carried out inspection. The accused failed to respond to numerous requests to… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Jun 11, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Telecommunications Jun 11, 2020
€1,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Jun 9, 2020
€2,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Jun 9, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN ·aepd ·Art. 6 Representatives Personal Data Telecommunications Jun 9, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6, 35 Video Surveillance Privacy Impact Assessment DPIA May 29, 2020
€100,000 Posti Group Oyj: Insufficient fulfilment of data subjects rights The decision relates to complaints alleging that data subjects received direct marketing from the company although they had requested that their postal data be deleted.… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 13, 14 +1 Personal Data Direct Marketing Marketing May 22, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM ·APD ·Art. 31, 37, 58 Notified Body Responsibilities and Operational Obligations Supervisory Authorities Law Enforcement Apr 28, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Accuracy Security Telecommunications Apr 23, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE ·HDPA ·Art. 5, 6 Video Surveillance IP Address Monitoring Apr 7, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Law Enforcement Mar 25, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN ·aepd ·Art. 58 Right of Access Procedures Right of Access Inspection Access Rights and Cooperation Obligations Mar 18, 2020
€4,000 Private Person: Insufficient legal basis for data processing On a beach, a private person secretly photographed female bathers. The incident was reported to the AEPD by the local police. SPAIN ·aepd ·Art. 5, 6 Processing Supervisory Authorities Law Enforcement Mar 16, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA ·azop ·Art. 15 Right of Access Procedures Right of Access Personal Data Mar 13, 2020
€6,000 Casa Gracio Operation: Non-compliance with general data processing principles The company used CCTV cameras in the premises of a hotel which also captured the public roads outside the hotel resulting in a violation of the so called principle of data… SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Feb 25, 2020
€75,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine preceded the complaint by the data subject, who argued that Vodafone España had signed a contract for the transfer of a telephone subscription with a third party without… SPAIN ·aepd ·Art. 5, 6 IP Address Consent Personal Data Feb 3, 2020
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine was preceded by a complaint from the data subject, who argued that he had received an e-mail from Vodafone España, which contained the billing of a telephone line that… SPAIN ·aepd ·Art. 5, 6 Personal Data Consent Telecommunications Feb 3, 2020
€4,000 Comune di Colledara: Insufficient legal basis for data processing Publication of documents relating to a public tender with personal data on a website ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Jan 30, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Jan 23, 2020
€3,600 Zhang Bordeta 2006, S.L. (Store and Restaurant): Non-compliance with general data processing principles The store and restaurant owner installed a video surveillance system which, among others, also took pictures of the sidewalk and thus of the public space, which violates the… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Jan 14, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Right of Access Security Insurance Jan 13, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing Several cases in which police officers have accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Fairness & Transparency Controllers Personal Data Jan 1, 2020
€300 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Personal Data Fairness & Transparency Controllers Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·Art. 6, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Processing Agreement Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€400 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·Art. 26 ·Insufficient data processing agreement Processing Agreement IP Address Data Processor Jan 1, 2020
€150,000 Aegean Marine Petroleum Network Inc.: Insufficient technical and organisational measures to ensure information security Companies outside the Aegean Marine Petroleum Group had access to its servers containing personal data and copied the contents of the servers, since Aegean Marine Petroleum failed… GREECE ·HDPA ·Art. 5, 6, 32 Security Privacy by Design & Default Personal Data Dec 19, 2019
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Telecommunications Security Dec 18, 2019
€2,000 Nursing Care Organisation: Insufficient fulfilment of data subjects rights The company failed to act on requests from the data subject to get access to his data and to have his data erased. BELGIUM ·APD ·Art. 12, 15, 17 Personal Data Supervisory Authorities Law Enforcement Dec 17, 2019
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM ·ICO ·Art. 32 Healthcare Healthcare Liability Dec 17, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company has excessively processed the personal data of his employees through the video cameras installed in the offices and in the places where there are cabinets where the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 IP Address Employees Personal Data Dec 13, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2019
€75,000 Curenergía Comercializador de último recurso: Insufficient legal basis for data processing An individual filed a complaint against the company alleging that the company had used its personal data as a former customer, such as first and last name, VAT identification… SPAIN ·aepd ·Art. 6 Personal Data Processing Supervisory Authorities Nov 28, 2019