Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1451–1500 of 2,273 sort newestlargest fineoldest
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches DPIA Security Jan 27, 2022
BfDI (Germany) - 24-191 II The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Art. 15, 20, 95 Telecommunications Recipient Data Portability Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD ·Art. 5, 6, 9 +3 Religious Beliefs Fairness & Transparency Social Media Jan 27, 2022
€40,000 T.S.M. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on T.S.M. s.r.l.. A data subject had filed a complaint with the DPA against the company for failing to comply with their requests… ITALY ·Garante ·Art. 13, 15, 21 +2 Personal Data Processing Agreement Processing Jan 27, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD ·Art. 5, 6, 9 +5 Religious Beliefs Social Media Fairness & Transparency Jan 27, 2022
€3.2M OTE Group: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 3.2 million on Cosmote subsidiary OTE Group. Among other things, OTE Group had contributed to Cosmote's security infrastructure. Cosmote… GREECE ·HDPA ·Art. 32 Data Breaches Notification Obligation Security Jan 27, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Healthcare Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Data Breaches Jan 26, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·Art. 5, 24, 28 +2 ·Insufficient technical and organisational measures to ensure information security Data Breaches Controllers Security Jan 26, 2022
Belgian DPA rules on competence in cross-border cookie consent complaint involving The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·APD/GBA Supervisory Authorities Cookies Legitimate Interest Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Right of Access Procedures Right of Access Personal Data Jan 20, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Data Breaches Encryption Security Jan 19, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Encryption Security Jan 19, 2022
€117,000 Santander Bank Polska S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 118,000 for failing to notify data subjects of a data breach. A former employee of the bank managed to gain unauthorized… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Notified Body Reporting and Notification Obligations Jan 19, 2022
€15,000 GARLEX SOLUTIONS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on GARLEX SOLUTIONS, S.L.. The data subject had received a call from the company to renew their electricity supply… SPAIN ·aepd ·Art. 6 Personal Data Processing Agreement Processing Jan 18, 2022
€56,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on VODAFONE ESPAÑA, S.A.U. due to insufficient legal basis for data processing. The data subject states that two telephone connections were… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Jan 18, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
€2,400 PHARMA TALENTS, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's… SPAIN ·aepd ·Art. 5, 32 Security Healthcare Personal Data Jan 14, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS ·AP ·Art. 12 Controllers Personal Data Data Controller Jan 14, 2022
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Personal Data Jan 13, 2022
€1,000 A.S.L. Napoli 1 Centro: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 1,000 on A.S.L. Napoli 1 Centro. An employee at the health authority had filed a complaint with the DPA against the… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Healthcare IP Address Jan 13, 2022
€14,000 Azienda sanitaria unica regionale Marche: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 14,000 on Azienda sanitaria unica regionale Marche. The DPA launched an investigation against the health department following media… ITALY ·Garante ·Art. 5, 32, 35 Healthcare Security Privacy by Design & Default Jan 13, 2022
€4,000 Medicina & Lavoro s.r.l.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Healthcare Personal Data Supervisory Authorities Jan 13, 2022
€9,000 EDUCANDO JUNTOS SL: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 9,000 on EDUCANDO JUNTOS SL. The controller had published photos of an employee on some of its channels on social networks and its… SPAIN ·aepd ·Art. 6, 17 Controllers Personal Data Processing Agreement Jan 11, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Personal Data Processing Jan 5, 2022
€1,000 Εγνατία Οδός Α.Ε.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 1,000 on Εγνατία Οδός Α.Ε. The company operated a video surveillance system to monitor the payment of tolls. A car owner, who had… GREECE ·HDPA ·Art. 12 Video Surveillance Monitoring Personal Data Jan 5, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Data Breaches Security Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Berlin has imposed a fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with their personal data… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Direct Marketing Jan 1, 2022
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2022
€250,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has failed to implement appropriate technical and organizational measures to protect personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Privacy by Design & Default Jan 1, 2022
€1,400 Dentist: Non-compliance with general data processing principles The Hungarian DPA has fined a dentist EUR 1,300. The controller had installed several surveillance cameras in their practice, which permanently recorded employees and patients.… HUNGARY ·NAIH ·Non-compliance with general data processing principles Video Surveillance Monitoring Healthcare Jan 1, 2022
Company: Insufficient legal basis for data processing The DPA of Bremen has imposed a five-digit fine on a company. The company had sent an unredacted social plan to all affected employees in the context of dismissals due to… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Employees Processing Jan 1, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jan 1, 2022
€65,000 MALTA DPA: Non-compliance with general data processing principles The controller has violated numerous GDPR regulations, involving special categories of personal data of numerous individuals. Art. 5, 6, 9 +3 ·Non-compliance with general data processing principles Personal Data IP Address Controllers Jan 1, 2022
Physician: Insufficient fulfilment of data subjects rights The DPA of Bremen imposed a fine on a physician for failing to respond to a data subject's request for access to their data in a timely manner. GERMANY ·Art. 12 ·Insufficient fulfilment of data subjects rights Healthcare Personal Data Supervisory Authorities Jan 1, 2022
Company: Insufficient fulfilment of information obligations The DPA of Bremen has imposed a three-digit fine on a company. The company offered its applicants an online application procedure on its website without informing users about the… GERMANY ·Art. 12, 13 ·Insufficient fulfilment of information obligations Personal Data Processing Human Resources Jan 1, 2022
€2,700 Covid-19 test center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Healthcare Security Jan 1, 2022
€1,800 Covid-19 test center: Non-compliance with general data processing principles The DPA of Hessen imposed a fine of EUR 1,800 on a Covid-19 test center. An employee had taken an adhesive label from the trash, written the test center's e-mail address on it and… GERMANY ·Art. 5, 6 ·Non-compliance with general data processing principles Healthcare Personal Data IP Address Jan 1, 2022
€1,300 Website operator: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,300 on a website operator. An individual had filed a complaint with the DPA against the controller due to the fact that the… HUNGARY ·NAIH ·Art. 5, 12, 31 Personal Data Controllers Supervisory Authorities Jan 1, 2022
€3,400 Company: Insufficient legal basis for data processing The Czech DPA imposed a fine of EUR 3,400 on a company. The data subject had concluded an energy supply contract with the controller in the past, but then duly terminated it.… CZECH REPUBLIC ·UOOU ·Insufficient legal basis for data processing Controllers Processors Processing Agreement Jan 1, 2022
Logistics company: Insufficient technical and organisational measures to ensure information security A logistics company had disposed of delivery lists in a public waste paper container. The lists contained a large amount of detailed information, such as the first and last names… GERMANY ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security IP Address Jan 1, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Processors Controllers Jan 1, 2022
€1,000 Covid-19 test center: Insufficient fulfilment of data subjects rights The DPA of Hamburg has fined a Covid-19 test center EUR 1,000 for failing to comply with the right of data subjects to have their personal data deleted. GERMANY ·Art. 17 ·Insufficient fulfilment of data subjects rights Healthcare Personal Data Processing Agreement Jan 1, 2022
Company: Insufficient fulfilment of data subjects rights The DPA of Bremen imposed a fine on a company for failing to respond to a data subject's request for access to their data in a timely manner. GERMANY ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Processing Agreement Jan 1, 2022
€16,400 Covid-19 test center: Insufficient legal basis for data processing The DPA of Hessen has fined a Covid-19 test center EUR 16,400. The controller had sent an e-mail containing personal data to several recipients in an open distribution list. The… GERMANY ·Art. 6, 33 ·Insufficient legal basis for data processing Data Breaches Healthcare IP Address Jan 1, 2022
€5,000 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on DW Dynamic Works LIMITED. The controller operated as a processor for Hermes Airport Ltd.. Hermes had suffered a cyberattack… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processors Jan 1, 2022
€50,000 Company: Insufficient fulfilment of data subjects rights The DPA of Niedersachsen has imposed a fine of EUR 50,000 on a company. The company sent out a newsletter by e-mail that could not be unsubscribed from due to technical… GERMANY ·Art. 15, 21 ·Insufficient fulfilment of data subjects rights Right to Object Personal Data Processing Agreement Jan 1, 2022
Medical care center: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a medical care center for having scanned a customer's ID card against their will and stored the copy. Once the customer complained, they… GERMANY ·Insufficient legal basis for data processing Healthcare Healthcare Personal Data Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processors Jan 1, 2022
Physician: Insufficient legal basis for data processing The DPA of Nordrhein-Westfalen has fined a physician. The physician had responded to a negative online reviews regarding their practice, disclosing personal data of a patient. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Personal Data Education Public Authority Jan 1, 2022