Skip to content
Content type · 2,662 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1451–1500 of 2,662 sort newestlargest fineoldest
€480 Private individual: Insufficient legal basis for data processing The Spanish DPA has fined a private individual. The individual had installed video surveillance cameras in a residential complex that also covered common areas. During its… SPAIN ·AEPD ·Art. 6, 13 Personal Data Supervisory Authorities Video Surveillance Dec 9, 2022
€230,000 Viking Line Oy Abp: Non-compliance with general data processing principles The Finnish DPA has imposed a fine of EUR 230,000 on Viking Line Oy Abp. A former employee had filed a complaint with the DPA. During its investigation, the DPA found that the… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Controllers Supervisory Authorities Dec 9, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Dec 9, 2022
€600 LORENT 2013, S.L: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on LORENT 2013, S.L.. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Dec 3, 2022
€300 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on a Homeowners Association. The association had installed several video surveillance cameras across the residential area which, among… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Dec 3, 2022
€3,000 INDECEMI, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,000 on INDECEMI, S.L.. A person had filed a complaint with the DPA against the controller after receiving an email from the controller… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Controllers Dec 3, 2022
€3,500 CASA 7 PERSONAL SHOPPER, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,500 on CASA 7 PERSONAL SHOPPER, S.L. The controller sent an e-mail with personal data to several recipients in an open distribution… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing Dec 2, 2022
€3,600 Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM: Insufficient legal basis for data processing The Spanish DPA has fined the Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM. The controller processed medical data from Covid-19… SPAIN ·AEPD ·Art. 9, 13 Personal Data Controllers Healthcare Dec 2, 2022
€6,000 A.R.N.A.S. Civico: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on A.R.N.A.S. Civico. Two employees of the controller had filed a complaint with the DPA. During its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Healthcare Controllers Dec 1, 2022
€6,000 Store owner (Joy Unique Collection): Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Joy Unique Collection' EUR 6,000 . The controller had operated video surveillance cameras in its premises without the required… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Dec 1, 2022
€3,000 Store owner (Woolen): Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Woolen' EUR 3,000 . The controller had operated video surveillance cameras in its premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Dec 1, 2022
€100,000 Lazio Region: Insufficient legal basis for data processing The Italian DPA has fined Lazio Region EUR 100,000. A trade union had filed a complaint with the DPA alleging that the Region had monitored the e-mail accounts of employees of the… ITALY ·Garante ·Art. 5, 6, 113 +1 Personal Data Processing Employees Dec 1, 2022
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Personal Data Types of Special Categories of Personal Data Healthcare Nov 30, 2022
€3,000 Company: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 3,000 on a company. The controller had installed a video surveillance system that also recorded the voices of both employees and… SPAIN ·AEPD ·Art. 6, 13 Personal Data Controllers Supervisory Authorities Nov 29, 2022
€500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Nov 29, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 25, 2022
€5,000 Association for the prevention and study of crimes, abuses and negligence in information technology and advanced communications (APEDANICA): Non-compliance with general data processing principles The Spanish DPA has fined the Association for the prevention and study of crimes, abuses and negligence in information technology and advanced communications (APEDANICA) EUR… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Transparency Nov 25, 2022
€1,000 Private individual: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on a private individual. Two individuals had filed a complaint with the DPA due to the fact that the controller had published… ITALY ·Garante ·Art. 2, 5, 6 +2 Personal Data Controllers Anonymization Nov 24, 2022
€1M Areti spa: Non-compliance with general data processing principles The Italian DPA has fined electricity supplier Areti spa EUR 1 million. A customer had filed a complaint with the DPA due to Areti classifying them as a defaulting customer, which… ITALY ·Garante ·Art. 5, 12, 15 +1 Personal Data Supervisory Authorities Processing Nov 24, 2022
€4,000 Società Lombarda Sport s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Società Lombarda Sport s.r.l. EUR 4,000. An individual had filed a complaint with the DPA. The individual had undergone a sports fitness examination with… ITALY ·Garante ·Art. 5, 9 Healthcare Processing Supervisory Authorities Nov 24, 2022
€1,000 STS Di Prisinzano s.r.l: Insufficient fulfilment of information obligations The Italian DPA has fined STS Di Prisinzano s.r.l EUR 1,000. The company had processed data of a customer in the context of a breakdown service without sufficiently informing the… ITALY ·Garante ·Art. 5, 13 Personal Data Supervisory Authorities Processing Nov 24, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Personal Data Security Nov 24, 2022
€600,000 ÉLECTRICITÉ DE FRANCE: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on ÉLECTRICITÉ DE FRANCE (EDF), France's largest electricity supplier. The DPA had received several complaints that individuals… CNIL ·Art. 7, 12, 13 +3 ·Insufficient fulfilment of data subjects rights Personal Data Right to Object Direct Marketing Nov 24, 2022
€3,000 Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Board of Surgeons and Dentists of the Province of Cagliari. The controller had disclosed data of a doctor to third parties… ITALY ·Garante ·Art. 2, 5, 6 Controllers Processing Healthcare Nov 24, 2022
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 300 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5 Controllers Processing Video Surveillance Nov 21, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Nov 21, 2022
€300 Homeowners Association Bld. Pipera 1-2E: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined Homeowners Association 'Bld. Pipera 1-2E' EUR 300 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Nov 18, 2022
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Personal Data Nov 16, 2022
€80,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANKINTER, S.A.. A person had filed a complaint with the DPA as personal data of a third person were also displayed to them when accessing… SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Processing Nov 15, 2022
€5,200 News service: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 5,200 on a news service. A customer had complained to the DPA about subscribing to a newsletter to receive a daily news digest, however,… HUNGARY ·NAIH ·Art. 6, 7, 12 Personal Data Consent Controllers Nov 15, 2022
€3,600 XASTRE DO PETO, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 3,600 on XASTRE DO PETO, S.L. (restaurant). An individual had filed a complaint with the DPA due to the fact that the controller required… SPAIN ·AEPD ·Art. 6, 13, 21 Personal Data Controllers Processing Nov 11, 2022
€48,000 Banco Bilbao Vizcaya Argentaria S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. An individual had filed a complaint with the DPA due to requesting information on one of their… SPAIN ·AEPD ·Art. 5, 32 Security Processing Privacy by Design & Default Nov 11, 2022
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE ·CNIL ·Art. 5, 13, 25 +2 Storage Limitation Privacy by Default Retention Period Nov 10, 2022
€500,000 Vodafone Italia S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500,000 on Vodafone Italia S.p.A.. A customer had filed a complaint with the DPA against Vodafone. The 80-year-old customer had been… ITALY ·Garante ·Art. 5, 6, 7 +3 Personal Data Consent Supervisory Authorities Nov 10, 2022
€5,000 Cisterna di Latina Municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Cisterna di Latina Municipality. An individual had filed a complaint with the DPA. The individual had submitted a request to the… ITALY ·Garante ·Art. 5, 12, 37 Public Authority Personal Data Supervisory Authorities Nov 10, 2022
€20,000 Sportitalia: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Sportitalia. The controller processed biometric data (fingerprints) of employees for the purpose of registering their… ITALY ·Garante ·Art. 5, 9, 13 +1 Types of Special Categories of Personal Data Personal Data Controllers Nov 10, 2022
€900 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on a Homeowners Association. The association had installed several video surveillance cameras across the residential area which, among… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Nov 10, 2022
€4,000 Villafranca di Verona municipality: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on Villafranca di Verona municipality. The municipality had published a document containing personal data of an employee on… ITALY ·Garante ·Art. 2, 5, 6 Public Authority Personal Data Processing Nov 10, 2022
€40,000 Azienda Usl Valle d'Aosta: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Usl Valle d'Aosta EUR 40,000. An employee and patient of the health department had filed a complaint with the DPA because a colleague who had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Security Privacy by Design & Default Nov 10, 2022
€10,000 I-Model s.r.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 10,000 on I-Model s.r.l. A data subject had filed a complaint with the DPA against the controller due to the fact that the… ITALY ·Garante ·Art. 6, 17 Personal Data Controllers Supervisory Authorities Nov 10, 2022
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 300 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Nov 10, 2022
€6,000 Conservatorio di Musica S. Cecilia di Roma: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on 'Conservatorio di Musica S. Cecilia di Roma'. A student of the educational institution had filed a complaint with the DPA for… ITALY ·Garante ·Art. 2, 5, 6 +1 Public Authority Controllers Supervisory Authorities Nov 10, 2022
€15,000 Poliambulatorio Radiologico 'il Sorriso' S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Poliambulatorio Radiologico 'il Sorriso' S.r.l.. A patient had filed a complaint with the DPA for not receiving sufficient… ITALY ·Garante ·Art. 5, 13, 37 Personal Data Controllers Supervisory Authorities Nov 10, 2022
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide access to information about the purpose of the processing, the storage period, the… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Recipient Supervision Nov 9, 2022
€1,000 SC Das Sense Society SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Das Sense Society SRL EUR 1,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Nov 9, 2022
€5,000 SC Prestige Media PHG SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on SC Prestige Media PHG SRL. The controller had published 23 documents containing information on the termination of employment… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Nov 8, 2022
€2,000 Romanian Post: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on the Romanian Post. The Post suffered a data breach where staff lost several mailings containing pension statements, employment… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Data Breaches Nov 7, 2022
€60,000 INFORMÁTICA MÉDICA, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 60,000 on INFORMÁTICA MÉDICA, S.L.. The company acted as a processor for other companies and had engaged a subcontractor without,… SPAIN ·AEPD ·Art. 28 Processors Controllers Processing Nov 7, 2022
€75,000 Burwebs S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Burwebs S.L. EUR 75,000. Burwebs operates websites with adult content. During its investigation, the DPA found that Burwebs did not process users' data… SPAIN ·AEPD ·Art. 5, 12, 13 +3 Personal Data Accountability Processing Nov 3, 2022
€70,000 UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC (UPS). A person had filed a complaint with the DPA because UPS had delivered a… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Nov 3, 2022