Content type · 1,535 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA · ·Art. 32 Nov 25, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE · ·Art. 5, 6, 13 +4 Nov 21, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN · ·Art. 5 Nov 14, 2019
€3,000 General Confederation of Labour ('CGT'): Insufficient legal basis for data processing The CGT, with the aim of convening a meeting, e-mailed personal data of the complainant, including her home address, family relationship, pregnancy status and the date of an… SPAIN · ·Art. 6 Nov 13, 2019
€9,000 Inteligo Media SA: Insufficient legal basis for data processing As part of the registration process on the webseite avocatnet.ro, the operator used an unfilled checkbox, by means of which users could declare that they did not wish to receive… ROMANIA · ·Art. 5, 6 Sep 26, 2019
€10,000 Merchant: Non-compliance with general data processing principles The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's… BELGIUM · ·Art. 5 Sep 17, 2019
€660,000 Morele.net: Insufficient technical and organisational measures to ensure information security The Polish data protection authority imposed a fine of over PLN 2.8 million (approx. €644,780) on Morele.net for insufficient organisational and technical safeguards, which led to… POLAND · ·Art. 32 Sep 10, 2019
€1,121 Private enforcement agent: Insufficient fulfilment of data subjects rights The fine of EUR 1, 121 was imposed on a private enforcement agent for processing of the personal data of data subject through recording by technical means for video surveillance… BULGARIA · ·Art. 12, 15 Sep 3, 2019
€5,113 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA · ·Art. 6, 25 Sep 3, 2019
€1,022 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA · ·Art. 6, 25 Sep 3, 2019
CNPD (Portugal) - Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Art. 2, 3, 5 +8 Sep 3, 2019
€60,000 AVON COSMETICS: Insufficient legal basis for data processing A consumer claimed that AVON COSMETICS had unlawfully processed his data without adequately verifying his identity, which led to his data being erroneously entered in a register… SPAIN · ·Art. 6 Aug 16, 2019
€4,290 Public area maintenance company: Non-compliance with general data processing principles An ex-employee complained that his employer unlawfully monitored his work by its CCTV. The employer argued that CCTV monitoring was necessary to assess, whether the employee… HUNGARY · ·Art. 5, 6, 13 Aug 2, 2019
€150,000 PWC Business Solutions: Insufficient legal basis for data processing The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to… GREECE · ·Art. 5, 6, 13 +1 Jul 30, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA · ·Art. 32 Jul 5, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA · ·Art. 32 Jul 2, 2019
€2,000 Local bank: Insufficient fulfilment of data subjects rights Customer of a local bank requested access to telephone conversation recordings as well as to CCTV recordings. The bank provided the copies of the recordings of telephone… HUNGARY · ·Art. 12, 15, 18 May 31, 2019
€400,000 SERGIC (Real Estate): Insufficient technical and organisational measures to ensure information security The CNIL based the penalty on two grounds: Lack of basic security measures and excessive data storage. As to the first, sensitive user documents uploaded by rental candidates… FRANCE · ·Art. 5 May 28, 2019
€1,400 Police Officer: Insufficient legal basis for data processing The police officer, using his official user ID but without reference to official duties, queried the owner data concerning the license plate of a person who he did not know well… GERMANY ·Art. 6 ·Insufficient legal basis for data processing May 9, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY · ·Art. 32 Apr 17, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Apr 12, 2019
€34,375 Hungarian political party: Insufficient fulfilment of data breach notification obligations NAIH imposed a fine of HUF 11,000,000 (EUR 34,375) on an undisclosed Hungarian political party for failing to notify the NAIH and relevant individuals about a data breach, and… HUNGARY · ·Art. 33, 34 Apr 5, 2019
€220,000 Private company working with data from publicly available sources: Insufficient fulfilment of information obligations The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the… POLAND · ·Art. 14 Mar 26, 2019
€50,000 N26: Insufficient legal basis for data processing The fine was imposed against against a bank (according to a newspaper N26) that had processed 'personal data of all former customers' without permission.The Bank has acknowledged… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Mar 1, 2019
€3,200 Mayor's Office of the city of Kecdkemét: Insufficient legal basis for data processing The fine was imposed on the Mayor’s Office of the city of Kecskemét for unlawful disclosure of the personal information of a whistleblower.NAIH imposed the fine after an employee… HUNGARY · ·Art. 5, 6 Feb 28, 2019
€27,100 Telecommunication service provider: Insufficient legal basis for data processing Repeated registration of prepaid services without the knowledge and consent of the data subject Employees of the telecommunications provider have used personal data and registered… BULGARIA · ·Art. 5, 6 Feb 26, 2019
€50M Google LLC: Insufficient legal basis for data processing The fine was imposed on the basis of complaints from the Austrian organisation 'None Of Your Business' and the French NGO 'La Quadrature du Net'. The complaints were filed on 25th… FRANCE · ·Art. 5, 6, 13 +1 Jan 21, 2019
€160,000 Taxa 4x35: Non-compliance with general data processing principles The Danish DPA reported the taxi company to the police and recommended a fine (of 1.2M DKK) for non-adherence to the data-minimization principle. While the company deleted the… DENMARK · ·Art. 5 Jan 1, 2019
€20,000 Hamburger Verkehrsverbund GmbH (HVV GmbH): Insufficient fulfilment of data breach notification obligations On July 6, 2018, HVV GmbH was informed by a customer about a security gap on the website www.hvv.de, which was caused by an update on February 5, 2018 and concerned the so-called… GERMANY ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Jan 1, 2019
€10,000 Newspaper: Insufficient legal basis for data processing The publication of the newspaper, both in hard copy and in electronic form, allegedly involved inconvenience, unnecessary and unlawful detention of a citizen, and revealed the… CYPRUS ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2019
€500 GERMANY DPA: Insufficient fulfilment of data subjects rights A data controller failed to comply with data subject´s request to access their personal data. Art. 15 ·Insufficient fulfilment of data subjects rights Jan 1, 2019
€800 Police Officer: Insufficient legal basis for data processing A police officer used a witness's personal data to contact her personally. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2019
€500 Bank: Insufficient legal basis for data processing A fine of 1000 BGN (or roughly 500 EUR) was imposed on a bank for calling a client for the unresolved bills of his neighbor. This provoked the client to evoke his right to be… BULGARIA · ·Art. 5, 6 Dec 4, 2018
€20,000 Knuddels.de: Insufficient technical and organisational measures to ensure information security After a hacker attack in July personal data of approx. 330.000 users, including passwords and email addresses had been revealed. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Nov 21, 2018
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL · ·Art. 5, 32 Jul 17, 2018