Skip to content
Content type · 1,535 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1501–1535 of 1,535 sort newestlargest fineoldest
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA ·ANSPDCP ·Art. 32 Right of Access Security Controllers Nov 25, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE ·CNIL ·Art. 5, 6, 13 +4 Personal Data Healthcare Processing Nov 21, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN ·aepd ·Art. 5 Accuracy IP Address Telecommunications Nov 14, 2019
€3,000 General Confederation of Labour ('CGT'): Insufficient legal basis for data processing The CGT, with the aim of convening a meeting, e-mailed personal data of the complainant, including her home address, family relationship, pregnancy status and the date of an… SPAIN ·aepd ·Art. 6 Personal Data IP Address Consent Nov 13, 2019
€9,000 Inteligo Media SA: Insufficient legal basis for data processing As part of the registration process on the webseite avocatnet.ro, the operator used an unfilled checkbox, by means of which users could declare that they did not wish to receive… ROMANIA ·ANSPDCP ·Art. 5, 6 Consent Right to Object Telecommunications Sep 26, 2019
€10,000 Merchant: Non-compliance with general data processing principles The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's… BELGIUM ·APD ·Art. 5 Personal Data IP Address Right of Access Sep 17, 2019
€660,000 Morele.net: Insufficient technical and organisational measures to ensure information security The Polish data protection authority imposed a fine of over PLN 2.8 million (approx. €644,780) on Morele.net for insufficient organisational and technical safeguards, which led to… POLAND ·UODO ·Art. 32 Security Law Enforcement Personal Data Sep 10, 2019
€1,121 Private enforcement agent: Insufficient fulfilment of data subjects rights The fine of EUR 1, 121 was imposed on a private enforcement agent for processing of the personal data of data subject through recording by technical means for video surveillance… BULGARIA ·KZLD ·Art. 12, 15 Video Surveillance Personal Data Monitoring Sep 3, 2019
€5,113 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·KZLD ·Art. 6, 25 Telecommunications Personal Data Integrity and Confidentiality Principle Sep 3, 2019
€1,022 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·KZLD ·Art. 6, 25 Integrity and Confidentiality Principle Telecommunications Personal Data Sep 3, 2019
CNPD (Portugal) - Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Art. 2, 3, 5 +8 Controllers Processing Personal Data Sep 3, 2019
€60,000 AVON COSMETICS: Insufficient legal basis for data processing A consumer claimed that AVON COSMETICS had unlawfully processed his data without adequately verifying his identity, which led to his data being erroneously entered in a register… SPAIN ·aepd ·Art. 6 Personal Data Processing Law Enforcement Aug 16, 2019
€4,290 Public area maintenance company: Non-compliance with general data processing principles An ex-employee complained that his employer unlawfully monitored his work by its CCTV. The employer argued that CCTV monitoring was necessary to assess, whether the employee… HUNGARY ·NAIH ·Art. 5, 6, 13 Monitoring Video Surveillance Audit Logs Aug 2, 2019
€150,000 PWC Business Solutions: Insufficient legal basis for data processing The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to… GREECE ·HDPA ·Art. 5, 6, 13 +1 Legitimate Interest Fairness & Transparency Controllers Jul 30, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 5, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA ·ANSPDCP ·Art. 32 Security Healthcare Personal Data Jul 2, 2019
€2,000 Local bank: Insufficient fulfilment of data subjects rights Customer of a local bank requested access to telephone conversation recordings as well as to CCTV recordings. The bank provided the copies of the recordings of telephone… HUNGARY ·NAIH ·Art. 12, 15, 18 Video Surveillance Personal Data Insurance May 31, 2019
€400,000 SERGIC (Real Estate): Insufficient technical and organisational measures to ensure information security The CNIL based the penalty on two grounds: Lack of basic security measures and excessive data storage. As to the first, sensitive user documents uploaded by rental candidates… FRANCE ·CNIL ·Art. 5 Security Access Controls Healthcare May 28, 2019
€1,400 Police Officer: Insufficient legal basis for data processing The police officer, using his official user ID but without reference to official duties, queried the owner data concerning the license plate of a person who he did not know well… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Public Authority Consent May 9, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Garante ·Art. 32 Controllers Data Breaches Processors Apr 17, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Anonymization Professional Secrecy Apr 12, 2019
€34,375 Hungarian political party: Insufficient fulfilment of data breach notification obligations NAIH imposed a fine of HUF 11,000,000 (EUR 34,375) on an undisclosed Hungarian political party for failing to notify the NAIH and relevant individuals about a data breach, and… HUNGARY ·NAIH ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 5, 2019
€220,000 Private company working with data from publicly available sources: Insufficient fulfilment of information obligations The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the… POLAND ·UODO ·Art. 14 Controllers Personal Data Data Controller Mar 26, 2019
€50,000 N26: Insufficient legal basis for data processing The fine was imposed against against a bank (according to a newspaper N26) that had processed 'personal data of all former customers' without permission.The Bank has acknowledged… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Insurance Personal Data Processing Mar 1, 2019
€3,200 Mayor's Office of the city of Kecdkemét: Insufficient legal basis for data processing The fine was imposed on the Mayor’s Office of the city of Kecskemét for unlawful disclosure of the personal information of a whistleblower.NAIH imposed the fine after an employee… HUNGARY ·NAIH ·Art. 5, 6 Data Breaches Education Public Authority Feb 28, 2019
€27,100 Telecommunication service provider: Insufficient legal basis for data processing Repeated registration of prepaid services without the knowledge and consent of the data subject Employees of the telecommunications provider have used personal data and registered… BULGARIA ·KZLD ·Art. 5, 6 Personal Data Telecommunications Consent Feb 26, 2019
€50M Google LLC: Insufficient legal basis for data processing The fine was imposed on the basis of complaints from the Austrian organisation 'None Of Your Business' and the French NGO 'La Quadrature du Net'. The complaints were filed on 25th… FRANCE ·CNIL ·Art. 5, 6, 13 +1 Fairness & Transparency Transparency Telecommunications Jan 21, 2019
€160,000 Taxa 4x35: Non-compliance with general data processing principles The Danish DPA reported the taxi company to the police and recommended a fine (of 1.2M DKK) for non-adherence to the data-minimization principle. While the company deleted the… DENMARK ·Datatilsynet ·Art. 5 Administrative Fines on Union Institutions, Bodies, Offices and Agencies Fines IP Address Jan 1, 2019
€20,000 Hamburger Verkehrsverbund GmbH (HVV GmbH): Insufficient fulfilment of data breach notification obligations On July 6, 2018, HVV GmbH was informed by a customer about a security gap on the website www.hvv.de, which was caused by an update on February 5, 2018 and concerned the so-called… GERMANY ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2019
€10,000 Newspaper: Insufficient legal basis for data processing The publication of the newspaper, both in hard copy and in electronic form, allegedly involved inconvenience, unnecessary and unlawful detention of a citizen, and revealed the… CYPRUS ·Art. 6 ·Insufficient legal basis for data processing Processing Telecommunications Law Enforcement Jan 1, 2019
€500 GERMANY DPA: Insufficient fulfilment of data subjects rights A data controller failed to comply with data subject´s request to access their personal data. Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Data Controller Jan 1, 2019
€800 Police Officer: Insufficient legal basis for data processing A police officer used a witness's personal data to contact her personally. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2019
€500 Bank: Insufficient legal basis for data processing A fine of 1000 BGN (or roughly 500 EUR) was imposed on a bank for calling a client for the unresolved bills of his neighbor. This provoked the client to evoke his right to be… BULGARIA ·KZLD ·Art. 5, 6 Right to be Forgotten Personal Data Insurance Dec 4, 2018
€20,000 Knuddels.de: Insufficient technical and organisational measures to ensure information security After a hacker attack in July personal data of approx. 330.000 users, including passwords and email addresses had been revealed. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Personal Data Nov 21, 2018
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL ·CNPD ·Art. 5, 32 Health Data Healthcare Healthcare Jul 17, 2018