Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1501–1550 of 2,273 sort newestlargest fineoldest
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Art. 24, 28 ·Insufficient data processing agreement Controllers Processors Processing Agreement Jan 1, 2022
€500 Private individual: Insufficient legal basis for data processing The DPA of Niedersachsen imposed a fine of EUR 5,00 on a private individual. The individual had taken pictures of numerous young women in public. In the course of its… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Processing Jan 1, 2022
Data protection officer: Insufficient legal basis for data processing The DPA of Thüringen has imposed a three-digit fine on the data protection officer of a company. The controller had posted a photo in a WhatsApp group of the company which showed… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing Agreement Jan 1, 2022
Supermarket: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a supermarket. A store detective had taken a photo of the data subject on the occasion of an alleged theft and transmitted it via the… GERMANY ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Processing Jan 1, 2022
€1,600 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA imposed a fine of EUR 1,600 on a physician. A patient had filed a complaint against the controller with the DPA. The patient had asked the doctor to send all… HUNGARY ·NAIH ·Art. 5, 12, 13 Healthcare Health Data Healthcare Jan 1, 2022
Debt collection company: Insufficient legal basis for data processing The DPA from Baden-Württemberg has imposed a fine on a debt collection company. The debt collection company had received investor information from an employee of an insolvent… GERMANY ·Art. 6, 14 ·Insufficient legal basis for data processing Insurance Personal Data Processing Agreement Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Jan 1, 2022
€6,500 Pharmacy: Non-compliance with general data processing principles The DPA of Baden-Württemberg imposed a fine of EUR 6,500 on a pharmacy. The pharmacy had disposed of a large number of personal documents, including diagnoses and medical… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Healthcare Healthcare IP Address Jan 1, 2022
€7,500 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 7,500 on DW Dynamic Works LIMITED. The controller operated as a processor for the Cypriot Ministry of Denfese. The minsitry had suffered… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processors Jan 1, 2022
€1,400 Covid-19 test center: Insufficient legal basis for data processing The DPA from Hamburg has imposed a fine of EUR 1,400 on a Covid-19 test center. The controller intended to fulfill its statutory documentation obligations and scanned the front… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Healthcare Controllers Personal Data Jan 1, 2022
€12,800 Political party: Insufficient legal basis for data processing The Bulgarian DPA has imposed a fine of EUR 12,800 on a political party. Several individuals had filed a complaint with the DPA because their personal data had been added to voter… BULGARIA ·KZLD ·Art. 6 Personal Data Consent Processing Agreement Jan 1, 2022
€5,000 Trucking company: Insufficient legal basis for data processing The Bulgarian DPA has imposed a fine of EUR 5,000 on a trucking company. The controller had disclosed personal data of a former employee to third parties without a valid legal… BULGARIA ·KZLD ·Art. 6 Controllers Personal Data Processing Agreement Jan 1, 2022
Credit agency: Insufficient fulfilment of data subjects rights The DPA of Berlin imposed a fine on a credit agency. In the course of its investigation, the DPA found that the controller had stored 27 false addresses and 13 false dates of… GERMANY ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Insurance Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a five-figure fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Direct Marketing Consent Personal Data Jan 1, 2022
€17,000 Bank of Cyprus Public Company Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Processing Agreement Jan 1, 2022
€5,000 Cyprus Electricity Authority: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Personal Data Jan 1, 2022
€25,000 PLUS REAL ADVERTISEMENT: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 25,000 on PLUS REAL ADVERTISEMENT. The controller had conducted advertising calls without the consent of the data subjects. In addition,… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Direct Marketing Controllers Dec 31, 2021
€30,000 INFO COMMUNICATION SERVICES: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 30,000 on INFO COMMUNICATION SERVICES. The controller had conducted advertising calls without the consent of the data subjects. In… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Controllers Direct Marketing Dec 31, 2021
€150M CNIL rejects Google's stay request and ne bis in idem challenge in cookie consent case Google LLC is a subsidiary owned wholly by Alphabet Inc. Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and… France ·Art. 56 Cookies Telecommunications Material scope (GDPR) Dec 31, 2021
€75,000 Greek Ministry of Tourism: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 75,000 on the Greek Ministry of Tourism. A data breach had occurred at the authority. According to the DPA, an attempt by a citizen to… GREECE ·HDPA ·Art. 13, 32, 33 +1 Data Breaches Notification Obligation Public Authority Dec 29, 2021
€300,000 FREE MOBILE: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has imposed a fine of EUR 300,000 on FREEE MOBILE. The CNIL had received numerous complaints regarding the company's failure to comply with data subjects'… FRANCE ·CNIL ·Art. 12, 15, 21 +2 Right to Object Data Subject Rights Exercise Modalities and Procedures Telecommunications Dec 28, 2021
€6,000 REAL CLUB NÁUTICO DE RIBADEO: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on REAL CLUB NÁUTICO DE RIBADEO. The controller had uploaded links to court decisions containing personal data of the data… SPAIN ·aepd ·Art. 6 Social Media Personal Data Controllers Dec 28, 2021
€2,000 Call shop manager: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on the manager of a call shop. In the context of a job vacancy, the manager had set up a stand where applicants could submit their… SPAIN ·aepd ·Art. 13 Personal Data Supervisory Authorities Processing Dec 28, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Insurance Dec 28, 2021
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Health Data Healthcare Dec 26, 2021
€5,000 Sfam España General s.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Sfam España General s.l.. A data subject had filed a complaint with the DPA against the controller for charging her… SPAIN ·aepd ·Art. 6 Controllers Personal Data Insurance Dec 22, 2021
€5,000 HUBSIDE IBÉRICA S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 HUBSIDE IBÉRICA S.L.. A data subject had filed a complaint with the DPA against the controller for charging her several… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Dec 22, 2021
€1.3M Lisbon City Council: Insufficient legal basis for data processing The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since… PORTUGAL ·CNPD ·Art. 5, 6, 9 +2 Religious Beliefs DPIA Fines Dec 21, 2021
€3,900 T. Stene Transport AS: €3,900 fine The Norwegian DPA has fined T. Stene Transport AS EUR 3,900 due to an unfair credit check on a data subject. NORWAY ·Datatilsynet ·Unknown Processing Agreement Personal Data Supervisory Authorities Dec 17, 2021
€2,000 Online retailer: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on an online retailer. The data subject bought a product from the controller's online store via eBay and paid with Paypal. However,… SPAIN ·aepd ·Art. 6 Processing Agreement Controllers Personal Data Dec 17, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY ·Garante ·Art. 5, 6, 9 Health Data Healthcare Personal Data Dec 17, 2021
€6,500 Travel agency: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 6,500 on a travel agency. A customer of the travel agency informed the DPA to suspect that the company might not process the data of its… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 17, 25 +1 Personal Data Security Processing Agreement Dec 16, 2021
€60,000 Banco Bilbao Vizcaya Argentaria S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria S.A.. A data subject filed a complaint with the DPA due to the fact that the controller repeatedly… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement Dec 16, 2021
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Security Public Authority Dec 16, 2021
€1,000 Università Telematica Internazionale Uninettuno: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,000 on Università Telematica Internazionale Uninettuno. A professor had filed a complaint with the DPA against the educational… ITALY ·Garante ·Art. 5 Education Personal Data IP Address Dec 16, 2021
€20,000 FCA Italy s.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined FCA Italy s.p.a. EUR 20,000. A former customer of the controller had asked the controller to provide him with the transcripts of telephone conversations… Garante ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Controllers IP Address Dec 16, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Garante ·Art. 5 Fairness & Transparency Recipient IP Address Dec 16, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Healthcare Healthcare Dec 16, 2021
Enel Energia S.p.A: Insufficient legal basis for data processing Originial fine summary: The Italian DPA has fined Enel Energia S.p.A EUR 26.5 million for numerous breaches of the GDPR. Following a complex preliminary investigation launched… ITALY ·Garante ·Art. 5, 6, 12 +7 Controllers Personal Data Direct Marketing Dec 16, 2021
€20,000 Corradi s.r.l.: Non-compliance with general data processing principles The company had left the e-mail account of the data subject active even after the termination of his employment and had automatically forwarded incoming e-mails. The company did… ITALY ·Garante ·Art. 5, 13, 157 Personal Data IP Address Processing Dec 16, 2021
€50,000 IZA OBRAS Y PROMOCIONES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IZA OBRAS Y PROMOCIONES, S.A. EUR 50,000. An employee had filed a complaint with the DPA against the company, alleging that the controller had… SPAIN ·aepd ·Art. 5 Personal Data Controllers Healthcare Dec 14, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY ·Datatilsynet ·Art. 6, 9 IP Address Fines Direct Marketing Dec 13, 2021
€2,000 SC Nobiotic Pharma SRL: Insufficient cooperation with supervisory authority Failure to provide requested information to the Romanian DPA within the required timeframe in violation of Art. 58 GDPR. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 13, 2021
€10,000 Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Warsaw University of Technology EUR 10,000. The university had reported a data breach to the authority pursuant to Art. 33 GDPR. One of the… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Education Dec 9, 2021
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·Art. 12, 13, 15 ·Insufficient fulfilment of data subjects rights Video Surveillance Right of Access Personal Data Dec 9, 2021
€10,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA has imposed a fine of EUR 10,000 against a company. The data subject had repeatedly received mail with advertising content from a company, although he had objected… APD ·Art. 12, 14, 15 +2 ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Processing Dec 8, 2021
€30,000 One Way Private Company: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 30,000 on One Way Private Company. The DPA received 17 complaints regarding illegal telephone calls for the purpose of advertising. The… GREECE ·HDPA ·Art. 11, 28, 32 Security Telecommunications Privacy by Design & Default Dec 8, 2021
€24,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U.. A data subject filed a complaint with the DPA against the company after they had denied him a financial transaction due to… SPAIN ·aepd ·Art. 6 Controllers Insurance Personal Data Dec 7, 2021
€608,000 Psykoterapiakeskus Vastaamo: Non-compliance with general data processing principles The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 33, 34 Integrity and Confidentiality Principle Liability Healthcare Dec 7, 2021
€6,000 Telekom Romania Communications SA: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) imposed a fine of EUR 6,000 on Telekom Romania Communications SA. A data subject had complained that the controller had sent invoices and messages to… ANSPDCP ·Art. 5, 17 ·Non-compliance with general data processing principles Personal Data Telecommunications IP Address Dec 6, 2021