Skip to content
Content type · 2,040 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1551–1600 of 2,040 sort newestlargest fineoldest
€490 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 490 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Mar 23, 2022
€9,700 Company: Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact… NORWAY ·Datatilsynet (NO) ·Art. 6, 13, 21 Right to Object Controllers Supervisory Authorities Mar 15, 2022
€10,000 Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 10,000 on Alfa Shipyard s.r.l.. The controller had failed to implement measures ordered by the DPA in due time. ITALY ·Garante ·Art. 58 Supervision Supervisory Authorities Controllers Mar 10, 2022
€2,000 Operatorul Briza Land S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has fined Operatorul Briza Land S.R.L. EUR 2,000. The controller failed to properly respond to a request for information. ROMANIA ·ANSPDCP ·Art. 15 Personal Data Controllers Supervisory Authorities Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Controllers Security Mar 10, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Garante ·Art. 2, 5, 6 +3 Personal Data Controllers Supervisory Authorities Mar 10, 2022
€2,000 Foreign language school: Insufficient fulfilment of data subjects rights The Hellenic DPA imposed a fine of EUR 2,000 on an employer (owner of a private foreign language school). An employee, who works as a language teacher in the school, had filed a… GREECE ·HDPA ·Art. 5, 13 Personal Data Controllers Supervisory Authorities Mar 9, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Mar 8, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·AZOP ·Art. 15 Personal Data Controllers Supervisory Authorities Mar 8, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Controllers Fairness & Transparency Personal Data Mar 3, 2022
€1,200 FRUTAS Y VERDURAS LOS CAMPEONES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,000 on FRUTAS Y VERDURAS LOS CAMPEONES, S.L.. The controller had installed a video surveillance system, however, without having… SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Video Surveillance Feb 23, 2022
€1,500 WORLDWIDE CLASSIC CARS NETWORK S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on WORLDWIDE CLASSIC CARS NETWORK S.L.. The controller had installed video surveillance cameras which, among other things,… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Feb 23, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Consent Feb 22, 2022
€3,000 Hotel operator: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a hotel operator. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Feb 22, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA ·ANSPDCP ·Art. 12, 13, 21 Personal Data Controllers Supervisory Authorities Feb 22, 2022
€2,500 Private person: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 2,500 on a private individual. The controller had installed video surveillance cameras at his house which, among other things,… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Feb 18, 2022
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a private individual. The data subject had filed a complaint against the data controller for publishing images of herself… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Access Controls Feb 16, 2022
€1,600 RECLAMADOR, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine RECLAMADOR, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the controller continued… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Processing Agreement Feb 14, 2022
€5,000 Arte del vivere S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Arte del vivere S.r.l.. A data subject filed a complaint with the DPA as his personal data had been published on the website… ITALY ·Garante ·Art. 12, 17, 157 Personal Data Controllers Supervisory Authorities Feb 10, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Processing Feb 10, 2022
€10,000 PINTODIS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined PINTODIS, S.L. EUR 10,000. The controller had installed several video cameras which also covered the food areas and changing rooms of their employees.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Feb 7, 2022
€300,000 SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS. in the amount of EUR 300,000. The data subject had received marketing emails from the controller… SPAIN ·AEPD ·Art. 6, 17, 28 Controllers Personal Data Supervisory Authorities Feb 4, 2022
€2,000 ASESORES DE SEGURIDAD PRIVADA, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on ASESORES DE SEGURIDAD PRIVADA, S.L.. The DPA criticized that the controller did not sufficiently inform the data subject about… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Feb 2, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Insurance Processing Agreement Feb 1, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 1, 2022
€5,000 Cyrana España General S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Cyrana España General S.L. EUR 5,000. The controller had sent an invoice to the data subject although no contractual relationship existed. SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Jan 31, 2022
€5,000 INCOPROSOL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined INCOPROSOL, S.L. EUR 5,000. The controller had recorded a telephone conversation with a customer without obtaining the customer's consent. SPAIN ·AEPD ·Art. 5 Controllers Processing Consent Jan 31, 2022
€2,000 Private club 'Ruian': Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 2,000 on the private club 'Ruian'. The controller had installed video surveillance cameras which, among other things, also… ITALY ·Garante ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jan 27, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches Security Anonymization Jan 27, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Recipient Data Portability Personal Data Jan 27, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
€1,200 Property Owner Community: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a property owners' community EUR 1,200. A property manager had sent a copy of the general meeting minutes to the director of the security company… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jan 21, 2022
APD/GBA · 11/2022 The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·Art. 4, 5, 7 +2 Legitimate Interest Supervisory Authorities Supervision Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Personal Data Right of Access Controllers Jan 20, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Encryption Controllers Jan 19, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Encryption Security Pseudonymization Jan 19, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
€2,000 MEETING PUERTO C.B.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on MEETING PUERTO C.B.. The data controller had unlawfully published a picture of the complainant with his partner on Facebook and… SPAIN ·AEPD ·Art. 6 Controllers Social Media Processing Jan 17, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS ·AP ·Art. 12 Personal Data Controllers Supervisory Authorities Jan 14, 2022
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Personal Data Controllers Jan 13, 2022
€9,000 EDUCANDO JUNTOS SL: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 9,000 on EDUCANDO JUNTOS SL. The controller had published photos of an employee on some of its channels on social networks and its… SPAIN ·AEPD ·Art. 6, 17 Personal Data Controllers Consent Jan 11, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€16,400 Covid-19 test center: Insufficient legal basis for data processing The DPA of Hessen has fined a Covid-19 test center EUR 16,400. The controller had sent an e-mail containing personal data to several recipients in an open distribution list. The… GERMANY ·Art. 6, 33 ·Insufficient legal basis for data processing Data Breaches Controllers Personal Data Jan 1, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Controllers Security Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Cyprus DPA ·Art. 24, 32 Security Controllers Processors Jan 1, 2022
GERMANY DPA: Insufficient legal basis for data processing The DPA of Thüringen has imposed a fine on a controller. The controller had installed a video surveillance camera in the public entrance area of an apartment building without a… Art. 6 ·Insufficient legal basis for data processing Controllers Supervisory Authorities Video Surveillance Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Cyprus DPA ·Art. 24, 28 Controllers Processors Processing Jan 1, 2022
Operator of a swimming pool: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a five-digit fine on the operator of an outdoor swimming pool. The controller had processed more visitor data than legally required for contact… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Controllers Processing Supervisory Authorities Jan 1, 2022
€65,000 MALTA DPA: Non-compliance with general data processing principles The controller has violated numerous GDPR regulations, involving special categories of personal data of numerous individuals. Art. 5, 6, 9 +3 ·Non-compliance with general data processing principles Supervisory Authorities Types of Special Categories of Personal Data Controllers Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Cyprus DPA ·Art. 28, 32 Security Controllers Processors Jan 1, 2022