Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1551–1600 of 2,273 sort newestlargest fineoldest
€843 Lawyer: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 843 on a lawyer for having unauthorizedly disclosed documents containing personal data of his client in the course of criminal proceedings. HUNGARY ·NAIH ·Art. 5, 6, 9 Personal Data Insurance Processing Agreement Dec 3, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Healthcare Dec 2, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€60,000 Irish Teacher Council: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 60,000 on the Irish Teaching Council. The Council notified the DPA of a data breach under Art. 33 of the GDPR. Accordingly, two employees… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Dec 2, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY ·Garante ·Art. 5, 32 Security Fines Privacy by Design & Default Dec 2, 2021
€5,000 INTRODUCTION BUSINESS CAPITAL MEDIA, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on INTRODUCTION BUSINESS CAPITAL MEDIA, S.L.. The data subject had received advertising calls from the controller, although the… SPAIN ·aepd ·Art. 21, 23, 48 Direct Marketing Personal Data Controllers Dec 1, 2021
€4,000 Pactum Poland Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Data Breaches Supervisory Authorities Supervision Dec 1, 2021
€20,000 DAVISER SERVICIOS, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 on DAVISER SERVICIOS, S.L.. The company had been processing biometric data (fingerprints) of employees for access to… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Agreement Nov 30, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·aepd ·Art. 17, 21 Controllers Personal Data Education Nov 30, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·aepd ·Art. 17, 21 Controllers Personal Data IP Address Nov 30, 2021
€4,000 TIGERS MARKET, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 4,000 on TIGERS MARKET, S.L.. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·aepd ·Art. 21, 23, 48 Direct Marketing Personal Data Controllers Nov 29, 2021
€110,000 UAB Prime Leasing: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000. The DPA conducted the investigation on its own initiative… LITHUANIA ·VDAI ·Art. 32 Data Breaches Encryption Notification Obligation Nov 29, 2021
€2,000 Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Valoris Center S.R.L.. The controller notified the DPA of a data breach pursuant to Art. 33 GDPR. A call center… ROMANIA ·ANSPDCP ·Art. 29, 32 Data Breaches Security Right of Access Nov 26, 2021
€585,000 Cabinet Office: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Cabinet Office EUR 585,000. On December 27, 2019, the Cabinet Office published a file on GOV.UK containing the names and uncensored addresses of… UNITED KINGDOM ·ICO ·Art. 5, 32 Data Breaches Security Education Nov 25, 2021
€400,000 B&T S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 400,000 on B&T S.p.A. Two data subjects had complained to the DPA about unsolicited SMS advertising. In addition, they stated that it was… ITALY ·Garante ·Art. 5, 6, 12 +3 Right to Object Data Subject Rights Exercise Modalities and Procedures Direct Marketing Nov 25, 2021
€2.8M Dutch Minister of Finance: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the Minister of Finance EUR 2,75 million. In the context of childcare benefit applications, tax offices had processed data on the dual nationality of… THE NETHERLANDS ·AP ·Art. 5, 6, 8 Education IP Address Processing Nov 25, 2021
€200,000 Aimon Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 200,000 on Aimon Srl. Two data subjects had complained about unsolicited SMS advertising from B&T S.p.A. to the DPA. In the course of the… ITALY ·Garante ·Art. 5, 6, 12 +1 Direct Marketing Processing Agreement Personal Data Nov 25, 2021
€9,000 UNIÓN FINANCIERA ASTURIANA S.A. E.F.C.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined UNIÓN FINANCIERA ASTURIANA S.A. E.F.C.. The controller had carried out a credit check on the data subject without any contractual basis for doing so.… SPAIN ·aepd ·Art. 6 Controllers Insurance Personal Data Nov 24, 2021
€27,200 YAY ehf.: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 28 +1 ·Non-compliance with general data processing principles Fairness & Transparency Personal Data IP Address Nov 23, 2021
€40,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Vodafone España, S.A.U. due to insufficient legal basis for data processing. A data subject had filed a complaint against the data… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Processing Nov 23, 2021
€51,000 Icelandic Ministry of Industry and Innovation: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 7 +4 ·Non-compliance with general data processing principles Fairness & Transparency Personal Data IP Address Nov 23, 2021
€40,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Vodafone España, S.A.U.. A data subject had filed a complaint with the DPA as the controller had transferred her cell phone line to… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Nov 23, 2021
€1,000 Neighborhood community: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 1000 on a neighborhood community. The reason for this was that the information sign about a video surveillance system did not contain… SPAIN ·aepd ·Art. 13 Video Surveillance Controllers Monitoring Nov 22, 2021
€3,000 SPAIN DPA: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a company. The company had requested various personal data from customers for appointment bookings. The DPA found that… aepd ·Art. 13 ·Insufficient fulfilment of information obligations Personal Data Controllers Processing Agreement Nov 22, 2021
€800 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 800 on a legal person. The accused did not respond to the complainant's repeated requests for copies of the telephone recordings. CZECH REPUBLIC ·UOOU ·Art. 12 Personal Data Supervisory Authorities Insurance Nov 19, 2021
€40,000 Vodafone España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Vodafone España SAU. An individual had filed a complaint with the DPA. The data subject claims to have received text messages from… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Nov 15, 2021
€30,000 Vodafone España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Vodafone España SAU. A data subject had filed a complaint with the AEPD against the data controller. The data subject states that he… SPAIN ·aepd ·Art. 6 Controllers Personal Data Telecommunications Nov 15, 2021
€2,900 Vodafone România SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,900 on VODAFONE România S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 3, 32 Data Breaches Integrity and Confidentiality Principle Telecommunications Nov 14, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Security Access Controls Nov 12, 2021
€150,000 TIM S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has fined mobile operator TIM S.p.A. EUR 150,000 for denying a data subject access to his phone data needed to defend himself in a criminal case. Since… ITALY ·Garante ·Art. 15 Right of Access Procedures Right of Access Personal Data Nov 11, 2021
€2,000 COOPERA RC SERVICES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 2,000 on COOPERA RC SERVICES. The controller had not provided sufficient contact details through which data subjects could… SPAIN ·aepd ·Art. 13 Controllers Telecommunications Personal Data Nov 2, 2021
€1,000 IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,000 on IKEA ROMÂNIA SA. The controller had sent a notification to the DPA about a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Nov 1, 2021
€5,000 S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security IP Address Nov 1, 2021
€1,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,000 on a legal person. For at least two months, the accused incorrectly included 50 entities in the published list of processors, even… CZECH REPUBLIC ·UOOU ·Art. 12 Personal Data Processing Agreement Processors Nov 1, 2021
€15,400 LUXEMBOURG DPA: Insufficient involvement of data protection officer The Luxembourg DPA has imposed a fine of EUR 15,400 on a company. According to the DPA, the controller failed to involve the data protection officer in all matters related to the… CNPD ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Processing Agreement Oct 27, 2021
€13,500 Car importer: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 13,500 on a car importer. A customer of one of the company's authorized repair shops filed a complaint with the DPA due to receiving… HUNGARY ·NAIH ·Art. 5, 6, 12 +1 Controllers Personal Data Processing Agreement Oct 27, 2021
€64,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Vodafone España, S.A.U. due to insufficient legal basis for data processing. The data subject had filed a complaint against the data… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Oct 26, 2021
€40,000 VODAFONE SERVICIOS, S.L.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on VODAFONE SERVICIOS, S.L.U.. A data subject filed a complaint with the DPA against the controller. The data subject is a client of the… SPAIN ·aepd ·Art. 6 Personal Data Controllers Telecommunications Oct 26, 2021
€40,000 VODAFONE SERVICIOS, S.L.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on VODAFONE SERVICIOS, S.L.U.. A data subject has filed a complaint with the AEPD against the data controller. The data subject states… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Oct 26, 2021
€380 Bank: Non-compliance with general data processing principles The Bulgarian DPA has fined a bank EUR 380 for the unlawful transfer of personal data to third parties. BULGARIA ·KZLD ·Art. 5 Processing Agreement Personal Data International Transfer Oct 26, 2021
€5,000 Glove Technology SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on Glove Technology SRL. The controller had installed a video surveillance system that audiovisually monitored employees… ROMANIA ·ANSPDCP ·Art. 5, 6 Video Surveillance Monitoring Controllers Oct 21, 2021
€3M CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 3,000,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. An individual had filed a complaint against the controller. The reason… SPAIN ·aepd ·Art. 6 Insurance Marketing Consent Oct 21, 2021
€70,000 Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 70,000 on VODAFONE ESPAÑA, S.A.U.. A data subject had filed a complaint with the DPA for having received promotional emails from… SPAIN ·aepd ·Art. 21 Right to Object Direct Marketing IP Address Oct 19, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY ·Datatilsynet ·Art. 5, 32 Encryption Access Controls Security Oct 18, 2021
€11,800 HIV Scotland: Insufficient technical and organisational measures to ensure information security The British DPA (ICO) has imposed a fine of EUR 11,800 on the non-profit organization HIV Scotland. The controller had sent an e-mail to 105 people, with e-mail addresses on the… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Privacy by Design & Default IP Address Oct 18, 2021
€78,000 Bank Millennium S.A: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 78,000 on Bank Millennium S.A.. The UODO had become aware of a data protection breach following a complaint against the bank. It… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 14, 2021
€20,000 ΚΑΠΑ ΛΑΜΔΑ ΩΜΕΓΑ ΔΙΑΦΗΜΙΣΤΙΚΗ ΕΜΠΟΡΙΚΗ ΜΟΝΟΠΡΟΣΩΠΗ ΕΤΑΙΡΕΙΑ ΠΕΡΙΟΡΙΣΜΕΝΗΣ ΕΥΘΥΝΗΣ: Insufficient legal basis for data processing The Hellenic DPA has fined ΚΑΠΑ ΛΑΜΔΑ ΩΜΕΓΑ ΔΙΑΦΗΜΙΣΤΙΚΗ ΕΜΠΟΡΙΚΗ ΜΟΝΟΠΡΟΣΩΠΗ ΕΤΑΙΡΕΙΑ ΠΕΡΙΟΡΙΣΜΕΝΗΣ ΕΥΘΥΝΗΣ EUR 20,000. The company had in several cases carried out marketing… GREECE ·HDPA ·Art. 6, 12, 21 Direct Marketing Marketing Consent Oct 14, 2021
€13,200 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA from Luxembourg has imposed a fine of EUR 13,200 on a company. According to the DPA, the controller firstly failed to involve the data protection officer in all matters… CNPD ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Processing Agreement Oct 13, 2021
€18,000 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA from Luxembourg has imposed a fine of EUR 13,200 on a company. According to the DPA, the controller failed to involve the data protection officer in all matters relating… CNPD ·Art. 37, 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Processing Agreement Oct 13, 2021
€40,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A woman filed a complaint against the controller based on the fact that the controller had sent telephone bills… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Telecommunications IP Address Oct 13, 2021