Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1551–1600 of 2,403 sort newestlargest fineoldest
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·AZOP ·Art. 15 Personal Data Supervisory Authorities Controllers Mar 8, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Mar 8, 2022
€7,000 Hörpu tónlistar- og ráðstefnuhúss ohf.: Non-compliance with general data processing principles The Icelandic DPA has fined Hörpu tónlistar- og ráðstefnuhúss ohf. EUR 7,000. The DPA had received a complaint regarding the concert hall's collection of ID number and date of… ICELAND ·Persónuvernd ·Art. 5, 6 Retention Period Personal Data Processing Mar 8, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Identification Mar 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Controllers Types of Special Categories of Personal Data Mar 3, 2022
€13,500 Company: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 13,500 on a company. An individual had filed a complaint with the DPA, stating that the company had published personal data such as their… HUNGARY ·NAIH ·Art. 5, 6, 12 +1 Personal Data Consent Supervisory Authorities Mar 2, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Personal Data Supervisory Authorities Feb 24, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA ·ANSPDCP ·Art. 12, 13, 21 Personal Data Controllers Supervisory Authorities Feb 22, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Consent Feb 22, 2022
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a private individual. The data subject had filed a complaint against the data controller for publishing images of herself… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Access Controls Feb 16, 2022
€30,000 ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 30,000 on the ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε. organization. A data subject who had suffered a car accident on the organization's premises filed a… GREECE ·HDPA ·Art. 12, 15 Personal Data Supervisory Authorities Monitoring Feb 15, 2022
€1,600 RECLAMADOR, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine RECLAMADOR, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the controller continued… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Feb 14, 2022
€5,000 Arte del vivere S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Arte del vivere S.r.l.. A data subject filed a complaint with the DPA as his personal data had been published on the website… ITALY ·Garante ·Art. 12, 17, 157 Personal Data Controllers Supervisory Authorities Feb 10, 2022
€1,500 Studio Colli Aniene Verderocca S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,500 on Studio Colli Aniene Verderocca S.r.l.. A data subject had filed a complaint with the DPA for unsolicited telephone advertising.… ITALY ·Garante ·Art. 12, 14, 15 +2 Personal Data Direct Marketing Supervisory Authorities Feb 10, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Storage Limitation Retention Period Fairness & Transparency Feb 10, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Personal Data Supervisory Authorities Feb 10, 2022
€10,000 Costampress S.p.A.: Insufficient legal basis for data processing The company had left the e-mail account of the data subject active even after the termination of his employment and did not provide sufficient information about this. ITALY ·Garante ·Art. 5, 12, 13 Personal Data Processing Supervisory Authorities Feb 10, 2022
€2,000 Comune di Guidizzolo: Insufficient legal basis for data processing The community published information about a court case on its website, including personal data such as the name and professional information of a data subject. ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Feb 10, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Personal Data Security Supervisory Authorities Feb 10, 2022
€634,000 Budapest Bank Zrt.: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has fined Budapest Bank Zrt. EUR 634,000. NAIH reports that the bank used an artificial intelligence-driven software solution to automate the evaluation… HUNGARY ·NAIH ·Art. 5, 6, 12 +5 Right to Object Legitimate Interest Personal Data Feb 8, 2022
€10,000 Εκδοτικού Οίκου Δίας: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the publisher Εκδοτικού Οίκου Δίας. A public figure had filed a complaint with the DPA. The publisher had published incorrect… CYPRUS ·Cyprus DPA ·Art. 5, 6 Personal Data Processing Telecommunications Feb 4, 2022
€300,000 SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS. in the amount of EUR 300,000. The data subject had received marketing emails from the controller… SPAIN ·AEPD ·Art. 6, 17, 28 Personal Data Controllers Supervisory Authorities Feb 4, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +8 Fairness & Transparency Marketing Transparency Feb 2, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 32 Security Personal Data Public Authority Feb 2, 2022
€2,000 ASESORES DE SEGURIDAD PRIVADA, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on ASESORES DE SEGURIDAD PRIVADA, S.L.. The DPA criticized that the controller did not sufficiently inform the data subject about… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Feb 2, 2022
€70,000 ORANGE ESPAÑA VIRTUAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined ORANGE ESPAÑA VIRTUAL, S.L. EUR 70,000. Two Orange España Virtual customers had filed complaints with the DPA. In the course of its investigation, the… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 1, 2022
€900,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined TELEFÓNICA MÓVILES ESPAÑA, S.A.U. EUR 900,000. Four Telefónica customers had filed complaints with the DPA. In the course of its investigation, the DPA… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications Feb 1, 2022
€700,000 Orange Espagne S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Orange Espagne S.A.U. EUR 700,000. Two Orange Espagne customers had filed complaints with the DPA. In the course of its investigation, the DPA found that… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€3.9M Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found… SPAIN ·AEPD ·Art. 5 Security Personal Data Processing Feb 1, 2022
€200,000 XFERA MÓVILES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined XFERA MÓVILES, S.A. EUR 200,000. Two Xfera customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€5,000 Cyrana España General S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Cyrana España General S.L. EUR 5,000. The controller had sent an invoice to the data subject although no contractual relationship existed. SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Jan 31, 2022
€3.2M OTE Group: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 3.2 million on Cosmote subsidiary OTE Group. Among other things, OTE Group had contributed to Cosmote's security infrastructure. Cosmote… GREECE ·HDPA ·Art. 32 Data Breaches Notification Obligation Security Jan 27, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +5 Fairness & Transparency Anonymization Pseudonymization Jan 27, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Data Portability Recipient Personal Data Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +3 Anonymization Pseudonymization Fairness & Transparency Jan 27, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches Anonymization Security Jan 27, 2022
€40,000 T.S.M. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on T.S.M. s.r.l.. A data subject had filed a complaint with the DPA against the company for failing to comply with their requests… ITALY ·Garante ·Art. 13, 15, 21 +2 Personal Data Supervisory Authorities Processing Jan 27, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·IMY ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jan 26, 2022
APD/GBA · 11/2022 The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·Art. 4, 5, 7 +2 Supervisory Authorities Legitimate Interest Supervision Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Right of Access Personal Data Controllers Jan 20, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Encryption Security Jan 19, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Encryption Security Pseudonymization Jan 19, 2022
€117,000 Santander Bank Polska S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 118,000 for failing to notify data subjects of a data breach. A former employee of the bank managed to gain unauthorized… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Personal Data Jan 19, 2022
€15,000 GARLEX SOLUTIONS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on GARLEX SOLUTIONS, S.L.. The data subject had received a call from the company to renew their electricity supply… SPAIN ·AEPD ·Art. 6 Personal Data Consent Supervisory Authorities Jan 18, 2022
€56,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on VODAFONE ESPAÑA, S.A.U. due to insufficient legal basis for data processing. The data subject states that two telephone connections were… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Jan 18, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
€2,400 PHARMA TALENTS, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's… SPAIN ·AEPD ·Art. 5, 32 Security Personal Data Privacy by Design & Default Jan 14, 2022