Skip to content
Content type · 2,040 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1601–1650 of 2,040 sort newestlargest fineoldest
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Cyprus DPA ·Art. 24, 32 Controllers Security Processors Jan 1, 2022
€2,700 Credit institution: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 2,700 on a credit institution. Several individuals had filed a complaint with the DPA due to the fact that the controller had… HUNGARY ·NAIH ·Art. 5, 6 Controllers Consent Processing Jan 1, 2022
Company: Non-compliance with general data processing principles The DPA of Bremen has imposed a five-digit fine on a company. The controller had unlawfully used GPS software in its company vehicles, allowing unrestricted monitoring of its… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Controllers Processing Monitoring Jan 1, 2022
€5,000 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on DW Dynamic Works LIMITED. The controller operated as a processor for Hermes Airport Ltd.. Hermes had suffered a cyberattack… CYPRUS ·Cyprus DPA ·Art. 32 Controllers Security Processors Jan 1, 2022
Data protection officer: Insufficient legal basis for data processing The DPA of Thüringen has imposed a three-digit fine on the data protection officer of a company. The controller had posted a photo in a WhatsApp group of the company which showed… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Controllers Personal Data Consent Jan 1, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Personal Data Jan 1, 2022
€8,900 Company: Insufficient technical and organisational measures to ensure information security The DPA of Niedersachsen imposed a fine of EUR 8,900 on a company. The company had a customer database on the Internet with thousands of entries. During its investigation, the DPA… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2022
€5,000 Trucking company: Insufficient legal basis for data processing The Bulgarian DPA has imposed a fine of EUR 5,000 on a trucking company. The controller had disclosed personal data of a former employee to third parties without a valid legal… BULGARIA ·CPDP ·Art. 6 Controllers Personal Data Employees Jan 1, 2022
€7,500 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 7,500 on DW Dynamic Works LIMITED. The controller operated as a processor for the Cypriot Ministry of Denfese. The minsitry had suffered… CYPRUS ·Cyprus DPA ·Art. 32 Security Controllers Processors Jan 1, 2022
€1,400 Covid-19 test center: Insufficient legal basis for data processing The DPA from Hamburg has imposed a fine of EUR 1,400 on a Covid-19 test center. The controller intended to fulfill its statutory documentation obligations and scanned the front… GERMANY ·HmbBfDI ·Art. 6 Controllers Personal Data Healthcare Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Berlin has imposed a fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with their personal data… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Controllers Processing Jan 1, 2022
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2022
€3,400 Company: Insufficient legal basis for data processing The Czech DPA imposed a fine of EUR 3,400 on a company. The data subject had concluded an energy supply contract with the controller in the past, but then duly terminated it.… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Insufficient legal basis for data processing Controllers Processors Personal Data Jan 1, 2022
€1,300 Website operator: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,300 on a website operator. An individual had filed a complaint with the DPA against the controller due to the fact that the… HUNGARY ·NAIH ·Art. 5, 12, 31 Personal Data Controllers Supervisory Authorities Jan 1, 2022
€1,600 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA imposed a fine of EUR 1,600 on a physician. A patient had filed a complaint against the controller with the DPA. The patient had asked the doctor to send all… HUNGARY ·NAIH ·Art. 5, 12, 13 Personal Data Controllers Supervisory Authorities Jan 1, 2022
€1,400 Dentist: Non-compliance with general data processing principles The Hungarian DPA has fined a dentist EUR 1,300. The controller had installed several surveillance cameras in their practice, which permanently recorded employees and patients.… HUNGARY ·NAIH ·Non-compliance with general data processing principles Video Surveillance Monitoring Personal Data Jan 1, 2022
€80,700 Beauty salon: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 80,700 on a beauty salon. The controller had installed video cameras in all its premises, which permanently recorded customers and… HUNGARY ·NAIH ·Insufficient legal basis for data processing Video Surveillance Direct Marketing Controllers Jan 1, 2022
Credit agency: Insufficient fulfilment of data subjects rights The DPA of Berlin imposed a fine on a credit agency. In the course of its investigation, the DPA found that the controller had stored 27 false addresses and 13 false dates of… GERMANY ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Jan 1, 2022
€250,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has failed to implement appropriate technical and organizational measures to protect personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 1, 2022
€30,000 INFO COMMUNICATION SERVICES: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 30,000 on INFO COMMUNICATION SERVICES. The controller had conducted advertising calls without the consent of the data subjects. In… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Controllers Supervisory Authorities Dec 31, 2021
€25,000 PLUS REAL ADVERTISEMENT: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 25,000 on PLUS REAL ADVERTISEMENT. The controller had conducted advertising calls without the consent of the data subjects. In addition,… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Controllers Consent Dec 31, 2021
€150M Google LLC is a subsidiary owned wholly by Alphabet Inc Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out… SAN-2021-023 ·France ·CNIL Material scope (GDPR) Supervision Supervisory Authorities Dec 31, 2021
€6,000 REAL CLUB NÁUTICO DE RIBADEO: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on REAL CLUB NÁUTICO DE RIBADEO. The controller had uploaded links to court decisions containing personal data of the data… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Social Media Dec 28, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Personal Data Dec 28, 2021
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Controllers Processing Dec 26, 2021
€5,000 HUBSIDE IBÉRICA S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 HUBSIDE IBÉRICA S.L.. A data subject had filed a complaint with the DPA against the controller for charging her several… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Dec 22, 2021
€5,000 Sfam España General s.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Sfam España General s.l.. A data subject had filed a complaint with the DPA against the controller for charging her… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Dec 22, 2021
€2,000 FUNDACION ESPANOLA DE MEDICINA ESTETICA Y LONGEVIDAD: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on FUNDACION ESPANOLA DE MEDICINA ESTETICA Y LONGEVIDAD. The DPA criticized that the data protection notice of the controller did… SPAIN ·AEPD ·Art. 7, 13 Consent Controllers Supervisory Authorities Dec 21, 2021
€2,000 Online retailer: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on an online retailer. The data subject bought a product from the controller's online store via eBay and paid with Paypal. However,… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Consent Dec 17, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY ·Garante ·Art. 5, 6, 9 Healthcare Personal Data Controllers Dec 17, 2021
€2,000 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 2,000. The data controller had installed video cameras in such a way that they could record images of the public space and… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Dec 17, 2021
€4,000 CLUB DEPORTIVO RITMO DE ANDALUCÍA: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on CLUB DEPORTIVO RITMO DE ANDALUCÍA. The DPA criticized that the data protection notice of the controller did not comply with the… SPAIN ·AEPD ·Art. 7, 13 Controllers Consent Supervisory Authorities Dec 17, 2021
Enel Energia S.p.A: Insufficient legal basis for data processing Originial fine summary: The Italian DPA has fined Enel Energia S.p.A EUR 26.5 million for numerous breaches of the GDPR. Following a complex preliminary investigation launched… ITALY ·Garante ·Art. 5, 6, 12 +7 Direct Marketing Personal Data Controllers Dec 16, 2021
€52,000 Motor insurance center: Non-compliance with general data processing principles The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25 Retention Period Controllers Insurance Dec 16, 2021
€20,000 FCA Italy s.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined FCA Italy s.p.a. EUR 20,000. A former customer of the controller had asked the controller to provide him with the transcripts of telephone conversations… Garante ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Dec 16, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Privacy by Design & Default Controllers Dec 16, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Garante ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2021
€60,000 Banco Bilbao Vizcaya Argentaria S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria S.A.. A data subject filed a complaint with the DPA due to the fact that the controller repeatedly… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Dec 16, 2021
€50,000 IZA OBRAS Y PROMOCIONES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IZA OBRAS Y PROMOCIONES, S.A. EUR 50,000. An employee had filed a complaint with the DPA against the company, alleging that the controller had… SPAIN ·AEPD ·Art. 5 Personal Data Retention Period Controllers Dec 14, 2021
€20,000 Elektro & Automasjon Systemer AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Elektro & Automasjon Systemer AS EUR 20,000. The controller had carried out a credit check on an individual, although there was no legal… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Processing Supervisory Authorities Dec 13, 2021
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·DPC ·Art. 12, 13, 15 Personal Data Right of Access Controllers Dec 9, 2021
€30,000 One Way Private Company: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 30,000 on One Way Private Company. The DPA received 17 complaints regarding illegal telephone calls for the purpose of advertising. The… GREECE ·HDPA ·Art. 11, 28, 32 Security Controllers Personal Data Dec 8, 2021
€608,000 Psykoterapiakeskus Vastaamo: Non-compliance with general data processing principles The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 33, 34 Integrity and Confidentiality Principle Personal Data Controllers Dec 7, 2021
€24,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U.. A data subject filed a complaint with the DPA against the company after they had denied him a financial transaction due to… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Dec 7, 2021
€6,000 Telekom Romania Communications SA: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) imposed a fine of EUR 6,000 on Telekom Romania Communications SA. A data subject had complained that the controller had sent invoices and messages to… ANSPDCP ·Art. 5, 17 ·Non-compliance with general data processing principles Personal Data Controllers Processing Dec 6, 2021
€6,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 6,800 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers Dec 1, 2021
€5,000 INTRODUCTION BUSINESS CAPITAL MEDIA, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on INTRODUCTION BUSINESS CAPITAL MEDIA, S.L.. The data subject had received advertising calls from the controller, although the… SPAIN ·AEPD ·Art. 21, 23, 48 Personal Data Direct Marketing Controllers Dec 1, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Processing Nov 30, 2021
€20,000 DAVISER SERVICIOS, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 on DAVISER SERVICIOS, S.L.. The company had been processing biometric data (fingerprints) of employees for access to… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Nov 30, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Processing Nov 30, 2021