Skip to content
Content type · 2,802 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1601–1650 of 2,802 sort newestlargest fineoldest
€265M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Meta Platforms Ireland Limited EUR 265 million. The DPA had launched an investigation against Meta in 2021 after media reports indicated that a dataset… Social Media Security Telecommunications Nov 25, 2022
€1,991 Betting place: Insufficient fulfilment of information obligations The Croation DPA (azop) has imposed a fine of EUR 1,991 on a betting place. The controller had installed a video surveillance system in its premises, however the DPA found that… CROATIA ·azop ·Art. 27 Video Surveillance Monitoring Controllers Nov 25, 2022
€1,991 Company in the hospitality industry: Insufficient fulfilment of information obligations The Croation DPA (azop) has imposed a fine of EUR 1,991 on a company in the hospitality industry. The controller had installed a video surveillance system in its premises, however… CROATIA ·azop ·Art. 27 Video Surveillance Monitoring Controllers Nov 25, 2022
€1,800 ALPA 57 PRODUCCIONES, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) has fined ALPA 57 PRODUCCIONES, S.L. for failing to provide information requested by the DPA during an investigation. The original fine of EUR 3,000 was… SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Law Enforcement Nov 25, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Right of Access Nov 25, 2022
€5,000 Association for the prevention and study of crimes, abuses and negligence in information technology and advanced communications (APEDANICA): Non-compliance with general data processing principles The Spanish DPA has fined the Association for the prevention and study of crimes, abuses and negligence in information technology and advanced communications (APEDANICA) EUR… SPAIN ·aepd ·Art. 5 Personal Data Controllers Fairness & Transparency Nov 25, 2022
€1M Areti spa: Non-compliance with general data processing principles The Italian DPA has fined electricity supplier Areti spa EUR 1 million. A customer had filed a complaint with the DPA due to Areti classifying them as a defaulting customer, which… ITALY ·Garante ·Art. 5, 12, 15 +1 Data Subject Rights Exercise Modalities and Procedures Personal Data IP Address Nov 24, 2022
€3,000 Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Board of Surgeons and Dentists of the Province of Cagliari. The controller had disclosed data of a doctor to third parties… ITALY ·Garante ·Art. 2, 5, 6 Healthcare Controllers Processing Agreement Nov 24, 2022
€4,000 Società Lombarda Sport s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Società Lombarda Sport s.r.l. EUR 4,000. An individual had filed a complaint with the DPA. The individual had undergone a sports fitness examination with… ITALY ·Garante ·Art. 5, 9 Healthcare Processing Agreement Processing Nov 24, 2022
€1,000 STS Di Prisinzano s.r.l: Insufficient fulfilment of information obligations The Italian DPA has fined STS Di Prisinzano s.r.l EUR 1,000. The company had processed data of a customer in the context of a breakdown service without sufficiently informing the… ITALY ·Garante ·Art. 5, 13 Personal Data Processing Agreement Processing Nov 24, 2022
€1,000 Private individual: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on a private individual. Two individuals had filed a complaint with the DPA due to the fact that the controller had published… ITALY ·Garante ·Art. 2, 5, 6 +2 Personal Data IP Address Controllers Nov 24, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Healthcare Recipient Nov 24, 2022
€600,000 ÉLECTRICITÉ DE FRANCE: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on ÉLECTRICITÉ DE FRANCE (EDF), France's largest electricity supplier. The DPA had received several complaints that individuals… CNIL ·Art. 7, 12, 13 +3 ·Insufficient fulfilment of data subjects rights Right to Object Data Subject Rights Exercise Modalities and Procedures Personal Data Nov 24, 2022
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 300 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers Nov 21, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Nov 21, 2022
€300 Homeowners Association Bld. Pipera 1-2E: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined Homeowners Association 'Bld. Pipera 1-2E' EUR 300 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision IP Address Nov 18, 2022
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Nov 16, 2022
€5,200 News service: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 5,200 on a news service. A customer had complained to the DPA about subscribing to a newsletter to receive a daily news digest, however,… HUNGARY ·NAIH ·Art. 6, 7, 12 Direct Marketing Marketing Personal Data Nov 15, 2022
€80,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANKINTER, S.A.. A person had filed a complaint with the DPA as personal data of a third person were also displayed to them when accessing… SPAIN ·aepd ·Art. 5, 32 Security Personal Data Insurance Nov 15, 2022
€3,600 XASTRE DO PETO, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 3,600 on XASTRE DO PETO, S.L. (restaurant). An individual had filed a complaint with the DPA due to the fact that the controller required… SPAIN ·aepd ·Art. 6, 13, 21 Controllers Personal Data Processing Nov 11, 2022
€48,000 Banco Bilbao Vizcaya Argentaria S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. An individual had filed a complaint with the DPA due to requesting information on one of their… SPAIN ·aepd ·Art. 5, 32 Processing Agreement IP Address Insurance Nov 11, 2022
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE ·CNIL ·Art. 5, 13, 25 +2 DPIA Storage Limitation Privacy by Default Nov 10, 2022
€40,000 Azienda Usl Valle d'Aosta: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Usl Valle d'Aosta EUR 40,000. An employee and patient of the health department had filed a complaint with the DPA because a colleague who had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Healthcare Health Data Nov 10, 2022
€500,000 Vodafone Italia S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500,000 on Vodafone Italia S.p.A.. A customer had filed a complaint with the DPA against Vodafone. The 80-year-old customer had been… ITALY ·Garante ·Art. 5, 6, 7 +3 IP Address Personal Data Telecommunications Nov 10, 2022
€5,000 Cisterna di Latina Municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Cisterna di Latina Municipality. An individual had filed a complaint with the DPA. The individual had submitted a request to the… ITALY ·Garante ·Art. 5, 12, 37 Personal Data Public Authority Supervisory Authorities Nov 10, 2022
€900 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on a Homeowners Association. The association had installed several video surveillance cameras across the residential area which, among… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Nov 10, 2022
€6,000 Conservatorio di Musica S. Cecilia di Roma: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on 'Conservatorio di Musica S. Cecilia di Roma'. A student of the educational institution had filed a complaint with the DPA for… ITALY ·Garante ·Art. 2, 5, 6 +1 Notified Body Responsibilities and Operational Obligations Education Public Authority Nov 10, 2022
€4,000 Villafranca di Verona municipality: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on Villafranca di Verona municipality. The municipality had published a document containing personal data of an employee on… ITALY ·Garante ·Art. 2, 5, 6 Personal Data IP Address Employees Nov 10, 2022
€10,000 I-Model s.r.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 10,000 on I-Model s.r.l. A data subject had filed a complaint with the DPA against the controller due to the fact that the… ITALY ·Garante ·Art. 6, 17 Controllers Personal Data Processing Agreement Nov 10, 2022
€5,000 Cisterna di Latina municipality: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Cisterna di Latina municipality. An individual had filed a complaint with the DPA because the municipality had not responded to… ITALY ·Garante ·Art. 5, 12, 37 Personal Data Public Authority Education Nov 10, 2022
€15,000 Poliambulatorio Radiologico 'il Sorriso' S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Poliambulatorio Radiologico 'il Sorriso' S.r.l.. A patient had filed a complaint with the DPA for not receiving sufficient… ITALY ·Garante ·Art. 5, 13, 37 Personal Data Controllers Healthcare Nov 10, 2022
€20,000 Sportitalia: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Sportitalia. The controller processed biometric data (fingerprints) of employees for the purpose of registering their… ITALY ·Garante ·Art. 5, 9, 13 +1 Employees Special Categories of Data IP Address Nov 10, 2022
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 300 on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers Nov 10, 2022
€1,000 SC Das Sense Society SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Das Sense Society SRL EUR 1,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Nov 9, 2022
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide access to information about the purpose of the processing, the storage period, the… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Controllers Data Controller Nov 9, 2022
€5,000 SC Prestige Media PHG SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on SC Prestige Media PHG SRL. The controller had published 23 documents containing information on the termination of employment… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers IP Address Personal Data Nov 8, 2022
€60,000 INFORMÁTICA MÉDICA, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 60,000 on INFORMÁTICA MÉDICA, S.L.. The company acted as a processor for other companies and had engaged a subcontractor without,… SPAIN ·aepd ·Art. 28 Processing Agreement Processors Controllers Nov 7, 2022
€2,000 Romanian Post: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on the Romanian Post. The Post suffered a data breach where staff lost several mailings containing pension statements, employment… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Nov 7, 2022
€70,000 UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on UNITED PARCEL SERVICE ESPAÑA LTD Y COMPAÑIA SRC (UPS). A person had filed a complaint with the DPA because UPS had delivered a… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Security IP Address Nov 3, 2022
€75,000 Burwebs S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Burwebs S.L. EUR 75,000. Burwebs operates websites with adult content. During its investigation, the DPA found that Burwebs did not process users' data… SPAIN ·aepd ·Art. 5, 12, 13 +3 Child Consent IP Address Accountability Nov 3, 2022
€180,000 Setúbal municipality: Non-compliance with general data processing principles The Portuguese DPA has imposed a fine of EUR 170,000 on Setúbal municipality. The DPA found data protection violations regarding the collection of personal data from Ukrainian… PORTUGAL ·CNPD ·Art. 5, 13, 37 Public Authority IP Address Personal Data Nov 2, 2022
€25,000 CAIXABANK S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 25,000 on CAIXABANK S.A.. The data subject had repeatedly and unsuccessfully requested that their address on file with the bank be… SPAIN ·aepd ·Art. 16 Personal Data Insurance Processing Agreement Nov 2, 2022
€2,000 Rapido Finance, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on Rapido Finance, S.L.. The data subject had received a message from a company on behalf of Rapid Finance requesting payment of… SPAIN ·aepd ·Art. 6 Personal Data Insurance Processing Agreement Nov 2, 2022
€1,700 Mayor: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1,700 on the mayor of Dobrzyniewo Duże municipality. The mayor had reported a data breach to the DPA pursuant to Art. 33 GDPR. An… POLAND ·UODO ·Art. 5, 25, 32 Data Breaches Security Privacy by Design & Default Nov 2, 2022
€5,000 CÍTRICOS TANTA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 5,000 on CÍTRICOS TANTA, S.L.. The controller had entered personal data of an employee in the Social Security General Employee Register… SPAIN ·aepd ·Art. 6 Integrity and Confidentiality Principle Controllers Personal Data Nov 2, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD ·Art. 5, 9, 12 +5 DPIA Privacy Shield Privacy Impact Assessment Nov 2, 2022
€56,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA for having unsuccessfully requested a copy of their phone contract from… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle IP Address Telecommunications Oct 31, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 2,000 on a member of a staff council. The individual had sent minutes of staff council meetings to unauthorized third parties that… SPAIN ·aepd ·Art. 6 Processing Agreement Processing Supervisory Authorities Oct 31, 2022
€70,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A customer of the bank had filed a complaint with the DPA. The customer had in the past,… SPAIN ·aepd ·Art. 5, 32 IP Address Personal Data Insurance Oct 31, 2022
€525,000 TECHPUMP SOLUTIONS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Techpump Solutions S.L. EUR 525,000. Techpump operates several websites with adult content. The DPA found several violations of data protection law… SPAIN ·aepd ·Art. 5, 6, 8 +5 Retention Period Storage Limitation Data Subject Rights Exercise Modalities and Procedures Oct 31, 2022