Skip to content
Content type · 2,035 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1751–1800 of 2,035 sort newestlargest fineoldest
€50,000 Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 50,000 on Caixabank S.A.. A data subject had filed a complaint with the DPA because he had received commercial advertising from… SPAIN ·AEPD ·Art. 6 Direct Marketing Personal Data Right to Object Jul 8, 2021
€5,000 Pediatrician: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined a pediatrician EUR 5,000. A father had asked the controller to view the medical records contained in his child's patient file via e-mail. However, the… GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Jul 8, 2021
€53,800 Nordbornholms Byggeforretning Aps: Insufficient legal basis for data processing The Danish DPA ( Datatilsynet) has imposed a fine of EUR 53,800 on Nordbornholms Byggeforretning Aps. In 2018, the DPA was contacted by a data subject who complained that his… DENMARK ·Datatilsynet (DK) ·Art. 5, 6 Legitimate Interest Personal Data Controllers Jul 7, 2021
€4,200 Marbella Resorts S.L.: Insufficient data processing agreement The Spanish DPA (AEPD) has imposed a fine of EUR 7,000 on Marbella Resorts S.L.. In the case at hand, the data subject had booked a room in the hotel complex of the controller. On… SPAIN ·AEPD ·Art. 28 Controllers Personal Data Processors Jul 6, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Jul 5, 2021
€25,000 Higher Education Institution: Non-compliance with general data processing principles The Finnish DPA imposed a fine of EUR 25,000 on a higher education institution for data protection violations in the processing of employee location data. The controller had… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6 Retention Period Controllers Processing Jul 5, 2021
Insurance company: Insufficient fulfilment of information obligations The DPA has ex officio, without prior notice, conducted a direct supervision over an insurance company based in Zagreb. Upon inspection of its business facility for carrying out… CROATIA ·AZOP ·Art. 13, 14 Controllers Supervisory Authorities Supervision Jul 5, 2021
€1,500 Private Individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. That private individual had published personal data of the data subject on a website without her… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Processing Jul 2, 2021
€1,000 SPAIN DPA: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000 on a company. The controller had used the personal data of a third party in order to obtain a microcredit. The DPA states… AEPD ·Art. 6 ·Insufficient legal basis for data processing Controllers Personal Data Supervisory Authorities Jul 1, 2021
€3,000 Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 30, 2021
€12,500 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 12,500 on a company. The company had installed a video surveillance system for the purpose of protecting company property,… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers Jun 29, 2021
€8,500 Magazine publisher: Insufficient legal basis for data processing The Finnish DPA has imposed a fine of EUR 8,500 on a magazine publisher. The DPA received four complaints against the magazine publisher for unsolicited telephone advertising.The… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 7, 12 +3 Direct Marketing Right to Object Consent Jun 24, 2021
€10,000 TNT EXPRESS WORLDWIDE SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 10,000 on TNT EXPRESS WORLDWIDE SPAIN, S.L.. The data subject had placed a private order with the controller and had entered the… AEPD ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers Processing Jun 22, 2021
€24,800 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 14,800 on a company. The background to the case is a complaint by a former employee who learned that the company's… Datatilsynet (NO) ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Supervisory Authorities Right to Object Personal Data Jun 22, 2021
€20,000 UAB VS FITNESS: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) has imposed a fine of EUR 20,000 on UAB VS FITNESS. After receiving a notification from an individual stating that scanning a fingerprint was necessary… LITHUANIA ·VDAI ·Art. 5, 9, 13 +2 Controllers DPIA Types of Special Categories of Personal Data Jun 21, 2021
€1.6M Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has fined Storstockholms Lokaltrafik (Stockholm Local Transport Company) EUR 1,600,000. The controller had equipped ticket inspectors with body-worn cameras, which… SWEDEN ·IMY ·Art. 5, 6, 13 Retention Period Identification Fairness & Transparency Jun 21, 2021
€35,300 Sopockie Towarzystwo Ubezpieczeń ERGO Hestia S.A.: Insufficient fulfilment of data breach notification obligations The controller had sent an email to that contained personal data of a customer to the wrong recipient. The leaked data included data such as the name, postal address of the data… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 21, 2021
€28,400 Magyar Telekom Nyrt.: Insufficient fulfilment of data subjects rights The Hungarian DPA (NAIH) has imposed a fine of EUR 28,400 on Magyar Telekom Nyrt. The controller had mistakenly sent an e-mail newsletter to the data subject. This occurred due to… HUNGARY ·NAIH ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Jun 18, 2021
€34,000 Huppuís ehf: Non-compliance with general data processing principles The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 34,000 on Huppuís ehf. A former employee filed a complaint against the controller with the DPA. The reason for this was… ICELAND ·Persónuvernd ·Art. 5, 6, 12 +1 Legitimate Interest Controllers Personal Data Jun 15, 2021
€1,200 Inmopiso Zaragoza S.L.: Insufficient fulfilment of information obligations The controller failed to provide accurate information about the data collection in accordance with Art. 13 GDPR. The original fine of EUR 2,000 was reduced to EUR 1,200 due to… SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Jun 14, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Retention Period Personal Data Jun 14, 2021
€7,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,600 on a company. This company had installed a video surveillance system for the purpose of protecting the company's… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers Jun 11, 2021
€7,200 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,200 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD (LU) ·Art. 5, 13, 32 ·Non-compliance with general data processing principles Supervisory Authorities Storage Limitation Retention Period Jun 11, 2021
€15,000 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA of Luxembourg (CNPD) has imposed a fine of EUR 15,000 on a company. During an investigation, the DPA found that the controller had not sufficiently involved the data… CNPD (LU) ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Personal Data Jun 11, 2021
€40,000 Aeroporto Guglielmo Marconi di Bologna S.p.a.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Encryption Jun 10, 2021
€40,000 aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 28, 32 Encryption Security Controllers Jun 10, 2021
€2.6M Foodinho s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Foodinho s.r.l. EUR 2,600,000. Foodinho is an Italian food delivery service. The investigation against Foodinho mainly focused on the drivers… ITALY ·Garante ·Art. 5, 13, 22 +5 Retention Period Privacy by Design & Default Controllers Jun 10, 2021
€2,000 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on an unknown controller. The accused did not respond to the subject's request to disclose what information the accused was… ÚOOÚ (CZ) ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Jun 9, 2021
€34,800 Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 34,800 on the directorate of the Östra Skaraborg Rescue Service. The DPA had received information that several fire stations in Östra… SWEDEN ·IMY ·Art. 5, 32 Controllers Processing Video Surveillance Jun 9, 2021
€19,600 Radiotelevisión del principado de Asturias: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 26,000 on Radiotelevisión del principado de Asturias. The fine consists of EUR 20,000 due to a violation of Art. 5 (1) c) GDPR and… SPAIN ·AEPD ·Art. 5, 12 Retention Period Controllers Personal Data Jun 7, 2021
€20,000 Master Distancia S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 25,000 on Master Distancia S.A.. The controller had included personal data of the data subject in a credit report register without… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Public Authority Jun 7, 2021
€6,000 Creator Energy S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on Creator Energy S.L.. The controller had used the personal data of the data subject without his consent to conclude… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 4, 2021
€15,000 PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ: Non-compliance with general data processing principles The Hellenic DPA has fined PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ EUR 15,000 due to the illegal installation and operation of a video surveillance system. The controller had installed a video… GREECE ·HDPA ·Art. 5 Accountability Controllers Transparency Jun 3, 2021
€4,000 Avalos Consultores, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Avalos Consultores, S.L.. The data subject, who was a client of the controller, filed a complaint with the AEPD because… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 2, 2021
€18,000 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA of Luxembourg has imposed a fine of EUR 18,000 on a company. According to the DPA, the controller firstly failed to involve the data protection officer in all matters… CNPD (LU) ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Personal Data May 31, 2021
€39,700 BRAbank ASA: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,700 on BRAbank ASA. The controller had reported a data breach to the DPA on September 6, 2019. On the controller's… NORWAY ·Datatilsynet (NO) ·Art. 24, 32 Security Controllers Personal Data May 28, 2021
€150,000 Azienda Provinciale per i Servizi Sanitari di Trento: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Provinciale per i Servizi Sanitari di Trento EUR 150,000. The controller had accidentally forwarded 293 medical reports of 175 patients… ITALY ·Garante ·Art. 5, 9 Controllers Healthcare Processing May 27, 2021
€100,000 Vodafone España, SAU: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Vodafone España, S.A.U.. A data subject had filed a complaint with the Spanish DPA against the telecommunications… SPAIN ·AEPD ·Art. 28 Controllers Processors Personal Data May 25, 2021
€4,000 Alava Norte, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Alava Norte, S.L. EUR 4,000. The controller had installed three 360° video surveillance cameras on the facade of one of its buildings to secure… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Security May 25, 2021
€6,000 Desolasol Restauración, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Desolasol Restauración S.L. EUR 6,000. The data subject had submitted a consumer complaint form to the restaurant because he was unable to… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing May 25, 2021
€900 Managing Director of a company: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on the managing director of a company. A data subject filed a complaint with the AEPD against the controller with whom he… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities May 25, 2021
€3,000 Physician: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined a physician EUR 3,000. The controller had left his/her former clinic and started working in a new clinic. The complainant had taken over the… SPAIN ·AEPD ·Art. 6 Controllers Healthcare Processing May 21, 2021
€45,000 Telefónica de España, S.A.U: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 75,000 on Telefonica de España, S.A.U.. A data subject had filed a complaint with the AEPD against the telecommunications company.… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications May 21, 2021
€39,000 Municipality of Oslo: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,000 on the Municipality of Oslo. On a website of the controller a subpoena from the public prosecutor's office… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Public Authority Personal Data Controllers May 20, 2021
€2,000 Banca Comercială Română S.A.: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined Banca Comercială Română S.A. EUR 2,000. A data subject had initiated a complaint with the DPA because the controller had used his personal… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing May 19, 2021
€500 Owners Association of Iasi Municipality: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has imposed a fine of EUR 500 on Asociație de Proprietari din municipiul Iași (Owners Association of Iasi Municipality). The controller did not provide… ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Controllers May 19, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out several credit checks on the data… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Consent May 18, 2021
€10,000 Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato: Insufficient legal basis for data processing The Hellenic DPA has fined the Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato EUR 10,000. The controller had… GREECE ·HDPA ·Art. 6, 12, 17 Public Authority Personal Data Controllers May 17, 2021
€30,000 Allianz Compañia de Seguros y Reaseguros, S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Allianz Compañia de Seguros y Reaseguros, S.A. EUR 30,000. The controller had sent an invoice to the data subject although no contractual… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance May 14, 2021
€200 Website operator: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on the operator of the website declaratieppr.ro. During the Covid19 pandemic, visitors to the site were able to fill out a… ROMANIA ·ANSPDCP ·Art. 5, 6, 13 +1 Personal Data Controllers Security May 14, 2021