Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1751–1800 of 2,273 sort newestlargest fineoldest
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement Apr 29, 2021
€2,000 Santa Ninfa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Santa Ninfa municipality. The municipality had published a resolution on its website that contained personal information… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Public Authority IP Address Apr 29, 2021
€15,000 Anytime Fitness Iberia S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on Anytime Fitness Iberia S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact… SPAIN ·aepd ·Art. 17, 21 Personal Data Controllers Processing Agreement Apr 27, 2021
€570 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 570 on a company. In the course of his professional activities, a data subject had made a telephone call to a company on… HUNGARY ·NAIH ·Art. 5, 6, 13 IP Address Controllers Accountability Apr 27, 2021
€1,400 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,400 on a company. In the course of his professional activities, a data subject had made a telephone call to the controller on… HUNGARY ·NAIH ·Art. 5, 6, 13 Accountability Controllers Personal Data Apr 27, 2021
€5,050 PNP S.A.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Polish DPA (UODO) for investigative purposes. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Apr 27, 2021
€3,000 Pagamastarde S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Pagamastarde S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·aepd ·Art. 17, 21 Controllers Personal Data Processing Agreement Apr 27, 2021
€100,000 Financial company: Insufficient technical and organisational measures to ensure information security The Belgian DPA (APD) has imposed a fine of EUR 100,000 on a financial company. A data subject had filed two complaints with the APD against the company. They were based on 20… BELGIUM ·APD ·Art. 5, 32 Personal Data Security Controllers Apr 26, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·aepd ·Art. 5, 6, 14 Integrity and Confidentiality Principle Fairness & Transparency Insurance Apr 23, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Recipient Security Apr 22, 2021
€4,000 HazteOir.Org: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on HazteOir.Org. The controller had published a brochure on sex education in schools which unlawfully contained the photos… SPAIN ·aepd ·Art. 6 Education Consent Personal Data Apr 22, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 14 +3 Retention Period Storage Limitation Personal Data Apr 21, 2021
€15,000 Fondazione Policlinico Tor Vergata di Roma: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Fondazione Policlinico Tor Vergata di Roma. In February 2020, a data subject filed a complaint with Garante alleging… ITALY ·Garante ·Art. 5, 13, 25 +1 Healthcare Personal Data Processing Agreement Apr 21, 2021
€2,800 Website operator: Non-compliance with general data processing principles The Hungarian DPA (NAIH) has imposed a fine of EUR 2,800 on a website operator. The controller had failed to prove the lawfulness of its processing of personal data upon request… HUNGARY ·NAIH ·Art. 5, 24 Accountability Controllers IP Address Apr 20, 2021
€8,000 Highcliffe Estates Marbella S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 8,000 on Highcliffe Estates Marbella S.L.. The controller had published a photo of the data subject on its website without his… SPAIN ·aepd ·Art. 6 Controllers Personal Data Consent Apr 20, 2021
€1,500 Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A.,… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Processors Apr 19, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Education Controllers Apr 16, 2021
€5,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on… ITALY ·Garante ·Art. 5, 6, 9 Healthcare Healthcare Personal Data Apr 15, 2021
€5,000 S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined S.C. Tip Top Food Industry S.R.L. EUR 5,000. The controller had installed several video cameras in the food areas and changing rooms to… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Video Surveillance Employees IP Address Apr 15, 2021
€2,000 Società triveneta di chirurgia: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Società triveneta di chirurgia. A physician had shown slides of a clinical case at a congress, which were subsequently… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Healthcare Apr 15, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Personal Data Apr 15, 2021
€12,000 Istituto Nazionale Previdenza Sociale (INPS): Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 12,000 on the Italian National Institute for Social Security (Istituto Nazionale della Previdenza Sociale). That fine was based… ITALY ·Garante ·Art. 5, 12, 15 Personal Data Education Controllers Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·aepd ·Art. 6 Controllers IP Address Telecommunications Apr 13, 2021
€750,000 TikTok: Insufficient fulfilment of information obligations The Dutch DPA (AP) has fined the video portal TikTok EUR 750,000 for violating the privacy of young children. The information that Dutch users - mostly young children - received… THE NETHERLANDS ·AP ·Art. 12 Minors Social Media Personal Data Apr 9, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Apr 8, 2021
€60,000 Kutxabank, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request… SPAIN ·aepd ·Art. 17 Right to be Forgotten Personal Data Data Subject Rights Exercise Modalities and Procedures Apr 8, 2021
€2,400 Promotech Digital S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined Promotech Digital S.L. EUR 2,400 for repeatedly sending the data subject advertising SMS, even though he never subscribed or agreed to receive… SPAIN ·aepd ·Art. 21 Direct Marketing Personal Data Controllers Apr 6, 2021
€3,000 Kukimbia S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Kukimbia S.L. EUR 3,000. The controller is a company that stores, transports and distributes goods. Documents containing personal data about the… SPAIN ·aepd ·Art. 32 Controllers Security Processing Agreement Apr 5, 2021
€3,000 Electrotecnica Bastida S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Electrotecnica Bastida S.L. EUR 3,000. Police officers had found 29 envelopes addressed to the controllers' respective employees on a vacant lot… SPAIN ·aepd ·Art. 32 Security Privacy by Design & Default Controllers Apr 5, 2021
€4,000 Stockhunters S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Stockhunters S.L.. The controller was not able to answer the data subject's requests regarding the use of his personal… SPAIN ·aepd ·Art. 13 Personal Data Controllers Insurance Apr 5, 2021
€10,000 Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security The Romania DPA (ANSPDCP) has fined Telekom Romania Mobile Communications S.A. EUR 10,000 for failing to implement adequate security measures to ensure the security of personal… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Security Mar 30, 2021
€7,000 TECNOMEDICAL S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 7,000 on TECNOMEDICAL S.r.l.. A data subject filed a complaint with the DPA after the controller failed to properly respond to… ITALY ·Garante ·Art. 12, 15 Health Data Healthcare Personal Data Mar 25, 2021
€4,000 Comune di Castellanza: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the municipality of Castellanza. The municipality had uploaded documents containing personal data of the data subject… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Mar 25, 2021
€4.5M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Fastweb S.p.A. EUR 4,500,000 for aggressive telemarketing. Following a complex preliminary investigation launched after hundreds of reports and… ITALY ·Garante ·Art. 5, 6, 7 +8 IP Address Telecommunications Direct Marketing Mar 25, 2021
€20,000 GEDI News Network Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on GEDI News Network Spa. A data subject filed a complaint with the Italian DPA against the controller regarding an… ITALY ·Garante ·Art. 12 Controllers Personal Data Telecommunications Mar 25, 2021
€6,000 Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (boarding school): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (CE) boarding school. The boarding school had published a document… ITALY ·Garante ·Art. 2, 5, 6 Education Personal Data Public Authority Mar 25, 2021
€1,425 Operator of a care facility: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,425 on the operator of a care facility. The operator had installed a total of 25 cameras in all rooms of the facility, with… HUNGARY ·NAIH ·Art. 5, 6, 13 Video Surveillance Healthcare Monitoring Mar 25, 2021
€30,000 OneDirect Srl: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 30,000 on OneDirect Srl. A data subject had filed two complaints with the DPA after receiving advertisements by e-mail from the… ITALY ·Garante ·Art. 6, 7, 30 +1 Right to Object Controllers Personal Data Mar 25, 2021
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY ·NAIH ·Art. 32, 33, 34 Encryption Integrity and Confidentiality Principle Healthcare Mar 24, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Health Data Mar 23, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Education Controllers Mar 22, 2021
€19,900 Basaren Drift AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 19,900 on Basaren Drift AS. The controller had installed video cameras in its premises which recorded both its employees… NORWAY ·Datatilsynet ·Art. 5, 6, 13 Video Surveillance Controllers Monitoring Mar 21, 2021
€4,900 Funeda Sp. z o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined Funeda Sp. z o.o. EUR 4,900 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Processing Agreement Mar 19, 2021
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 60,000 on Vodafone Spain. The data subject had been a customer of the controller several years ago. After receiving payment reminders… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Mar 16, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet ·Art. 5, 6, 24 +1 Data Breaches IP Address Security Mar 15, 2021
€2,000 Heredad de Urueña S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Heredad de Urueña S.A. EUR 2,000 because its personal data processing policy did not comply with the requirements of Art. 13 GDPR. In addition, the… SPAIN ·aepd ·Art. 13 Personal Data Controllers Processing Agreement Mar 15, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data IP Address Accuracy Mar 15, 2021
€12,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U. EUR 20,000. An identity thief had obtained the data of a third party without authorization and applied for a microcredit… SPAIN ·aepd ·Art. 6 Controllers Recipient IP Address Mar 12, 2021
€8.2M Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Since 2018, the Spanish DPA (AEPD) had received a total of 191 complaints against Vodafone España, S.A.U. The data subjects complained about advertising calls and messages (e-mail… SPAIN ·aepd ·Art. 21, 23, 24 +3 Right to Object Fines Telecommunications Mar 11, 2021
€80,000 Planet Group Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 80,000 on Planet Group Spa. The controller made promotional calls on behalf of TIM s.p.a.. Several of these calls were made… ITALY ·Garante ·Art. 5, 6, 12 +2 Right to Object Data Subject Rights Exercise Modalities and Procedures Direct Marketing Mar 11, 2021