Skip to content
Content type · 2,035 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1801–1850 of 2,035 sort newestlargest fineoldest
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Retention Period Personal Data May 13, 2021
€2.9M Iren Mercato S.p.A.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Iren Mercato S.p.A. EUR 2,856,169 for failing to verify that all transfers of data of recipients of promotional activities were covered by consent.… ITALY ·Garante ·Art. 5, 6, 7 Personal Data Controllers Consent May 13, 2021
€2,000 Telekom Romania Communications SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Telekom Romania Communications SA. The controller had made an advertising call to the data subject although the… ANSPDCP ·Art. 6, 21 ·Insufficient fulfilment of data subjects rights Personal Data Right to Object Direct Marketing May 13, 2021
€2,400 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,400 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD (LU) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Accountability May 12, 2021
€3,000 Solram T Y R S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on Solram T Y R S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·AEPD ·Art. 17 Personal Data Controllers Supervisory Authorities May 12, 2021
€1,900 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,900 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD (LU) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Accountability May 12, 2021
€5,000 KARIERA A.E.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 5,000 on ΚARIERA A.E.. A data subject had filed a complaint with the DPA against the controller due to the fact that the controller… GREECE ·HDPA ·Art. 17, 21, 25 Personal Data Controllers Supervisory Authorities May 12, 2021
€5,000 A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ: Non-compliance with general data processing principles The Hellenic DPA has fined A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ EUR 5,000. The controller had not responded to requests for information and deletion from the data subject.… GREECE ·HDPA ·Art. 5, 12, 15 +1 Personal Data Controllers Consent May 12, 2021
€1,000 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,000 on a company. The controller had installed a video surveillance system with the purposes of the protection of… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers May 12, 2021
€2,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,600 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers May 12, 2021
€2,000 World Class România S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on World Class România S.A.. The controller had published the termination letter of an employee in a WhatsApp group used… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Controllers Security May 7, 2021
€1.5M EDP Energía, S.A.U: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Energía, S.A.U.. The decision follows, in particular, several complaints received for processing personal data… SPAIN ·AEPD ·Art. 13, 25 Personal Data Controllers Representatives May 4, 2021
€1.5M EDP Comercializadora, S.A.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing… SPAIN ·AEPD ·Art. 13, 25 Personal Data Controllers Representatives May 4, 2021
EDPS: CJEU violated Regulation 2018/1725 over cookies and consent on its website A data subject complained around cookies and similar technologies used in connection to audiovisual material on the website of the Court of Justice of the European Union (CJEU),… 2019-0878 ·European Union ·Art. 7 Consent Information Provision Modalities and Communication Methods Personal Data May 3, 2021
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Persónuvernd ·Art. 32 Data Breaches Security Controllers Apr 29, 2021
€3,000 Pagamastarde S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Pagamastarde S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Apr 27, 2021
€15,000 Anytime Fitness Iberia S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on Anytime Fitness Iberia S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Apr 27, 2021
€5,050 PNP S.A.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Polish DPA (UODO) for investigative purposes. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Controllers Apr 27, 2021
€570 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 570 on a company. In the course of his professional activities, a data subject had made a telephone call to a company on… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Accountability Apr 27, 2021
€1,400 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,400 on a company. In the course of his professional activities, a data subject had made a telephone call to the controller on… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Accountability Apr 27, 2021
€100,000 Financial company: Insufficient technical and organisational measures to ensure information security The Belgian DPA (APD) has imposed a fine of EUR 100,000 on a financial company. A data subject had filed two complaints with the APD against the company. They were based on 20… BELGIUM ·APD/GBA ·Art. 5, 32 Personal Data Controllers Security Apr 26, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·AEPD ·Art. 5, 6, 14 Integrity and Confidentiality Principle Personal Data Retention Period Apr 23, 2021
€4,000 HazteOir.Org: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on HazteOir.Org. The controller had published a brochure on sex education in schools which unlawfully contained the photos… SPAIN ·AEPD ·Art. 6 Personal Data Consent Controllers Apr 22, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Personal Data Controllers Apr 22, 2021
€1,500 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed a surveillance camera on his property, which recorded, among other… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Security Apr 22, 2021
€15,000 Fondazione Policlinico Tor Vergata di Roma: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Fondazione Policlinico Tor Vergata di Roma. In February 2020, a data subject filed a complaint with Garante alleging… ITALY ·Garante ·Art. 5, 13, 25 +1 Personal Data Privacy by Design & Default Controllers Apr 21, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 14 +3 Personal Data Retention Period Storage Limitation Apr 21, 2021
€2,800 Website operator: Non-compliance with general data processing principles The Hungarian DPA (NAIH) has imposed a fine of EUR 2,800 on a website operator. The controller had failed to prove the lawfulness of its processing of personal data upon request… HUNGARY ·NAIH ·Art. 5, 24 Controllers Personal Data Accountability Apr 20, 2021
€8,000 Highcliffe Estates Marbella S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 8,000 on Highcliffe Estates Marbella S.L.. The controller had published a photo of the data subject on its website without his… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Apr 20, 2021
€1,500 Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A.,… ROMANIA ·ANSPDCP ·Art. 29, 32 Controllers Security Processors Apr 19, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Controllers Supervisory Authorities Apr 16, 2021
€3,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller resides on the 1st floor of an apartment building, where he is the owner of… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Processing Apr 15, 2021
€2,000 Società triveneta di chirurgia: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Società triveneta di chirurgia. A physician had shown slides of a clinical case at a congress, which were subsequently… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Controllers Healthcare Apr 15, 2021
€5,000 S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined S.C. Tip Top Food Industry S.R.L. EUR 5,000. The controller had installed several video cameras in the food areas and changing rooms to… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Retention Period Controllers Personal Data Apr 15, 2021
€5,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Controllers Healthcare Apr 15, 2021
€12,000 Istituto Nazionale Previdenza Sociale (INPS): Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 12,000 on the Italian National Institute for Social Security (Istituto Nazionale della Previdenza Sociale). That fine was based… ITALY ·Garante ·Art. 5, 12, 15 Personal Data Controllers Supervisory Authorities Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications Apr 13, 2021
€3,400 Miljø- og Kvalitetsledelse AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 3,400 on Miljø- og Kvalitetsledelse AS. At one of the carwashes operated by the controller, incidents of vandalism had… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Processing Supervisory Authorities Apr 9, 2021
€60,000 Kutxabank, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request… SPAIN ·AEPD ·Art. 17 Personal Data Right to be Forgotten Controllers Apr 8, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Storage Limitation Retention Period Apr 8, 2021
€2,400 Promotech Digital S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined Promotech Digital S.L. EUR 2,400 for repeatedly sending the data subject advertising SMS, even though he never subscribed or agreed to receive… SPAIN ·AEPD ·Art. 21 Personal Data Direct Marketing Controllers Apr 6, 2021
€3,000 Kukimbia S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Kukimbia S.L. EUR 3,000. The controller is a company that stores, transports and distributes goods. Documents containing personal data about the… SPAIN ·AEPD ·Art. 32 Controllers Security Personal Data Apr 5, 2021
€4,000 Stockhunters S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Stockhunters S.L.. The controller was not able to answer the data subject's requests regarding the use of his personal… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Apr 5, 2021
€3,000 Electrotecnica Bastida S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Electrotecnica Bastida S.L. EUR 3,000. Police officers had found 29 envelopes addressed to the controllers' respective employees on a vacant lot… SPAIN ·AEPD ·Art. 32 Security Controllers Personal Data Apr 5, 2021
€10,000 Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security The Romania DPA (ANSPDCP) has fined Telekom Romania Mobile Communications S.A. EUR 10,000 for failing to implement adequate security measures to ensure the security of personal… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Controllers Mar 30, 2021
€7,000 TECNOMEDICAL S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 7,000 on TECNOMEDICAL S.r.l.. A data subject filed a complaint with the DPA after the controller failed to properly respond to… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Mar 25, 2021
€1,425 Operator of a care facility: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,425 on the operator of a care facility. The operator had installed a total of 25 cameras in all rooms of the facility, with… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Processing Mar 25, 2021
€20,000 GEDI News Network Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on GEDI News Network Spa. A data subject filed a complaint with the Italian DPA against the controller regarding an… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Mar 25, 2021
€30,000 OneDirect Srl: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 30,000 on OneDirect Srl. A data subject had filed two complaints with the DPA after receiving advertisements by e-mail from the… ITALY ·Garante ·Art. 6, 7, 30 +1 Personal Data Controllers Processing Mar 25, 2021
€4.5M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Fastweb S.p.A. EUR 4,500,000 for aggressive telemarketing. Following a complex preliminary investigation launched after hundreds of reports and… ITALY ·Garante ·Art. 5, 6, 7 +8 Direct Marketing Personal Data Controllers Mar 25, 2021