Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1801–1850 of 2,273 sort newestlargest fineoldest
€3,000 Comune di San Marco in Lamis: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,000 on the municipality of San Marco in Lamis. The municipality had uploaded documents containing personal data of the data… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Mar 11, 2021
€15,000 Mediacom s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Mediacom s.r.l.. The controller carried out advertising calls on behalf of TIM s.p.a.. Several of the calls were made… ITALY ·Garante ·Art. 5, 6 Direct Marketing Controllers Personal Data Mar 11, 2021
€8,000 Filigrana Comunicación S.L.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Filigrana Comunicación S.L.U. EUR 8,000. The controller operates a website that provides information on internships offered by the Spanish Ministry of… SPAIN ·aepd ·Art. 6, 13, 14 IP Address Personal Data Controllers Mar 10, 2021
€50,000 Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Equifax Iberica S.L. EUR 50,000 for a violation of Art. 6 (1) f) GDPR. The controller had added the data subject to a debtor register without… SPAIN ·aepd ·Art. 6 Legitimate Interest Personal Data Insurance Mar 10, 2021
€200 Self Employed Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 200 on a self employed person. The accused obtained scans of identity cards from foreign subjects who booked accommodation there and kept… CZECH REPUBLIC ·UOOU ·Art. 5, 6, 12 +4 Personal Data Consent Processing Mar 10, 2021
€90,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 150,000 on Xfera Móviles S.A.. The DPA had received two complaints from a data subject. The first complaint concerned the sending of… SPAIN ·aepd ·Art. 5, 17, 32 Telecommunications Controllers Personal Data Mar 10, 2021
€15,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 15,000 on a homeowners' association. The controller had publicly displayed the record of a homeowners' meeting in the elevator of the… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Mar 9, 2021
€14,900 Dragefossen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) imposed a fine of EUR 14,900 on the energy company Dragefossen AS. The latter had installed a webcam on the roof of its office building in the… NORWAY ·Datatilsynet ·Art. 5, 6 Video Surveillance Monitoring Audit Logs Mar 8, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA ·ANSPDCP ·Art. 32, 58 Security Personal Data Controllers Mar 4, 2021
€6,000 KEPIDES: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 6,000 against KEPIDES (real estate company). The controller had submitted a list of buyers of the properties it manages to a parliamentary… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Anonymization Controllers Security Mar 3, 2021
€40,000 Electricity Authority of Cyprus: Insufficient legal basis for data processing The Cypriot DPA imposed a fine of EUR 40,000 on the Electricity Authority of Cyprus. The controller used an automated system based on the so-called Brad-Factor to manage, monitor… Art. 6, 9 ·Insufficient legal basis for data processing Employees Controllers Personal Data Mar 3, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Art. 12, 15, 31 +1 ·Insufficient fulfilment of information obligations Right of Access Procedures Right of Access Inspection Access Rights and Cooperation Obligations Mar 3, 2021
€9,000 SPAIN DPA: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 9,000 on a website operator. The controller had published photos of the data subject on its website without the consent of the data… aepd ·Art. 6, 13 ·Insufficient legal basis for data processing Controllers Personal Data Processing Agreement Mar 2, 2021
€200,000 I-DE Redes Eléctricas Inteligentes, S.A.U: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on I-DE Redes Eléctricas Inteligentes, S.A.U. The DPA received complaints from Waitum, S.L. and Servicios Aby 2018, S.L.… SPAIN ·aepd ·Art. 5, 6 Integrity and Confidentiality Principle Controllers IP Address Mar 2, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA ·VDAI ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 2, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Health Data Healthcare Feb 26, 2021
€3,000 IT sprendimai sėkmei: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 3,000 on the company 'IT sprendimai sėkmei'. The DPA had opened an investigation regarding a quarantine app introduced in Lithuania… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Privacy Impact Assessment Healthcare Feb 26, 2021
€2,000 Comune di Conflenti: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 2,000 on the municipality of Conflenti. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Employees Feb 25, 2021
€6,000 Comune di Commezzadura: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 6,000 on the municipality of Commezzadura. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare IP Address Feb 25, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY ·Garante ·Art. 5, 25, 35 Fairness & Transparency DPIA IP Address Feb 25, 2021
€12,000 Avilon Center 2016 S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 20,000 on Avilon Center 2016 S.L. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·aepd ·Art. 21, 23, 48 Personal Data Controllers Direct Marketing Feb 24, 2021
Deutsche Wohnen SE: Non-compliance with general data processing principles Originally, a fine in the amount of EUR 14.500.000 was issued against Deutsche Wohnen SE for using an archiving system for the storage of personal data of tenants that, according… GERMANY ·Art. 5, 25 ·Non-compliance with general data processing principles Fines Personal Data Controllers Feb 23, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Right to Object Processing Feb 23, 2021
Security company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A data controller using the services of the security company reported the breach of personal data to the DPA, arising after an employee of the security company recorded the video… CROATIA ·azop ·Art. 32 Security Controllers Processors Feb 22, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet ·Art. 5 Fines Administrative Fines on Union Institutions, Bodies, Offices and Agencies Storage Limitation Feb 12, 2021
€120,000 Vodafone España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A former customer had received e-mails containing electronic bills even after he had terminated his… SPAIN ·aepd ·Art. 5, 6 Personal Data Controllers Telecommunications Feb 12, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Prior Consultation IP Address Controllers Feb 11, 2021
€24,000 Vamavi Phone S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Vamavi Phone S.L.. The data subject had received an advertising call from the controller made on behalf of Vodafone España,… SPAIN ·aepd ·Art. 21, 23, 28 +1 Direct Marketing Controllers Personal Data Feb 11, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Data Breaches Integrity and Confidentiality Principle Security Feb 11, 2021
€440,000 OLVG: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) imposed a fine of EUR 440,000 on the Amsterdam hospital OLVG. The controller had taken insufficient measures between 2018 and 2020 to prevent access by… THE NETHERLANDS ·AP ·Art. 32 Healthcare Healthcare Health Data Feb 11, 2021
€5,000 Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da Pietrelcina: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Foundation for Religion and Worship 'Casa sollievo della sofferenza' Opera di San Pio da Pietrelcina. On January… ITALY ·Garante ·Art. 5, 9 Notification Obligation Data Breaches Personal Data Feb 11, 2021
€1,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine of EUR 1,000 on ING Bank N.V. Amsterdam - Bucharest Branch. It was found that the controller had sent files to a contractual partner in… ROMANIA ·ANSPDCP ·Art. 29, 32 Integrity and Confidentiality Principle Professional Secrecy Security Feb 10, 2021
€65,000 Lursoft IT SIA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined Lursoft IT SIA EUR 65,000 for the illegal processing of personal data by publishing documents containing personal data on its website 'www.lursoft.lv'.… LATVIA ·DSI ·Art. 6 Personal Data Controllers Processing Feb 9, 2021
€3,000 Patio Ancestral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on Patio Ancestral S.L.. The complainant worked for a construction company and had carried out some renovation work for the… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Feb 8, 2021
€5,000 Private Person: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 5,000 for illegal camera surveillance. The data subject had rented two rooms in the apartment of the controller. The… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Personal Data Feb 8, 2021
€12,000 Orthodontic Clinic: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined an orthodontic clinic EUR 12,000. The web form that new patients used to sign up contained mandatory fields for all sorts of patient personal data.… THE NETHERLANDS ·AP ·Art. 32 Encryption Healthcare Security Feb 4, 2021
€19,300 Cyberbook AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Cyberbook AS NOK 200,000 (EUR 19,300) for the illegal automatic forwarding of e-mails from a former employee. The forwarding took place for… NORWAY ·Datatilsynet ·Art. 5, 6 Personal Data Employees Processing Agreement Feb 3, 2021
€100,000 Iberdrola Clientes: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 100,000 on Iberdrola Clientes, SAU. The data subject had terminated an existing contract with the controller due to a move and… SPAIN ·aepd ·Art. 5, 17 Controllers Personal Data Processing Agreement Feb 3, 2021
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Right to Object Personal Data Processing Feb 2, 2021
€80 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 80 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Right to Object Processing Feb 1, 2021
€24,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Xfera Móviles S.A.. The data subject claimed a violation of its right to information to the AEPD. The AEPD then issued a… SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision Feb 1, 2021
€3,000 IDFINANCE Spain, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on IDFINANCE Spain S.L.. A person had received a debt collection email from IDFinance that contained a link for the payment of… aepd ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Insurance Security Controllers Feb 1, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY ·Garante ·Art. 5, 9 Healthcare Health Data Data Breaches Jan 27, 2021
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Prior Consultation Jan 27, 2021
€75,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Data Breaches Access Controls Jan 27, 2021
€50,000 Azienda USL della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 50,000 on Azienda USL della Romagna. Upon her arrival at the gynecology unit of a hospital operated by the controller (for the… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Healthcare Jan 27, 2021
€150,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Encryption Access Controls Jan 27, 2021
€50,000 Family Service / N.D.P.K. nv.: Insufficient legal basis for data processing The Belgian DPA imposed a fine of EUR 50,000 on Family Service / N.D.P.K. nv. The controller is an advertising agency that, among other things, sends expectant mothers gift boxes… BELGIUM ·APD ·Art. 5, 6, 7 +4 Controllers IP Address Processing Agreement Jan 27, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 IP Address Personal Data Education Jan 27, 2021
€25,000 BELGIUM DPA: Insufficient technical and organisational measures to ensure information security The Belgian DPA fined a mobile operator EUR 25,000. The controller had assigned the data subject's phone number to an unauthorized third party, causing the data subject to lose… APD ·Art. 5, 24, 32 +2 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Social Media Jan 22, 2021