Content type · 1,941 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY · ·Art. 5, 13, 14 +4 Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY · ·Art. 5, 6, 9 +1 Dec 17, 2020
€6,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well… FRANCE · ·Art. 32, 33 Dec 17, 2020
€3,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 3,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data as MRI and X-ray images as well as… FRANCE · ·Art. 32, 33 Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY · ·Art. 12 Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY · ·Art. 5, 13, 14 +2 Dec 17, 2020
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY · ·Art. 5, 6 Dec 17, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Dec 16, 2020
€1,940 HUNGARY DPA: Insufficient fulfilment of information obligations The Hungarian DPA (NAIH) imposed a fine of HUF 700,000 (EUR 1,940) against a construction company. The controller had installed a video surveillance system at a construction site… ·Art. 5, 13 ·Insufficient fulfilment of information obligations Dec 16, 2020
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Dec 11, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Dec 11, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY · ·Art. 5, 6, 9 +2 Dec 10, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS · ·Art. 33 Dec 10, 2020
€2,850 Smart Cities Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the Polish DPA (UODO). The controller failed to provide personal data and other information requested by UODO for investigative… POLAND · ·Art. 31, 58 Dec 9, 2020
€18,850 TUiR Warta S.A.: Insufficient fulfilment of data breach notification obligations An insurance agent hired by the controller had sent an email to unauthorized third parties in regard to insurance policies that contained personal data of two of the company's… POLAND · ·Art. 33, 34 Dec 9, 2020
€35M CNIL fines Amazon Europe Core €35M for placing cookies without consent Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating… France ·Art. 6, 9, 83 +1 Dec 7, 2020
€3,000 Comercio Online Levante, S.L.: Insufficient technical and organisational measures to ensure information security A woman filed a complaint with the Spanish DPA (AEPD) against Comercio Online Levante, S.L. due to the fact that she was shown the personal data of another user when trying to… SPAIN · ·Art. 5, 32 Dec 2, 2020
€6,000 Servicio de Alojamientos Responsables, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine in the amount of EUR 6,000 against the controller for unauthorized conclusion of a contract in the name of the data subject without his/her… SPAIN · ·Art. 6 Dec 2, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Nov 26, 2020
€3,000 Charly Mike s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Charly Mike s.r.l.. The controller is the hotel operator of the Hotel Olimpo in Alberobello. Garante received a complaint… ITALY · ·Art. 5, 13 Nov 26, 2020
€1,500 Private Individual: Insufficient legal basis for data processing The Belgian DPA (APD) imposed a fine against private individuals. The controllers installed video cameras on their private property, two of which were positioned in a way that… BELGIUM · ·Art. 6, 25 Nov 25, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Nov 19, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… ·Art. 5 ·Non-compliance with general data processing principles Nov 18, 2020
€900,000 Telecoms provider (1&1 Telecom GmbH): Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's… GERMANY · ·Art. 32 Nov 11, 2020
DSB (Austria) - DSB-D124.1749 The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… DSB-D124.1749 ·Art. 4, 9 Nov 5, 2020
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY · ·Art. 5, 13 Oct 29, 2020
€20,000 Gaypa s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee's email account active and had access to the data subject's… ITALY · ·Art. 5, 12, 13 Oct 29, 2020
€200 Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Oct 24, 2020
€54,800 Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak: Insufficient fulfilment of data subjects rights The data controller denied the data subject access to the video material recorded by CCTV in a local store, with which the data subject wanted to prove that he or she had not… HUNGARY · ·Art. 12, 15, 18 +1 Oct 23, 2020
€3,000 Avata Hispania, S.L.: Insufficient legal basis for data processing Infringement of Art. 28 (3) g) GDPR, since personal data were further processed after the controller had terminated the contractual relationship with the processor. SPAIN · ·Art. 5, 6, 28 Oct 3, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 9 +1 Sep 30, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 13 +2 Sep 30, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. Proceedings were initiated following an inspection carried out in response to a complaint. The accused processed and… CZECH REPUBLIC · ·Art. 5, 13, 28 +1 Sep 25, 2020
€7,800 Iweb Internet Learning, S.L.: Insufficient fulfilment of information obligations Lack of information in the privacy policy (information on the data controller) as well as inadequate obtaining of consent, as only a general consent could be given without… SPAIN · ·Art. 7, 12, 13 Sep 22, 2020
€8,000 Private Person: Non-compliance with general data processing principles Operation of a CCTV camera that also monitored public space outside the premises of the data controller. GREECE · ·Art. 5 Sep 11, 2020
IP - 07121-1/2020/1570 The IP received a request for an opinion concerning sending of an SMS message to users about the new #StayHealthy app created by the National Institute of Public Health (NIJZ).… 07121-1/2020/1570 ·Slovenia ·Art. 6, 58 Sep 11, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Sep 7, 2020
€3,000 Barcelona Airport Security Guard Association ('AVSAB'): Non-compliance with general data processing principles A member of the AVSAB security committee used WhatsApp to send messages to private phone numbers containing personal information about employees. This was a violation of the… SPAIN · ·Art. 5 Sep 7, 2020
DSB (Austria) - 2020-0.303.727 In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that website contained wrong statements about her.… 2020-0.303.727 ·Art. 17, 85 Sep 1, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Aug 12, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA · ·Art. 32 Jul 30, 2020
HDPA (Greece) - 23/2020 The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Art. 4, 5, 12 +6 Jul 30, 2020
€5,000 Operator of CCTV of a residential building: Insufficient legal basis for data processing The operator of video cameras on a residential property had installed cameras there to monitor the shared area of two blocks of flats. The data controller argued that the owners… BELGIUM · ·Art. 6, 7 Jul 14, 2020
€200,000 Merlini s.r.l.: Insufficient legal basis for data processing The company had carried out telemarketing activities on behalf of Wind Tre S.p.A. through a third party provider as data processor without sufficient legal basis fpr data… ITALY · ·Art. 5, 6, 7 +2 Jul 13, 2020
€5,000 Global Business Travel Spain SLU: Insufficient technical and organisational measures to ensure information security The fine was preceded by an employee's access to health data of a person concerned. In the course of its investigations, the Data Protection Authority found that Global Business… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jul 10, 2020
€5,000 Municipal employee: Insufficient legal basis for data processing In the context of a municipal election in 2018, the data controller had sent election advertisements to a group of employees of the same municipal administration, unlawfully using… BELGIUM · ·Art. 5, 6 Jun 8, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ·Art. 5, 6 ·Insufficient legal basis for data processing May 26, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE · ·Art. 5, 6 Apr 7, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS · ·Art. 9, 32 Mar 24, 2020