Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1851–1900 of 2,403 sort newestlargest fineoldest
€6,000 Creator Energy S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on Creator Energy S.L.. The controller had used the personal data of the data subject without his consent to conclude… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 4, 2021
€49,200 Moss municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Personal Data Public Authority Jun 4, 2021
€4,000 Avalos Consultores, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Avalos Consultores, S.L.. The data subject, who was a client of the controller, filed a complaint with the AEPD because… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 2, 2021
€18,000 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA of Luxembourg has imposed a fine of EUR 18,000 on a company. According to the DPA, the controller firstly failed to involve the data protection officer in all matters… CNPD (LU) ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Personal Data May 31, 2021
€39,700 BRAbank ASA: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,700 on BRAbank ASA. The controller had reported a data breach to the DPA on September 6, 2019. On the controller's… NORWAY ·Datatilsynet (NO) ·Art. 24, 32 Security Controllers Personal Data May 28, 2021
€100,000 Vodafone España, SAU: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Vodafone España, S.A.U.. A data subject had filed a complaint with the Spanish DPA against the telecommunications… SPAIN ·AEPD ·Art. 28 Processors Controllers Personal Data May 25, 2021
€6,000 Desolasol Restauración, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Desolasol Restauración S.L. EUR 6,000. The data subject had submitted a consumer complaint form to the restaurant because he was unable to… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing May 25, 2021
€900 Managing Director of a company: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on the managing director of a company. A data subject filed a complaint with the AEPD against the controller with whom he… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities May 25, 2021
€45,000 Telefónica de España, S.A.U: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 75,000 on Telefonica de España, S.A.U.. A data subject had filed a complaint with the AEPD against the telecommunications company.… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications May 21, 2021
€39,000 Municipality of Oslo: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,000 on the Municipality of Oslo. On a website of the controller a subpoena from the public prosecutor's office… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Types of Special Categories of Personal Data Controllers May 20, 2021
€2,000 Banca Comercială Română S.A.: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined Banca Comercială Română S.A. EUR 2,000. A data subject had initiated a complaint with the DPA because the controller had used his personal… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing May 19, 2021
€500 Owners Association of Iasi Municipality: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has imposed a fine of EUR 500 on Asociație de Proprietari din municipiul Iași (Owners Association of Iasi Municipality). The controller did not provide… ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Controllers May 19, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out several credit checks on the data… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Consent May 18, 2021
€10,000 Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato: Insufficient legal basis for data processing The Hellenic DPA has fined the Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato EUR 10,000. The controller had… GREECE ·HDPA ·Art. 6, 12, 17 Personal Data Controllers Supervisory Authorities May 17, 2021
€200 Website operator: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on the operator of the website declaratieppr.ro. During the Covid19 pandemic, visitors to the site were able to fill out a… ROMANIA ·ANSPDCP ·Art. 5, 6, 13 +1 Personal Data Controllers Security May 14, 2021
€800 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 800 on a legal person. The accused did not respond to its former employee's request to delete their former work email and even told the… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Supervisory Authorities Processing Agreement May 14, 2021
€30,000 Allianz Compañia de Seguros y Reaseguros, S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Allianz Compañia de Seguros y Reaseguros, S.A. EUR 30,000. The controller had sent an invoice to the data subject although no contractual… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance May 14, 2021
€2.9M Iren Mercato S.p.A.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Iren Mercato S.p.A. EUR 2,856,169 for failing to verify that all transfers of data of recipients of promotional activities were covered by consent.… ITALY ·Garante ·Art. 5, 6, 7 Consent Controllers Personal Data May 13, 2021
€2,000 Telekom Romania Communications SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Telekom Romania Communications SA. The controller had made an advertising call to the data subject although the… ANSPDCP ·Art. 6, 21 ·Insufficient fulfilment of data subjects rights Right to Object Direct Marketing Personal Data May 13, 2021
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Retention Period Personal Data May 13, 2021
€5,000 A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ: Non-compliance with general data processing principles The Hellenic DPA has fined A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ EUR 5,000. The controller had not responded to requests for information and deletion from the data subject.… GREECE ·HDPA ·Art. 5, 12, 15 +1 Personal Data Controllers Consent May 12, 2021
€2,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,600 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Accountability May 12, 2021
€1,000 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,000 on a company. The controller had installed a video surveillance system with the purposes of the protection of… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Accountability May 12, 2021
€5,000 KARIERA A.E.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 5,000 on ΚARIERA A.E.. A data subject had filed a complaint with the DPA against the controller due to the fact that the controller… GREECE ·HDPA ·Art. 17, 21, 25 Personal Data Controllers Supervisory Authorities May 12, 2021
€3,000 Solram T Y R S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on Solram T Y R S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·AEPD ·Art. 17 Personal Data Controllers Supervisory Authorities May 12, 2021
€2,000 World Class România S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on World Class România S.A.. The controller had published the termination letter of an employee in a WhatsApp group used… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Controllers Security May 7, 2021
€1.5M EDP Comercializadora, S.A.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing… SPAIN ·AEPD ·Art. 13, 25 Controllers Personal Data Supervisory Authorities May 4, 2021
€1.5M EDP Energía, S.A.U: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Energía, S.A.U.. The decision follows, in particular, several complaints received for processing personal data… SPAIN ·AEPD ·Art. 13, 25 Personal Data Controllers Supervisory Authorities May 4, 2021
EDPS: CJEU violated Regulation 2018/1725 over cookies and consent on its website A data subject complained around cookies and similar technologies used in connection to audiovisual material on the website of the Court of Justice of the European Union (CJEU),… 2019-0878 ·European Union ·Art. 7 Consent Information Provision Modalities and Communication Methods Cookies May 3, 2021
€100M CNIL closes Google cookies case after accepting compliance adjustments On 7 December 2020, the CNIL fined Google €100,000,000 for not complying with the cookies regulation. The CNIL had also given Google a limited time to adapt their cookies settings… France ·Art. 7 Cookies Personal Data Consent Apr 30, 2021
€2,000 Santa Ninfa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Santa Ninfa municipality. The municipality had published a resolution on its website that contained personal information… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Public Authority Processing Apr 29, 2021
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Persónuvernd ·Art. 32 Data Breaches Security Controllers Apr 29, 2021
€5,050 PNP S.A.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Polish DPA (UODO) for investigative purposes. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Apr 27, 2021
€1,400 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,400 on a company. In the course of his professional activities, a data subject had made a telephone call to the controller on… HUNGARY ·NAIH ·Art. 5, 6, 13 Accountability Controllers Personal Data Apr 27, 2021
€3,000 Pagamastarde S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Pagamastarde S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Apr 27, 2021
€15,000 Anytime Fitness Iberia S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on Anytime Fitness Iberia S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Apr 27, 2021
€570 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 570 on a company. In the course of his professional activities, a data subject had made a telephone call to a company on… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Accountability Apr 27, 2021
€100,000 Financial company: Insufficient technical and organisational measures to ensure information security The Belgian DPA (APD) has imposed a fine of EUR 100,000 on a financial company. A data subject had filed two complaints with the APD against the company. They were based on 20… BELGIUM ·APD/GBA ·Art. 5, 32 Personal Data Controllers Security Apr 26, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·AEPD ·Art. 5, 6, 14 Integrity and Confidentiality Principle Retention Period Fairness & Transparency Apr 23, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Security Controllers Apr 22, 2021
€4,000 HazteOir.Org: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on HazteOir.Org. The controller had published a brochure on sex education in schools which unlawfully contained the photos… SPAIN ·AEPD ·Art. 6 Consent Personal Data Controllers Apr 22, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 14 +3 Retention Period Storage Limitation Personal Data Apr 21, 2021
€15,000 Fondazione Policlinico Tor Vergata di Roma: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Fondazione Policlinico Tor Vergata di Roma. In February 2020, a data subject filed a complaint with Garante alleging… ITALY ·Garante ·Art. 5, 13, 25 +1 Privacy by Design & Default Personal Data Controllers Apr 21, 2021
€8,000 Highcliffe Estates Marbella S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 8,000 on Highcliffe Estates Marbella S.L.. The controller had published a photo of the data subject on its website without his… SPAIN ·AEPD ·Art. 6 Personal Data Consent Controllers Apr 20, 2021
€2,800 Website operator: Non-compliance with general data processing principles The Hungarian DPA (NAIH) has imposed a fine of EUR 2,800 on a website operator. The controller had failed to prove the lawfulness of its processing of personal data upon request… HUNGARY ·NAIH ·Art. 5, 24 Accountability Controllers Personal Data Apr 20, 2021
€1,500 Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A.,… ROMANIA ·ANSPDCP ·Art. 29, 32 Controllers Security Processors Apr 19, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Controllers Supervisory Authorities Apr 16, 2021
€12,000 Istituto Nazionale Previdenza Sociale (INPS): Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 12,000 on the Italian National Institute for Social Security (Istituto Nazionale della Previdenza Sociale). That fine was based… ITALY ·Garante ·Art. 5, 12, 15 Personal Data Controllers Supervisory Authorities Apr 15, 2021
€5,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Controllers Apr 15, 2021
€5,000 S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined S.C. Tip Top Food Industry S.R.L. EUR 5,000. The controller had installed several video cameras in the food areas and changing rooms to… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Retention Period Controllers Processing Apr 15, 2021