Skip to content
Content type · 2,035 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1901–1950 of 2,035 sort newestlargest fineoldest
€1,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine of EUR 1,000 on ING Bank N.V. Amsterdam - Bucharest Branch. It was found that the controller had sent files to a contractual partner in… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data Feb 10, 2021
€65,000 Lursoft IT SIA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined Lursoft IT SIA EUR 65,000 for the illegal processing of personal data by publishing documents containing personal data on its website 'www.lursoft.lv'.… LATVIA ·DSI ·Art. 6 Personal Data Controllers Processing Feb 9, 2021
€5,000 Private Person: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 5,000 for illegal camera surveillance. The data subject had rented two rooms in the apartment of the controller. The… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Security Feb 8, 2021
€3,000 Patio Ancestral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on Patio Ancestral S.L.. The complainant worked for a construction company and had carried out some renovation work for the… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Feb 8, 2021
€100,000 Iberdrola Clientes: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 100,000 on Iberdrola Clientes, SAU. The data subject had terminated an existing contract with the controller due to a move and… SPAIN ·AEPD ·Art. 5, 17 Personal Data Controllers Supervisory Authorities Feb 3, 2021
€3,000 IDFINANCE Spain, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on IDFINANCE Spain S.L.. A person had received a debt collection email from IDFinance that contained a link for the payment of… AEPD ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Personal Data Controllers Security Feb 1, 2021
€24,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Xfera Móviles S.A.. The data subject claimed a violation of its right to information to the AEPD. The AEPD then issued a… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Feb 1, 2021
€50,000 Azienda USL della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 50,000 on Azienda USL della Romagna. Upon her arrival at the gynecology unit of a hospital operated by the controller (for the… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Personal Data Controllers Jan 27, 2021
€50,000 Family Service / N.D.P.K. nv.: Insufficient legal basis for data processing The Belgian DPA imposed a fine of EUR 50,000 on Family Service / N.D.P.K. nv. The controller is an advertising agency that, among other things, sends expectant mothers gift boxes… BELGIUM ·APD/GBA ·Art. 5, 6, 7 +4 Recipient Controllers Personal Data Jan 27, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY ·Garante ·Art. 5, 9 Healthcare Personal Data Controllers Jan 27, 2021
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Personal Data Controllers Types of Special Categories of Personal Data Jan 27, 2021
€25,000 BELGIUM DPA: Insufficient technical and organisational measures to ensure information security The Belgian DPA fined a mobile operator EUR 25,000. The controller had assigned the data subject's phone number to an unauthorized third party, causing the data subject to lose… APD/GBA ·Art. 5, 24, 32 +2 ·Insufficient technical and organisational measures to ensure information security Supervisory Authorities Personal Data Security Jan 22, 2021
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 75,000 on Telefónica Móviles España, SAU. The controller had assigned five telephone lines with five numbers to the data subject as… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Jan 21, 2021
€50,000 Alterna Operador Integral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 50,000 on Alterna Operador Integral S.L.. A switch of the electricity supplier had taken place without the consent of the data… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jan 21, 2021
€1,200 Individual: Non-compliance with general data processing principles The controller installed cameras on his building, which were directed towards parts of the public space. However, no recording took place, as the cameras only served as a… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Jan 20, 2021
€9,700 Aquateknikk AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Aquateknikk AS NOK 100,000 (EUR 9,700). The controller had carried out a credit rating on an individual without there being a customer… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Controllers Processing Jan 19, 2021
€4,600 Anwara Sp. z.o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) fined the company Anwara Sp. z.o.o. EUR 4,600. The controller had not cooperated with the DPA and had not provided it with all the information necessary for… POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Controllers Jan 15, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Controllers Processors Processing Jan 14, 2021
€30,000 Azienda sanitaria provinciale di Enna: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 30,000 on Azienda sanitaria provinciale di Enna. The controller processed biometric data of employees for the purpose of… ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Controllers Personal Data Jan 14, 2021
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY ·Garante ·Art. 5, 32 Security Controllers Personal Data Jan 14, 2021
€18,000 Azienda Usl di Bologna: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Usl di Bologna EUR 18,000. In a hospital operated by the controller, 49 patients in the oncology ward received discharge letters with… ITALY ·Garante ·Art. 5, 9 Controllers Healthcare Processing Jan 14, 2021
€2M Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Caixabank S.A. EUR 6,000,000 for violations of Art. 6 GDPR, Art. 13 GDPR and Art. 14 GDPR. Customers of the bank were supposed to accept new privacy… SPAIN ·AEPD ·Art. 6, 13, 14 Legitimate Interest Personal Data Controllers Jan 13, 2021
€30,000 Enea S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information… POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 11, 2021
€7,250 Gveik AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Gveik AS EUR 7,250. The controller had carried out a credit check on an individual, although there was no legal basis for doing so. NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Processing Insurance Jan 7, 2021
€9,700 Lindstrand Trading AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined Lindstrand Trading AS EUR 9,700. The controller had carried out four credit checks on individuals and individual companies, although… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Processing Insurance Jan 6, 2021
€19,000 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of EUR 19,000 on a hospital operator. A former employee had unlawfully copied the personal data of 100 patients from the hospital's computer… UODO ·Art. 34, 58 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Supervisory Authorities Jan 5, 2021
€20,000 Nestor SAS: Insufficient fulfilment of information obligations The French DPA (CNIL) fined the company Nestor EUR 20,000. The CNIL notes that the privacy policy provided during the registration process on the company´s website did not contain… FRANCE ·CNIL ·Art. 12, 13 Controllers Supervisory Authorities Processing Jan 5, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out four credit checks on the data… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Consent Jan 4, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Jan 4, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles Supervisory Authorities Controllers Processors Jan 1, 2021
€4M Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… AUSTRIA ·DSB ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 1, 2021
€16,000 Electronics store: Non-compliance with general data processing principles The DPA from Lower Saxony has imposed a fine of EUR 16,000 on an electronics store. The company had installed a video surveillance system which permanently recorded employees,… GERMANY ·Art. 5, 17, 35 ·Non-compliance with general data processing principles Retention Period DPIA Controllers Jan 1, 2021
€700,000 Customer loyalty program: €700,000 fine According to the newspaper 'Der Standard', the Austrian DPA has imposed a fine of EUR 1.2 million on a customer loyalty program in 2021. Further information has not yet been… AUSTRIA ·DSB ·Unknown Controllers Supervisory Authorities Jan 1, 2021
GERMANY DPA: Insufficient technical and organisational measures to ensure information security The camera images of a store were distributed without the knowledge and intention of the controller due to a faulty configuration. The distribution involved recordings of… Art. 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Supervisory Authorities Jan 1, 2021
€500 SLOVAKIA DPA: Insufficient cooperation with supervisory authority The Slovak DPA has imposed a fine of EUR 500 on a controller for failing to cooperate with the DPA. Slovak Data Protection Office ·Art. 31 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Jan 1, 2021
€3,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) fined ING Bank N.V. Amsterdam - Bucharest office in the amount of EUR 3,000. The bank had contacted the data subject by e-mail for the purpose of… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Dec 30, 2020
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 28, 2020
€50,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 50,000 on a company for several violations of the GDPR. The controller is a company that carries out parking ticket controls. The… APD/GBA ·Art. 5, 12, 14 +2 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Dec 23, 2020
€15,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 15,000 on a company due to insufficient fulfilment of data subject rights. The controller is a debt collection agency which was… APD/GBA ·Art. 5, 6, 12 +2 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Dec 23, 2020
€6,000 Iberdrola Clientes, SAU: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) fined Iberdrola Clientes, SAU EUR 6,000. The data subject had received promotional calls from two different telephone numbers of the controller although the… SPAIN ·AEPD ·Art. 21, 23, 48 Personal Data Direct Marketing Controllers Dec 22, 2020
€36,000 Banco Bilbao Vizcaya Argentaria, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Dec 21, 2020
€6,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well… FRANCE ·CNIL ·Art. 32, 33 Security Controllers Personal Data Dec 17, 2020
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·DPC ·Art. 5, 32, 33 Data Breaches Notification Obligation Personal Data Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Dec 17, 2020
€3,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 3,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data as MRI and X-ray images as well as… FRANCE ·CNIL ·Art. 32, 33 Security Controllers Personal Data Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Storage Limitation Retention Period Controllers Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 Controllers DPIA Personal Data Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data Public Authority Controllers Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Personal Data Controllers Dec 17, 2020