Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1901–1950 of 2,403 sort newestlargest fineoldest
€2,000 Società triveneta di chirurgia: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Società triveneta di chirurgia. A physician had shown slides of a clinical case at a congress, which were subsequently… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Controllers Apr 15, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Privacy by Design & Default Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Apr 13, 2021
€750,000 TikTok: Insufficient fulfilment of information obligations The Dutch DPA (AP) has fined the video portal TikTok EUR 750,000 for violating the privacy of young children. The information that Dutch users - mostly young children - received… THE NETHERLANDS ·AP ·Art. 12 Personal Data Supervisory Authorities Supervision Apr 9, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Storage Limitation Retention Period Apr 8, 2021
€60,000 Kutxabank, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request… SPAIN ·AEPD ·Art. 17 Right to be Forgotten Personal Data Controllers Apr 8, 2021
€2,400 Promotech Digital S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined Promotech Digital S.L. EUR 2,400 for repeatedly sending the data subject advertising SMS, even though he never subscribed or agreed to receive… SPAIN ·AEPD ·Art. 21 Direct Marketing Personal Data Controllers Apr 6, 2021
€3,000 Kukimbia S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Kukimbia S.L. EUR 3,000. The controller is a company that stores, transports and distributes goods. Documents containing personal data about the… SPAIN ·AEPD ·Art. 32 Controllers Security Personal Data Apr 5, 2021
€4,000 Stockhunters S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Stockhunters S.L.. The controller was not able to answer the data subject's requests regarding the use of his personal… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Apr 5, 2021
€3,000 Electrotecnica Bastida S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Electrotecnica Bastida S.L. EUR 3,000. Police officers had found 29 envelopes addressed to the controllers' respective employees on a vacant lot… SPAIN ·AEPD ·Art. 32 Security Personal Data Controllers Apr 5, 2021
€10,000 Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security The Romania DPA (ANSPDCP) has fined Telekom Romania Mobile Communications S.A. EUR 10,000 for failing to implement adequate security measures to ensure the security of personal… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 30, 2021
€6,000 Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (boarding school): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (CE) boarding school. The boarding school had published a document… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Mar 25, 2021
€7,000 TECNOMEDICAL S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 7,000 on TECNOMEDICAL S.r.l.. A data subject filed a complaint with the DPA after the controller failed to properly respond to… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Mar 25, 2021
€1,425 Operator of a care facility: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,425 on the operator of a care facility. The operator had installed a total of 25 cameras in all rooms of the facility, with… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Mar 25, 2021
€30,000 OneDirect Srl: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 30,000 on OneDirect Srl. A data subject had filed two complaints with the DPA after receiving advertisements by e-mail from the… ITALY ·Garante ·Art. 6, 7, 30 +1 Personal Data Controllers Supervisory Authorities Mar 25, 2021
€4,000 Comune di Castellanza: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the municipality of Castellanza. The municipality had uploaded documents containing personal data of the data subject… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Mar 25, 2021
€4.5M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Fastweb S.p.A. EUR 4,500,000 for aggressive telemarketing. Following a complex preliminary investigation launched after hundreds of reports and… ITALY ·Garante ·Art. 5, 6, 7 +8 Direct Marketing Personal Data Controllers Mar 25, 2021
€20,000 GEDI News Network Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on GEDI News Network Spa. A data subject filed a complaint with the Italian DPA against the controller regarding an… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Mar 25, 2021
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY ·NAIH ·Art. 32, 33, 34 Encryption Security Personal Data Mar 24, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Right of Access Mar 23, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Controllers Supervisory Authorities Mar 22, 2021
€19,900 Basaren Drift AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 19,900 on Basaren Drift AS. The controller had installed video cameras in its premises which recorded both its employees… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 13 Controllers Supervisory Authorities Personal Data Mar 21, 2021
€4,900 Funeda Sp. z o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined Funeda Sp. z o.o. EUR 4,900 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Personal Data Mar 19, 2021
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 60,000 on Vodafone Spain. The data subject had been a customer of the controller several years ago. After receiving payment reminders… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications Mar 16, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 24 +1 Personal Data Security Public Authority Mar 15, 2021
€2,000 Heredad de Urueña S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Heredad de Urueña S.A. EUR 2,000 because its personal data processing policy did not comply with the requirements of Art. 13 GDPR. In addition, the… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Mar 15, 2021
€12,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U. EUR 20,000. An identity thief had obtained the data of a third party without authorization and applied for a microcredit… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Recipient Mar 12, 2021
€15,000 Mediacom s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Mediacom s.r.l.. The controller carried out advertising calls on behalf of TIM s.p.a.. Several of the calls were made… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Consent Mar 11, 2021
€8.2M Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Since 2018, the Spanish DPA (AEPD) had received a total of 191 complaints against Vodafone España, S.A.U. The data subjects complained about advertising calls and messages (e-mail… SPAIN ·AEPD ·Art. 21, 23, 24 +3 Right to Object Direct Marketing Supervisory Authorities Mar 11, 2021
€3,000 Comune di San Marco in Lamis: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,000 on the municipality of San Marco in Lamis. The municipality had uploaded documents containing personal data of the data… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Mar 11, 2021
€80,000 Planet Group Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 80,000 on Planet Group Spa. The controller made promotional calls on behalf of TIM s.p.a.. Several of these calls were made… ITALY ·Garante ·Art. 5, 6, 12 +2 Right to Object Direct Marketing Controllers Mar 11, 2021
€200 Self Employed Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 200 on a self employed person. The accused obtained scans of identity cards from foreign subjects who booked accommodation there and kept… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 12 +4 Personal Data Consent Processing Mar 10, 2021
€90,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 150,000 on Xfera Móviles S.A.. The DPA had received two complaints from a data subject. The first complaint concerned the sending of… SPAIN ·AEPD ·Art. 5, 17, 32 Personal Data Controllers Security Mar 10, 2021
€8,000 Filigrana Comunicación S.L.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Filigrana Comunicación S.L.U. EUR 8,000. The controller operates a website that provides information on internships offered by the Spanish Ministry of… SPAIN ·AEPD ·Art. 6, 13, 14 Personal Data Controllers Consent Mar 10, 2021
€50,000 Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Equifax Iberica S.L. EUR 50,000 for a violation of Art. 6 (1) f) GDPR. The controller had added the data subject to a debtor register without… SPAIN ·AEPD ·Art. 6 Legitimate Interest Personal Data Controllers Mar 10, 2021
€15,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 15,000 on a homeowners' association. The controller had publicly displayed the record of a homeowners' meeting in the elevator of the… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Mar 9, 2021
€14,900 Dragefossen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) imposed a fine of EUR 14,900 on the energy company Dragefossen AS. The latter had installed a webcam on the roof of its office building in the… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Processing Mar 8, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA ·ANSPDCP ·Art. 32, 58 Security Personal Data Controllers Mar 4, 2021
€6,000 KEPIDES: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 6,000 against KEPIDES (real estate company). The controller had submitted a list of buyers of the properties it manages to a parliamentary… CYPRUS ·Cyprus DPA ·Art. 32 Anonymization Security Controllers Mar 3, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Cyprus DPA ·Art. 12, 15, 31 +1 Right of Access Personal Data Supervisory Authorities Mar 3, 2021
€40,000 Electricity Authority of Cyprus: Insufficient legal basis for data processing The Cypriot DPA imposed a fine of EUR 40,000 on the Electricity Authority of Cyprus. The controller used an automated system based on the so-called Brad-Factor to manage, monitor… Cyprus DPA ·Art. 6, 9 ·Insufficient legal basis for data processing Controllers Personal Data Consent Mar 3, 2021
€200,000 I-DE Redes Eléctricas Inteligentes, S.A.U: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on I-DE Redes Eléctricas Inteligentes, S.A.U. The DPA received complaints from Waitum, S.L. and Servicios Aby 2018, S.L.… SPAIN ·AEPD ·Art. 5, 6 Integrity and Confidentiality Principle Retention Period Controllers Mar 2, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA ·VDAI ·Art. 32 Security Personal Data Controllers Mar 2, 2021
€9,000 SPAIN DPA: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 9,000 on a website operator. The controller had published photos of the data subject on its website without the consent of the data… AEPD ·Art. 6, 13 ·Insufficient legal basis for data processing Supervisory Authorities Personal Data Controllers Mar 2, 2021
€3,000 IT sprendimai sėkmei: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 3,000 on the company 'IT sprendimai sėkmei'. The DPA had opened an investigation regarding a quarantine app introduced in Lithuania… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Controllers Security Feb 26, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Controllers Types of Special Categories of Personal Data Feb 26, 2021
€6,000 Comune di Commezzadura: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 6,000 on the municipality of Commezzadura. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Processing Feb 25, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY ·Garante ·Art. 5, 25, 35 Retention Period Controllers DPIA Feb 25, 2021
€2,000 Comune di Conflenti: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 2,000 on the municipality of Conflenti. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Feb 25, 2021