Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1901–1950 of 2,273 sort newestlargest fineoldest
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data Public Authority Education Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Health Data Healthcare Dec 17, 2020
€55,400 Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) imposed a fine of HUF 20,500,000 (EUR 55,400) on Robinson Tours Idegenforgalmi és Szolgáltató Kft. (Robinson Tours Ltd.) The travel agent's reservation… HUNGARY ·NAIH ·Art. 25, 32, 34 Data Breaches Security Processing Agreement Dec 16, 2020
€1,940 HUNGARY DPA: Insufficient fulfilment of information obligations The Hungarian DPA (NAIH) imposed a fine of HUF 700,000 (EUR 1,940) against a construction company. The controller had installed a video surveillance system at a construction site… NAIH ·Art. 5, 13 ·Insufficient fulfilment of information obligations Video Surveillance Monitoring Employees Dec 16, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… NAIH ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Health Data Personal Data Healthcare Dec 16, 2020
€1,385 Next Time Media Agency Ltd. (Next Time Media Ügynökség Kft.): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) imposed a fine of HUF 50,000 (EUR 1,385) on Next Time Media Ügynökség Kft. (Next Time Media Agency Ltd.). The web agency had been contracted by the travel… HUNGARY ·NAIH ·Art. 32 Security Telecommunications Personal Data Dec 16, 2020
€10,000 Online Services: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined the operator of the online store banderacatalana.cat. EUR 10,000 for a violation of Art. 13 GDPR. The operator stated on its website privacy notices… SPAIN ·aepd ·Art. 6, 8, 13 IP Address Personal Data Processing Agreement Dec 15, 2020
€6,250 LATVIA DPA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined an employer EUR 6,250 for sending personal data of an employee, including health data, to fellow employees by email. The DSI found that the data… DSI ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Healthcare Health Data Dec 15, 2020
€443,000 Virgin Mobile Polska: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Virgin Mobile Polska EUR 443,000 due to a data leak that allowed unauthorized third parties to access personal data stored by Virgin Mobile Polska as a… POLAND ·UODO ·Art. 5, 25, 32 Security Telecommunications Processing Agreement Dec 14, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Healthcare Dec 11, 2020
€5M Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Banco Bilbao Vizcaya Argentaria, S.A. EUR 5,000,000 for violating Art. 6 GDPR (EUR 3,000,000) and Art. 13 GDPR (EUR 2,000,000). The bank had not… SPAIN ·aepd ·Art. 6, 13 Processing Agreement Personal Data Insurance Dec 11, 2020
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Right of Access Right of Access Procedures Supervisory Authorities Dec 11, 2020
€4,000 Borjamotor, S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 4,000 on Borjamotor, S.A. The company kept sending commercial advertisements to the data subject via email and SMS, even though the… SPAIN ·aepd ·Art. 7 Direct Marketing Personal Data Consent Dec 10, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Dec 10, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY ·NAIH ·Art. 5, 6, 9 +2 Education Personal Data IP Address Dec 10, 2020
€10,000 SPAIN DPA: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of 10,000 EUR on a company for violating Art. 5 GDPR. The company sent an e-mail to a third party with the dismissal and settlement document… aepd ·Art. 5 ·Non-compliance with general data processing principles IP Address Personal Data Processing Agreement Dec 9, 2020
€40,000 Xfera Moviles S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Xfera Móviles, S.A. due to insufficient legal basis for data processing. The data subject states that two telephone and internet… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Dec 9, 2020
€18,850 TUiR Warta S.A.: Insufficient fulfilment of data breach notification obligations An insurance agent hired by the controller had sent an email to unauthorized third parties in regard to insurance policies that contained personal data of two of the company's… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 9, 2020
€2,850 Smart Cities Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the Polish DPA (UODO). The controller failed to provide personal data and other information requested by UODO for investigative… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Dec 9, 2020
€35M CNIL fines Amazon Europe Core €35M for placing cookies without consent Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating… France ·Art. 6, 9, 83 +1 Cookies Telecommunications Direct Marketing Dec 7, 2020
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet ·Art. 6, 32 Education Public Authority Personal Data Dec 3, 2020
€6,000 Servicio de Alojamientos Responsables, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine in the amount of EUR 6,000 against the controller for unauthorized conclusion of a contract in the name of the data subject without his/her… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Dec 2, 2020
€5,000 Asociación de Víctimas por Arbitrariedades Judiciales, (JAVA): Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on the association for publishing the personal data of the data subjects on its website. The data had been unlawfully recorded… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Agreement Dec 2, 2020
€3,000 Comercio Online Levante, S.L.: Insufficient technical and organisational measures to ensure information security A woman filed a complaint with the Spanish DPA (AEPD) against Comercio Online Levante, S.L. due to the fact that she was shown the personal data of another user when trying to… SPAIN ·aepd ·Art. 5, 32 Controllers Personal Data Security Dec 2, 2020
€800 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 800 on a legal person. The complainant had worked with the accused over the years as an employee, collaborator, author, licensor, and… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Supervisory Authorities Processing Agreement Dec 1, 2020
€100,000 Apotheka e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Consent Dec 1, 2020
€100,000 Azeta.ee e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare Consent IP Address Dec 1, 2020
€100,000 Südameapteegi e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare Consent IP Address Dec 1, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of Eur 2,000 on a legal person. The accused failed to comply with the request to erase the auction notice with the personal data and failed to… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Processing Agreement Supervisory Authorities Nov 30, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent the subject a commercial offer via SMS after assuring the data subject that their data was… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Processing Agreement Supervisory Authorities Nov 30, 2020
€1,200 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine in the amount of EUR 1,200 on a private individual for impersonating a third party on the social networks Tinder and WhatsApp by using images… SPAIN ·aepd ·Art. 5 IP Address Personal Data Consent Nov 27, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Garante ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Health Data Integrity and Confidentiality Principle Nov 26, 2020
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·aepd ·Art. 6, 13, 14 Recipient Personal Data IP Address Nov 25, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Privacy by Design & Default Personal Data Nov 24, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY ·Garante ·Art. 5, 13 Personal Data IP Address Employees Nov 23, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Telecommunications Supervisory Authorities Nov 23, 2020
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis. The company had sent an invoice to a data subject without being able to prove that it had a contract… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Nov 19, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Fairness & Transparency Nov 19, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… NAIH ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers IP Address Nov 18, 2020
€2,000 Anmavas 61, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning… SPAIN ·aepd ·Art. 58 Right to be Forgotten Supervisory Authorities Data Subject Rights Exercise Modalities and Procedures Nov 18, 2020
€2.3M Carrefour France: Non-compliance with general data processing principles The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that… CNIL ·Art. 5, 12, 13 +5 ·Non-compliance with general data processing principles Processing Agreement IP Address Personal Data Nov 18, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY ·Garante ·Art. 9 Personal Data Healthcare Education Nov 17, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY ·Garante ·Art. 12, 13, 14 Video Surveillance Personal Data Education Nov 17, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing In 2019, after an arbitration procedure, the company agreed to the early termination of a contract with the data subject and to the deletion of the personal data concerned.… SPAIN ·aepd ·Art. 5, 6 Personal Data Telecommunications Processing Nov 16, 2020
€1.4M Ticketmaster UK Limited: Insufficient technical and organisational measures to ensure information security Ticketmaster UK Limited has been fined GBP 1.25 million (approximately EUR 1.405 million) for failing to protect the personal data of its customers with adequate security… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Processing Agreement Personal Data Nov 13, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY ·Garante ·Art. 5, 6, 7 +7 IP Address Telecommunications Security Nov 12, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The company ported a telephone number of the data subject without their consent (missing signature on the porting contract). SPAIN ·aepd ·Art. 5, 6 Consent Personal Data Telecommunications Nov 11, 2020
€900,000 Telecoms provider (1&1 Telecom GmbH): Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's… GERMANY ·BfDI ·Art. 32 Telecommunications IP Address Access Controls Nov 11, 2020
DSB (Austria) - DSB-D124.1749 The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… DSB-D124.1749 ·Art. 4, 9 Insurance Healthcare Health Data Nov 5, 2020
€75,000 Telefonica Moviles Espana, S.A.U.: Insufficient legal basis for data processing Processing of personal data of the data subject without sufficient legal basis. The company had issued several invoices to the data subject and collected invoice amounts from his… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Nov 5, 2020