Skip to content
Content type · 374 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 374 sort newestlargest fineoldest
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Mar 5, 2024
€3M Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ): Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 2,995,140 on the Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ). The controller had suffered a data breach which resulted in… GREECE ·HDPA ·Art. 5, 32 Data Breaches Security Controllers Feb 28, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Feb 26, 2024
€800,000 NTT Data Italia S.P.A: Insufficient fulfilment of data breach notification obligations The Italian DPA has imposed a fine of EUR 800,000 on NTT Data Italia S.P.A. The fine is related to the fine imposed on UniCredit (ETid-2227). UniCredit had contracted NTT to carry… ITALY ·Garante ·Art. 28, 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Feb 8, 2024
€36,000 HISPAPOST, S.A.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine on HISPAPOST, S.A.. The police had found over a thousand abandoned letters containing the Hispapost logo. Hispapost had been contracted by… SPAIN ·aepd ·Art. 28 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 1, 2024
€2,300 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a data controller EUR 2,300 for failing to report a data breach to the DPA and data subjects in a timely manner. UODO ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 18, 2024
€3,000 TECHNINK LEB SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on TECHNINK LEB SRL. The controller had suffered a data breach in which personal customer data had been unlawfully disclosed.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Jan 15, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jan 1, 2024
€6,000 Online retailer: Insufficient fulfilment of data breach notification obligations The DPA of Hamburg has imposed a fine of EUR 6,000 on an online retailer for failing to report a data breach in a timely manner. GERMANY ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2024
€2,300 District Court Krakow: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined the District Court in Krakow EUR 2,300 for failing to report a data breach to the DPA and data subjects in a timely manner. POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Dec 19, 2023
€5,900 AUSTRIA DPA: Insufficient fulfilment of data breach notification obligations The Austrian DPA fined a controller EUR 5,900 for failing to report a data breach in a timely manner and for not cooperating with the DPA. dsb ·Art. 31, 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Dec 12, 2023
€45,000 Open University of Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 45,000 on Open University of Cyprus. The university had suffered a data breach involving hackers publishing personal data of students,… Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 22, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Right of Access Nov 13, 2023
€48,000 INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P.: Non-compliance with general data processing principles The Spanish DPA has imposed a finea INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P. The controller had suffered a data breach in which personal patient and employee data had… SPAIN ·aepd ·Art. 5, 32, 34 Data Breaches Healthcare Employees Nov 2, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·aepd ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Social Media Oct 25, 2023
€3,000 Mensajero SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Mensajero SRL. The controller had suffered a data breach where a link on the controller's website was publicly accessible… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 24, 2023
€24,000 Insurance company: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an insurance company EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 18, 2023
€600,000 GROUPE CANAL +: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on GROUPE CANAL+ for multiple violations of the GDPR. The DPA determined that the data controller failed to demonstrate that it… FRANCE ·CNIL ·Art. 7, 12, 13 +5 Data Breaches IP Address Controllers Oct 12, 2023
€24,000 Link4 Towarzystwo Ubezpieczeń S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Link4 Towarzystwo Ubezpieczeń S. A. EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 8, 2023
€70,000 Uipath SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 70,000 on Uipath SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. During its investigation, the DPA… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security IP Address Aug 21, 2023
€12,000 Azienda Socio Sanitaria Territoriale Ovest Milanese: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare IP Address Jul 18, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Law Enforcement Jul 18, 2023
€3,400 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,400 on a company. The controller had reported a data breach to the DPA. The company car of a senior employee had been broken into,… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Data Breaches Security Jul 18, 2023
€2,500 Company: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a company EUR 2,500 for failing to report a data breach to the DPA and data subjects. POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 12, 2023
€81,000 Heilsuveru: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has fined Heilsuveru EUR 81,000. The controller had reported a data breach to the DPA, as two unauthorized persons had managed to view personal data. During its… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jul 3, 2023
€2,500 Farmacia Ardealul SRL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 2,500 on Farmacia Ardealul SRL. The controller had reported a data breach to the DPA. During its investigation, the DPA found that an… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Jun 27, 2023
€205,000 Digi Telecommunications and Services Ltd.: Insufficient technical and organisational measures to ensure information security The Hungarian DPA has imposed a fine of EUR 205,000 against Digi Telecommunications and Services Ltd. The controller had suffered a data breach in which an unauthorized party… HUNGARY ·NAIH ·Art. 5, 32 Data Breaches Security Telecommunications Jun 22, 2023
€2,000 BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found… ROMANIA ·ANSPDCP ·Art. 5 Data Breaches IP Address Processing Agreement Jun 15, 2023
€8,000 Artima S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on Artima S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that employees of… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Video Surveillance Jun 15, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest Insurance Jun 8, 2023
€18,000 AUTOMOBILE BAVARIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 18,000 on AUTOMOBILE BAVARIA SRL. The data controller had notified the authority of a data breach pursuant to Art. 33 GDPR. Unknown… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Controllers May 18, 2023
€6,700 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,700 on a municipality. The controller had reported a data breach to the DPA. During its investigation, the DPA found that the controller… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Privacy by Design & Default May 16, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€2,200 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,200 on a municipality. The controller had reported a data breach to the DPA. An employee had unauthorizedly copied a document containing… POLAND ·UODO ·Art. 5, 25, 32 Data Breaches Security Privacy by Design & Default May 5, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default May 2, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Data Breaches Security Storage Limitation Apr 20, 2023
€7.6M TIM S.p.A.: Insufficient legal basis for data processing The Italian DPA has fined TIM S.p.A. EUR 7,631,175. The DPA had received numerous complaints about the telecommunications provider, mainly for unauthorized telemarketing… ITALY ·Garante ·Art. 5, 6, 7 +5 Telecommunications Direct Marketing Controllers Apr 13, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Data Breaches Integrity and Confidentiality Principle Health Data Mar 23, 2023
€145,000 AFIANZA ASESORES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 145,000 on AFIANZA ASESORES S.L.. The controller had reported a data breach to the DPA, stating that a backpack containing a USB stick… SPAIN ·aepd ·Art. 5, 32 Encryption Data Breaches Security Mar 16, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Encryption Data Breaches Integrity and Confidentiality Principle Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Right of Access Mar 14, 2023
€220,000 Argon Medical Devices: Insufficient fulfilment of data breach notification obligations The Norwegian DPA has fined Argon Medical Devices EUR 220,000. The controller failed to notify the DPA of a data breach that involved personal data of all its European employees… NORWAY ·Datatilsynet ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Mar 8, 2023
€11,100 Housing cooperative: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 11,100 on a housing cooperative. The controller had disclosed personal data of a member of the cooperative to an unauthorized person. The… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Mar 1, 2023
€750,000 Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain… Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Feb 27, 2023
€40,000 Vodafone: Insufficient fulfilment of data breach notification obligations The Hellenic DPA has imposed a fine of EUR 40,000 on Vodafone. An individual had filed a complaint with the DPA because, following a request for access to records of conversations… GREECE ·HDPA ·Art. 15, 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Feb 20, 2023
€7,200 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,200 on a company. The controller had suffered a data breach that resulted in the loss of personal data. During its investigation, the… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Processors Feb 8, 2023
€5,000 Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Medijobs Platform SRL. The controller had informed the DPA about a data breach according to Art. 33 GDPR. Unauthorized third… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 8, 2023
€321 Housing association: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 321 on a housing association. The controller had suffered a data breach involving the theft of documents, including a copy of a notarial… POLAND ·UODO ·Art. 5, 28, 33 +1 Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Feb 7, 2023