Content type · 240 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€46,000 Azienda Sanitaria Locale Roma: Insufficient legal basis for data processing The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most… ITALY · ·Art. 2, 5, 6 +1 May 26, 2022
€5,000 MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on MED LIFE S.A.. The company had disposed of documents containing sensitive patient data in a publicly accessible garbage can. An… ROMANIA · ·Art. 32 May 24, 2022
€7,000 Azienda Socio Sanitaria Territoriale Dei Sette Laghi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the healthcare facility Azienda Socio Sanitaria Territoriale Dei Sette Laghi. A patient had mistakenly received… ITALY · ·Art. 5, 9, 32 May 22, 2022
€2,500 'Isabella Gonzaga' high school: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the 'Isabella Gonzaga' high school. The school had published a document, which also contained personal health data of some… ITALY · ·Art. 2, 5, 6 +1 Apr 28, 2022
€1,500 Direzione Didattica Statale 1° Circolo-Eboli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on the school 'Direzione Didattica Statale 1° Circolo-Eboli'. The educational institution had sent a document containing the names… ITALY · ·Art. 2, 5, 6 +1 Apr 28, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY · ·Art. 5, 9 Apr 28, 2022
€1,000 ASST di Lodi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 1,000 on ASST di Lodi. The healthcare facility had reported a data breach to the DPA pursuant to Art. 33 GDPR. A patient had… ITALY · ·Art. 5, 9, 32 Apr 26, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY · ·Art. 28 Apr 7, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY · ·Art. 5, 13, 14 +4 Apr 7, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM · ·Art. 5, 6, 9 Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM · ·Art. 5, 6, 9 +3 Apr 4, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM · ·Art. 5, 6, 9 +3 Apr 4, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM · ·Art. 5 Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY · ·Art. 5, 9, 32 Mar 10, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY · ·Art. 5, 9 Feb 10, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 26, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Jan 26, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Jan 5, 2022
€1,600 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA imposed a fine of EUR 1,600 on a physician. A patient had filed a complaint against the controller with the DPA. The patient had asked the doctor to send all… HUNGARY · ·Art. 5, 12, 13 Jan 1, 2022
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND · ·Art. 5, 12, 13 +2 Dec 26, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY · ·Art. 5, 6, 9 Dec 17, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY · ·Art. 5, 25, 32 +1 Dec 16, 2021
€52,000 Motor insurance center: Non-compliance with general data processing principles The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of… FINLAND · ·Art. 5, 25 Dec 16, 2021
€608,000 Psykoterapiakeskus Vastaamo: Non-compliance with general data processing principles The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An… FINLAND · ·Art. 5, 33, 34 Dec 7, 2021
€6,000 Società H San Raffaele Resnati s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. The DPA initiated an investigation against the health care provider after it… ITALY · ·Art. 5, 9 Nov 25, 2021
€8,000 Health Protection Agency of Sardinia (ATS): Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 8,000 on the Health Protection Agency of Sardinia (ATS). A patient had mistakenly received medical records and clinical… ITALY · ·Art. 5, 9 Oct 14, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK · ·Art. 32 Sep 29, 2021
€2,000 Istituto Comprensivo - IC Cosenza III “V. Negroni”: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo - IC Cosenza III “V. Negroni”. The educational institution had published a document, which also contained… ITALY · ·Art. 2, 5, 6 +1 Sep 21, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY · ·Art. 32 Sep 20, 2021
€18,000 CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of… SPAIN · ·Art. 5 Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK · ·Art. 32 Sep 17, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK · ·Art. 32 Sep 8, 2021
€600 DSB Austria: sharing medical assessment with municipality lacked Art. 9(2) legal basis Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had… Art. 4, 5, 9 +1 Aug 5, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA · ·Art. 9 Aug 5, 2021
€80,700 Medicals Nordic I/S: Non-compliance with general data processing principles The Danish DPA (Datatilsynet) has fined Medicals Nordic I/S EUR 80,700. In January 2021, the DPA became aware that Medicals Nordic was using WhatsApp to transmit confidential… DENMARK · ·Non-compliance with general data processing principles Jul 9, 2021
€5,000 Pediatrician: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined a pediatrician EUR 5,000. A father had asked the controller to view the medical records contained in his child's patient file via e-mail. However, the… GREECE · ·Art. 12, 15 Jul 8, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·Art. 5, 6, 9 +2 ·Non-compliance with general data processing principles Jun 7, 2021
€49,200 Moss municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the… NORWAY · ·Art. 32 Jun 4, 2021
€39,000 Municipality of Oslo: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,000 on the Municipality of Oslo. On a website of the controller a subpoena from the public prosecutor's office… NORWAY · ·Art. 5, 6 May 20, 2021
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY · ·Art. 5, 6, 9 +2 May 13, 2021
€7,000 TECNOMEDICAL S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 7,000 on TECNOMEDICAL S.r.l.. A data subject filed a complaint with the DPA after the controller failed to properly respond to… ITALY · ·Art. 12, 15 Mar 25, 2021
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY · ·Art. 32, 33, 34 Mar 24, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA · ·Art. 32 Mar 23, 2021
€3,000 IT sprendimai sėkmei: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 3,000 on the company 'IT sprendimai sėkmei'. The DPA had opened an investigation regarding a quarantine app introduced in Lithuania… LITHUANIA · ·Art. 5, 13, 24 +3 Feb 26, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA · ·Art. 5, 13, 24 +3 Feb 26, 2021
€6,000 Azienda Ospedaliera Universitaria Careggi: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Azienda Ospedaliera Universitaria Careggi for a breach of Art. 5 GDPR and Art. 9 GDPR. Azienda Ospedaliera… ITALY · ·Art. 5, 9 Feb 25, 2021
€45,000 Istituti ospedalieri bergamaschi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 45,000 on Istituti ospedalieri bergamaschi. The DPA initiated an investigation against the controller after it reported a data… ITALY · ·Art. 5, 9, 32 Feb 11, 2021
€440,000 OLVG: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) imposed a fine of EUR 440,000 on the Amsterdam hospital OLVG. The controller had taken insufficient measures between 2018 and 2020 to prevent access by… THE NETHERLANDS · ·Art. 32 Feb 11, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY · ·Art. 5, 9 Jan 27, 2021
€50,000 Azienda USL della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 50,000 on Azienda USL della Romagna. Upon her arrival at the gynecology unit of a hospital operated by the controller (for the… ITALY · ·Art. 5, 9, 32 Jan 27, 2021