Skip to content
Content type · 240 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 240 sort newestlargest fineoldest
€5,000 Ciechi Ardizzone Gioeni di Catania: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Ciechi Ardizzone Gioeni di Catania residential home for blind people. A visitor to the residence filed a complaint… ITALY ·Garante ·Art. 5, 12, 13 +1 Video Surveillance Integrity and Confidentiality Principle Fairness & Transparency Sep 16, 2021
€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Garante ·Art. 2, 5, 6 +6 Audit Logs Fairness & Transparency Privacy Shield Sep 16, 2021
€56,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Vodafone España, S.A.U. due to insufficient legal basis for data processing. The data subject stated that unauthorized third parties… SPAIN ·aepd ·Art. 6 Telecommunications Processing Agreement Personal Data Sep 14, 2021
€56,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Vodafone España, S.A.U. for insufficient legal basis for data processing. The data subject stated that he received a call from Vodafone in… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Sep 14, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet ·Art. 32 Security Healthcare Health Data Sep 8, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Notified Body Competence Challenges and Dispute Resolution Social Media Fairness & Transparency Sep 2, 2021
€1,500 MOVE Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to… Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Aug 20, 2021
€135,000 Insurance company: Insufficient technical and organisational measures to ensure information security The DPA of Luxembourg has imposed a fine of EUR 135,000 on an insurance company. On October 19, 2018, an employee of the controller had sent an e-mail to an uninvolved third party… LUXEMBOURG ·CNPD ·Art. 5, 32, 33 Data Breaches Security Insurance Aug 5, 2021
€200 Private Individual: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on a private individual due to the unlawful disclosure of personal data. The controller had disclosed personal data of… ROMANIA ·ANSPDCP ·Art. 5, 6, 14 Personal Data Social Media Controllers Jul 30, 2021
€2.5M Mercadona S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals… SPAIN ·aepd ·Art. 5, 6, 9 +4 Criminal Data Privacy Impact Assessment IP Address Jul 26, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 +1 Integrity and Confidentiality Principle Fines IP Address Jul 22, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Controllers Fines Integrity and Confidentiality Principle Jul 22, 2021
€30,000 Flowbird Italia s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 30,000 on Flowbird Italia s.r.l.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 Fines IP Address Processing Agreement Jul 22, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… Garante ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles DPIA Privacy Impact Assessment Fairness & Transparency Jul 22, 2021
€1.8M SGAM AG2R LA MONDIALE: Non-compliance with general data processing principles The French DPA (CNIL) has fined private insurer SGAM AG2R LA MONDIALE EUR 1,750,000. The CNIL had carried out an inspection at the AG2R LA MONDIALE group in 2019. On this… FRANCE ·CNIL ·Art. 5, 13, 14 Insurance Storage Limitation Retention Period Jul 20, 2021
€80,700 Medicals Nordic I/S: Non-compliance with general data processing principles The Danish DPA (Datatilsynet) has fined Medicals Nordic I/S EUR 80,700. In January 2021, the DPA became aware that Medicals Nordic was using WhatsApp to transmit confidential… DENMARK ·Datatilsynet ·Non-compliance with general data processing principles Healthcare Health Data Healthcare Jul 9, 2021
€29,000 Mermaids: Insufficient technical and organisational measures to ensure information security The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR.… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Encryption Data Breaches Jul 5, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·azop ·Art. 32 Data Breaches Controllers Processors Jul 5, 2021
€1.6M Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has fined Storstockholms Lokaltrafik (Stockholm Local Transport Company) EUR 1,600,000. The controller had equipped ticket inspectors with body-worn cameras, which… SWEDEN ·Art. 5, 6, 13 ·Insufficient legal basis for data processing Video Surveillance Monitoring Fairness & Transparency Jun 21, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Personal Data Security Jun 14, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·Art. 5, 6, 9 +2 ·Non-compliance with general data processing principles Data Breaches Integrity and Confidentiality Principle Health Data Jun 7, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Encryption Security Jun 7, 2021
€50,000 Region Stockholm: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·Art. 5, 13, 14 ·Insufficient fulfilment of information obligations Data Breaches Healthcare Encryption Jun 7, 2021
€25,000 Region Värmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Värmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·Art. 5, 13 ·Insufficient fulfilment of information obligations Data Breaches Healthcare Encryption Jun 7, 2021
€25,000 Region Sörmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Sörmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·Art. 5, 13 ·Insufficient fulfilment of information obligations Data Breaches Healthcare Encryption Jun 7, 2021
€120,000 Azienda Usl della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Usl della Romagna EUR 120,000. The local health authority of Romagna had accidentally transmitted a patient's report regarding an… ITALY ·Garante ·Art. 5, 9 Healthcare IP Address Processing Agreement May 27, 2021
€4,000 Alava Norte, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Alava Norte, S.L. EUR 4,000. The controller had installed three 360° video surveillance cameras on the facade of one of its buildings to secure… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring May 25, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Recipient Security Apr 22, 2021
€4,000 HazteOir.Org: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on HazteOir.Org. The controller had published a brochure on sex education in schools which unlawfully contained the photos… SPAIN ·aepd ·Art. 6 Education Personal Data Consent Apr 22, 2021
€3,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller resides on the 1st floor of an apartment building, where he is the owner of… SPAIN ·aepd ·Art. 5, 13 Audit Logs IP Address Controllers Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·aepd ·Art. 6 IP Address Controllers Processing Agreement Apr 13, 2021
€10,000 Hospital Campogrande DE: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 10,000 on Hospital Campogrande DE. A patient filed a complaint against the controller with the DPA. The controller had performed an… SPAIN ·aepd ·Art. 5 Healthcare Healthcare IP Address Mar 10, 2021
€300,000 VfB Stuttgart 1893 AG: Non-compliance with general data processing principles The DPA from Baden-Württemberg has imposed a fine of EUR 300,000 on the soccer club VfB Stuttgart 1893 AG for negligent breach of data protection accountability under Art. 5 (2)… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Accountability Controllers IP Address Mar 10, 2021
€6,000 Comune di Commezzadura: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 6,000 on the municipality of Commezzadura. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare IP Address Feb 25, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Prior Consultation Public Authority IP Address Feb 11, 2021
€3,000 IDFINANCE Spain, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on IDFINANCE Spain S.L.. A person had received a debt collection email from IDFinance that contained a link for the payment of… aepd ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Insurance Personal Data Controllers Feb 1, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out four credit checks on the data… NORWAY ·Datatilsynet ·Art. 5, 6 Insurance Controllers Personal Data Jan 4, 2021
Private individual: Insufficient legal basis for data processing The DPA from Brandenburg imposed a three-digit fine on a company employee. The individual had sent an Excel spreadsheet with employee data of 56 employees to her private e-mail… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Employees Human Resources Processing Agreement Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried the investigation process of a friend against the background of a… GERMANY ·Insufficient legal basis for data processing Public Authority Education Public Sector Jan 1, 2021
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-digit fine on a company employee. The employee had forwarded application documents received by his employer from his work e-mail address… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Anonymization Processing Processing Agreement Jan 1, 2021
€400 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes. The officer had purchased a notebook for private use on an Internet platform. Since the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Scientific Research Processing Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security A company had stored telecommunications hardware, a server and backup technology in a guest bathroom. The server cabinet, which did not have an intact lock, also served as a… GERMANY ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Human Resources Jan 1, 2021
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Health Data Healthcare Dec 17, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Dec 10, 2020
€100,000 Apotheka e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Consent Dec 1, 2020
€100,000 Südameapteegi e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare Consent IP Address Dec 1, 2020
€100,000 Azeta.ee e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare Consent IP Address Dec 1, 2020
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·aepd ·Art. 6, 13, 14 Recipient Personal Data IP Address Nov 25, 2020
€12,000 Recambios Villalegre S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined the company for posting photos of a person on Facebook and WhatsApp and accusing the individual of theft in related posts. The photos were obtained… SPAIN ·aepd ·Art. 6, 13 Video Surveillance Social Media Monitoring Nov 23, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY ·Garante ·Art. 5, 13 Personal Data IP Address Employees Nov 23, 2020