Skip to content
Content type · 408 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 408 sort newestlargest fineoldest
€3,000 Senira Limited: Insufficient cooperation with supervisory authority The Cypriot DPA fined Senira Limited EUR 3,000 for failing to sufficiently cooperate with the DPA. CYPRUS ·Cyprus DPA ·Art. 31 Supervisory Authorities Supervision Processing Agreement Sep 4, 2024
€50,000 SANTANDER CONSUMER FINANCE, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 50,000 on SANTANDER CONSUMER FINANCE, S.A.. The fine followed a complaint from an individual who received advertising from the company,… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Insurance Aug 22, 2024
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Notification Obligation Data Breaches Personal Data Aug 20, 2024
€150,000 BANCO CETELEM, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO CETELEM, S.A.. A person had filed a complaint against the controller with the DPA due to the fact that debits had been made from their… SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Insurance Jun 25, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 24, 2024
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A data subject had filed a complaint with the DPA because the controller had proposed to a credit… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Jun 12, 2024
€160,000 ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A person had filed a complaint with the DPA because their ex-partner had been given… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Jun 10, 2024
€6,000 Ambitious People Group B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 6,000 on the recruitment company Ambitious People Group B.V. . The controller had not deleted the data of data subjects after they had… THE NETHERLANDS ·AP ·Art. 12, 17 Personal Data Controllers Supervisory Authorities Jun 4, 2024
€70,000 CAIXABANK S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK S.A.. A person had filed a complaint with the DPA because an employee of the controller had accidentally disclosed… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing May 28, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… AEPD ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data May 7, 2024
€1,200 ARRENDAMIENTOS DEUDORES, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ARRENDAMIENTOS DEUDORES, S.L.. The controller had carried out a credit check on the data subject without any valid legal basis for this. The… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance May 7, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Apr 23, 2024
€1,000 CONSULTORÍA PERITACIONES ALMERIENSES, S.L: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on CONSULTORÍA PERITACIONES ALMERIENSES, S.L for failing to comply with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Insurance Apr 19, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Insurance Apr 12, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·AEPD ·Art. 6 Consent Personal Data Security Apr 12, 2024
€326,000 Santander Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 326,000 for failing to report a data breach to the DPA and data subjects in a timely manner. POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€18,000 Toyota Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Toyota Bank Polska S.A. EUR 18,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€4,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.. A data subject had filed a complaint against the controller with the… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Feb 13, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY ·Garante ·Art. 5, 32 Security Controllers Identification Feb 8, 2024
€2,000 Account Exchange SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Account Exchange SRL for using personal data without the consent of the data subjects. ROMANIA ·ANSPDCP ·Art. 5, 6 Consent Personal Data Processing Feb 7, 2024
€160,000 SANITAS, S.A. DE SEGUROS: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on SANITAS, S.A. DE SEGUROS. A customer had filed a complaint with the DPA due to the fact that the controller had concluded a contract without… SPAIN ·AEPD ·Art. 6, 9 Consent Controllers Processing Feb 6, 2024
€500 Attorney: Insufficient cooperation with supervisory authority The French DPA has imposed a fine of EUR 500 on an attorney. The fine was imposed due to a lack of cooperation with the DPA. FRANCE ·CNIL ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Insurance Jan 22, 2024
€5,000 Attorney: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5000 on an attorney. The fine was imposed due to a lack of cooperation with the DPA and a lack of fulfillment of a request of erasure of… FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right to be Forgotten Personal Data Supervisory Authorities Jan 15, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS ·AP ·Art. 35 DPIA Personal Data Security Jan 15, 2024
€17,000 Alior Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 17,000 on Alior Bank SA. The investigation was initiated following complaints that the bank continued to send unsolicited electronic… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 12, 2024
€496,000 Company: Non-compliance with general data processing principles The DPA of Hessen has imposed a fine of EUR 496,000 on a company. The DPA identified several GDPR violations, including transmitting customer data to the incorrect recipient and… GERMANY ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Recipient Supervisory Authorities Processing Jan 1, 2024
€24,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 24,000 on Hora Credit IFN SA. The controller had accidentally sent documents containing the personal data of another person to a customer by… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Personal Data Controllers Security Dec 7, 2023
€10,000 Alpha Bank: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 10,000 on Alpha Bank. A data subject had filed a complaint with the DPA due to the controller's failure to respond to a request of… GREECE ·HDPA ·Art. 12, 15 Personal Data Supervisory Authorities Controllers Nov 23, 2023
€1,500 Libra Internet Bank SA: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 1500 on Libra Internet Bank SA for failing to comply with an order issued by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Nov 20, 2023
€200,000 CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. The controller had included the data subject's personal data in a credit… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Insurance Nov 13, 2023
€20,000 Piraeus Leasing S.M.S.A.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000 on Piraeus Leasing S.M.S.A.. An individual had filed a complaint with the DPA because the controller processed an image on which… GREECE ·HDPA ·Art. 5, 15 Personal Data Controllers Supervisory Authorities Nov 10, 2023
€43,000 Indcap AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 43,000 on Indecap AB. The controller had accidentally sent an email to a large number of its customers containing an Excel document… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 7, 2023
€3,000 OTP BANK ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA. The controller had accidentally transmitted personal data of an individual to an unauthorized third party.… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 3, 2023
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·AEPD ·Art. 5, 25, 32 Privacy by Design & Default Privacy by Default Privacy by Design Oct 26, 2023
€50,000 Oney Servicios Financieros E.F.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on Oney Servicios Financieros E.F.C... The controller had submitted data from the data subject to a credit information system… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Oct 23, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN ·AEPD ·Art. 25, 32 Security Privacy by Design & Default Controllers Oct 20, 2023
€24,000 Insurance company: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an insurance company EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 18, 2023
€15,000 ILUNION SEGURIDAD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on ILUNION SEGURIDAD, S.A. The controller had sent labor communications by e-mail without using the blind copy option, revealing… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing Insurance Oct 10, 2023
€24,000 Link4 Towarzystwo Ubezpieczeń S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Link4 Towarzystwo Ubezpieczeń S. A. EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 8, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·AZOP ·Art. 5, 6, 12 +2 Personal Data Legitimate Interest Controllers Oct 5, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has fined NN Asigurări de Viață S.A. EUR 1,000. A person had filed a complaint for receiving advertising messages, although they had objected to receiving… ROMANIA ·ANSPDCP ·Art. 21 Direct Marketing Personal Data Processing Sep 18, 2023
€42,000 Intesa Sanpaolo Spa: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 15 Personal Data Supervisory Authorities Insurance Sep 14, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Personal Data Identification Aug 28, 2023
€2.5M Open Bank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined Open Bank, S.A. EUR 2,5 million. A data subject had filed a complaint with the DPA after being asked to provide proof of origin for payments on their… SPAIN ·AEPD ·Art. 25, 32 Privacy by Design & Default Security Personal Data Jul 28, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Supervisory Authorities Jul 18, 2023
€25,000 CaixaBank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 25,000 on CaixaBank, S.A.. An individual had filed a complaint with the DPA due to the fact that when they requested information from the… SPAIN ·AEPD ·Art. 32 Security Controllers Personal Data Jul 4, 2023
€24,000 Almennri innheimtu ehf: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 24,000 on Almennri innheimtu ehf. The controller had submitted information on loan defaults for registration even though the required… ICELAND ·Persónuvernd ·Art. 5, 6, 8 +1 Controllers Processing Insurance Jun 27, 2023
€51,000 eCommerce 2020 ApS: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 51,000 on eCommerce 2020 ApS. The controller had submitted information on loan defaults for registration even though the required… ICELAND ·Persónuvernd ·Art. 5, 6, 8 +1 Controllers Processing Insurance Jun 27, 2023
€257,000 Creditinfo Lánstraust hf.: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 257,000 on Creditinfo Lánstraust hf.. The controller had registered information on loan defaults even though the required registration… ICELAND ·Persónuvernd ·Art. 5, 6, 8 +1 Controllers Processing Insurance Jun 27, 2023
€2,000 BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found… ROMANIA ·ANSPDCP ·Art. 5 Controllers Personal Data Processing Jun 15, 2023