Skip to content
Content type · 394 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 394 sort newestlargest fineoldest
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·aepd ·Art. 6 Processing Agreement Insurance Personal Data Apr 12, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN ·aepd ·Art. 5, 32 Security IP Address Controllers Apr 12, 2024
€326,000 Santander Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 326,000 for failing to report a data breach to the DPA and data subjects in a timely manner. POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Mar 12, 2024
€18,000 Toyota Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Toyota Bank Polska S.A. EUR 18,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 12, 2024
€4,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.. A data subject had filed a complaint against the controller with the… SPAIN ·aepd ·Art. 15 Personal Data Controllers Insurance Feb 13, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY ·Garante ·Art. 5, 32 Security Insurance Controllers Feb 8, 2024
€2,000 Account Exchange SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Account Exchange SRL for using personal data without the consent of the data subjects. ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Insurance Consent Feb 7, 2024
€160,000 SANITAS, S.A. DE SEGUROS: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on SANITAS, S.A. DE SEGUROS. A customer had filed a complaint with the DPA due to the fact that the controller had concluded a contract without… SPAIN ·aepd ·Art. 6, 9 Insurance Controllers Processing Agreement Feb 6, 2024
€500 Attorney: Insufficient cooperation with supervisory authority The French DPA has imposed a fine of EUR 500 on an attorney. The fine was imposed due to a lack of cooperation with the DPA. FRANCE ·CNIL ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Jan 22, 2024
€5,000 Attorney: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5000 on an attorney. The fine was imposed due to a lack of cooperation with the DPA and a lack of fulfillment of a request of erasure of… FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right to be Forgotten Personal Data Supervisory Authorities Jan 15, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS ·AP ·Art. 35 DPIA Privacy Impact Assessment Security Jan 15, 2024
€17,000 Alior Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 17,000 on Alior Bank SA. The investigation was initiated following complaints that the bank continued to send unsolicited electronic… ROMANIA ·ANSPDCP ·Art. 5, 6 IP Address Processing Agreement Personal Data Jan 12, 2024
€496,000 Company: Non-compliance with general data processing principles The DPA of Hessen has imposed a fine of EUR 496,000 on a company. The DPA identified several GDPR violations, including transmitting customer data to the incorrect recipient and… GERMANY ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Recipient IP Address Insurance Jan 1, 2024
€24,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 24,000 on Hora Credit IFN SA. The controller had accidentally sent documents containing the personal data of another person to a customer by… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Personal Data Controllers Security Dec 7, 2023
€10,000 Alpha Bank: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 10,000 on Alpha Bank. A data subject had filed a complaint with the DPA due to the controller's failure to respond to a request of… GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 23, 2023
€1,500 Libra Internet Bank SA: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 1500 on Libra Internet Bank SA for failing to comply with an order issued by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Processing Agreement Nov 20, 2023
€200,000 CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. The controller had included the data subject's personal data in a credit… SPAIN ·aepd ·Art. 6 Controllers Personal Data Insurance Nov 13, 2023
€20,000 Piraeus Leasing S.M.S.A.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000 on Piraeus Leasing S.M.S.A.. An individual had filed a complaint with the DPA because the controller processed an image on which… GREECE ·HDPA ·Art. 5, 15 Insurance IP Address Personal Data Nov 10, 2023
€43,000 Indcap AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 43,000 on Indecap AB. The controller had accidentally sent an email to a large number of its customers containing an Excel document… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Insurance Nov 7, 2023
€3,000 OTP BANK ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA. The controller had accidentally transmitted personal data of an individual to an unauthorized third party.… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Nov 3, 2023
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·aepd ·Art. 5, 25, 32 Privacy by Default Privacy by Design Privacy by Design & Default Oct 26, 2023
€50,000 Oney Servicios Financieros E.F.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on Oney Servicios Financieros E.F.C... The controller had submitted data from the data subject to a credit information system… SPAIN ·aepd ·Art. 5 Personal Data Controllers IP Address Oct 23, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN ·aepd ·Art. 25, 32 Security Privacy by Design & Default Controllers Oct 20, 2023
€24,000 Insurance company: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an insurance company EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Oct 18, 2023
€15,000 ILUNION SEGURIDAD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on ILUNION SEGURIDAD, S.A. The controller had sent labor communications by e-mail without using the blind copy option, revealing… SPAIN ·aepd ·Art. 5, 32 IP Address Controllers Insurance Oct 10, 2023
€24,000 Link4 Towarzystwo Ubezpieczeń S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Link4 Towarzystwo Ubezpieczeń S. A. EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 8, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·azop ·Art. 5, 6, 12 +2 Controllers Personal Data Legitimate Interest Oct 5, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has fined NN Asigurări de Viață S.A. EUR 1,000. A person had filed a complaint for receiving advertising messages, although they had objected to receiving… ROMANIA ·ANSPDCP ·Art. 21 Insurance Direct Marketing Personal Data Sep 18, 2023
€42,000 Intesa Sanpaolo Spa: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 15 Insurance Personal Data Supervisory Authorities Sep 14, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Recipient Healthcare Aug 28, 2023
€2.5M Open Bank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined Open Bank, S.A. EUR 2,5 million. A data subject had filed a complaint with the DPA after being asked to provide proof of origin for payments on their… SPAIN ·aepd ·Art. 25, 32 Security Personal Data Privacy by Design & Default Jul 28, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jul 18, 2023
€25,000 CaixaBank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 25,000 on CaixaBank, S.A.. An individual had filed a complaint with the DPA due to the fact that when they requested information from the… SPAIN ·aepd ·Art. 32 Security Privacy by Design & Default Controllers Jul 4, 2023
€257,000 Creditinfo Lánstraust hf.: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 257,000 on Creditinfo Lánstraust hf.. The controller had registered information on loan defaults even though the required registration… ICELAND ·Art. 5, 6, 8 +1 ·Insufficient legal basis for data processing Controllers Insurance Processing Agreement Jun 27, 2023
€24,000 Almennri innheimtu ehf: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 24,000 on Almennri innheimtu ehf. The controller had submitted information on loan defaults for registration even though the required… ICELAND ·Art. 5, 6, 8 +1 ·Insufficient legal basis for data processing Controllers Insurance Processing Jun 27, 2023
€51,000 eCommerce 2020 ApS: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 51,000 on eCommerce 2020 ApS. The controller had submitted information on loan defaults for registration even though the required… ICELAND ·Art. 5, 6, 8 +1 ·Insufficient legal basis for data processing Controllers Insurance Processing Agreement Jun 27, 2023
€2,000 BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found… ROMANIA ·ANSPDCP ·Art. 5 Data Breaches IP Address Controllers Jun 15, 2023
€210,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 210,000 on Piraeus Bank. During its investigation, the DPA found that the bank had processed personal data of customers in violation of… GREECE ·HDPA ·Art. 5, 6, 15 +1 Personal Data IP Address Security Jun 12, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest IP Address Jun 8, 2023
€20,000 RCI BANQUE, S.A. SUCURSAL EN ESPAÑA: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 RCI BANQUE, S.A. SUCURSAL EN ESPAÑA. A data subject complained that she was receiving text messages from the controller,… SPAIN ·aepd ·Art. 17 Personal Data Controllers Processing Agreement Jun 7, 2023
€42,000 PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA. An individual had filed a complaint with the DPA because the controller had disclosed… SPAIN ·aepd ·Art. 5, 32 Insurance IP Address Processing Agreement Jun 1, 2023
€300,000 Deutsche Kreditbank: Insufficient fulfilment of data subjects rights The DPA of Berlin has imposed a fine of EUR 300,000 on Deutsche Kreditbank. A customer had filed a complaint with the DPA. The customer had submitted an application for a credit… GERMANY ·Art. 5, 15, 22 ·Insufficient fulfilment of data subjects rights Insurance Controllers Personal Data May 31, 2023
€10,000 Santander Consumer Bank S.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Santander Consumer Bank S.p.a. EUR 10,000 for not sufficiently fulfilling its obligation to comply with a data subject's request for access to their data. ITALY ·Garante ·Art. 12 Personal Data Supervisory Authorities Insurance May 17, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€11,000 Libra Internet Bank SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 11,000 on Libra Internet Bank SA. An individual had filed a complaint against the bank due to the bank's failure to fully comply with… ROMANIA ·ANSPDCP ·Art. 12, 15 Data Subject Rights Exercise Modalities and Procedures Personal Data Supervisory Authorities May 11, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·azop ·Art. 6, 13, 28 +1 Security Personal Data Controllers May 4, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default May 2, 2023
€84,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. During its investigation, the DPA found that the controller had registered alleged debts of a former… SPAIN ·aepd ·Art. 6, 15 Controllers Personal Data Insurance Apr 4, 2023
€1,000 INMARAN ASESORES S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on INMARAN ASESORES S.L. for failing to comply with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Mar 24, 2023