Content type · 394 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN · ·Art. 6 Apr 12, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN · ·Art. 5, 32 Apr 12, 2024
€326,000 Santander Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 326,000 for failing to report a data breach to the DPA and data subjects in a timely manner. POLAND · ·Art. 33, 34 Mar 12, 2024
€18,000 Toyota Bank Polska S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Toyota Bank Polska S.A. EUR 18,000 for failing to report a data breach to the DPA in a timely manner. POLAND · ·Art. 33 Mar 12, 2024
€4,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.. A data subject had filed a complaint against the controller with the… SPAIN · ·Art. 15 Feb 13, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY · ·Art. 5, 32 Feb 8, 2024
€2,000 Account Exchange SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Account Exchange SRL for using personal data without the consent of the data subjects. ROMANIA · ·Art. 5, 6 Feb 7, 2024
€160,000 SANITAS, S.A. DE SEGUROS: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on SANITAS, S.A. DE SEGUROS. A customer had filed a complaint with the DPA due to the fact that the controller had concluded a contract without… SPAIN · ·Art. 6, 9 Feb 6, 2024
€500 Attorney: Insufficient cooperation with supervisory authority The French DPA has imposed a fine of EUR 500 on an attorney. The fine was imposed due to a lack of cooperation with the DPA. FRANCE · ·Insufficient cooperation with supervisory authority Jan 22, 2024
€5,000 Attorney: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5000 on an attorney. The fine was imposed due to a lack of cooperation with the DPA and a lack of fulfillment of a request of erasure of… FRANCE · ·Insufficient fulfilment of data subjects rights Jan 15, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS · ·Art. 35 Jan 15, 2024
€17,000 Alior Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 17,000 on Alior Bank SA. The investigation was initiated following complaints that the bank continued to send unsolicited electronic… ROMANIA · ·Art. 5, 6 Jan 12, 2024
€496,000 Company: Non-compliance with general data processing principles The DPA of Hessen has imposed a fine of EUR 496,000 on a company. The DPA identified several GDPR violations, including transmitting customer data to the incorrect recipient and… GERMANY ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Jan 1, 2024
€24,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 24,000 on Hora Credit IFN SA. The controller had accidentally sent documents containing the personal data of another person to a customer by… ROMANIA · ·Art. 12, 15, 32 +1 Dec 7, 2023
€10,000 Alpha Bank: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 10,000 on Alpha Bank. A data subject had filed a complaint with the DPA due to the controller's failure to respond to a request of… GREECE · ·Art. 12, 15 Nov 23, 2023
€1,500 Libra Internet Bank SA: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 1500 on Libra Internet Bank SA for failing to comply with an order issued by the DPA. ROMANIA · ·Art. 58 Nov 20, 2023
€200,000 CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. The controller had included the data subject's personal data in a credit… SPAIN · ·Art. 6 Nov 13, 2023
€20,000 Piraeus Leasing S.M.S.A.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000 on Piraeus Leasing S.M.S.A.. An individual had filed a complaint with the DPA because the controller processed an image on which… GREECE · ·Art. 5, 15 Nov 10, 2023
€43,000 Indcap AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 43,000 on Indecap AB. The controller had accidentally sent an email to a large number of its customers containing an Excel document… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Nov 7, 2023
€3,000 OTP BANK ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA. The controller had accidentally transmitted personal data of an individual to an unauthorized third party.… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Nov 3, 2023
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN · ·Art. 5, 25, 32 Oct 26, 2023
€50,000 Oney Servicios Financieros E.F.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 50,000 on Oney Servicios Financieros E.F.C... The controller had submitted data from the data subject to a credit information system… SPAIN · ·Art. 5 Oct 23, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN · ·Art. 25, 32 Oct 20, 2023
€24,000 Insurance company: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined an insurance company EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND · ·Art. 33 Oct 18, 2023
€15,000 ILUNION SEGURIDAD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on ILUNION SEGURIDAD, S.A. The controller had sent labor communications by e-mail without using the blind copy option, revealing… SPAIN · ·Art. 5, 32 Oct 10, 2023
€24,000 Link4 Towarzystwo Ubezpieczeń S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Link4 Towarzystwo Ubezpieczeń S. A. EUR 24,000 for failing to report a data breach to the DPA in a timely manner. POLAND · ·Art. 33 Oct 8, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA · ·Art. 5, 6, 12 +2 Oct 5, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has fined NN Asigurări de Viață S.A. EUR 1,000. A person had filed a complaint for receiving advertising messages, although they had objected to receiving… ROMANIA · ·Art. 21 Sep 18, 2023
€42,000 Intesa Sanpaolo Spa: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY · ·Art. 15 Sep 14, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Aug 28, 2023
€2.5M Open Bank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined Open Bank, S.A. EUR 2,5 million. A data subject had filed a complaint with the DPA after being asked to provide proof of origin for payments on their… SPAIN · ·Art. 25, 32 Jul 28, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA · ·Art. 32 Jul 18, 2023
€25,000 CaixaBank, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 25,000 on CaixaBank, S.A.. An individual had filed a complaint with the DPA due to the fact that when they requested information from the… SPAIN · ·Art. 32 Jul 4, 2023
€257,000 Creditinfo Lánstraust hf.: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 257,000 on Creditinfo Lánstraust hf.. The controller had registered information on loan defaults even though the required registration… ICELAND ·Art. 5, 6, 8 +1 ·Insufficient legal basis for data processing Jun 27, 2023
€24,000 Almennri innheimtu ehf: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 24,000 on Almennri innheimtu ehf. The controller had submitted information on loan defaults for registration even though the required… ICELAND ·Art. 5, 6, 8 +1 ·Insufficient legal basis for data processing Jun 27, 2023
€51,000 eCommerce 2020 ApS: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 51,000 on eCommerce 2020 ApS. The controller had submitted information on loan defaults for registration even though the required… ICELAND ·Art. 5, 6, 8 +1 ·Insufficient legal basis for data processing Jun 27, 2023
€2,000 BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found… ROMANIA · ·Art. 5 Jun 15, 2023
€210,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 210,000 on Piraeus Bank. During its investigation, the DPA found that the bank had processed personal data of customers in violation of… GREECE · ·Art. 5, 6, 15 +1 Jun 12, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE · ·Art. 5, 6, 9 +6 Jun 8, 2023
€20,000 RCI BANQUE, S.A. SUCURSAL EN ESPAÑA: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 RCI BANQUE, S.A. SUCURSAL EN ESPAÑA. A data subject complained that she was receiving text messages from the controller,… SPAIN · ·Art. 17 Jun 7, 2023
€42,000 PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA. An individual had filed a complaint with the DPA because the controller had disclosed… SPAIN · ·Art. 5, 32 Jun 1, 2023
€300,000 Deutsche Kreditbank: Insufficient fulfilment of data subjects rights The DPA of Berlin has imposed a fine of EUR 300,000 on Deutsche Kreditbank. A customer had filed a complaint with the DPA. The customer had submitted an application for a credit… GERMANY ·Art. 5, 15, 22 ·Insufficient fulfilment of data subjects rights May 31, 2023
€10,000 Santander Consumer Bank S.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Santander Consumer Bank S.p.a. EUR 10,000 for not sufficiently fulfilling its obligation to comply with a data subject's request for access to their data. ITALY · ·Art. 12 May 17, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA · ·Art. 32 May 12, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA · ·Art. 32 May 12, 2023
€11,000 Libra Internet Bank SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 11,000 on Libra Internet Bank SA. An individual had filed a complaint against the bank due to the bank's failure to fully comply with… ROMANIA · ·Art. 12, 15 May 11, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA · ·Art. 6, 13, 28 +1 May 4, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security May 2, 2023
€84,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. During its investigation, the DPA found that the controller had registered alleged debts of a former… SPAIN · ·Art. 6, 15 Apr 4, 2023
€1,000 INMARAN ASESORES S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on INMARAN ASESORES S.L. for failing to comply with an order issued by the DPA. SPAIN · ·Art. 58 Mar 24, 2023