Skip to content
Content type · 178 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–178 of 178 sort newestlargest fineoldest
€15,000 PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ: Non-compliance with general data processing principles The Hellenic DPA has fined PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ EUR 15,000 due to the illegal installation and operation of a video surveillance system. The controller had installed a video… GREECE ·HDPA ·Art. 5 Accountability Controllers Transparency Jun 3, 2021
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Retention Period Personal Data May 13, 2021
EDPS: CJEU violated Regulation 2018/1725 over cookies and consent on its website A data subject complained around cookies and similar technologies used in connection to audiovisual material on the website of the Court of Justice of the European Union (CJEU),… 2019-0878 ·European Union ·Art. 7 Consent Information Provision Modalities and Communication Methods Cookies May 3, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·AEPD ·Art. 5, 6, 14 Integrity and Confidentiality Principle Retention Period Personal Data Apr 23, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY ·Garante ·Art. 5, 25, 35 Retention Period Controllers DPIA Feb 25, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles Supervisory Authorities Controllers Processors Jan 1, 2021
€10,000 Online Services: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined the operator of the online store banderacatalana.cat. EUR 10,000 for a violation of Art. 13 GDPR. The operator stated on its website privacy notices… SPAIN ·AEPD ·Art. 6, 8, 13 Personal Data Consent Supervisory Authorities Dec 15, 2020
€35M CNIL · SAN-2020-013 Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating… France ·Art. 6, 9, 83 +1 Telecommunications Personal Data Supervisory Authorities Dec 7, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Healthcare Nov 19, 2020
€1,500 BELGIUM DPA: Non-compliance with general data processing principles The Belgian DPA (APD/GBA) imposed a fine of EUR 1,500 on a social housing company for non-compliance with several principles of the GDPR such as data processing as well as the… APD/GBA ·Art. 5, 6, 12 +3 ·Non-compliance with general data processing principles Supervisory Authorities Fairness & Transparency Transparency Nov 13, 2020
€600,000 Google Belgium SA: Insufficient fulfilment of data subjects rights The Belgian data protection authority has fined Google Belgium SA, a subsidiary of Google, 600,000 euros. The reasons for the fine were the rejection of an application by a data… APD/GBA ·Art. 5, 6, 12 +1 ·Insufficient fulfilment of data subjects rights Right to be Forgotten Personal Data Fairness & Transparency Jul 14, 2020
€800,000 Iliad Italia S.p.A.: Non-compliance with general data processing principles The fine relates to data protection infringements concerning the processing of customer data for the activation of SIM cards and the manner in which payment data was recorded. In… ITALY ·Garante ·Art. 5, 25 Integrity and Confidentiality Principle Personal Data Transparency Jul 13, 2020
€5,000 School Fitness Holiday & Franchising S.L.: Non-compliance with general data processing principles Breach of transparency principle. No further information available at the moment. SPAIN ·AEPD ·Art. 5 Transparency Processing Fairness & Transparency Jul 10, 2020
€3,000 Salad Market S.L. (Catering Company): Insufficient fulfilment of information obligations Fines for lack of sufficient data processing information in relation to video surveillance on business premises and for insufficient information when cookies were used on its… SPAIN ·AEPD ·Art. 13, 14 Supervisory Authorities Cookies Video Surveillance Jun 9, 2020
€4,000 Liceo Artistico Statale di Napoli: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information in the teacher rankings published on the Institute's website. This… ITALY ·Garante ·Art. 5, 6, 9 Retention Period Fairness & Transparency Healthcare Mar 6, 2020
€4,000 Liceo Scientifico Nobel di Torre del Greco: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information of more than 2000 teachers in the teacher rankings published on the… ITALY ·Garante ·Art. 5, 6, 9 Retention Period Fairness & Transparency Healthcare Mar 6, 2020
€8,000 LITHUANIA DPA: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) fined a company EUR 8,000 for conducting sound recordings on public transport buses in violation of Article 5 GDPR, Article 13 GDPR, Article 24 GDPR and… VDAI ·Art. 5, 13, 24 +1 ·Non-compliance with general data processing principles Supervisory Authorities DPIA Accountability Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Fairness & Transparency Jan 1, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Fairness & Transparency Jan 1, 2020
€900 TODOTECNICOS24H S.L.: Insufficient fulfilment of information obligations TODOTECNICOS24H had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Transparency Nov 7, 2019
€900 Cerrajero Online: Insufficient fulfilment of information obligations The company had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Transparency Nov 6, 2019
€2,860 Unknown Company: Non-compliance with general data processing principles An employee was on sick leave when his employer checked his desktop, laptop and emails to ensure that his work-related duties were being covered in his absence. The employer then… HUNGARY ·NAIH ·Art. 5, 6, 13 +2 Retention Period Legitimate Interest Storage Limitation Oct 15, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Processors Territorial scope (GDPR) Sep 3, 2019
€150,000 PWC Business Solutions: Insufficient legal basis for data processing The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to… GREECE ·HDPA ·Art. 5, 6, 13 +1 Legitimate Interest Controllers Personal Data Jul 30, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Garante ·Art. 32 Controllers Processors Security Apr 17, 2019
€1,560 Debt collector: Non-compliance with general data processing principles A data subject requested information about and erasure of the data processed, which the debt collector refused stating that it could not identify the subject. For identification… HUNGARY ·NAIH ·Art. 5 Personal Data Controllers Transparency Feb 20, 2019
€50M Google LLC: Insufficient legal basis for data processing The fine was imposed on the basis of complaints from the Austrian organisation 'None Of Your Business' and the French NGO 'La Quadrature du Net'. The complaints were filed on 25th… FRANCE ·CNIL ·Art. 5, 6, 13 +1 Fairness & Transparency Transparency Consent Jan 21, 2019
€50,000 Unknown Company: Insufficient fulfilment of data subjects rights The data controller had engaged an external company to carry out the duties of access to data according to Art. 15 GDPR. However, the engaged company conducted the correspondence… GERMANY ·Art. 15, 28 ·Insufficient fulfilment of data subjects rights Controllers Fairness & Transparency Personal Data Jan 1, 2019