Skip to content
Content type · 472 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 472 sort newestlargest fineoldest
€10,000 Azienda sanitaria locale Roma 3: Insufficient fulfilment of data breach notification obligations The Italian DPA has fined Azienda sanitaria locale Roma 3 EUR 10,000 for failing to report a data breach to the DPA in a timely manner and to properly document the data breach. ITALY ·Garante ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 21, 2024
€1,000 CLÍNICA PARÍS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on CLÍNICA PARÍS, S.L for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Mar 20, 2024
€1,000 DENTAL REY-GAR, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on DENTAL REY-GAR, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Mar 7, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Recipient Feb 8, 2024
€300,000 Medtronic Italia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Medtronic Italia. The controller had sent emails in an open distribution list to hundreds of individuals using the… ITALY ·Garante ·Art. 5, 9, 12 +2 Healthcare IP Address Personal Data Feb 8, 2024
€30,000 CENTRO MÉDICO SALUS BALEARES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 30,000 on CENTRO MÉDICO SALUS BALEARES, S.L.. An individual had filed a complaint with the DPA due to the clinic's use of an electronic… SPAIN ·aepd ·Art. 5, 32 Healthcare IP Address Processing Agreement Feb 8, 2024
€5,000 Dentist: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5,000 on a dentist due to a lack of data security and a failure to respect the right of access of a data subject. FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right of Access Right of Access Procedures Healthcare Jan 31, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Healthcare Encryption Healthcare Jan 17, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Fines Supervisory Authorities Processing Agreement Jan 1, 2024
€2,500 Doctor´s Office: Insufficient technical and organisational measures to ensure information security The DPA of Hessen has imposed a fine of EUR 2,500 on a doctor´s office. The controller hired an office manager who worked partly from home. The manager worked with patient files,… GERMANY ·Art. 5, 6, 9 +1 ·Insufficient technical and organisational measures to ensure information security Healthcare Security Controllers Jan 1, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jan 1, 2024
€3,700 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,700 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Health Data Controllers Jan 1, 2024
€3,300 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,300 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Controllers Jan 1, 2024
€23,000 Polish Minister of Health: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 23,000 on the Polish Minister of Health. The controller had accessed information via a database relating to a physician who had prescribed… POLAND ·UODO ·Art. 25, 32, 34 Healthcare Security Controllers Dec 20, 2023
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… CYPRUS ·Art. 5 ·Non-compliance with general data processing principles Healthcare Health Data Healthcare Dec 7, 2023
€40,000 Azienda socio sanitaria territoriale nord Milano, C.F.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Azienda socio sanitaria territoriale nord Milano, C.F.. During its investigation, the DPA found that a patient's spouse had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare IP Address Processing Agreement Dec 7, 2023
€10,000 Pharmacy owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,000 on a pharmacy owner. The controller had disposed of a large number of personal documents, including medical information of data… SPAIN ·aepd ·Art. 5, 32 Healthcare Healthcare IP Address Nov 24, 2023
€72,000 Eurocollege Oxford English Institute S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 72,000 on Eurocollege Oxford English Institute S.L. The data subject stated that they had signed a training contract with the affiliated… SPAIN ·aepd ·Art. 5, 6, 9 Healthcare IP Address Education Nov 17, 2023
€18,000 Cluster S.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 18,000 on Cluster S-r.l. A data subject had complained to the DPA because their son's health-related data and their own personal data had… ITALY ·Garante ·Art. 5, 32 Anonymization Healthcare Personal Data Nov 16, 2023
€48,000 INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P.: Non-compliance with general data processing principles The Spanish DPA has imposed a finea INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P. The controller had suffered a data breach in which personal patient and employee data had… SPAIN ·aepd ·Art. 5, 32, 34 Data Breaches Healthcare Employees Nov 2, 2023
€7,000 Ophthalmologic institute: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 7,000 on a ophthalmologic institute. The controller had responded to an online review, disclosing personal data of a patient. SPAIN ·aepd ·Art. 5, 32 Personal Data Healthcare Controllers Oct 26, 2023
€40,000 Azienda socio sanitaria territoriale di Lodi CF: Non-compliance with general data processing principles The Italian DPA has imposed a fine of ERU 40,000 on the health authority Azienda socio sanitaria territoriale di Lodi CF. Employees of the health authority had accessed the file… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Healthcare IP Address Oct 12, 2023
€1,000 GREECE DPA: Non-compliance with general data processing principles Unlawful disclosure of health data. HDPA ·Art. 5 ·Non-compliance with general data processing principles Health Data Healthcare IP Address Oct 11, 2023
€1,500 NORDETIA CLINICS MÓSTOLES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,500 on NORDETIA CLINICS MÓSTOLES S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email… SPAIN ·aepd ·Art. 5, 32 Healthcare IP Address Controllers Oct 10, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·azop ·Art. 5, 6, 12 +2 Controllers Personal Data Insurance Oct 5, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY ·Garante ·Art. 5, 32 Healthcare Health Data Healthcare Sep 28, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Healthcare Healthcare Sep 28, 2023
€5,000 Physician: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on a physician for unlawfully disclosing patient data. ITALY ·Garante ·Art. 5, 9 Health Data Healthcare IP Address Sep 28, 2023
€5,000 Ministero dell'Ambiente e della Sicurezza Energetica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Ministero dell'Ambiente e della Sicurezza Energetica. The controller had published a document on its website that contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Health Data Healthcare Education Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Health Data Sep 28, 2023
€10,000 Phyisician: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 10,000 on a physician. The physician had responded to an online review regarding their practice, disclosing personal health data of a… AUSTRIA ·dsb ·Art. 5, 9 Health Data Healthcare IP Address Sep 26, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN ·aepd ·Art. 9, 13 Health Data Healthcare Personal Data Sep 25, 2023
€1,600 Company: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 1,600 on a company providing psychotherapy services. A customer had submitted a request for access to their stored personal data.… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 15 Personal Data Healthcare Processing Agreement Sep 4, 2023
€10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… ITALY ·Garante ·Art. 5, 9, 12 +5 Recipient Healthcare Healthcare Aug 31, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Recipient Access Controls Aug 28, 2023
€2,000 Med Life SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Med Life SA. The controller had refused to disclose certain video recordings of the reception of a hospital to the data… ROMANIA ·ANSPDCP ·Art. 12, 15 Healthcare Personal Data Healthcare Aug 3, 2023
€10,000 GYMOOGIMNASIOS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined GYMOOGIMNASIOS S.L. EUR 10,000. The controller had installed a reservation system where data subjects had to consent to the processing of health-related… SPAIN ·aepd ·Art. 5, 7 IP Address Controllers Healthcare Aug 2, 2023
€12,000 Azienda Socio Sanitaria Territoriale Ovest Milanese: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare IP Address Jul 18, 2023
€81,000 Heilsuveru: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has fined Heilsuveru EUR 81,000. The controller had reported a data breach to the DPA, as two unauthorized persons had managed to view personal data. During its… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jul 3, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Access Controls Jun 28, 2023
€22,500 Irish Departement of Health: Non-compliance with general data processing principles The Irish DPA (DPC) has fined the Irish Department of Health EUR 22,500. The DPA launched an investigation into the department following public allegations that the department… IRELAND ·Art. 5, 6, 9 ·Non-compliance with general data processing principles Healthcare Personal Data IP Address Jun 16, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest Insurance Jun 8, 2023
€5,000 Azienda Tutela della Salute della Sardegna: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Azienda Tutela della Salute della Sardegna. The health authority had placed a sign at the gate of a physician's practice… ITALY ·Garante ·Art. 2, 5, 9 Healthcare Processing Agreement Processing Jun 7, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY ·Garante ·Art. 2, 5, 9 +1 Health Data Healthcare Healthcare Jun 1, 2023
€10,000 Camedi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Camedi s.r.l. Medical Center. A person had filed a complaint with the DPA because they had received invoices as well as… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Healthcare Security Jun 1, 2023
€15,000 Thin Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Thin Srl. The authority took action following a complaint from a GP who alleged that the company had breached data protection… ITALY ·Garante ·Art. 5, 9, 13 Healthcare Health Data Anonymization Jun 1, 2023
€3,000 NORDETIA CLINICS IBERIA, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined NORDETIA CLINICS IBERIA, S.L. EUR 3,000 for failing to provide information requested by the DPA during an investigation. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement May 24, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY ·Garante ·Art. 5, 6, 32 Healthcare Health Data Security May 17, 2023
€15,000 Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Education Health Data Healthcare Apr 27, 2023
€15,000 Citynews S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Citynews S.p.A. EUR 15,000. The controller had published an article in a newspaper reporting on the arrest of an individual, including health data of the… ITALY ·Garante ·Art. 5, 9 Healthcare Health Data IP Address Apr 14, 2023