Content type · 2,035 documents in this view · 3,836 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3611 Processing 2650 Personal Data 2423 Controllers 2035 Processing Agreement 1116 Security 1022 Supervision 865 Healthcare 622 Public Authority 573 Law Enforcement 572 Monitoring 551 Consent 509
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Dec 17, 2020
€1,940 HUNGARY DPA: Insufficient fulfilment of information obligations The Hungarian DPA (NAIH) imposed a fine of HUF 700,000 (EUR 1,940) against a construction company. The controller had installed a video surveillance system at a construction site… ·Art. 5, 13 ·Insufficient fulfilment of information obligations Dec 16, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Dec 16, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN · ·Art. 5, 32 Dec 11, 2020
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Dec 11, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY · ·Art. 5, 6, 9 +2 Dec 10, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS · ·Art. 33 Dec 10, 2020
€18,850 TUiR Warta S.A.: Insufficient fulfilment of data breach notification obligations An insurance agent hired by the controller had sent an email to unauthorized third parties in regard to insurance policies that contained personal data of two of the company's… POLAND · ·Art. 33, 34 Dec 9, 2020
€2,850 Smart Cities Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the Polish DPA (UODO). The controller failed to provide personal data and other information requested by UODO for investigative… POLAND · ·Art. 31, 58 Dec 9, 2020
€35M CNIL · SAN-2020-013 Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating… France ·Art. 6, 9, 83 +1 Dec 7, 2020
€3,000 Comercio Online Levante, S.L.: Insufficient technical and organisational measures to ensure information security A woman filed a complaint with the Spanish DPA (AEPD) against Comercio Online Levante, S.L. due to the fact that she was shown the personal data of another user when trying to… SPAIN · ·Art. 5, 32 Dec 2, 2020
€6,000 Servicio de Alojamientos Responsables, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine in the amount of EUR 6,000 against the controller for unauthorized conclusion of a contract in the name of the data subject without his/her… SPAIN · ·Art. 6 Dec 2, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Nov 26, 2020
€3,000 Charly Mike s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Charly Mike s.r.l.. The controller is the hotel operator of the Hotel Olimpo in Alberobello. Garante received a complaint… ITALY · ·Art. 5, 13 Nov 26, 2020
€1,500 Private Individual: Insufficient legal basis for data processing The Belgian DPA (APD) imposed a fine against private individuals. The controllers installed video cameras on their private property, two of which were positioned in a way that… BELGIUM · ·Art. 6, 25 Nov 25, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Nov 19, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… ·Art. 5 ·Non-compliance with general data processing principles Nov 18, 2020
€900,000 Telecoms provider (1&1 Telecom GmbH): Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's… GERMANY · ·Art. 32 Nov 11, 2020
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Nov 5, 2020
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY · ·Art. 5, 13 Oct 29, 2020
€20,000 Gaypa s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee's email account active and had access to the data subject's… ITALY · ·Art. 5, 12, 13 Oct 29, 2020
€200 Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Oct 24, 2020
€54,800 Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak: Insufficient fulfilment of data subjects rights The data controller denied the data subject access to the video material recorded by CCTV in a local store, with which the data subject wanted to prove that he or she had not… HUNGARY · ·Art. 12, 15, 18 +1 Oct 23, 2020
€3,000 Avata Hispania, S.L.: Insufficient legal basis for data processing Infringement of Art. 28 (3) g) GDPR, since personal data were further processed after the controller had terminated the contractual relationship with the processor. SPAIN · ·Art. 5, 6, 28 Oct 3, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 9 +1 Sep 30, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY · ·Art. 5, 6, 13 +2 Sep 30, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. Proceedings were initiated following an inspection carried out in response to a complaint. The accused processed and… CZECH REPUBLIC · ·Art. 5, 13, 28 +1 Sep 25, 2020
€7,800 Iweb Internet Learning, S.L.: Insufficient fulfilment of information obligations Lack of information in the privacy policy (information on the data controller) as well as inadequate obtaining of consent, as only a general consent could be given without… SPAIN · ·Art. 7, 12, 13 Sep 22, 2020
IP Slovenia: ZEKom-1 governs legal basis for NIJZ #StayHealthy SMS to users The IP received a request for an opinion concerning sending of an SMS message to users about the new #StayHealthy app created by the National Institute of Public Health (NIJZ).… 07121-1/2020/1570 · ·Art. 6, 58 Sep 11, 2020
€8,000 Private Person: Non-compliance with general data processing principles Operation of a CCTV camera that also monitored public space outside the premises of the data controller. GREECE · ·Art. 5 Sep 11, 2020
€3,000 Barcelona Airport Security Guard Association ('AVSAB'): Non-compliance with general data processing principles A member of the AVSAB security committee used WhatsApp to send messages to private phone numbers containing personal information about employees. This was a violation of the… SPAIN · ·Art. 5 Sep 7, 2020
Datatilsynet (Norway)- 20/02254 The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) · ·Art. 57, 58 Sep 7, 2020
DSB: online article about former politician is journalistic processing under Art. 85 GDPR In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that website contained wrong statements about her.… 2020-0.303.727 ·Austria ·Art. 17, 85 Sep 1, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND · ·Art. 32 Aug 12, 2020
HDPA 23/2020: Complaint against HEDNO S.A. for denial of employment certificate The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Greece ·Art. 4, 5, 12 +6 Jul 30, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA · ·Art. 32 Jul 30, 2020
€5,000 Operator of CCTV of a residential building: Insufficient legal basis for data processing The operator of video cameras on a residential property had installed cameras there to monitor the shared area of two blocks of flats. The data controller argued that the owners… BELGIUM · ·Art. 6, 7 Jul 14, 2020
€200,000 Merlini s.r.l.: Insufficient legal basis for data processing The company had carried out telemarketing activities on behalf of Wind Tre S.p.A. through a third party provider as data processor without sufficient legal basis fpr data… ITALY · ·Art. 5, 6, 7 +2 Jul 13, 2020
€5,000 Global Business Travel Spain SLU: Insufficient technical and organisational measures to ensure information security The fine was preceded by an employee's access to health data of a person concerned. In the course of its investigations, the Data Protection Authority found that Global Business… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jul 10, 2020
€5,000 Municipal employee: Insufficient legal basis for data processing In the context of a municipal election in 2018, the data controller had sent election advertisements to a group of employees of the same municipal administration, unlawfully using… BELGIUM · ·Art. 5, 6 Jun 8, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ·Art. 5, 6 ·Insufficient legal basis for data processing May 26, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE · ·Art. 5, 6 Apr 7, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS · ·Art. 9, 32 Mar 24, 2020
€8,000 Speech and Special Education Centre - Mihou Dimitra: Insufficient fulfilment of data subjects rights The complainant had requested access to his child's data and to tax information. This request was rejected by the data controller. In addition, the data controller had violated an… GREECE · ·Art. 15, 58 Mar 20, 2020
€5,800 Unknown Company: Insufficient fulfilment of data subjects rights The data controller has not complied with its obligation regarding the right of access to video recordings and was also unable to demonstrate that his data processing activities… HUNGARY · ·Art. 6, 15 Mar 19, 2020
€6,000 Oliveros Ustrell, S.L.: Insufficient legal basis for data processing The company forwarded an unsigned porting contract to the operator Vodafone. However, the data controller was unable to provide evidence of the order. For this reason, the… SPAIN · ·Art. 5, 6 Mar 19, 2020
€525,000 Royal Dutch Tennis Association ('KNLTB'): Insufficient legal basis for data processing The Dutch Data Protection Authority has fined the Royal Dutch Tennis Association ('KNLTB') with EUR 525,000 for selling the personal data of more than 350,000 of its members to… THE NETHERLANDS · ·Art. 5, 6 Mar 3, 2020
€2,500 Grupo Valsor Y Losan, S.L.: Insufficient technical and organisational measures to ensure information security The controller had disclosed personal data to a third party in a property purchase agreement (breach of principles of integrity and confidentiality of personal data) SPAIN · ·Art. 5 Feb 14, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Jan 1, 2020
€7,000 GERMANY DPA: Insufficient cooperation with supervisory authority The Bavarian DPA has imposed a fine on a company. The controller had refused access to the business premises and data processing equipment during an on-site inspection carried out… Art. 58 ·Insufficient cooperation with supervisory authority Jan 1, 2020