Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1951–2000 of 2,403 sort newestlargest fineoldest
€12,000 Avilon Center 2016 S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 20,000 on Avilon Center 2016 S.L. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·AEPD ·Art. 21, 23, 48 Direct Marketing Personal Data Controllers Feb 24, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Supervisory Authorities Feb 23, 2021
Deutsche Wohnen SE: Non-compliance with general data processing principles Originally, a fine in the amount of EUR 14.500.000 was issued against Deutsche Wohnen SE for using an archiving system for the storage of personal data of tenants that, according… GERMANY ·Art. 5, 25 ·Non-compliance with general data processing principles Personal Data Controllers Processing Feb 23, 2021
Security company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A data controller using the services of the security company reported the breach of personal data to the DPA, arising after an employee of the security company recorded the video… CROATIA ·AZOP ·Art. 32 Security Controllers Processors Feb 22, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet (DK) ·Art. 5 Storage Limitation Fines Personal Data Feb 12, 2021
€120,000 Vodafone España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A former customer had received e-mails containing electronic bills even after he had terminated his… SPAIN ·AEPD ·Art. 5, 6 Personal Data Controllers Processing Feb 12, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Controllers Personal Data Feb 11, 2021
€5,000 Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da Pietrelcina: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Foundation for Religion and Worship 'Casa sollievo della sofferenza' Opera di San Pio da Pietrelcina. On January… ITALY ·Garante ·Art. 5, 9 Data Breaches Notification Obligation Personal Data Feb 11, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Integrity and Confidentiality Principle Privacy by Design & Default Security Feb 11, 2021
€24,000 Vamavi Phone S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Vamavi Phone S.L.. The data subject had received an advertising call from the controller made on behalf of Vodafone España,… SPAIN ·AEPD ·Art. 21, 23, 28 +1 Direct Marketing Personal Data Controllers Feb 11, 2021
€440,000 OLVG: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) imposed a fine of EUR 440,000 on the Amsterdam hospital OLVG. The controller had taken insufficient measures between 2018 and 2020 to prevent access by… THE NETHERLANDS ·AP ·Art. 32 Security Controllers Personal Data Feb 11, 2021
€1,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine of EUR 1,000 on ING Bank N.V. Amsterdam - Bucharest Branch. It was found that the controller had sent files to a contractual partner in… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data Feb 10, 2021
€65,000 Lursoft IT SIA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined Lursoft IT SIA EUR 65,000 for the illegal processing of personal data by publishing documents containing personal data on its website 'www.lursoft.lv'.… LATVIA ·DSI ·Art. 6 Personal Data Controllers Processing Feb 9, 2021
€3,000 Patio Ancestral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on Patio Ancestral S.L.. The complainant worked for a construction company and had carried out some renovation work for the… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Liability Feb 8, 2021
€5,000 Private Person: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 5,000 for illegal camera surveillance. The data subject had rented two rooms in the apartment of the controller. The… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Security Feb 8, 2021
€12,000 Orthodontic Clinic: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined an orthodontic clinic EUR 12,000. The web form that new patients used to sign up contained mandatory fields for all sorts of patient personal data.… THE NETHERLANDS ·AP ·Art. 32 Encryption Security Personal Data Feb 4, 2021
€19,300 Cyberbook AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Cyberbook AS NOK 200,000 (EUR 19,300) for the illegal automatic forwarding of e-mails from a former employee. The forwarding took place for… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Processing Employees Feb 3, 2021
€100,000 Iberdrola Clientes: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 100,000 on Iberdrola Clientes, SAU. The data subject had terminated an existing contract with the controller due to a move and… SPAIN ·AEPD ·Art. 5, 17 Personal Data Controllers Supervisory Authorities Feb 3, 2021
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Supervisory Authorities Feb 2, 2021
€80 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 80 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Supervisory Authorities Feb 1, 2021
€24,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Xfera Móviles S.A.. The data subject claimed a violation of its right to information to the AEPD. The AEPD then issued a… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Personal Data Feb 1, 2021
€3,000 IDFINANCE Spain, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on IDFINANCE Spain S.L.. A person had received a debt collection email from IDFinance that contained a link for the payment of… AEPD ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Personal Data Controllers Security Feb 1, 2021
€50,000 Azienda USL della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 50,000 on Azienda USL della Romagna. Upon her arrival at the gynecology unit of a hospital operated by the controller (for the… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Personal Data Controllers Jan 27, 2021
€75,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities Jan 27, 2021
€50,000 Family Service / N.D.P.K. nv.: Insufficient legal basis for data processing The Belgian DPA imposed a fine of EUR 50,000 on Family Service / N.D.P.K. nv. The controller is an advertising agency that, among other things, sends expectant mothers gift boxes… BELGIUM ·APD/GBA ·Art. 5, 6, 7 +4 Personal Data Controllers Consent Jan 27, 2021
€150,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Personal Data Jan 27, 2021
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Types of Special Categories of Personal Data Jan 27, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Jan 27, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY ·Garante ·Art. 5, 9 Healthcare Personal Data Types of Special Categories of Personal Data Jan 27, 2021
€25,000 BELGIUM DPA: Insufficient technical and organisational measures to ensure information security The Belgian DPA fined a mobile operator EUR 25,000. The controller had assigned the data subject's phone number to an unauthorized third party, causing the data subject to lose… APD/GBA ·Art. 5, 24, 32 +2 ·Insufficient technical and organisational measures to ensure information security Supervisory Authorities Personal Data Security Jan 22, 2021
€50,000 Alterna Operador Integral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 50,000 on Alterna Operador Integral S.L.. A switch of the electricity supplier had taken place without the consent of the data… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jan 21, 2021
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 75,000 on Telefónica Móviles España, SAU. The controller had assigned five telephone lines with five numbers to the data subject as… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Jan 21, 2021
€1,200 Individual: Non-compliance with general data processing principles The controller installed cameras on his building, which were directed towards parts of the public space. However, no recording took place, as the cameras only served as a… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Jan 20, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent unsolicited commercial communications to the complainant and failed to respond to their repeated… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jan 19, 2021
€9,700 Aquateknikk AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Aquateknikk AS NOK 100,000 (EUR 9,700). The controller had carried out a credit rating on an individual without there being a customer… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Controllers Processing Jan 19, 2021
€4,600 Anwara Sp. z.o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) fined the company Anwara Sp. z.o.o. EUR 4,600. The controller had not cooperated with the DPA and had not provided it with all the information necessary for… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Jan 15, 2021
€30,000 Azienda sanitaria provinciale di Enna: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 30,000 on Azienda sanitaria provinciale di Enna. The controller processed biometric data of employees for the purpose of… ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Controllers Personal Data Jan 14, 2021
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY ·Garante ·Art. 5, 32 Security Controllers Personal Data Jan 14, 2021
€2,000 Poliambulatorio Talenti S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) fined Poliambulatorio Talenti S.r.l. EUR 2,000 for failing to respond to the data subject's request for access to his and his daughters' data in a timely… ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Healthcare Jan 14, 2021
€2M Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Caixabank S.A. EUR 6,000,000 for violations of Art. 6 GDPR, Art. 13 GDPR and Art. 14 GDPR. Customers of the bank were supposed to accept new privacy… SPAIN ·AEPD ·Art. 6, 13, 14 Legitimate Interest Personal Data Controllers Jan 13, 2021
€10,000 BELGIUM DPA: Insufficient legal basis for data processing Managing a fan page on Facebook without the data subject's permission and failing to comply with the data subject's request after exercising his or her right to object. APD/GBA ·Art. 6, 12, 21 ·Insufficient legal basis for data processing Supervisory Authorities Right to Object Personal Data Jan 12, 2021
€30,000 Enea S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information… POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 11, 2021
€19,000 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of EUR 19,000 on a hospital operator. A former employee had unlawfully copied the personal data of 100 patients from the hospital's computer… UODO ·Art. 34, 58 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Supervisory Authorities Jan 5, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 5, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Jan 4, 2021
€118,500 CZECH REPUBLIC DPA: Insufficient legal basis for data processing The Czech DPA (UOOU) fined 11 companies a total of EUR 118,500 for sending unrequested postal advertising messages to the mailboxes of various citizens. Based on a decision by the… ÚOOÚ (CZ) ·Art. 6, 14 ·Insufficient legal basis for data processing Supervisory Authorities Personal Data Direct Marketing Jan 4, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out four credit checks on the data… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Consent Jan 4, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Public Authority Personal Data Supervisory Authorities Jan 1, 2021
€5,000 Private individual: Insufficient legal basis for data processing The DPA of Hamburg imposed a fine of EUR 5,000 on a private individual. The individual had filmed numerous young women in public. Some of the recorded female persons were… GERMANY ·HmbBfDI ·Art. 5, 6 Consent Personal Data Processing Jan 1, 2021
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. A restaurant employee obtained first names, last… Unknown Supervisory Authorities Personal Data Healthcare Jan 1, 2021