Skip to content
Content type · 2,802 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1951–2000 of 2,802 sort newestlargest fineoldest
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Privacy Impact Assessment Health Data Apr 7, 2022
€15,000 Rebirth s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Rebirth s.r.l. EUR 15,000. The controller had installed 14 surveillance cameras in a café it operated without, however, informing about the video… ITALY ·Garante ·Art. 5, 13, 114 +1 Video Surveillance Monitoring Controllers Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Video Surveillance Integrity and Confidentiality Principle IP Address Apr 7, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Storage Limitation Security Apr 7, 2022
€20,000 Made in Italy s.r.l.s.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on Made in Italy s.r.l.s.. A data subject had filed a complaint with the DPA after receiving promotional calls from the… Garante ·Art. 6, 7, 15 +5 ·Insufficient legal basis for data processing Controllers Personal Data Direct Marketing Apr 7, 2022
€50,000 Palumbo Superyacht Ancona s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Palumbo Superyacht Ancona s.r.l. EUR 50,000. The company had blocked an employee's company email account without permission. The employee had reported… ITALY ·Garante ·Art. 5, 12, 13 +3 Storage Limitation IP Address Employees Apr 7, 2022
€500 Property owners' association: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined a property owners' association EUR 500 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Apr 7, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY ·Garante ·Art. 28 Processing Agreement IP Address Data Processor Apr 7, 2022
€1.3M Danske Bank: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 1.3 million on Danske Bank. The DPA had opened an investigation against the bank after it informed the DPA that it had a problem with the… DENMARK ·Datatilsynet ·Art. 5 Accountability IP Address Processing Agreement Apr 5, 2022
€463,000 Bank of Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined the Bank of Ireland EUR 463,000. The bank had reported 22 data breaches to the DPA under Article 33 GDPR. As part of its investigation, the DPA found that… Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Apr 5, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM ·APD ·Art. 5, 6, 9 Health Data Healthcare Archiving Apr 4, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data DPIA Healthcare Apr 4, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Data Breaches Integrity and Confidentiality Principle Accuracy Apr 4, 2022
€5,000 Mayor: Insufficient legal basis for data processing The Hellenic DPA has fined a mayor EUR 5,000. The mayor had sent documents of an employee of the municipality to third parties without the employee's consent. The DPA considered… GREECE ·HDPA ·Art. 5 IP Address Employees Consent Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data DPIA Healthcare Apr 4, 2022
€7,500 Company: Insufficient fulfilment of data subjects rights The Belgian DPA has imposed a fine of EUR 7,500 on a company. A former managing director had filed a complaint against the company with the DPA. In the context of being dismissed,… BELGIUM ·APD ·Art. 5, 6, 15 +4 Personal Data IP Address Employees Apr 1, 2022
€1,300 Workshop: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,300 on a workshop. The workshop had installed a video surveillance system to protect the company's assets. However, the cameras also… HUNGARY ·NAIH ·Art. 5, 6, 13 Video Surveillance Monitoring Legitimate Interest Mar 29, 2022
€2,000 Condor SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Mar 28, 2022
€720,000 Klarna Bank AB: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 720,000 on Klarna Bank AB. Klarna is a financial company that processes a large number of personal data in various ways. As part of its… SWEDEN ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Processing Agreement Personal Data IP Address Mar 28, 2022
€2,000 Kaufland Romania SCS: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland Romania SCS. A data subject had filed a complaint with the DPA concerning the controller's failure to comply with… ANSPDCP ·Art. 15 ·Insufficient fulfilment of data subjects rights Video Surveillance Monitoring Controllers Mar 25, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK ·Datatilsynet ·Art. 36 DPIA Privacy Impact Assessment Security Mar 25, 2022
€10,000 Brav s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Brav s.r.l.. The operator of the online platform had reported a data breach to the DPA pursuant to Art. 33 GDPR. Unauthorized… ITALY ·Garante ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Security Mar 24, 2022
€490 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 490 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Mar 23, 2022
€4,000 English School Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email… Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 22, 2022
€5,000 English School staff union (ESSA): Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 21, 2022
€9,700 Company: Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact… NORWAY ·Datatilsynet ·Art. 6, 13, 21 Right to Object Controllers Employees Mar 15, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… Art. 5, 24 Social Media Telecommunications Data Breaches Mar 15, 2022
€2,000 Operatorul Briza Land S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has fined Operatorul Briza Land S.R.L. EUR 2,000. The controller failed to properly respond to a request for information. ROMANIA ·ANSPDCP ·Art. 15 Controllers Personal Data Supervisory Authorities Mar 10, 2022
€10,000 Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 10,000 on Alfa Shipyard s.r.l.. The controller had failed to implement measures ordered by the DPA in due time. ITALY ·Garante ·Art. 58 Supervisory Authorities Supervision Controllers Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare Health Data Mar 10, 2022
€8,000 Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo: Insufficient legal basis for data processing The Italian DPA (Garante) has fined the Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo EUR 8,000. A former employee of the environmental agency had filed a complaint… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Processing Employees Mar 10, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Data Breaches Encryption Notification Obligation Mar 10, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Garante ·Art. 2, 5, 6 +3 Healthcare Personal Data Controllers Mar 10, 2022
€2,000 Foreign language school: Insufficient fulfilment of data subjects rights The Hellenic DPA imposed a fine of EUR 2,000 on an employer (owner of a private foreign language school). An employee, who works as a language teacher in the school, had filed a… GREECE ·HDPA ·Art. 5, 13 Right to Object Education Personal Data Mar 9, 2022
€2,000 Employer: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 2,000 on an employer. An employee had filed a complaint due to the employer's failure to comply with the employee's right to object. The… GREECE ·HDPA ·Art. 5, 13 Right to Object Audit Logs Monitoring Mar 9, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·azop ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 8, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·azop ·Art. 15 Video Surveillance Personal Data Accuracy Mar 8, 2022
€7,000 Hörpu tónlistar- og ráðstefnuhúss ohf.: Non-compliance with general data processing principles The Icelandic DPA has fined Hörpu tónlistar- og ráðstefnuhúss ohf. EUR 7,000. The DPA had received a complaint regarding the concert hall's collection of ID number and date of… ICELAND ·Art. 5, 6 ·Non-compliance with general data processing principles IP Address Personal Data Monitoring Mar 8, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Security Access Controls Mar 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Controllers Healthcare Mar 3, 2022
€13,500 Company: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 13,500 on a company. An individual had filed a complaint with the DPA, stating that the company had published personal data such as their… HUNGARY ·NAIH ·Art. 5, 6, 12 +1 Personal Data Processing Agreement Consent Mar 2, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Public Authority Public Sector Feb 24, 2022
€1,200 FRUTAS Y VERDURAS LOS CAMPEONES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,000 on FRUTAS Y VERDURAS LOS CAMPEONES, S.L.. The controller had installed a video surveillance system, however, without having… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Feb 23, 2022
€1,500 WORLDWIDE CLASSIC CARS NETWORK S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on WORLDWIDE CLASSIC CARS NETWORK S.L.. The controller had installed video surveillance cameras which, among other things,… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Monitoring Feb 23, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Agreement Feb 22, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA ·ANSPDCP ·Art. 12, 13, 21 Personal Data Video Surveillance Controllers Feb 22, 2022
€3,000 Hotel operator: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a hotel operator. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Monitoring IP Address Feb 22, 2022
€1,000 MALAGATROM, S.L.U.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on MALAGATROM, S.L.U. for failing to comply with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Feb 22, 2022
€1,000 Store owner: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined a store owner EUR 1,000 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Supervisory Authorities Feb 21, 2022
€1,500 RESTATURANTE FUENTEBRO, S.C.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined RESTATURANTE FUENTEBRO, S.C. EUR 1,500 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Supervisory Authorities Feb 21, 2022