Skip to content
Content type · 2,035 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2001–2035 of 2,035 sort newestlargest fineoldest
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2020
Ski rental company: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 7 +9 Personal Data Controllers Consent Jan 1, 2020
€1,900 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights A person had received an invoice for ordered goods, which, however, came from a different company than the one from which she had ordered the goods. Therefore, the data subject… ÚOOÚ (CZ) ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Jan 1, 2020
€8,000 LITHUANIA DPA: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) fined a company EUR 8,000 for conducting sound recordings on public transport buses in violation of Article 5 GDPR, Article 13 GDPR, Article 24 GDPR and… VDAI ·Art. 5, 13, 24 +1 ·Non-compliance with general data processing principles Supervisory Authorities DPIA Accountability Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Fairness & Transparency Jan 1, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jan 1, 2020
The complainant belongs to a political party and is a member of the city council of an Austrian municipality In November, the municipality held a meeting on the "parking space concept", to which a certain group of addressees, including the complainant, was invited. The complainant did… DSB-D123.768/0004-DSB/201 ·Austria ·DSB Public Authority Pseudonymization Anonymization Dec 18, 2019
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM ·APD/GBA ·Art. 6, 12, 13 Personal Data Fairness & Transparency IP Address Dec 17, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Controllers Nov 25, 2019
€16M Austrian Post: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 16,000,000 on the Austrian Post. The controller had sold information regarding the political affinity to third parties without a… AUSTRIA ·DSB ·Art. 5, 6 Controllers Processing Supervisory Authorities Oct 29, 2019
€2,500 UTTIS INDUSTRIES SRL: Insufficient fulfilment of information obligations The sanctions were applied to the controller because he could not prove that the data subjects were informed about the processing of personal data / images through the video… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Controllers Processing Oct 17, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Legitimate Interest Public Authority Sep 3, 2019
€150,000 PWC Business Solutions: Insufficient legal basis for data processing The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to… GREECE ·HDPA ·Art. 5, 6, 13 +1 Legitimate Interest Controllers Personal Data Jul 30, 2019
€2,850 Financial Enterprise: Insufficient legal basis for data processing A client of a financial enterprise complained that the financial enterprise transferred his data after he objected against the processing and did not provide information on the… HUNGARY ·NAIH ·Art. 5, 6, 21 Legitimate Interest Controllers Processing Jun 26, 2019
€2,850 HUNGARY DPA: Insufficient legal basis for data processing The individual requested the deletion of his contact data (including his telephone number), however the controller further processed his contact data for claim enforcement… NAIH ·Art. 5, 6, 17 ·Insufficient legal basis for data processing Legitimate Interest Personal Data Controllers Jun 26, 2019
€15,150 HUNGARY DPA: Insufficient fulfilment of data breach notification obligations The data controller did not fulfil its data breach notification obligations when a flash memory with personal data was lost. NAIH ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 25, 2019
€2,850 Claim management company: Insufficient legal basis for data processing The complainants stated during the case that they concluded a credit agreement with the bank, which sold its claim against the complainants and transferred their respective data… HUNGARY ·NAIH ·Art. 5, 6 Legitimate Interest Controllers Personal Data Jun 3, 2019
€2,000 Local bank: Insufficient fulfilment of data subjects rights Customer of a local bank requested access to telephone conversation recordings as well as to CCTV recordings. The bank provided the copies of the recordings of telephone… HUNGARY ·NAIH ·Art. 12, 15, 18 Personal Data Controllers Insurance May 31, 2019
€92,146 Organizer of SZIGET festival and VOLT festival: Insufficient legal basis for data processing The NAIH found that there were inappropriate legal bases is use and that the controller did not comply with the principle of purpose limitation. Also, information on the data… HUNGARY ·NAIH ·Art. 5, 6, 13 Personal Data Controllers Processing May 23, 2019
€61,500 Payment service provider UAB MisterTango: Insufficient fulfilment of data breach notification obligations During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a… LITHUANIA ·VDAI ·Art. 5, 32, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations May 16, 2019
€12,950 Sports association: Insufficient legal basis for data processing One sports association published personal data referring to judges who were granted judicial licenses online. However, not only their names were provided, but also their exact… POLAND ·UODO ·Art. 6 Personal Data Controllers Liability Apr 25, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Garante ·Art. 32 Controllers Processors Security Apr 17, 2019
€9,400 HUNGARY DPA: Insufficient legal basis for data processing A data controller used a, in the point of view of NAIH, wrong legal basis for processing of personal data (Art. 6.1.b) for the assignment of claims. NAIH ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing Apr 17, 2019
€1,900 HUNGARY DPA: Insufficient fulfilment of data subjects rights The data controller did not fulfil the data subject's access request. NAIH ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Right of Access Apr 5, 2019
€220,000 Private company working with data from publicly available sources: Insufficient fulfilment of information obligations The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the… POLAND ·UODO ·Art. 14 Personal Data Controllers Supervisory Authorities Mar 26, 2019
€1,560 Debt collector: Non-compliance with general data processing principles A data subject requested information about and erasure of the data processed, which the debt collector refused stating that it could not identify the subject. For identification… HUNGARY ·NAIH ·Art. 5 Personal Data Controllers Transparency Feb 20, 2019
€5,000 State Hospital: Insufficient fulfilment of data subjects rights A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Cyprus DPA ·Art. 15 Personal Data Controllers Fines Jan 1, 2019
€500 GERMANY DPA: Insufficient fulfilment of data subjects rights A data controller failed to comply with data subject´s request to access their personal data. Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Jan 1, 2019
€50,000 Unknown Company: Insufficient fulfilment of data subjects rights The data controller had engaged an external company to carry out the duties of access to data according to Art. 15 GDPR. However, the engaged company conducted the correspondence… GERMANY ·Art. 15, 28 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Fairness & Transparency Jan 1, 2019
€14,000 Doctor: Insufficient legal basis for data processing A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Cyprus DPA ·Art. 5, 6 Controllers Processing Healthcare Jan 1, 2019
€2,200 Private person: Insufficient legal basis for data processing The fine was imposed against a private person who was using CCTV at his home. The video surveillance covered areas which are intended for the general use of the residents of the… AUSTRIA ·DSB ·Art. 5, 6, 13 Controllers Consent Processing Dec 20, 2018
€5,000 Kolibri Image Regina und Dirk Maass GbR: Insufficient data processing agreement Please note: According to our information this fine has been withdrawn in the meantime. Kolibri Image had send a request to the Data Protection Authority of Hessen asking how to… GERMANY ·HmbBfDI ·Art. 28 Controllers Processors Processing Dec 17, 2018
Norwegian DPA: Legelisten.no may process healthcare reviews without prior consent Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Norway ·Datatilsynet (NO) Consent Legitimate Interest Supervisory Authorities Nov 8, 2017