Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2001–2050 of 2,403 sort newestlargest fineoldest
€12,500 Energy supplier: €12,500 fine The DPA of Hamburg has imposed a fine of EUR 12,5000 on an energy supplier. The company had outsourced and sold its heating energy division. Customers affected by the transfer… GERMANY ·HmbBfDI ·Unknown Right to Object Personal Data International Transfer Jan 1, 2021
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a cemetery had put out an open list in which visitors had to enter their contact data. A cemetery employee obtained first names, last… Unknown Supervisory Authorities Public Authority Personal Data Jan 1, 2021
Real estate agent: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a fine on a real estate agent. The real estate agent had contacted an individual and offered him to sell a property he owned. Since the… GERMANY ·Art. 6, 12 ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Data Subject Rights Exercise Modalities and Procedures Jan 1, 2021
€400 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes. The officer had purchased a notebook for private use on an Internet platform. Since the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Scientific Research Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer used a witness's personal data to contact her personally. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2021
Gym owner: Data Protection Authority of Saxony The owner of a gym had apologized for the late opening of the gym, but at the same time shifted the responsibility to an employee who was named. As a result, their personal data… GERMANY ·Unknown Supervisory Authorities Personal Data Employees Jan 1, 2021
Attorney: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on an attorney. The attorney had been in dispute with a client for several years over a monetary claim. For two years, he published the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Insurance Jan 1, 2021
Clinic: Insufficient involvement of data protection officer The DPA from Berlin has imposed a fine on a clinic. The clinic had appointed the clinic manager, who was also a shareholder of the clinic, as the data protection officer. A data… GERMANY ·Insufficient involvement of data protection officer Supervisory Authorities Notified Body Independence Scientific Panel Independence Jan 1, 2021
€12,500 Energy supplier: €12,500 fine The DPA of Hamburg has imposed a fine of EUR 12,5000 on an energy supplier. The company had outsourced and sold its heating energy division. Customers affected by the transfer… GERMANY ·HmbBfDI ·Unknown Right to Object Personal Data International Transfer Jan 1, 2021
€4M Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… AUSTRIA ·DSB ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 1, 2021
€600 Private individual: Non-compliance with general data processing principles The Austrian DPA imposed a fine of EUR 600 on a private individual. The individual had contacted a public institution to draw their attention to the fact that the statement of a… AUSTRIA ·DSB ·Art. 5, 9 Integrity and Confidentiality Principle Personal Data Healthcare Jan 1, 2021
€3,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) fined ING Bank N.V. Amsterdam - Bucharest office in the amount of EUR 3,000. The bank had contacted the data subject by e-mail for the purpose of… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Consent Dec 30, 2020
€1,000 Qualitance QBS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Qualitance QBS SA EUR 1,000 for a violation of Art. 32 GDPR. The company had sent information by email to 295 individuals, disclosing the email… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Dec 29, 2020
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 28, 2020
€15,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 15,000 on a company due to insufficient fulfilment of data subject rights. The controller is a debt collection agency which was… APD/GBA ·Art. 5, 6, 12 +2 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers Dec 23, 2020
€50,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 50,000 on a company for several violations of the GDPR. The controller is a company that carries out parking ticket controls. The… APD/GBA ·Art. 5, 12, 14 +2 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers Dec 23, 2020
€2,000 S.C. C&V Water Control S.A.: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) fined S.C. C&V Water Control S.A. EUR 2,000 for failure to comply with the data protection authority's request for information in the course of an… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Dec 22, 2020
€6,000 Iberdrola Clientes, SAU: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) fined Iberdrola Clientes, SAU EUR 6,000. The data subject had received promotional calls from two different telephone numbers of the controller although the… SPAIN ·AEPD ·Art. 21, 23, 48 Direct Marketing Personal Data Controllers Dec 22, 2020
€36,000 Banco Bilbao Vizcaya Argentaria, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Dec 21, 2020
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives Personal Data Supervision Dec 20, 2020
€200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 200 on a legal person. The accused sent the data subject, despite his objection and therefore his disagreement with further processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Direct Marketing Dec 18, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Personal Data Controllers Dec 17, 2020
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·DPC ·Art. 5, 32, 33 Data Breaches Notification Obligation Security Dec 17, 2020
€3,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 3,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data as MRI and X-ray images as well as… FRANCE ·CNIL ·Art. 32, 33 Security Controllers Personal Data Dec 17, 2020
€6,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well… FRANCE ·CNIL ·Art. 32, 33 Security Controllers Personal Data Dec 17, 2020
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… UODO ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Controllers Processing Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Storage Limitation Retention Period Controllers Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Dec 17, 2020
€55,400 Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) imposed a fine of HUF 20,500,000 (EUR 55,400) on Robinson Tours Idegenforgalmi és Szolgáltató Kft. (Robinson Tours Ltd.) The travel agent's reservation… HUNGARY ·NAIH ·Art. 25, 32, 34 Data Breaches Security Personal Data Dec 16, 2020
€1,385 Next Time Media Agency Ltd. (Next Time Media Ügynökség Kft.): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) imposed a fine of HUF 50,000 (EUR 1,385) on Next Time Media Ügynökség Kft. (Next Time Media Agency Ltd.). The web agency had been contracted by the travel… HUNGARY ·NAIH ·Art. 32 Security Personal Data Privacy by Design & Default Dec 16, 2020
€1,940 HUNGARY DPA: Insufficient fulfilment of information obligations The Hungarian DPA (NAIH) imposed a fine of HUF 700,000 (EUR 1,940) against a construction company. The controller had installed a video surveillance system at a construction site… NAIH ·Art. 5, 13 ·Insufficient fulfilment of information obligations Supervisory Authorities Integrity and Confidentiality Principle Controllers Dec 16, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… NAIH ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Supervisory Authorities Retention Period Personal Data Dec 16, 2020
€6,250 LATVIA DPA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined an employer EUR 6,250 for sending personal data of an employee, including health data, to fellow employees by email. The DSI found that the data… DSI ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Types of Special Categories of Personal Data Processing Dec 15, 2020
€10,000 Online Services: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined the operator of the online store banderacatalana.cat. EUR 10,000 for a violation of Art. 13 GDPR. The operator stated on its website privacy notices… SPAIN ·AEPD ·Art. 6, 8, 13 Personal Data Consent Supervisory Authorities Dec 15, 2020
€443,000 Virgin Mobile Polska: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Virgin Mobile Polska EUR 443,000 due to a data leak that allowed unauthorized third parties to access personal data stored by Virgin Mobile Polska as a… POLAND ·UODO ·Art. 5, 25, 32 Security Personal Data Telecommunications Dec 14, 2020
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Dec 11, 2020
€5M Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Banco Bilbao Vizcaya Argentaria, S.A. EUR 5,000,000 for violating Art. 6 GDPR (EUR 3,000,000) and Art. 13 GDPR (EUR 2,000,000). The bank had not… SPAIN ·AEPD ·Art. 6, 13 Personal Data Consent Supervisory Authorities Dec 11, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·IMY ·Art. 5, 32 Encryption Security Controllers Dec 11, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY ·NAIH ·Art. 5, 6, 9 +2 Controllers Personal Data Processing Dec 10, 2020
€4,000 Borjamotor, S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 4,000 on Borjamotor, S.A. The company kept sending commercial advertisements to the data subject via email and SMS, even though the… SPAIN ·AEPD ·Art. 7 Consent Personal Data Processing Dec 10, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 10, 2020
€2,850 Smart Cities Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the Polish DPA (UODO). The controller failed to provide personal data and other information requested by UODO for investigative… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Dec 9, 2020
€40,000 Xfera Moviles S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Xfera Móviles, S.A. due to insufficient legal basis for data processing. The data subject states that two telephone and internet… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Dec 9, 2020
€10,000 SPAIN DPA: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of 10,000 EUR on a company for violating Art. 5 GDPR. The company sent an e-mail to a third party with the dismissal and settlement document… AEPD ·Art. 5 ·Non-compliance with general data processing principles Personal Data Processing Supervisory Authorities Dec 9, 2020
€18,850 TUiR Warta S.A.: Insufficient fulfilment of data breach notification obligations An insurance agent hired by the controller had sent an email to unauthorized third parties in regard to insurance policies that contained personal data of two of the company's… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 9, 2020
€35M CNIL · SAN-2020-013 Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating… France ·Art. 6, 9, 83 +1 Telecommunications Personal Data Supervisory Authorities Dec 7, 2020