Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2051–2100 of 2,403 sort newestlargest fineoldest
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet (NO) ·Art. 6, 32 Personal Data Security Public Authority Dec 3, 2020
€5,000 Asociación de Víctimas por Arbitrariedades Judiciales, (JAVA): Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on the association for publishing the personal data of the data subjects on its website. The data had been unlawfully recorded… SPAIN ·AEPD ·Art. 6 Personal Data Consent Supervisory Authorities Dec 2, 2020
€6,000 Servicio de Alojamientos Responsables, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine in the amount of EUR 6,000 against the controller for unauthorized conclusion of a contract in the name of the data subject without his/her… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Consent Dec 2, 2020
€3,000 Comercio Online Levante, S.L.: Insufficient technical and organisational measures to ensure information security A woman filed a complaint with the Spanish DPA (AEPD) against Comercio Online Levante, S.L. due to the fact that she was shown the personal data of another user when trying to… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Security Dec 2, 2020
€100,000 Südameapteegi e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Consent Personal Data Identification Dec 1, 2020
€800 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 800 on a legal person. The complainant had worked with the accused over the years as an employee, collaborator, author, licensor, and… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Agreement Dec 1, 2020
€100,000 Azeta.ee e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Consent Personal Data Identification Dec 1, 2020
€100,000 Apotheka e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Consent Personal Data Identification Dec 1, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent the subject a commercial offer via SMS after assuring the data subject that their data was… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Processing Agreement Supervisory Authorities Nov 30, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of Eur 2,000 on a legal person. The accused failed to comply with the request to erase the auction notice with the personal data and failed to… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Nov 30, 2020
€1,200 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine in the amount of EUR 1,200 on a private individual for impersonating a third party on the social networks Tinder and WhatsApp by using images… SPAIN ·AEPD ·Art. 5 Personal Data Processing Consent Nov 27, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Garante ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Healthcare Nov 26, 2020
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·AEPD ·Art. 6, 13, 14 Recipient Personal Data Consent Nov 25, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Personal Data Supervisory Authorities Nov 24, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY ·Garante ·Art. 5, 13 Personal Data Supervisory Authorities Processing Nov 23, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Supervisory Authorities Supervision Nov 23, 2020
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis. The company had sent an invoice to a data subject without being able to prove that it had a contract… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Nov 19, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Fairness & Transparency Integrity and Confidentiality Principle Nov 19, 2020
€2,000 Anmavas 61, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Right to be Forgotten Nov 18, 2020
€2.3M Carrefour France: Non-compliance with general data processing principles The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that… CNIL ·Art. 5, 12, 13 +5 ·Non-compliance with general data processing principles Direct Marketing Personal Data International Transfer Nov 18, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… NAIH ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers Processing Nov 18, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY ·Garante ·Art. 9 Personal Data Healthcare Processing Nov 17, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY ·Garante ·Art. 12, 13, 14 Personal Data Supervisory Authorities Public Authority Nov 17, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing In 2019, after an arbitration procedure, the company agreed to the early termination of a contract with the data subject and to the deletion of the personal data concerned.… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Nov 16, 2020
€1.4M Ticketmaster UK Limited: Insufficient technical and organisational measures to ensure information security Ticketmaster UK Limited has been fined GBP 1.25 million (approximately EUR 1.405 million) for failing to protect the personal data of its customers with adequate security… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Personal Data Processing Agreement Nov 13, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY ·Garante ·Art. 5, 6, 7 +7 Direct Marketing Accountability Personal Data Nov 12, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The company ported a telephone number of the data subject without their consent (missing signature on the porting contract). SPAIN ·AEPD ·Art. 5, 6 Consent Personal Data Processing Nov 11, 2020
€900,000 Telecoms provider (1&1 Telecom GmbH): Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's… GERMANY ·BfDI ·Art. 32 Personal Data Controllers Security Nov 11, 2020
€75,000 Telefonica Moviles Espana, S.A.U.: Insufficient legal basis for data processing Processing of personal data of the data subject without sufficient legal basis. The company had issued several invoices to the data subject and collected invoice amounts from his… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Nov 5, 2020
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Controllers Pseudonymization Healthcare Nov 5, 2020
€30,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis due to errors in the correct assignment of customer contracts. In this case, Vodafone demanded a debt… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Nov 3, 2020
€20M Marriott International, Inc: Insufficient technical and organisational measures to ensure information security Original Summary: The ICO issued a notice of its intention to fine Marriott International Inc due to a cyber incident which was notified to the ICO by Marriott in November 2018. A… UNITED KINGDOM ·ICO ·Art. 32 Personal Data Security Fines Oct 30, 2020
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Processing Oct 29, 2020
€20,000 Gaypa s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee's email account active and had access to the data subject's… ITALY ·Garante ·Art. 5, 12, 13 Personal Data Controllers Processing Oct 29, 2020
€1,000 American College of Greece: Insufficient fulfilment of information obligations The Hellenic DPA (HDPA) imposed a fine of EUR 1,000 against the American College of Greece for violations of the right of access and the right to erasure of personal data. HDPA ·Art. 12 ·Insufficient fulfilment of information obligations Personal Data Supervisory Authorities Right to be Forgotten Oct 29, 2020
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis due to errors in the correct assignment of customer contracts. SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Oct 28, 2020
€54,800 Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak: Insufficient fulfilment of data subjects rights The data controller denied the data subject access to the video material recorded by CCTV in a local store, with which the data subject wanted to prove that he or she had not… HUNGARY ·NAIH ·Art. 12, 15, 18 +1 Right of Access Personal Data Controllers Oct 23, 2020
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… Cyprus DPA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Oct 22, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Oct 21, 2020
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company had not provided the ANSPDCP with requested information. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Oct 20, 2020
€1,000 Grant Ideas Ltd: Insufficient legal basis for data processing Sending emails to data subjects without sufficient legal basis. CYPRUS ·Cyprus DPA ·Art. 5, 6 Personal Data Processing Oct 19, 2020
€15,000 Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found… Cyprus DPA ·Art. 5, 15, 32 +1 ·Insufficient technical and organisational measures to ensure information security Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 19, 2020
€30,000 PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Spain ·AEPD ·Art. 22 Consent Personal Data Supervisory Authorities Oct 16, 2020
€22M British Airways: Insufficient technical and organisational measures to ensure information security In July 2019, the ICO issued a notice of its intention to fine British Airways £183.39M for GDPR infringements which likely involve a breach of Art. 32 GDPR. The proposed fine… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Personal Data Oct 16, 2020
€3,000 S.C. Marsorom S.R.L.: Insufficient technical and organisational measures to ensure information security Disclosure of personal data of customers on the companies website due to inadequate technical and organisational measures to ensure information security. ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 15, 2020
€12,030 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 12,030 on a legal person. The accused did not comply with the complainant's request to erase their data. The company implemented an… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 12 Personal Data Supervisory Authorities Storage Limitation Oct 14, 2020
€5,000 Caja Rural San José de Nules S. Cooperativa de Crédito: Non-compliance with general data processing principles The company published information with the names and surnames of its employees, which led to the disclosure of the data subject's financial situation. SPAIN ·AEPD ·Art. 5 Personal Data Processing Employees Oct 9, 2020
€50,000 Centro de Investigación y Estudio para la Obesidad, SL: Insufficient legal basis for data processing Fines for the transfer of the data subject's personal data to Evo Finance EFC, SA in the course of processing a health insurance application, without a sufficient legal basis for… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Insurance Oct 9, 2020
€60,000 Lycamobile: Insufficient legal basis for data processing Fine for processing of personal data without sufficient legal basis due to incorrect information about the owners of prepaid phone cards (mismatch between the registered owners in… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Oct 6, 2020
€4,000 Callesgarcia, S.L.: Insufficient legal basis for data processing Usage of a photo of the data subjects for commercial purposes without sufficient legal basis. SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Oct 6, 2020