Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2051–2100 of 2,273 sort newestlargest fineoldest
€4,000 De Vere Spain S.L.: Insufficient fulfilment of data subjects rights The company did not respond to the data subject's request to stop processing his or her data, and therefore data subject continued to receive commercial calls. aepd ·Art. 21 ·Insufficient fulfilment of data subjects rights Personal Data Processing Supervisory Authorities Jul 2, 2020
€24,000 Iberdrola Clientes: Non-compliance with general data processing principles A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Security Jul 2, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK ·Datatilsynet ·Art. 5, 6, 33 +1 Data Breaches Personal Data Public Authority Jun 30, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Insurance Healthcare Security Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE ·HDPA ·Art. 5 Personal Data Education IP Address Jun 29, 2020
€13,500 Department of Home Affairs: Insufficient fulfilment of data subjects rights Fines for failure to comply with the right of access to personal data under Articles 12 and 15 GDPR. The Isle of Man has declared the GDPR - although it is not an EU state - to be… ISLE OF MAN ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Right of Access Procedures Right of Access Fines Jun 25, 2020
€7,500 Miraclia (telecommunications company): Insufficient legal basis for data processing The recording of telephone jokes via an app constitutes processing of personal data in accordance with the applicable data protection law, as the voices of individuals may… SPAIN ·aepd ·Art. 5, 6 Consent Personal Data Telecommunications Jun 23, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY ·Datatilsynet ·Art. 32 Health Data Healthcare Healthcare Jun 22, 2020
€10,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The company sent an e-mail to the person concerned without his consent. Thereupon the person concerned requested timely information about the entries in the database concerning… APD ·Art. 5, 6, 15 ·Insufficient fulfilment of data subjects rights Personal Data Consent Processing Agreement Jun 19, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Processing Jun 18, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 16, 2020
€1,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The data subject repeatedly received e-mails with advertising content from a company, although the data subject had objected to the processing of his personal data and requested… APD ·Art. 17, 21, 31 ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Processing Agreement Jun 16, 2020
€75,000 Xfera Moviles S.A.: Insufficient legal basis for data processing The data subject received a notice from a debt collection company demanding payments in connection with Xfera Móviles' services, even though the claimant had not been a customer… SPAIN ·aepd ·Art. 6 Personal Data Consent Telecommunications Jun 15, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Telecommunications Jun 11, 2020
€4,010 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 4,010 on a legal person. The order was issued based on the carried out inspection. The accused failed to respond to numerous requests to… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Jun 11, 2020
€2,000 Attorney: Insufficient technical and organisational measures to ensure information security In the course of proceedings, an attorney submitted documents whose backs contained personal data of other parties. SPAIN ·aepd ·Art. 32 Security Personal Data Insurance Jun 9, 2020
€5,000 Consulting de Seguridad e Investigacion Mira Dp Madrid S.L.: Insufficient legal basis for data processing A data subject has received marketing messages without having consented. SPAIN ·aepd ·Art. 5, 6 Insurance Direct Marketing Personal Data Jun 9, 2020
€39,000 Xfera Moviles S.A.: Insufficient legal basis for data processing A customer claimed to have received an SMS from Xfera Móviles informing about the non-payment and the resulting suspension of the service in relation to the account of another… SPAIN ·aepd ·Art. 5 Personal Data Telecommunications Processing Jun 9, 2020
€25,000 Glovoapp23: Insufficient involvement of data protection officer The company had not appointed a Data Protection Officer ('DPO') to whom requests from data subjects could be addressed, and the company's website did not contain information about… SPAIN ·aepd ·Art. 37 Supervisory Authorities Personal Data Jun 9, 2020
€75,000 Equifax Iberica, S.L.: Insufficient fulfilment of data subjects rights The Data Subject has requested by e-mail the deletion of his data from the file of the National Association of Financial Credit Institutions ('ASNEF'). Equifax Iberica had replied… SPAIN ·aepd ·Art. 15 Personal Data Insurance Supervisory Authorities Jun 9, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN ·aepd ·Art. 6 Personal Data Representatives Telecommunications Jun 9, 2020
€1,168 Entrepreneur running a non-public nursery and pre-school: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. POLAND ·UODO ·Art. 31, 58 Data Breaches Supervisory Authorities Supervision Jun 3, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6, 35 Video Surveillance DPIA Privacy Impact Assessment May 29, 2020
€1,000 Non-profit organisation: Insufficient fulfilment of data subjects rights The Belgian data protection authority has imposed a fine of EUR 1000 on a non-profit organisation for sending out direct marketing messages, despite the fact that data subjects… BELGIUM ·APD ·Art. 6, 21 Right to Object Right to be Forgotten Legitimate Interest May 29, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Insurance Personal Data May 26, 2020
€100,000 Posti Group Oyj: Insufficient fulfilment of data subjects rights The decision relates to complaints alleging that data subjects received direct marketing from the company although they had requested that their postal data be deleted.… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 13, 14 +1 Direct Marketing Personal Data Marketing May 22, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Education Public Authority May 17, 2020
€6,700 JobTeam A/S DKK: Insufficient fulfilment of data subjects rights The company has deleted personal data affected by a request for access without legal reason. DENMARK ·Datatilsynet ·Art. 15 Personal Data Employees Supervisory Authorities May 15, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·Art. 5, 6 ·Insufficient legal basis for data processing Healthcare Personal Data Healthcare May 12, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Personal Data May 5, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS ·AP ·Art. 5, 9 Consent Biometric Data Personal Data Apr 30, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 29, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM ·APD ·Art. 31, 37, 58 Notified Body Responsibilities and Operational Obligations Supervisory Authorities Scientific Panel Independence Apr 28, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Accuracy Security Telecommunications Apr 23, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ANSPDCP ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Personal Data Healthcare Health Data Apr 23, 2020
€2,890 Bank: Insufficient legal basis for data processing Due to an administrative error, the personal data of the data subject were registered and transferred to the Central Credit Information System (CCI) in connection with a loan… HUNGARY ·NAIH ·Art. 5, 6 Personal Data Insurance Processing Mar 26, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company did not provide the data protection authority with the requested information in a timely manner. The AEPD's request was preceded by a request from a data subject for… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Personal Data Mar 25, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Telecommunications Security Personal Data Mar 25, 2020
€3,000 Dante International: Insufficient legal basis for data processing The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. ROMANIA ·ANSPDCP ·Art. 6, 21 Personal Data Processing Supervisory Authorities Mar 25, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Mar 25, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Law Enforcement Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS ·AP ·Art. 9, 32 Healthcare Health Data Access Controls Mar 24, 2020
€8,000 Speech and Special Education Centre - Mihou Dimitra: Insufficient fulfilment of data subjects rights The complainant had requested access to his child's data and to tax information. This request was rejected by the data controller. In addition, the data controller had violated an… GREECE ·HDPA ·Art. 15, 58 Healthcare Controllers Personal Data Mar 20, 2020
€6,000 Oliveros Ustrell, S.L.: Insufficient legal basis for data processing The company forwarded an unsigned porting contract to the operator Vodafone. However, the data controller was unable to provide evidence of the order. For this reason, the… SPAIN ·aepd ·Art. 5, 6 Controllers Personal Data Processing Mar 19, 2020
€5,800 Unknown Company: Insufficient fulfilment of data subjects rights The data controller has not complied with its obligation regarding the right of access to video recordings and was also unable to demonstrate that his data processing activities… HUNGARY ·NAIH ·Art. 6, 15 Right of Access Right of Access Procedures Controllers Mar 19, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN ·aepd ·Art. 58 Right of Access Procedures Inspection Access Rights and Cooperation Obligations Right of Access Mar 18, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Mar 16, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA ·azop ·Art. 15 Right of Access Procedures Right of Access Personal Data Mar 13, 2020
€5M Google LLC: Insufficient fulfilment of data subjects rights Original Fine Summary: The Swedish data protection authority has fined Google LLC € 7 million for failing to adequately comply with its obligations regarding the right of data… SWEDEN ·Art. 5, 6, 17 ·Insufficient fulfilment of data subjects rights Personal Data Telecommunications Supervisory Authorities Mar 11, 2020
€7,000 Hørsholm Municipality: Insufficient technical and organisational measures to ensure information security A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and… DENMARK ·Datatilsynet ·Art. 5, 32 Security Personal Data Public Authority Mar 10, 2020