Skip to content
Content type · 2,650 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2051–2100 of 2,650 sort newestlargest fineoldest
€6,000 Creator Energy S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on Creator Energy S.L.. The controller had used the personal data of the data subject without his consent to conclude… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 4, 2021
€15,000 PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ: Non-compliance with general data processing principles The Hellenic DPA has fined PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ EUR 15,000 due to the illegal installation and operation of a video surveillance system. The controller had installed a video… GREECE ·HDPA ·Art. 5 Accountability Controllers Transparency Jun 3, 2021
€4,000 Avalos Consultores, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Avalos Consultores, S.L.. The data subject, who was a client of the controller, filed a complaint with the AEPD because… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 2, 2021
€150,000 Azienda Provinciale per i Servizi Sanitari di Trento: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Provinciale per i Servizi Sanitari di Trento EUR 150,000. The controller had accidentally forwarded 293 medical reports of 175 patients… ITALY ·Garante ·Art. 5, 9 Controllers Healthcare Processing May 27, 2021
€2,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 2,000 on a private individual for the unauthorized use of video surveillance cameras, which also recorded parts of public space… SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Monitoring May 27, 2021
€120,000 Azienda Usl della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Usl della Romagna EUR 120,000. The local health authority of Romagna had accidentally transmitted a patient's report regarding an… ITALY ·Garante ·Art. 5, 9 Healthcare Processing International Transfer May 27, 2021
€4,000 Alava Norte, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Alava Norte, S.L. EUR 4,000. The controller had installed three 360° video surveillance cameras on the facade of one of its buildings to secure… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Security May 25, 2021
€6,000 Desolasol Restauración, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Desolasol Restauración S.L. EUR 6,000. The data subject had submitted a consumer complaint form to the restaurant because he was unable to… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing May 25, 2021
€900 Managing Director of a company: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on the managing director of a company. A data subject filed a complaint with the AEPD against the controller with whom he… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities May 25, 2021
€3,000 Physician: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined a physician EUR 3,000. The controller had left his/her former clinic and started working in a new clinic. The complainant had taken over the… SPAIN ·AEPD ·Art. 6 Controllers Healthcare Processing May 21, 2021
€45,000 Telefónica de España, S.A.U: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 75,000 on Telefonica de España, S.A.U.. A data subject had filed a complaint with the AEPD against the telecommunications company.… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications May 21, 2021
€3,000 Homeowners Association: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·AEPD ·Art. 5, 12 Retention Period Processing Supervisory Authorities May 21, 2021
€39,000 Municipality of Oslo: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,000 on the Municipality of Oslo. On a website of the controller a subpoena from the public prosecutor's office… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Public Authority Personal Data Controllers May 20, 2021
€500 Owners Association of Iasi Municipality: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has imposed a fine of EUR 500 on Asociație de Proprietari din municipiul Iași (Owners Association of Iasi Municipality). The controller did not provide… ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Controllers May 19, 2021
€2,000 Banca Comercială Română S.A.: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined Banca Comercială Română S.A. EUR 2,000. A data subject had initiated a complaint with the DPA because the controller had used his personal… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing May 19, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out several credit checks on the data… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Consent May 18, 2021
€10,000 Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato: Insufficient legal basis for data processing The Hellenic DPA has fined the Municipal Organization for Pre-School Education and Social Solidarity (DOPAKA) of the municipality of Tavros Moschato EUR 10,000. The controller had… GREECE ·HDPA ·Art. 6, 12, 17 Public Authority Personal Data Controllers May 17, 2021
€200 Website operator: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on the operator of the website declaratieppr.ro. During the Covid19 pandemic, visitors to the site were able to fill out a… ROMANIA ·ANSPDCP ·Art. 5, 6, 13 +1 Personal Data Controllers Security May 14, 2021
€30,000 Allianz Compañia de Seguros y Reaseguros, S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Allianz Compañia de Seguros y Reaseguros, S.A. EUR 30,000. The controller had sent an invoice to the data subject although no contractual… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance May 14, 2021
€2.9M Iren Mercato S.p.A.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Iren Mercato S.p.A. EUR 2,856,169 for failing to verify that all transfers of data of recipients of promotional activities were covered by consent.… ITALY ·Garante ·Art. 5, 6, 7 Personal Data Controllers Consent May 13, 2021
€20,000 Synlab Med srl: Non-compliance with general data processing principles The Italian DPA has fined Synlab Med srl EUR 20,000. The company conducted Covid-19 tests for various regional health authorities. In this context, the company had inadvertently… ITALY ·Garante ·Art. 2, 5, 9 Healthcare Processing Supervisory Authorities May 13, 2021
€84,000 Comune di Bolzano: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Retention Period Personal Data May 13, 2021
€2,000 Telekom Romania Communications SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Telekom Romania Communications SA. The controller had made an advertising call to the data subject although the… ANSPDCP ·Art. 6, 21 ·Insufficient fulfilment of data subjects rights Personal Data Right to Object Direct Marketing May 13, 2021
€1,900 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,900 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD (LU) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Accountability May 12, 2021
€2,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,600 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers May 12, 2021
€2,400 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,400 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD (LU) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Accountability May 12, 2021
€5,000 A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ: Non-compliance with general data processing principles The Hellenic DPA has fined A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ EUR 5,000. The controller had not responded to requests for information and deletion from the data subject.… GREECE ·HDPA ·Art. 5, 12, 15 +1 Personal Data Controllers Consent May 12, 2021
€1,000 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,000 on a company. The controller had installed a video surveillance system with the purposes of the protection of… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers May 12, 2021
€2,000 World Class România S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on World Class România S.A.. The controller had published the termination letter of an employee in a WhatsApp group used… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Controllers Security May 7, 2021
Disqus Inc.: Insufficient legal basis for data processing On May 5, 2021, the Norwegian DPA (Datatilsynet) announced that it intents to fine Disqus Inc. EUR 2, 500, 000 for violations of Art. 5 (1), (2) GDPR, Art. 6 GDPR, Art. 12 GDPR… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 12 +1 Supervisory Authorities Supervision Processing May 5, 2021
€1.5M EDP Comercializadora, S.A.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing… SPAIN ·AEPD ·Art. 13, 25 Personal Data Controllers Representatives May 4, 2021
€1.5M EDP Energía, S.A.U: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Energía, S.A.U.. The decision follows, in particular, several complaints received for processing personal data… SPAIN ·AEPD ·Art. 13, 25 Personal Data Controllers Representatives May 4, 2021
€2,000 Santa Ninfa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Santa Ninfa municipality. The municipality had published a resolution on its website that contained personal information… ITALY ·Garante ·Art. 2, 5, 6 Public Authority Personal Data Processing Apr 29, 2021
€570 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 570 on a company. In the course of his professional activities, a data subject had made a telephone call to a company on… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Accountability Apr 27, 2021
€1,400 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,400 on a company. In the course of his professional activities, a data subject had made a telephone call to the controller on… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Accountability Apr 27, 2021
€100,000 Financial company: Insufficient technical and organisational measures to ensure information security The Belgian DPA (APD) has imposed a fine of EUR 100,000 on a financial company. A data subject had filed two complaints with the APD against the company. They were based on 20… BELGIUM ·APD/GBA ·Art. 5, 32 Personal Data Controllers Security Apr 26, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·AEPD ·Art. 5, 6, 14 Integrity and Confidentiality Principle Personal Data Retention Period Apr 23, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Personal Data Controllers Apr 22, 2021
€1,500 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed a surveillance camera on his property, which recorded, among other… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Security Apr 22, 2021
€4,000 HazteOir.Org: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on HazteOir.Org. The controller had published a brochure on sex education in schools which unlawfully contained the photos… SPAIN ·AEPD ·Art. 6 Personal Data Consent Controllers Apr 22, 2021
€15,000 Fondazione Policlinico Tor Vergata di Roma: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Fondazione Policlinico Tor Vergata di Roma. In February 2020, a data subject filed a complaint with Garante alleging… ITALY ·Garante ·Art. 5, 13, 25 +1 Personal Data Privacy by Design & Default Controllers Apr 21, 2021
€8,000 Highcliffe Estates Marbella S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 8,000 on Highcliffe Estates Marbella S.L.. The controller had published a photo of the data subject on its website without his… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Apr 20, 2021
€2,800 Website operator: Non-compliance with general data processing principles The Hungarian DPA (NAIH) has imposed a fine of EUR 2,800 on a website operator. The controller had failed to prove the lawfulness of its processing of personal data upon request… HUNGARY ·NAIH ·Art. 5, 24 Controllers Personal Data Accountability Apr 20, 2021
€1,500 Pub owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the owner of a pub EUR 1,500 due to the unauthorized use of two video surveillance cameras covering parts of the public space. SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Monitoring Apr 19, 2021
€1,500 Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A.,… ROMANIA ·ANSPDCP ·Art. 29, 32 Controllers Security Processors Apr 19, 2021
€5,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Controllers Healthcare Apr 15, 2021
€5,000 S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined S.C. Tip Top Food Industry S.R.L. EUR 5,000. The controller had installed several video cameras in the food areas and changing rooms to… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Retention Period Controllers Personal Data Apr 15, 2021
€3,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller resides on the 1st floor of an apartment building, where he is the owner of… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Processing Apr 15, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Personal Data Apr 15, 2021
€2,000 Società triveneta di chirurgia: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Società triveneta di chirurgia. A physician had shown slides of a clinical case at a congress, which were subsequently… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Controllers Healthcare Apr 15, 2021