Skip to content
Content type · 2,273 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2101–2150 of 2,273 sort newestlargest fineoldest
€14,000 Gladsaxe Municipality: Insufficient technical and organisational measures to ensure information security A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city… DENMARK ·Datatilsynet ·Art. 5, 32 Encryption Security Personal Data Mar 10, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Personal Data Mar 9, 2020
€4,400 Vis Consulting Sp. z o.o.: Insufficient cooperation with supervisory authority The company prevented an inspection by the data protection authority. As a result, the company has violated Article 31 in conjunction with Article 58(1)(e) and (f) of the GDPR. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Accountability Mar 9, 2020
€870 Creditor: Insufficient legal basis for data processing Sending of SMS to a data subject as a reminder for a debt, even when the debt has already been paid. HUNGARY ·NAIH ·Art. 5, 6 Insurance Personal Data Processing Mar 9, 2020
€3,000 San Giorgio Jonico: Insufficient legal basis for data processing Publication of a citizen's personal data on a website and failure to comply with requests for deletion. ITALY ·Garante ·Art. 5, 6, 17 Personal Data Education Processing Mar 5, 2020
School in Gdansk (Danzig) (fine imposed against town of Gdansk): Insufficient legal basis for data processing Original summary: A school in Gdansk used biometric fingerprint scanners to authenticate students for the payment process in the school canteen. Although the parents had given… POLAND ·UODO ·Art. 5, 9 Education Consent Biometric Data Mar 4, 2020
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing According to the AEPD, the data subject has received several SMS from a separate operator indicating the activation of a new contract. The reason for this was that an employee of… SPAIN ·aepd ·Art. 5, 6 Legitimate Interest Personal Data Consent Mar 4, 2020
€42,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security According to the AEPD, the company had not been able to demonstrate adequate measures to ensure information security, leading to unauthorized access to personal data of a client. SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Right of Access Mar 3, 2020
€24,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing According to the AEPD, the company sent two SMS to an clients mobile number informing about a rate change in its contract and confirming the purchase of a new mobile phone,… SPAIN ·aepd ·Art. 5, 6 Legitimate Interest Personal Data Consent Mar 3, 2020
€40,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing According to the AEPD, the company sent an SMS to an clients mobile number confirming that a telephone contract with that number had been signed even though the client was not a… SPAIN ·aepd ·Art. 5, 6 Legitimate Interest Personal Data Consent Mar 3, 2020
€525,000 Royal Dutch Tennis Association ('KNLTB'): Insufficient legal basis for data processing The Dutch Data Protection Authority has fined the Royal Dutch Tennis Association ('KNLTB') with EUR 525,000 for selling the personal data of more than 350,000 of its members to… THE NETHERLANDS ·AP ·Art. 5, 6 Legitimate Interest Marketing Personal Data Mar 3, 2020
€3,600 AEMA Hispánica: Non-compliance with general data processing principles The company had sent the payroll of an employee to another employee and therefore disclosed personal data to an unauthorised party. SPAIN ·aepd ·Art. 5 Personal Data Processing IP Address Feb 28, 2020
€120,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone España was unable to prove to the data protection authority that the data subject had given his consent to the processing of his personal data for the provision of a… SPAIN ·aepd ·Art. 5, 6 Personal Data Consent Telecommunications Feb 27, 2020
€48,000 HM Hospitales: Insufficient legal basis for data processing The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the… SPAIN ·aepd ·Art. 5, 6 Consent Healthcare Healthcare Feb 25, 2020
€5,000 Public Power Corporation S.A.: Insufficient fulfilment of data subjects rights The Decision clarified that data subjects have a right of access to the processing of their personal data and that they must also be provided with a copy of the personal data… GREECE ·HDPA ·Art. 15 Right of Access Procedures Right of Access Personal Data Feb 21, 2020
€2,560 L.E. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca EUR 2,557 was imposed on L.E. EOOD for unlawful processing of personal data of data subject I.S. without the knowing and the consent of the data subject and also… BULGARIA ·KZLD ·Art. 6, 25, 32 Integrity and Confidentiality Principle Security Personal Data Feb 20, 2020
€2,560 T.K. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to… BULGARIA ·KZLD ·Art. 25, 32 Integrity and Confidentiality Principle Security Liability Feb 20, 2020
€2,500 Grupo Valsor Y Losan, S.L.: Insufficient technical and organisational measures to ensure information security The controller had disclosed personal data to a third party in a property purchase agreement (breach of principles of integrity and confidentiality of personal data) SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Controllers Feb 14, 2020
€80,000 Iberdrola Clientes: Insufficient legal basis for data processing Iberdola Clientes, an electricity company, terminated the data subject's contract without its consent, concluded three new contracts with the data subject, processed his personal… SPAIN ·aepd ·Art. 6 Personal Data International Transfer Consent Feb 14, 2020
€3,000 Colegio Arenales Carabanchel (School): Insufficient legal basis for data processing The decision of the data protection authority states that the school transferred pictures (and therefore personal data) to third parties, who published them without legal basis. SPAIN ·aepd ·Art. 6 Personal Data Education Processing Feb 14, 2020
€4,000 Comune di Urago: Insufficient legal basis for data processing The local council has published on its website information containing a person's personal data, including health information. ITALY ·Garante ·Art. 5, 6 Healthcare Personal Data Education Feb 13, 2020
€3,000 Vodafone Romania: Insufficient technical and organisational measures to ensure information security Vodafone Romania had incorrectly processed personal data of an individual in order to process a complaint, which was subsequently sent to a wrong e-mail address. The reason for… ANSPDCP ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Personal Data Feb 11, 2020
€800 Automoción: Insufficient legal basis for data processing An employee created a fake profile about a female colleague on an erotic portal, which contained, among other things, her contact details, a photo of her and information about her… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Supervisory Authorities Feb 3, 2020
€50,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The fine was preceded by a complaint from a data subject who argued that Vodafone España had sent invoices containing his personal data, such as name, identity card and address,… SPAIN ·aepd ·Art. 5 Personal Data IP Address Telecommunications Feb 3, 2020
€5,000 Queseria Artesenal Ameco S.L.: Insufficient legal basis for data processing The company processed personal data of customers without required consent. SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Consent Feb 3, 2020
€6,670 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The company repeatedly sent advertising messages to a data subject, although the data subject had objected to the processing of his data. SPAIN ·aepd ·Art. 5, 6, 21 Direct Marketing Insurance Personal Data Feb 3, 2020
€75,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine preceded the complaint by the data subject, who argued that Vodafone España had signed a contract for the transfer of a telephone subscription with a third party without… SPAIN ·aepd ·Art. 5, 6 IP Address Consent Personal Data Feb 3, 2020
€60,000 Xfera Moviles S.A.: Insufficient legal basis for data processing According to the data protection authority, XFERA MOVILES has violated Article 6(1) of the GDPR, as the company has unlawfully processed data, including bank details, customer… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Feb 3, 2020
€20,000 Iberia Lineas Aereas de Espana, S.A. Operadora Unipersonal: Insufficient legal basis for data processing Iberia continued to send e-mails to the data subject, despite the data subject had requested the withdrawal of his consent and the erasure of his personal data and that the… SPAIN ·aepd ·Art. 5, 6, 21 Personal Data IP Address Consent Feb 3, 2020
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine was preceded by a complaint from the data subject, who argued that he had received an e-mail from Vodafone España, which contained the billing of a telephone line that… SPAIN ·aepd ·Art. 5, 6 Personal Data Consent Telecommunications Feb 3, 2020
€75,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The data subject, a former customer of the company, continued to receive invoice notifications, although at that time there was neither a contractual relationship nor any payment… SPAIN ·aepd ·Art. 5, 6 Personal Data IP Address Telecommunications Feb 3, 2020
€4,000 Comune di Colledara: Insufficient legal basis for data processing Publication of documents relating to a public tender with personal data on a website ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Jan 30, 2020
€1,450 Accounting firm: Insufficient technical and organisational measures to ensure information security A printed customer list of an accounting firm, which also contained personal data, could be accessed by unauthorized persons. HUNGARY ·NAIH ·Art. 24, 32 Security Insurance Personal Data Jan 24, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Jan 23, 2020
€10,000 Community of Francavilla Fontana: Insufficient legal basis for data processing The community published on its website information about a court trial, including personal data such as health data about a data subject. ITALY ·Garante ·Art. 5, 6 Healthcare Personal Data Health Data Jan 15, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Garante ·Art. 5, 6, 17 +2 Telecommunications Integrity and Confidentiality Principle Direct Marketing Jan 15, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Right of Access Security Insurance Jan 13, 2020
€75,000 EDP España S.A.U.: Insufficient legal basis for data processing The company processed personal data such as first and last name, tax number, address and mobile phone number without the consent of the data subject SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Jan 7, 2020
€75,000 EDP Comercializadora, S.A.U.: Insufficient legal basis for data processing The company processed personal data in connection with a gas contract without the consent of the applicant. The decision finds that the applicant received an invoice for a gas… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Jan 7, 2020
€10,000 Asociación de Médicos Demócratas: Insufficient legal basis for data processing The Asociación de Médicos Demócratas has processed personal data of its members, despite having been warned by the AEPD that it carried out the processing without the consent of… SPAIN ·aepd ·Art. 6 Healthcare Consent Personal Data Jan 7, 2020
€44,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The company had sent a contract with personal data, including the applicant's name, address and telephone number, to the wrong recipient. SPAIN ·aepd ·Art. 5 Recipient Personal Data IP Address Jan 7, 2020
€5,110 Utility Company: Insufficient legal basis for data processing The fine of EUR ca. 5,113 was imposed on a Bulgarian utility company for unlawful processing of the personal data of the data subject V.V. The personal data of V.V. was unlawfully… BULGARIA ·KZLD ·Art. 6 Integrity and Confidentiality Principle Personal Data Processing Jan 6, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
Corporation: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. GERMANY ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Jan 1, 2020
Ski rental company: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 5, 6, 7 +9 IP Address Controllers Personal Data Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·Art. 6, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Processing Agreement Jan 1, 2020
€19,200 CZECH REPUBLIC DPA: Non-compliance with general data processing principles A company copied personal data from public registers, which was considered illegal by the Czech DPA, as it was not deemed necessary. UOOU ·Art. 5, 6, 12 +8 ·Non-compliance with general data processing principles Personal Data IP Address Processing Agreement Jan 1, 2020
€1,900 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights A person had received an invoice for ordered goods, which, however, came from a different company than the one from which she had ordered the goods. Therefore, the data subject… UOOU ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Data Controller Jan 1, 2020
Public university: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 6, 13 Personal Data Education Processing Jan 1, 2020