Skip to content
Content type · 2,802 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2101–2150 of 2,802 sort newestlargest fineoldest
Company: Insufficient fulfilment of information obligations The DPA of Bremen has imposed a three-digit fine on a company. The company offered its applicants an online application procedure on its website without informing users about the… GERMANY ·Art. 12, 13 ·Insufficient fulfilment of information obligations Personal Data Processing Human Resources Jan 1, 2022
Company: Insufficient legal basis for data processing The DPA of Bremen has imposed a five-digit fine on a company. The company had sent an unredacted social plan to all affected employees in the context of dismissals due to… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Employees Personal Data Special Categories of Data Jan 1, 2022
Company: Insufficient legal basis for data processing The Latvian DPA has fined a company for issuing loyalty cards to customers without a valid legal basis. LATVIA ·DSI ·Art. 5, 6 Processing Agreement Processing Supervisory Authorities Jan 1, 2022
€80,700 Beauty salon: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 80,700 on a beauty salon. The controller had installed video cameras in all its premises, which permanently recorded customers and… HUNGARY ·NAIH ·Insufficient legal basis for data processing Video Surveillance Direct Marketing Controllers Jan 1, 2022
€7,500 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 7,500 on DW Dynamic Works LIMITED. The controller operated as a processor for the Cypriot Ministry of Denfese. The minsitry had suffered… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Processors Controllers Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Six fines for failing to provide information requested by the DPA during an investigation. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Fines Jan 1, 2022
€17,000 Bank of Cyprus Public Company Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Privacy by Design & Default Jan 1, 2022
Supermarket: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a supermarket. A store detective had taken a photo of the data subject on the occasion of an alleged theft and transmitted it via the… GERMANY ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Processing Agreement Jan 1, 2022
€5,000 Cyprus Judo Federation: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine on the Cyprus Judo Federation. The father of a member had filed a complaint with the DPA because the judo coach of his minor son had published… Art. 31 ·Insufficient cooperation with supervisory authority Social Media Supervisory Authorities Supervision Jan 1, 2022
€2,700 Covid-19 test center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Healthcare Security Jan 1, 2022
Company: Insufficient fulfilment of data breach notification obligations The DPA from Bremen has fined a company for failing to inform the DPA pursuant to Art. 33 GDPR that an employee's business email account had been hacked. GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2022
Physician: Insufficient fulfilment of data subjects rights The DPA of Bremen imposed a fine on a physician for failing to respond to a data subject's request for access to their data in a timely manner. GERMANY ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Healthcare Supervisory Authorities Jan 1, 2022
€1,000 Covid-19 test center: Insufficient fulfilment of data subjects rights The DPA of Hamburg has fined a Covid-19 test center EUR 1,000 for failing to comply with the right of data subjects to have their personal data deleted. GERMANY ·Art. 17 ·Insufficient fulfilment of data subjects rights Healthcare Personal Data Processing Agreement Jan 1, 2022
Company: Insufficient fulfilment of data subjects rights The DPA of Bremen imposed a fine on a company for failing to respond to a data subject's request for access to their data in a timely manner. GERMANY ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Processing Agreement Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a five-figure fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Direct Marketing Consent Personal Data Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Public Sector Controllers Jan 1, 2022
€250,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has failed to implement appropriate technical and organizational measures to protect personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Privacy by Design & Default Jan 1, 2022
Debt collection company: Insufficient legal basis for data processing The DPA from Baden-Württemberg has imposed a fine on a debt collection company. The debt collection company had received investor information from an employee of an insolvent… GERMANY ·Art. 6, 14 ·Insufficient legal basis for data processing Insurance Personal Data Processing Jan 1, 2022
€20,000 Company: €20,000 fine The DPA from Baden-Württemberg has imposed a fine of EUR 20,000 on a company. The company had developed a new office plan that took into account the vaccination status of its… GERMANY ·Unknown Employees Processing Agreement Supervisory Authorities Jan 1, 2022
€1,600 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA imposed a fine of EUR 1,600 on a physician. A patient had filed a complaint against the controller with the DPA. The patient had asked the doctor to send all… HUNGARY ·NAIH ·Art. 5, 12, 13 Healthcare Health Data Healthcare Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Jan 1, 2022
€60M Google Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Google Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Processing Agreement Dec 31, 2021
€60M Facebook Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Facebook Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Social Media Cookies Direct Marketing Dec 31, 2021
€90M Google LLC: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 90,000,000 on GOOGLE LLC. The CNIL received several complaints regarding the manner in which cookies could be… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Processing Agreement Dec 31, 2021
€25,000 PLUS REAL ADVERTISEMENT: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 25,000 on PLUS REAL ADVERTISEMENT. The controller had conducted advertising calls without the consent of the data subjects. In addition,… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Direct Marketing Controllers Dec 31, 2021
€30,000 INFO COMMUNICATION SERVICES: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 30,000 on INFO COMMUNICATION SERVICES. The controller had conducted advertising calls without the consent of the data subjects. In… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Controllers Direct Marketing Dec 31, 2021
€75,000 Greek Ministry of Tourism: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 75,000 on the Greek Ministry of Tourism. A data breach had occurred at the authority. According to the DPA, an attempt by a citizen to… GREECE ·HDPA ·Art. 13, 32, 33 +1 Data Breaches Notification Obligation Public Sector Dec 29, 2021
€2,000 Call shop manager: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on the manager of a call shop. In the context of a job vacancy, the manager had set up a stand where applicants could submit their… SPAIN ·aepd ·Art. 13 Personal Data Processing Supervisory Authorities Dec 28, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Privacy by Design & Default Dec 28, 2021
€300,000 FREE MOBILE: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has imposed a fine of EUR 300,000 on FREEE MOBILE. The CNIL had received numerous complaints regarding the company's failure to comply with data subjects'… FRANCE ·CNIL ·Art. 12, 15, 21 +2 Right to Object Data Subject Rights Exercise Modalities and Procedures Telecommunications Dec 28, 2021
€6,000 REAL CLUB NÁUTICO DE RIBADEO: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on REAL CLUB NÁUTICO DE RIBADEO. The controller had uploaded links to court decisions containing personal data of the data… SPAIN ·aepd ·Art. 6 Social Media Personal Data Controllers Dec 28, 2021
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Healthcare Health Data Dec 26, 2021
€1,500 LA OFICINA BAR: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined LA OFICINA BAR. The bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. The… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Dec 23, 2021
€5,000 Sfam España General s.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Sfam España General s.l.. A data subject had filed a complaint with the DPA against the controller for charging her… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Dec 22, 2021
€5,000 HUBSIDE IBÉRICA S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 HUBSIDE IBÉRICA S.L.. A data subject had filed a complaint with the DPA against the controller for charging her several… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Dec 22, 2021
€2,000 FUNDACION ESPANOLA DE MEDICINA ESTETICA Y LONGEVIDAD: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on FUNDACION ESPANOLA DE MEDICINA ESTETICA Y LONGEVIDAD. The DPA criticized that the data protection notice of the controller did… SPAIN ·aepd ·Art. 7, 13 Controllers Processing Agreement Consent Dec 21, 2021
€1.3M Lisbon City Council: Insufficient legal basis for data processing The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since… PORTUGAL ·CNPD ·Art. 5, 6, 9 +2 Religious Beliefs DPIA Fines Dec 21, 2021
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 6,000 on a private individual. The person had shared a video on Twitter showing images of a sexual assault by a man on a woman. The… SPAIN ·aepd ·Art. 6 Legitimate Interest Social Media Processing Dec 21, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY ·Garante ·Art. 5, 6, 9 Health Data Healthcare Controllers Dec 17, 2021
€3,900 T. Stene Transport AS: €3,900 fine The Norwegian DPA has fined T. Stene Transport AS EUR 3,900 due to an unfair credit check on a data subject. NORWAY ·Datatilsynet ·Unknown Personal Data Processing Agreement Supervisory Authorities Dec 17, 2021
€2,000 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 2,000. The data controller had installed video cameras in such a way that they could record images of the public space and… SPAIN ·aepd ·Art. 5 Controllers IP Address Processing Dec 17, 2021
€2,000 Online retailer: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on an online retailer. The data subject bought a product from the controller's online store via eBay and paid with Paypal. However,… SPAIN ·aepd ·Art. 6 Processing Agreement Controllers Personal Data Dec 17, 2021
€4,000 CLUB DEPORTIVO RITMO DE ANDALUCÍA: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on CLUB DEPORTIVO RITMO DE ANDALUCÍA. The DPA criticized that the data protection notice of the controller did not comply with the… SPAIN ·aepd ·Art. 7, 13 Processing Agreement Controllers Consent Dec 17, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Garante ·Art. 5 Fairness & Transparency Recipient Personal Data Dec 16, 2021
€6,500 Travel agency: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 6,500 on a travel agency. A customer of the travel agency informed the DPA to suspect that the company might not process the data of its… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 17, 25 +1 Personal Data Security Processing Dec 16, 2021
€52,000 Motor insurance center: Non-compliance with general data processing principles The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25 Insurance Healthcare Health Data Dec 16, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Healthcare Healthcare Dec 16, 2021
€60,000 Banco Bilbao Vizcaya Argentaria S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria S.A.. A data subject filed a complaint with the DPA due to the fact that the controller repeatedly… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Insurance Dec 16, 2021
€75,000 Bank: Insufficient involvement of data protection officer The Belgian DPA has imposed a fine of EUR 75,000 on a bank. The DPA identified a conflict of interest regarding the data protection officer. In addition to his work as data… BELGIUM ·APD ·Art. 38 Notified Body Responsibilities and Operational Obligations Supervisory Authorities Processing Agreement Dec 16, 2021
€1,200 Private individual: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined a private individual EUR 1,200 for failing to provide sufficient information about a video surveillance system installed at their property. SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Supervisory Authorities Dec 16, 2021