Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2151–2200 of 2,403 sort newestlargest fineoldest
€1,500 Tour & People Max S.L.: Insufficient fulfilment of data subjects rights Unsolicited marketing calls though data subjects had expressed their objection to data processing. In addition to the GDPR, this was also seen as a violation of Article 48(1)(b)… SPAIN ·AEPD ·Art. 21 Direct Marketing Right to Object Personal Data Jul 31, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA ·ANSPDCP ·Art. 32 Security Pseudonymization Anonymization Jul 30, 2020
HDPA 23/2020: Complaint against HEDNO S.A. for denial of employment certificate The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Greece ·Art. 4, 5, 12 +6 Right of Access Personal Data Processors Jul 30, 2020
€2,000 Community of Manduria: Insufficient legal basis for data processing The community transmitted personal data of a community employee to the press without sufficient legal basis. ITALY ·Garante ·Art. 5, 6 Personal Data Processing Employees Jul 30, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Insurance Supervision Jul 30, 2020
€3,000 Community of San Giorgio Jonico: Insufficient legal basis for data processing Publication of personal data on the municipal website with regard to legal proceedings. ITALY ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Jul 29, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK ·Datatilsynet (DK) ·Art. 5 Retention Period Personal Data Processing Jul 28, 2020
€5,000 SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security Unauthorised disclosure of the data of five Tarom passengers due to inadequate technical and organisational measures for secure data processing. Among other things, the company… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Jul 27, 2020
€1,700 Employer: Insufficient fulfilment of data subjects rights Failure to change the private address of an employee to his new address and to delete the old address as well as insufficient enabling of the employer to exercise his/her rights. HUNGARY ·NAIH ·Art. 12, 15, 17 Personal Data Employees Jul 23, 2020
€10,000 El Periódico de Catalunya, S.L.U.: Insufficient legal basis for data processing Following a request for erasure addressed to the company, the data subject received another newsletter from the newspaper, although El Periódico de Catalunya claimed to have… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Jul 23, 2020
€70,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The data subject's account was debited for two telephone lines that he had never ordered or approved. This constituted unlawful processing of personal data, since the data… SPAIN ·AEPD ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Processing Jul 23, 2020
€55,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing Telefónica Móviles España has processed the personal data of a data subject, such as first and last name and bank details, in order to activate three telephone lines that were… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Jul 23, 2020
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The company had carried out the number porting of his telephone line from his current company without his consent. Personal data was transferred from the former telephone operator… SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Jul 23, 2020
€24,000 Banco Bilbao Vizcaya Argentaria, SA: Insufficient legal basis for data processing BBVA had no legitimate basis for processing the data of the data subject and had therefore infringed Article 6(1) of the GDPR, since the company processed solvency and credit… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Insurance Jul 20, 2020
€40,000 Iberia Lae SA Operadora Unipersonal: Insufficient cooperation with supervisory authority The company did not grant the data subject access to telephone records. The applicant's request for access did not receive a reply, despite the prior order of the AEPD. SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Jul 20, 2020
€70,000 Xfera Moviles S.A.: Non-compliance with general data processing principles A data subject had received a call from another Xfera Móviles customer who stated that the company had charged his bank account with an invoice, disclosing the personal details of… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Jul 20, 2020
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The privacy notice required under Articles 12 to 14 of the GDPR was placed in the contacts section of the website… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Supervisory Authorities Processing Agreement Jul 20, 2020
€80,000 Orange Espagne S.A.U.: Insufficient legal basis for data processing The company had unlawfully activated several telephone line contracts using the personal data of a data subject. This constituted an unlawful processing operation, since the data… SPAIN ·AEPD ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Processing Jul 20, 2020
€28 Google Ireland Ltd.: Insufficient fulfilment of data subjects rights ⇄ Failure to respond to a data subjects request to access information (Art. 15 GDPR - here: about data processed in the context of Google AdWords) in due time. HUNGARY ·NAIH ·Art. 12, 15 Personal Data Telecommunications Jul 16, 2020
€22,300 Office for geodesy and cartography: Insufficient cooperation with supervisory authority Refusal of access to the premises by the supervisory authority in the course of an audit. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Jul 15, 2020
€600,000 Google Belgium SA: Insufficient fulfilment of data subjects rights The Belgian data protection authority has fined Google Belgium SA, a subsidiary of Google, 600,000 euros. The reasons for the fine were the rejection of an application by a data… APD/GBA ·Art. 5, 6, 12 +1 ·Insufficient fulfilment of data subjects rights Right to be Forgotten Personal Data Fairness & Transparency Jul 14, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide evidence that the data subject had consented to the scanning or copying of their ID card… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 7 +3 Personal Data Identification Consent Jul 14, 2020
€17M Wind Tre S.p.A.: Insufficient legal basis for data processing Fines for several unlawful data processing activities relating to direct marketing. Hundreds of data subjects claimed to have received unsolicited communications sent without… ITALY ·Garante ·Art. 5, 6, 12 +2 Consent Personal Data Processing Jul 13, 2020
€800,000 Iliad Italia S.p.A.: Non-compliance with general data processing principles The fine relates to data protection infringements concerning the processing of customer data for the activation of SIM cards and the manner in which payment data was recorded. In… ITALY ·Garante ·Art. 5, 25 Integrity and Confidentiality Principle Personal Data Transparency Jul 13, 2020
€3,400 East Power Sp. z o.o.: Insufficient cooperation with supervisory authority After three subpoenas to East Power, in which the latter failed to provide sufficient explanations on a direct marketing complaint, the data protection authority found that East… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Personal Data Jul 10, 2020
€55,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The company had changed a contract for a mobile phone connection to a new owner, whereby the personal data of a data subject such as his address and telephone numbers were freely… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Personal Data Security Jul 10, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet (NO) ·Art. 32, 35 DPIA Security Types of Special Categories of Personal Data Jul 10, 2020
€15,000 Proleasing Motors SRL: Insufficient technical and organisational measures to ensure information security The company had failed to take adequate technical and organisational measures to ensure data security, which led to the publication on Facebook of a document containing a password… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Jul 9, 2020
€830,000 Bureau Krediet Registration ('BKR'): Insufficient fulfilment of data subjects rights BKR had required the payment of a fee when individuals requested access to their personal data and only provided access to their data once a year free of charge by post. THE NETHERLANDS ·AP ·Art. 12, 15 Personal Data Supervision Supervisory Authorities Jul 6, 2020
€15,000 Mapei S.p.A.: Insufficient fulfilment of data subjects rights Mapei failed to respond to the request for access to personal data of the data subject. In addition, Mapei had left the e-mail account of the person concerned active even after… ITALY ·Garante ·Art. 5, 12, 13 +1 Right of Access Personal Data Supervisory Authorities Jul 2, 2020
€24,000 Iberdrola Clientes: Non-compliance with general data processing principles A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Security Personal Data Jul 2, 2020
€4,000 De Vere Spain S.L.: Insufficient fulfilment of data subjects rights The company did not respond to the data subject's request to stop processing his or her data, and therefore data subject continued to receive commercial calls. AEPD ·Art. 21 ·Insufficient fulfilment of data subjects rights Personal Data Processing Supervisory Authorities Jul 2, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK ·Datatilsynet (DK) ·Art. 5, 6, 33 +1 Data Breaches Personal Data Types of Special Categories of Personal Data Jun 30, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Insurance Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE ·HDPA ·Art. 5 Personal Data Processing Education Jun 29, 2020
€13,500 Department of Home Affairs: Insufficient fulfilment of data subjects rights Fines for failure to comply with the right of access to personal data under Articles 12 and 15 GDPR. The Isle of Man has declared the GDPR - although it is not an EU state - to be… ISLE OF MAN ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Inspection Access Rights and Cooperation Obligations Jun 25, 2020
€7,500 Miraclia (telecommunications company): Insufficient legal basis for data processing The recording of telephone jokes via an app constitutes processing of personal data in accordance with the applicable data protection law, as the voices of individuals may… SPAIN ·AEPD ·Art. 5, 6 Consent Personal Data Processing Jun 23, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Personal Data Health Data Jun 22, 2020
€10,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The company sent an e-mail to the person concerned without his consent. Thereupon the person concerned requested timely information about the entries in the database concerning… APD/GBA ·Art. 5, 6, 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Consent Jun 19, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Supervision Jun 18, 2020
€1,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The data subject repeatedly received e-mails with advertising content from a company, although the data subject had objected to the processing of his personal data and requested… APD/GBA ·Art. 17, 21, 31 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Direct Marketing Personal Data Jun 16, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 16, 2020
€75,000 Xfera Moviles S.A.: Insufficient legal basis for data processing The data subject received a notice from a debt collection company demanding payments in connection with Xfera Móviles' services, even though the claimant had not been a customer… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Jun 15, 2020
€4,010 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 4,010 on a legal person. The order was issued based on the carried out inspection. The accused failed to respond to numerous requests to… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Jun 11, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Jun 11, 2020
€5,000 Consulting de Seguridad e Investigacion Mira Dp Madrid S.L.: Insufficient legal basis for data processing A data subject has received marketing messages without having consented. SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Jun 9, 2020
€25,000 Glovoapp23: Insufficient involvement of data protection officer The company had not appointed a Data Protection Officer ('DPO') to whom requests from data subjects could be addressed, and the company's website did not contain information about… SPAIN ·AEPD ·Art. 37 Supervisory Authorities Personal Data Jun 9, 2020
€2,000 Attorney: Insufficient technical and organisational measures to ensure information security In the course of proceedings, an attorney submitted documents whose backs contained personal data of other parties. SPAIN ·AEPD ·Art. 32 Security Personal Data Insurance Jun 9, 2020
€39,000 Xfera Moviles S.A.: Insufficient legal basis for data processing A customer claimed to have received an SMS from Xfera Móviles informing about the non-payment and the resulting suspension of the service in relation to the account of another… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications Jun 9, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN ·AEPD ·Art. 6 Personal Data Telecommunications Representatives Jun 9, 2020