Skip to content
Content type · 2,565 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2151–2200 of 2,565 sort newestlargest fineoldest
€12,910 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€8,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,800 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€8,340 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 200 on a legal person. The accused sent the data subject, despite his objection and therefore his disagreement with further processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Right to Object Direct Marketing Dec 18, 2020
€8,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,800 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€11,830 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€10,070 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€9,420 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€26,710 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Education Dec 17, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Storage Limitation Healthcare Retention Period Dec 17, 2020
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Dec 17, 2020
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… UODO ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Privacy by Design & Default Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle IP Address Personal Data Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 Health Data DPIA Healthcare Dec 17, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… NAIH ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Personal Data Health Data Healthcare Dec 16, 2020
€10,000 Online Services: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined the operator of the online store banderacatalana.cat. EUR 10,000 for a violation of Art. 13 GDPR. The operator stated on its website privacy notices… SPAIN ·aepd ·Art. 6, 8, 13 IP Address Personal Data Processing Agreement Dec 15, 2020
€6,250 LATVIA DPA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined an employer EUR 6,250 for sending personal data of an employee, including health data, to fellow employees by email. The DSI found that the data… DSI ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Health Data Healthcare Dec 15, 2020
€29,500 Uppsalahem AB: Insufficient legal basis for data processing The Swedish DPA (Integritetsskyddsmyndigheten) fined the housing company Uppsalahem AB SEK 300,000 (EUR 29,500). The housing company had installed surveillance cameras in an… SWEDEN ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Legitimate Interest Monitoring Dec 15, 2020
€5M Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Banco Bilbao Vizcaya Argentaria, S.A. EUR 5,000,000 for violating Art. 6 GDPR (EUR 3,000,000) and Art. 13 GDPR (EUR 2,000,000). The bank had not… SPAIN ·aepd ·Art. 6, 13 Processing Agreement Personal Data Insurance Dec 11, 2020
€4,000 Borjamotor, S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 4,000 on Borjamotor, S.A. The company kept sending commercial advertisements to the data subject via email and SMS, even though the… SPAIN ·aepd ·Art. 7 Direct Marketing Personal Data Consent Dec 10, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY ·NAIH ·Art. 5, 6, 9 +2 Education Personal Data IP Address Dec 10, 2020
€10,000 SPAIN DPA: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of 10,000 EUR on a company for violating Art. 5 GDPR. The company sent an e-mail to a third party with the dismissal and settlement document… aepd ·Art. 5 ·Non-compliance with general data processing principles Personal Data IP Address Processing Agreement Dec 9, 2020
€40,000 Xfera Moviles S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on Xfera Móviles, S.A. due to insufficient legal basis for data processing. The data subject states that two telephone and internet… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Dec 9, 2020
€7,300 Perfomeclic: Insufficient legal basis for data processing The French DPA (CNIL) imposed a fine of EUR 7,300 on the company Perfomeclic. The company had sent commercial advertising emails without a proof of prior consent and without… FRANCE ·CNIL ·Art. 5, 14, 21 +1 Direct Marketing Processing Agreement Consent Dec 7, 2020
€35M CNIL fines Amazon Europe Core €35M for placing cookies without consent Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating… France ·Art. 6, 9, 83 +1 Cookies Telecommunications Direct Marketing Dec 7, 2020
€5,000 Asociación de Víctimas por Arbitrariedades Judiciales, (JAVA): Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on the association for publishing the personal data of the data subjects on its website. The data had been unlawfully recorded… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Dec 2, 2020
€6,000 Servicio de Alojamientos Responsables, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine in the amount of EUR 6,000 against the controller for unauthorized conclusion of a contract in the name of the data subject without his/her… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Dec 2, 2020
€100,000 Apotheka e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Personal Data Dec 1, 2020
€100,000 Südameapteegi e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Consent Dec 1, 2020
€100,000 Azeta.ee e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Consent Dec 1, 2020
€1,200 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine in the amount of EUR 1,200 on a private individual for impersonating a third party on the social networks Tinder and WhatsApp by using images… SPAIN ·aepd ·Art. 5 IP Address Personal Data Consent Nov 27, 2020
€3,000 Charly Mike s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Charly Mike s.r.l.. The controller is the hotel operator of the Hotel Olimpo in Alberobello. Garante received a complaint… ITALY ·Garante ·Art. 5, 13 Video Surveillance Monitoring Controllers Nov 26, 2020
€10,000 Reti Televisive Italiane S.p.a.: Non-compliance with general data processing principles The television station broadcasted a documentary about the link between emissions from a local ceramics plant and health problems in the population, in which the person… ITALY ·Garante ·Art. 5 Healthcare IP Address Telecommunications Nov 26, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Garante ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Health Data Integrity and Confidentiality Principle Nov 26, 2020
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·aepd ·Art. 6, 13, 14 Recipient Personal Data IP Address Nov 25, 2020
€19,500 Gnosjö Municipality: Insufficient legal basis for data processing The Swedish DPA imposed a fine on the municipality of Gnosjö for illegal video surveillance in a care home for persons with certain functional disabilities. SWEDEN ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Video Surveillance Healthcare Monitoring Nov 25, 2020
€1,500 Private Individual: Insufficient legal basis for data processing The Belgian DPA (APD) imposed a fine against private individuals. The controllers installed video cameras on their private property, two of which were positioned in a way that… BELGIUM ·APD ·Art. 6, 25 Processing Controllers Processing Agreement Nov 25, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Privacy by Design & Default Personal Data Nov 24, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Telecommunications Processing Nov 23, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY ·Garante ·Art. 5, 13 Personal Data Employees IP Address Nov 23, 2020
€12,000 Recambios Villalegre S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined the company for posting photos of a person on Facebook and WhatsApp and accusing the individual of theft in related posts. The photos were obtained… SPAIN ·aepd ·Art. 6, 13 Video Surveillance Social Media Monitoring Nov 23, 2020
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis. The company had sent an invoice to a data subject without being able to prove that it had a contract… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Nov 19, 2020
€4,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 4,800 on a legal person. In the course of the business activities, the accused contacted business entities, owners of industrial rights,… CZECH REPUBLIC ·UOOU ·Art. 6, 12 Processing Processing Agreement Supervisory Authorities Nov 19, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Healthcare Right of Access Procedures Nov 19, 2020
€2.3M Carrefour France: Non-compliance with general data processing principles The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that… CNIL ·Art. 5, 12, 13 +5 ·Non-compliance with general data processing principles Processing Agreement IP Address Personal Data Nov 18, 2020