Skip to content
Content type · 2,650 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2151–2200 of 2,650 sort newestlargest fineoldest
Deutsche Wohnen SE: Non-compliance with general data processing principles Originally, a fine in the amount of EUR 14.500.000 was issued against Deutsche Wohnen SE for using an archiving system for the storage of personal data of tenants that, according… GERMANY ·Art. 5, 25 ·Non-compliance with general data processing principles Controllers Personal Data Processing Feb 23, 2021
Security company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A data controller using the services of the security company reported the breach of personal data to the DPA, arising after an employee of the security company recorded the video… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Feb 22, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet (DK) ·Art. 5 Storage Limitation Personal Data Fines Feb 12, 2021
€120,000 Vodafone España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A former customer had received e-mails containing electronic bills even after he had terminated his… SPAIN ·AEPD ·Art. 5, 6 Personal Data Controllers Processing Feb 12, 2021
€1,600 Ripobruna 207, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 2,000 against Ripobruna 207, S.L. (restaurant) for the unauthorized use of two video surveillance cameras that also recorded parts of… SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Monitoring Feb 12, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Feb 11, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers Feb 11, 2021
€60,000 Roma Servizi per La Mobilita S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined Roma Servizi per La Mobilita S.r.l. EUR 60,000 for failing to take adequate technical and organizational measures regarding the data of citizens… ITALY ·Garante ·Art. 32 Security Controllers Processors Feb 11, 2021
€5,000 Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da Pietrelcina: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Foundation for Religion and Worship 'Casa sollievo della sofferenza' Opera di San Pio da Pietrelcina. On January… ITALY ·Garante ·Art. 5, 9 Data Breaches Notification Obligation Personal Data Feb 11, 2021
€1,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine of EUR 1,000 on ING Bank N.V. Amsterdam - Bucharest Branch. It was found that the controller had sent files to a contractual partner in… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data Feb 10, 2021
€65,000 Lursoft IT SIA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined Lursoft IT SIA EUR 65,000 for the illegal processing of personal data by publishing documents containing personal data on its website 'www.lursoft.lv'.… LATVIA ·DSI ·Art. 6 Personal Data Controllers Processing Feb 9, 2021
€3,000 Patio Ancestral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on Patio Ancestral S.L.. The complainant worked for a construction company and had carried out some renovation work for the… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Feb 8, 2021
€5,000 Private Person: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 5,000 for illegal camera surveillance. The data subject had rented two rooms in the apartment of the controller. The… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Security Feb 8, 2021
€2,000 Private Person: Non-compliance with general data processing principles Unauthorized use of two video surveillance cameras that also recorded parts of the public space, such as sidewalks and properties behind those. SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Monitoring Feb 4, 2021
€19,300 Cyberbook AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Cyberbook AS NOK 200,000 (EUR 19,300) for the illegal automatic forwarding of e-mails from a former employee. The forwarding took place for… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Processing Employees Feb 3, 2021
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Processing Feb 2, 2021
€80 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 80 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Right to Object Processing Feb 1, 2021
€50,000 Azienda USL della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 50,000 on Azienda USL della Romagna. Upon her arrival at the gynecology unit of a hospital operated by the controller (for the… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Personal Data Controllers Jan 27, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY ·Garante ·Art. 5, 9 Healthcare Personal Data Controllers Jan 27, 2021
€50,000 Family Service / N.D.P.K. nv.: Insufficient legal basis for data processing The Belgian DPA imposed a fine of EUR 50,000 on Family Service / N.D.P.K. nv. The controller is an advertising agency that, among other things, sends expectant mothers gift boxes… BELGIUM ·APD/GBA ·Art. 5, 6, 7 +4 Recipient Controllers Personal Data Jan 27, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Public Authority Personal Data Processing Jan 27, 2021
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Personal Data Controllers Healthcare Jan 27, 2021
€50,000 Alterna Operador Integral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 50,000 on Alterna Operador Integral S.L.. A switch of the electricity supplier had taken place without the consent of the data… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Consent Jan 21, 2021
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 75,000 on Telefónica Móviles España, SAU. The controller had assigned five telephone lines with five numbers to the data subject as… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications Jan 21, 2021
€26,710 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Jan 20, 2021
€1,200 Individual: Non-compliance with general data processing principles The controller installed cameras on his building, which were directed towards parts of the public space. However, no recording took place, as the cameras only served as a… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Jan 20, 2021
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Jan 20, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent unsolicited commercial communications to the complainant and failed to respond to their repeated… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jan 19, 2021
€9,700 Aquateknikk AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Aquateknikk AS NOK 100,000 (EUR 9,700). The controller had carried out a credit rating on an individual without there being a customer… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Controllers Processing Jan 19, 2021
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY ·Garante ·Art. 5, 32 Security Controllers Personal Data Jan 14, 2021
€38,600 Coop Finnmark SA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Coop Finnmark SA NOK 400,000 (EUR 38,600). The manager of the store in question recorded CCTV footage with a mobile phone and shared the… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Processing Video Surveillance Supervisory Authorities Jan 14, 2021
€18,000 Azienda Usl di Bologna: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Usl di Bologna EUR 18,000. In a hospital operated by the controller, 49 patients in the oncology ward received discharge letters with… ITALY ·Garante ·Art. 5, 9 Controllers Healthcare Processing Jan 14, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Controllers Processors Processing Jan 14, 2021
€30,000 Azienda sanitaria provinciale di Enna: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 30,000 on Azienda sanitaria provinciale di Enna. The controller processed biometric data of employees for the purpose of… ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Controllers Personal Data Jan 14, 2021
€2M Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Caixabank S.A. EUR 6,000,000 for violations of Art. 6 GDPR, Art. 13 GDPR and Art. 14 GDPR. Customers of the bank were supposed to accept new privacy… SPAIN ·AEPD ·Art. 6, 13, 14 Legitimate Interest Personal Data Controllers Jan 13, 2021
€38,600 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined a company NOK 400,000 (EUR 38,600) for the illegal automatic forwarding of an employee's email inbox. The automatic forwarding was activated… Datatilsynet (NO) ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Supervisory Authorities Employees Jan 12, 2021
€10,000 BELGIUM DPA: Insufficient legal basis for data processing Managing a fan page on Facebook without the data subject's permission and failing to comply with the data subject's request after exercising his or her right to object. APD/GBA ·Art. 6, 12, 21 ·Insufficient legal basis for data processing Supervisory Authorities Right to Object Personal Data Jan 12, 2021
€10M notebooksbilliger.de: Insufficient legal basis for data processing The DPA of Lower Saxony (LfD Niedersachsen) imposed a fine of EUR 10,4 million on the electronics retailer notebooksbilliger.de.The company had video-monitored its employees for… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Video Surveillance Monitoring Jan 8, 2021
€7,250 Gveik AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Gveik AS EUR 7,250. The controller had carried out a credit check on an individual, although there was no legal basis for doing so. NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Processing Insurance Jan 7, 2021
€9,700 Lindstrand Trading AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined Lindstrand Trading AS EUR 9,700. The controller had carried out four credit checks on individuals and individual companies, although… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Processing Insurance Jan 6, 2021
€20,000 Nestor SAS: Insufficient fulfilment of information obligations The French DPA (CNIL) fined the company Nestor EUR 20,000. The CNIL notes that the privacy policy provided during the registration process on the company´s website did not contain… FRANCE ·CNIL ·Art. 12, 13 Controllers Supervisory Authorities Processing Jan 5, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out four credit checks on the data… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Consent Jan 4, 2021
€118,500 CZECH REPUBLIC DPA: Insufficient legal basis for data processing The Czech DPA (UOOU) fined 11 companies a total of EUR 118,500 for sending unrequested postal advertising messages to the mailboxes of various citizens. Based on a decision by the… ÚOOÚ (CZ) ·Art. 6, 14 ·Insufficient legal basis for data processing Supervisory Authorities Personal Data Public Authority Jan 4, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Jan 4, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Public Authority Personal Data Supervisory Authorities Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer had queried the new partner of a friend's ex-wife because he feared that… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
Medical clinic: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on a medical clinic. The clinic had installed 21 cameras in its premises for the purpose of protection against crime and property damage.… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Consent Processing Video Surveillance Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer repeatedly had accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried his stepson's investigative process in order to prepare him for… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
Job center employee: Insufficient legal basis for data processing A job center employee had accessed data in social database systems and in the civil register for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021