Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2201–2250 of 2,403 sort newestlargest fineoldest
€75,000 Equifax Iberica, S.L.: Insufficient fulfilment of data subjects rights The Data Subject has requested by e-mail the deletion of his data from the file of the National Association of Financial Credit Institutions ('ASNEF'). Equifax Iberica had replied… SPAIN ·AEPD ·Art. 15 Personal Data Supervisory Authorities Insurance Jun 9, 2020
€1,168 Entrepreneur running a non-public nursery and pre-school: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Data Breaches Jun 3, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6, 35 Retention Period DPIA Profiling May 29, 2020
€1,000 Non-profit organisation: Insufficient fulfilment of data subjects rights The Belgian data protection authority has imposed a fine of EUR 1000 on a non-profit organisation for sending out direct marketing messages, despite the fact that data subjects… BELGIUM ·APD/GBA ·Art. 6, 21 Direct Marketing Right to Object Legitimate Interest May 29, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ÚOOÚ (CZ) ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing May 26, 2020
€100,000 Posti Group Oyj: Insufficient fulfilment of data subjects rights The decision relates to complaints alleging that data subjects received direct marketing from the company although they had requested that their postal data be deleted.… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 13, 14 +1 Personal Data Marketing Direct Marketing May 22, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·DPC ·Art. 5, 6 Personal Data Processing Public Authority May 17, 2020
€6,700 JobTeam A/S DKK: Insufficient fulfilment of data subjects rights The company has deleted personal data affected by a request for access without legal reason. DENMARK ·Datatilsynet (DK) ·Art. 15 Personal Data Supervisory Authorities Employees May 15, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·IMY ·Art. 5, 6 Personal Data Processing Public Authority May 12, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance May 5, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS ·AP ·Art. 5, 9 Consent Personal Data Processing Apr 30, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·IMY ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 29, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM ·APD/GBA ·Art. 31, 37, 58 Supervisory Authorities Data Breaches Personal Data Apr 28, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Privacy by Design & Default Apr 23, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ANSPDCP ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Personal Data Healthcare Types of Special Categories of Personal Data Apr 23, 2020
€2,890 Bank: Insufficient legal basis for data processing Due to an administrative error, the personal data of the data subject were registered and transferred to the Central Credit Information System (CCI) in connection with a loan… HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 26, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Mar 25, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company did not provide the data protection authority with the requested information in a timely manner. The AEPD's request was preceded by a request from a data subject for… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Personal Data Mar 25, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Mar 25, 2020
€3,000 Dante International: Insufficient legal basis for data processing The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. ROMANIA ·ANSPDCP ·Art. 6, 21 Personal Data Processing Supervision Mar 25, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS ·AP ·Art. 9, 32 Security Healthcare Controllers Mar 24, 2020
€8,000 Speech and Special Education Centre - Mihou Dimitra: Insufficient fulfilment of data subjects rights The complainant had requested access to his child's data and to tax information. This request was rejected by the data controller. In addition, the data controller had violated an… GREECE ·HDPA ·Art. 15, 58 Personal Data Controllers Supervisory Authorities Mar 20, 2020
€6,000 Oliveros Ustrell, S.L.: Insufficient legal basis for data processing The company forwarded an unsigned porting contract to the operator Vodafone. However, the data controller was unable to provide evidence of the order. For this reason, the… SPAIN ·AEPD ·Art. 5, 6 Controllers Personal Data Processing Mar 19, 2020
€5,800 Unknown Company: Insufficient fulfilment of data subjects rights The data controller has not complied with its obligation regarding the right of access to video recordings and was also unable to demonstrate that his data processing activities… HUNGARY ·NAIH ·Art. 6, 15 Right of Access Controllers Processing Mar 19, 2020
€30,000 Telefónica: Insufficient cooperation with supervisory authority Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and… SPAIN ·AEPD ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 18, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Accountability Mar 16, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA ·AZOP ·Art. 15 Right of Access Personal Data Supervisory Authorities Mar 13, 2020
€5M Google LLC: Insufficient fulfilment of data subjects rights Original Fine Summary: The Swedish data protection authority has fined Google LLC € 7 million for failing to adequately comply with its obligations regarding the right of data… SWEDEN ·IMY ·Art. 5, 6, 17 Personal Data Supervisory Authorities Telecommunications Mar 11, 2020
€7,000 Hørsholm Municipality: Insufficient technical and organisational measures to ensure information security A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Security Personal Data Public Authority Mar 10, 2020
€14,000 Gladsaxe Municipality: Insufficient technical and organisational measures to ensure information security A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Encryption Security Personal Data Mar 10, 2020
€870 Creditor: Insufficient legal basis for data processing Sending of SMS to a data subject as a reminder for a debt, even when the debt has already been paid. HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 9, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Mar 9, 2020
€4,400 Vis Consulting Sp. z o.o.: Insufficient cooperation with supervisory authority The company prevented an inspection by the data protection authority. As a result, the company has violated Article 31 in conjunction with Article 58(1)(e) and (f) of the GDPR. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Personal Data Mar 9, 2020
€3,000 San Giorgio Jonico: Insufficient legal basis for data processing Publication of a citizen's personal data on a website and failure to comply with requests for deletion. ITALY ·Garante ·Art. 5, 6, 17 Personal Data Processing Public Authority Mar 5, 2020
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing According to the AEPD, the data subject has received several SMS from a separate operator indicating the activation of a new contract. The reason for this was that an employee of… SPAIN ·AEPD ·Art. 5, 6 Legitimate Interest Personal Data Consent Mar 4, 2020
School in Gdansk (Danzig) (fine imposed against town of Gdansk): Insufficient legal basis for data processing Original summary: A school in Gdansk used biometric fingerprint scanners to authenticate students for the payment process in the school canteen. Although the parents had given… POLAND ·UODO ·Art. 5, 9 Consent Personal Data Processing Mar 4, 2020
€40,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing According to the AEPD, the company sent an SMS to an clients mobile number confirming that a telephone contract with that number had been signed even though the client was not a… SPAIN ·AEPD ·Art. 5, 6 Legitimate Interest Personal Data Consent Mar 3, 2020
€24,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing According to the AEPD, the company sent two SMS to an clients mobile number informing about a rate change in its contract and confirming the purchase of a new mobile phone,… SPAIN ·AEPD ·Art. 5, 6 Legitimate Interest Personal Data Consent Mar 3, 2020
€42,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security According to the AEPD, the company had not been able to demonstrate adequate measures to ensure information security, leading to unauthorized access to personal data of a client. SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Right of Access Mar 3, 2020
€525,000 Royal Dutch Tennis Association ('KNLTB'): Insufficient legal basis for data processing The Dutch Data Protection Authority has fined the Royal Dutch Tennis Association ('KNLTB') with EUR 525,000 for selling the personal data of more than 350,000 of its members to… THE NETHERLANDS ·AP ·Art. 5, 6 Legitimate Interest Personal Data Consent Mar 3, 2020
€3,600 AEMA Hispánica: Non-compliance with general data processing principles The company had sent the payroll of an employee to another employee and therefore disclosed personal data to an unauthorised party. SPAIN ·AEPD ·Art. 5 Personal Data Processing Employees Feb 28, 2020
€120,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone España was unable to prove to the data protection authority that the data subject had given his consent to the processing of his personal data for the provision of a… SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Feb 27, 2020
€48,000 HM Hospitales: Insufficient legal basis for data processing The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the… SPAIN ·AEPD ·Art. 5, 6 Consent Personal Data Processing Feb 25, 2020
€5,000 Public Power Corporation S.A.: Insufficient fulfilment of data subjects rights The Decision clarified that data subjects have a right of access to the processing of their personal data and that they must also be provided with a copy of the personal data… GREECE ·HDPA ·Art. 15 Right of Access Personal Data Processing Feb 21, 2020
€2,560 T.K. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to… BULGARIA ·CPDP ·Art. 25, 32 Security Personal Data Privacy by Design & Default Feb 20, 2020
€2,560 L.E. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca EUR 2,557 was imposed on L.E. EOOD for unlawful processing of personal data of data subject I.S. without the knowing and the consent of the data subject and also… BULGARIA ·CPDP ·Art. 6, 25, 32 Security Personal Data Privacy by Design & Default Feb 20, 2020
€2,500 Grupo Valsor Y Losan, S.L.: Insufficient technical and organisational measures to ensure information security The controller had disclosed personal data to a third party in a property purchase agreement (breach of principles of integrity and confidentiality of personal data) SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Security Personal Data Feb 14, 2020
€3,000 Colegio Arenales Carabanchel (School): Insufficient legal basis for data processing The decision of the data protection authority states that the school transferred pictures (and therefore personal data) to third parties, who published them without legal basis. SPAIN ·AEPD ·Art. 6 Personal Data Education Public Authority Feb 14, 2020
€80,000 Iberdrola Clientes: Insufficient legal basis for data processing Iberdola Clientes, an electricity company, terminated the data subject's contract without its consent, concluded three new contracts with the data subject, processed his personal… SPAIN ·AEPD ·Art. 6 Personal Data Consent International Transfer Feb 14, 2020