Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2201–2250 of 3,446 sort newestlargest fineoldest
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Security Storage Limitation Apr 7, 2022
€1.3M Danske Bank: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 1.3 million on Danske Bank. The DPA had opened an investigation against the bank after it informed the DPA that it had a problem with the… DENMARK ·Datatilsynet ·Art. 5 Accountability IP Address Processing Agreement Apr 5, 2022
€463,000 Bank of Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined the Bank of Ireland EUR 463,000. The bank had reported 22 data breaches to the DPA under Article 33 GDPR. As part of its investigation, the DPA found that… Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Apr 5, 2022
€5,000 Mayor: Insufficient legal basis for data processing The Hellenic DPA has fined a mayor EUR 5,000. The mayor had sent documents of an employee of the municipality to third parties without the employee's consent. The DPA considered… GREECE ·HDPA ·Art. 5 IP Address Employees Processing Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 DPIA Health Data Audit Logs Apr 4, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Data Breaches Integrity and Confidentiality Principle Accuracy Apr 4, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data DPIA Healthcare Apr 4, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM ·APD ·Art. 5, 6, 9 Health Data Healthcare Archiving Apr 4, 2022
€7,500 Company: Insufficient fulfilment of data subjects rights The Belgian DPA has imposed a fine of EUR 7,500 on a company. A former managing director had filed a complaint against the company with the DPA. In the context of being dismissed,… BELGIUM ·APD ·Art. 5, 6, 15 +4 Personal Data Employees IP Address Apr 1, 2022
€1,300 Workshop: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,300 on a workshop. The workshop had installed a video surveillance system to protect the company's assets. However, the cameras also… HUNGARY ·NAIH ·Art. 5, 6, 13 Video Surveillance Monitoring Legitimate Interest Mar 29, 2022
€2,000 Condor SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Mar 28, 2022
€720,000 Klarna Bank AB: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 720,000 on Klarna Bank AB. Klarna is a financial company that processes a large number of personal data in various ways. As part of its… SWEDEN ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Personal Data Processing Agreement IP Address Mar 28, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK ·Datatilsynet ·Art. 36 DPIA Privacy Impact Assessment Healthcare Mar 25, 2022
€2,000 Kaufland Romania SCS: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland Romania SCS. A data subject had filed a complaint with the DPA concerning the controller's failure to comply with… ANSPDCP ·Art. 15 ·Insufficient fulfilment of data subjects rights Video Surveillance Monitoring Personal Data Mar 25, 2022
€10,000 Brav s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Brav s.r.l.. The operator of the online platform had reported a data breach to the DPA pursuant to Art. 33 GDPR. Unauthorized… ITALY ·Garante ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Security Mar 24, 2022
€490 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 490 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Mar 23, 2022
€4,000 English School Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email… Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 22, 2022
€5,000 English School staff union (ESSA): Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 21, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… Art. 5, 24 Social Media Telecommunications Processing Agreement Mar 15, 2022
€9,700 Company: Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact… NORWAY ·Datatilsynet ·Art. 6, 13, 21 Right to Object Controllers Processing Agreement Mar 15, 2022
€8,000 Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo: Insufficient legal basis for data processing The Italian DPA (Garante) has fined the Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo EUR 8,000. A former employee of the environmental agency had filed a complaint… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Employees Processing Mar 10, 2022
€10,000 Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 10,000 on Alfa Shipyard s.r.l.. The controller had failed to implement measures ordered by the DPA in due time. ITALY ·Garante ·Art. 58 Supervisory Authorities Supervision Controllers Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Health Data Healthcare Mar 10, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Encryption Data Breaches Notification Obligation Mar 10, 2022
€2,000 Operatorul Briza Land S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has fined Operatorul Briza Land S.R.L. EUR 2,000. The controller failed to properly respond to a request for information. ROMANIA ·ANSPDCP ·Art. 15 Controllers Personal Data Supervisory Authorities Mar 10, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Garante ·Art. 2, 5, 6 +3 Personal Data Healthcare Controllers Mar 10, 2022
€2,000 Employer: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 2,000 on an employer. An employee had filed a complaint due to the employer's failure to comply with the employee's right to object. The… GREECE ·HDPA ·Art. 5, 13 Right to Object Audit Logs Monitoring Mar 9, 2022
€2,000 Foreign language school: Insufficient fulfilment of data subjects rights The Hellenic DPA imposed a fine of EUR 2,000 on an employer (owner of a private foreign language school). An employee, who works as a language teacher in the school, had filed a… GREECE ·HDPA ·Art. 5, 13 Right to Object Education Controllers Mar 9, 2022
€7,000 Hörpu tónlistar- og ráðstefnuhúss ohf.: Non-compliance with general data processing principles The Icelandic DPA has fined Hörpu tónlistar- og ráðstefnuhúss ohf. EUR 7,000. The DPA had received a complaint regarding the concert hall's collection of ID number and date of… ICELAND ·Art. 5, 6 ·Non-compliance with general data processing principles Personal Data IP Address Processing Agreement Mar 8, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·azop ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 8, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·azop ·Art. 15 Video Surveillance Accuracy Personal Data Mar 8, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Access Controls Security Mar 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Controllers Healthcare Mar 3, 2022
€13,500 Company: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 13,500 on a company. An individual had filed a complaint with the DPA, stating that the company had published personal data such as their… HUNGARY ·NAIH ·Art. 5, 6, 12 +1 Personal Data Processing Agreement Consent Mar 2, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Public Authority Public Sector Feb 24, 2022
€1,500 WORLDWIDE CLASSIC CARS NETWORK S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on WORLDWIDE CLASSIC CARS NETWORK S.L.. The controller had installed video surveillance cameras which, among other things,… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Monitoring Feb 23, 2022
€1,200 FRUTAS Y VERDURAS LOS CAMPEONES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,000 on FRUTAS Y VERDURAS LOS CAMPEONES, S.L.. The controller had installed a video surveillance system, however, without having… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Feb 23, 2022
€3,000 IAMSAT Muntenia SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on IAMSAT Muntenia SA. The DPA launched an investigation following a complaint from a former employee who claimed that the… ROMANIA ·ANSPDCP ·Art. 12, 13, 21 Personal Data Video Surveillance Controllers Feb 22, 2022
€3,000 Hotel operator: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a hotel operator. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers Monitoring Feb 22, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Feb 22, 2022
€1,000 MALAGATROM, S.L.U.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on MALAGATROM, S.L.U. for failing to comply with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Feb 22, 2022
€1,500 RESTATURANTE FUENTEBRO, S.C.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined RESTATURANTE FUENTEBRO, S.C. EUR 1,500 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Supervisory Authorities Feb 21, 2022
€1,000 Store owner: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined a store owner EUR 1,000 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Supervisory Authorities Feb 21, 2022
€2,500 Private person: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 2,500 on a private individual. The controller had installed video surveillance cameras at his house which, among other things,… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Feb 18, 2022
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a private individual. The data subject had filed a complaint against the data controller for publishing images of herself… SPAIN ·aepd ·Art. 6 Controllers Personal Data Data Controller Feb 16, 2022
€30,000 ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 30,000 on the ΛΙΜΕΝΟΣ ΗΡΑΚΛΕΙΟΥ Α.Ε. organization. A data subject who had suffered a car accident on the organization's premises filed a… GREECE ·HDPA ·Art. 12, 15 Video Surveillance Personal Data Monitoring Feb 15, 2022
€1,600 RECLAMADOR, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine RECLAMADOR, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the controller continued… SPAIN ·aepd ·Art. 17, 21 Personal Data Controllers Processing Agreement Feb 14, 2022
€2M Amazon Road Transport Spain S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Amazon Road Transport Spain S.L. EUR 2,000,000. The AEPD had received a complaint from a trade union against the company. Amazon Road required… aepd ·Art. 6, 10 ·Insufficient legal basis for data processing Criminal Data Processing Agreement Processing Feb 11, 2022
€10,000 Costampress S.p.A.: Insufficient legal basis for data processing The company had left the e-mail account of the data subject active even after the termination of his employment and did not provide sufficient information about this. ITALY ·Garante ·Art. 5, 12, 13 Personal Data Processing Employees Feb 10, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Fairness & Transparency IP Address Retention Period Feb 10, 2022