Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2251–2300 of 2,403 sort newestlargest fineoldest
€4,000 Comune di Urago: Insufficient legal basis for data processing The local council has published on its website information containing a person's personal data, including health information. ITALY ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Feb 13, 2020
€3,000 Vodafone Romania: Insufficient technical and organisational measures to ensure information security Vodafone Romania had incorrectly processed personal data of an individual in order to process a complaint, which was subsequently sent to a wrong e-mail address. The reason for… ANSPDCP ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Processing Feb 11, 2020
€75,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine preceded the complaint by the data subject, who argued that Vodafone España had signed a contract for the transfer of a telephone subscription with a third party without… SPAIN ·AEPD ·Art. 5, 6 Consent Personal Data Processing Feb 3, 2020
€20,000 Iberia Lineas Aereas de Espana, S.A. Operadora Unipersonal: Insufficient legal basis for data processing Iberia continued to send e-mails to the data subject, despite the data subject had requested the withdrawal of his consent and the erasure of his personal data and that the… SPAIN ·AEPD ·Art. 5, 6, 21 Personal Data Consent Processing Feb 3, 2020
€6,670 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The company repeatedly sent advertising messages to a data subject, although the data subject had objected to the processing of his data. SPAIN ·AEPD ·Art. 5, 6, 21 Direct Marketing Personal Data Processing Feb 3, 2020
€50,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The fine was preceded by a complaint from a data subject who argued that Vodafone España had sent invoices containing his personal data, such as name, identity card and address,… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications Feb 3, 2020
€60,000 Xfera Moviles S.A.: Insufficient legal basis for data processing According to the data protection authority, XFERA MOVILES has violated Article 6(1) of the GDPR, as the company has unlawfully processed data, including bank details, customer… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Feb 3, 2020
€800 Automoción: Insufficient legal basis for data processing An employee created a fake profile about a female colleague on an erotic portal, which contained, among other things, her contact details, a photo of her and information about her… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Supervisory Authorities Feb 3, 2020
€75,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The data subject, a former customer of the company, continued to receive invoice notifications, although at that time there was neither a contractual relationship nor any payment… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Feb 3, 2020
€5,000 Queseria Artesenal Ameco S.L.: Insufficient legal basis for data processing The company processed personal data of customers without required consent. SPAIN ·AEPD ·Art. 5, 6 Consent Personal Data Processing Feb 3, 2020
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine was preceded by a complaint from the data subject, who argued that he had received an e-mail from Vodafone España, which contained the billing of a telephone line that… SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Feb 3, 2020
€4,000 Comune di Colledara: Insufficient legal basis for data processing Publication of documents relating to a public tender with personal data on a website ITALY ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Jan 30, 2020
€1,450 Accounting firm: Insufficient technical and organisational measures to ensure information security A printed customer list of an accounting firm, which also contained personal data, could be accessed by unauthorized persons. HUNGARY ·NAIH ·Art. 24, 32 Security Personal Data Insurance Jan 24, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Garante ·Art. 5, 32 Security Personal Data Processing Jan 23, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Garante ·Art. 5, 6, 17 +2 Integrity and Confidentiality Principle Direct Marketing Storage Limitation Jan 15, 2020
€10,000 Community of Francavilla Fontana: Insufficient legal basis for data processing The community published on its website information about a court trial, including personal data such as health data about a data subject. ITALY ·Garante ·Art. 5, 6 Personal Data Types of Special Categories of Personal Data Processing Jan 15, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Cyprus DPA ·Art. 32 Right of Access Personal Data Security Jan 13, 2020
€10,000 Asociación de Médicos Demócratas: Insufficient legal basis for data processing The Asociación de Médicos Demócratas has processed personal data of its members, despite having been warned by the AEPD that it carried out the processing without the consent of… SPAIN ·AEPD ·Art. 6 Consent Personal Data Healthcare Jan 7, 2020
€44,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The company had sent a contract with personal data, including the applicant's name, address and telephone number, to the wrong recipient. SPAIN ·AEPD ·Art. 5 Personal Data Processing Recipient Jan 7, 2020
€75,000 EDP Comercializadora, S.A.U.: Insufficient legal basis for data processing The company processed personal data in connection with a gas contract without the consent of the applicant. The decision finds that the applicant received an invoice for a gas… SPAIN ·AEPD ·Art. 6 Consent Personal Data Processing Jan 7, 2020
€75,000 EDP España S.A.U.: Insufficient legal basis for data processing The company processed personal data such as first and last name, tax number, address and mobile phone number without the consent of the data subject SPAIN ·AEPD ·Art. 6 Personal Data Consent Processing Jan 7, 2020
€5,110 Utility Company: Insufficient legal basis for data processing The fine of EUR ca. 5,113 was imposed on a Bulgarian utility company for unlawful processing of the personal data of the data subject V.V. The personal data of V.V. was unlawfully… BULGARIA ·CPDP ·Art. 6 Personal Data Integrity and Confidentiality Principle Liability Jan 6, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·HmbBfDI ·Art. 26 Personal Data Processing Agreement Processors Jan 1, 2020
€3,850 Television broadcaster: Insufficient fulfilment of information obligations A TV broadcaster had provided information on its website about the processing of personal data, which was however hidden and inaccurate (links to outdated legal provisions). CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Telecommunications Processing Jan 1, 2020
Public university: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 13 Personal Data Education Public Authority Jan 1, 2020
Corporation: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. GERMANY ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·HmbBfDI ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security Accidental loss of personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities Jan 1, 2020
€19,200 CZECH REPUBLIC DPA: Non-compliance with general data processing principles A company copied personal data from public registers, which was considered illegal by the Czech DPA, as it was not deemed necessary. ÚOOÚ (CZ) ·Art. 5, 6, 12 +8 ·Non-compliance with general data processing principles Supervisory Authorities Personal Data Processing Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·HmbBfDI ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·HmbBfDI ·Art. 6, 32 Security Personal Data Privacy by Design & Default Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Fairness & Transparency Jan 1, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2020
€1,900 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights A person had received an invoice for ordered goods, which, however, came from a different company than the one from which she had ordered the goods. Therefore, the data subject… ÚOOÚ (CZ) ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Jan 1, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Fairness & Transparency Jan 1, 2020
Ski rental company: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 7 +9 Controllers Consent Personal Data Jan 1, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 12, 28 Personal Data Health Data Healthcare Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·HmbBfDI ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 1, 2020
€150,000 Aegean Marine Petroleum Network Inc.: Insufficient technical and organisational measures to ensure information security Companies outside the Aegean Marine Petroleum Group had access to its servers containing personal data and copied the contents of the servers, since Aegean Marine Petroleum failed… GREECE ·HDPA ·Art. 5, 6, 32 Security Personal Data Processing Dec 19, 2019
The complainant belongs to a political party and is a member of the city council of an Austrian municipality In November, the municipality held a meeting on the "parking space concept", to which a certain group of addressees, including the complainant, was invited. The complainant did… DSB-D123.768/0004-DSB/201 ·Austria ·DSB Public Authority Pseudonymization Anonymization Dec 18, 2019
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Telecommunications Dec 18, 2019
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM ·APD/GBA ·Art. 6, 12, 13 Personal Data Fairness & Transparency IP Address Dec 17, 2019
€2,000 Nursing Care Organisation: Insufficient fulfilment of data subjects rights The company failed to act on requests from the data subject to get access to his data and to have his data erased. BELGIUM ·APD/GBA ·Art. 12, 15, 17 Personal Data Supervisory Authorities Dec 17, 2019
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Dec 16, 2019
€6,000 SC Enel Energie S.A. (Electricity Distributor): Insufficient legal basis for data processing The sanctions were imposed following a complaint alleging that Enel Energie had unlawfully processed an individual's personal data and was unable to prove that it had obtained the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Right to Object Personal Data Consent Dec 16, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company has excessively processed the personal data of his employees through the video cameras installed in the offices and in the places where there are cabinets where the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Retention Period Personal Data Processing Dec 13, 2019
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused provided the data subject with access to their personal data only after being requested to do so by… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Agreement Dec 13, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company processed biometric data (fingerprints) of the employees for access to certain rooms tough less intrusive means for the privacy of the data subjects could be used… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Retention Period Types of Special Categories of Personal Data Personal Data Dec 13, 2019
€3M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Processing Dec 11, 2019
€8.5M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6, 17 +1 Integrity and Confidentiality Principle Storage Limitation Direct Marketing Dec 11, 2019