Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2251–2300 of 3,446 sort newestlargest fineoldest
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Fairness & Transparency IP Address Storage Limitation Feb 10, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Personal Data Public Authority Education Feb 10, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Garante ·Art. 5, 9 Data Breaches Health Data Healthcare Feb 10, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Education Public Authority Feb 10, 2022
€1,500 Studio Colli Aniene Verderocca S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,500 on Studio Colli Aniene Verderocca S.r.l.. A data subject had filed a complaint with the DPA for unsolicited telephone advertising.… ITALY ·Garante ·Art. 12, 14, 15 +2 Personal Data Direct Marketing Processing Agreement Feb 10, 2022
€5,000 Arte del vivere S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Arte del vivere S.r.l.. A data subject filed a complaint with the DPA as his personal data had been published on the website… ITALY ·Garante ·Art. 12, 17, 157 Personal Data Controllers IP Address Feb 10, 2022
€634,000 Budapest Bank Zrt.: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has fined Budapest Bank Zrt. EUR 634,000. NAIH reports that the bank used an artificial intelligence-driven software solution to automate the evaluation… HUNGARY ·NAIH ·Art. 5, 6, 12 +5 Right to Object Legitimate Interest Data Subject Rights Exercise Modalities and Procedures Feb 8, 2022
€1,000 Cafe operator: Non-compliance with general data processing principles The cafe used CCTV cameras which also captured the public space outside resulting in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Feb 7, 2022
€10,000 PINTODIS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined PINTODIS, S.L. EUR 10,000. The controller had installed several video cameras which also covered the food areas and changing rooms of their employees.… SPAIN ·aepd ·Art. 5 IP Address Employees Monitoring Feb 7, 2022
€10,000 Εκδοτικού Οίκου Δίας: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the publisher Εκδοτικού Οίκου Δίας. A public figure had filed a complaint with the DPA. The publisher had published incorrect… CYPRUS ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Telecommunications Feb 4, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual. The individual had published audiovisual material of a court trial on Twitter without obtaining the… SPAIN ·aepd ·Art. 6 Social Media Consent Processing Feb 4, 2022
€900 Private person: Non-compliance with general data processing principles Unlawful usage of video surveillance cameras which also monitored parts of the public space (violation of principle of data minimization). SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Feb 4, 2022
€300,000 SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS. in the amount of EUR 300,000. The data subject had received marketing emails from the controller… SPAIN ·aepd ·Art. 6, 17, 28 Insurance Controllers Processing Agreement Feb 4, 2022
€1,000 Café owner: Non-compliance with general data processing principles The DPA from Luxembourg has imposed a fine of EUR 1,000 on a café owner. The owner had installed two video surveillance cameras in the café for the purpose of protecting company… LUXEMBOURG ·CNPD ·Art. 5, 13 Video Surveillance Monitoring IP Address Feb 2, 2022
€2,000 ASESORES DE SEGURIDAD PRIVADA, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on ASESORES DE SEGURIDAD PRIVADA, S.L.. The DPA criticized that the controller did not sufficiently inform the data subject about… SPAIN ·aepd ·Art. 13 Personal Data Controllers Insurance Feb 2, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM ·APD ·Art. 5, 6, 9 +8 Fairness & Transparency IP Address Direct Marketing Feb 2, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet ·Art. 5, 6, 32 Data Breaches Security Education Feb 2, 2022
€200,000 XFERA MÓVILES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined XFERA MÓVILES, S.A. EUR 200,000. Two Xfera customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters… SPAIN ·aepd ·Art. 5 IP Address Processing Agreement Telecommunications Feb 1, 2022
€700,000 Orange Espagne S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Orange Espagne S.A.U. EUR 700,000. Two Orange Espagne customers had filed complaints with the DPA. In the course of its investigation, the DPA found that… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€3.9M Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Security Feb 1, 2022
€900,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined TELEFÓNICA MÓVILES ESPAÑA, S.A.U. EUR 900,000. Four Telefónica customers had filed complaints with the DPA. In the course of its investigation, the DPA… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY ·Datatilsynet ·Art. 6 Controllers Insurance Processing Feb 1, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Controllers Personal Data Feb 1, 2022
€70,000 ORANGE ESPAÑA VIRTUAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined ORANGE ESPAÑA VIRTUAL, S.L. EUR 70,000. Two Orange España Virtual customers had filed complaints with the DPA. In the course of its investigation, the… SPAIN ·aepd ·Art. 5 IP Address Telecommunications Processing Agreement Feb 1, 2022
€1,500 Property Owner Community: Insufficient legal basis for data processing Use of CCTV cameras in building complex without obtaining the consent of all the property owners. SPAIN ·aepd ·Art. 6 Video Surveillance Consent Processing Jan 31, 2022
€5,000 Cyrana España General S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Cyrana España General S.L. EUR 5,000. The controller had sent an invoice to the data subject although no contractual relationship existed. SPAIN ·aepd ·Art. 6 Controllers IP Address Personal Data Jan 31, 2022
€5,000 INCOPROSOL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined INCOPROSOL, S.L. EUR 5,000. The controller had recorded a telephone conversation with a customer without obtaining the customer's consent. SPAIN ·aepd ·Art. 5 Controllers IP Address Consent Jan 31, 2022
€40,000 T.S.M. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on T.S.M. s.r.l.. A data subject had filed a complaint with the DPA against the company for failing to comply with their requests… ITALY ·Garante ·Art. 13, 15, 21 +2 Personal Data Processing Agreement Processing Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD ·Art. 5, 6, 9 +3 Religious Beliefs Fairness & Transparency Social Media Jan 27, 2022
€3.2M OTE Group: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 3.2 million on Cosmote subsidiary OTE Group. Among other things, OTE Group had contributed to Cosmote's security infrastructure. Cosmote… GREECE ·HDPA ·Art. 32 Data Breaches Notification Obligation Security Jan 27, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches DPIA Security Jan 27, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD ·Art. 5, 6, 9 +5 Religious Beliefs Social Media Fairness & Transparency Jan 27, 2022
€2,000 Private club 'Ruian': Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 2,000 on the private club 'Ruian'. The controller had installed video surveillance cameras which, among other things, also… ITALY ·Garante ·Art. 5, 13 Video Surveillance IP Address Controllers Jan 27, 2022
BfDI (Germany) - 24-191 II The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Art. 15, 20, 95 Telecommunications Recipient Data Portability Jan 27, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Data Breaches Healthcare Jan 26, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·Art. 5, 24, 28 +2 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Data Breaches Jan 26, 2022
Belgian DPA rules on competence in cross-border cookie consent complaint involving The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·APD/GBA Cookies Legitimate Interest Supervisory Authorities Jan 21, 2022
€2,000 Website operator: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) imposed a fine of EUR 2,000 on a website operator for the lack of a privacy policy on its website, in violation of Art. 13 GDPR. SPAIN ·aepd ·Art. 13 Processing Agreement Supervisory Authorities Jan 21, 2022
€1,200 Property Owner Community: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a property owners' community EUR 1,200. A property manager had sent a copy of the general meeting minutes to the director of the security company… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Agreement Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Right of Access Procedures Right of Access Controllers Jan 20, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Encryption Security Jan 19, 2022
€117,000 Santander Bank Polska S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 118,000 for failing to notify data subjects of a data breach. A former employee of the bank managed to gain unauthorized… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 19, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Data Breaches Encryption Security Jan 19, 2022
€56,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on VODAFONE ESPAÑA, S.A.U. due to insufficient legal basis for data processing. The data subject states that two telephone connections were… SPAIN ·aepd ·Art. 6 Personal Data Telecommunications Processing Agreement Jan 18, 2022
€15,000 GARLEX SOLUTIONS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on GARLEX SOLUTIONS, S.L.. The data subject had received a call from the company to renew their electricity supply… SPAIN ·aepd ·Art. 6 Personal Data Processing Agreement Processing Jan 18, 2022
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,500 on a private individual. The person had installed video cameras in the apartment building where he lives, which recorded, among… SPAIN ·aepd ·Art. 5 IP Address Processing Processing Agreement Jan 17, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
€2,000 MEETING PUERTO C.B.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on MEETING PUERTO C.B.. The data controller had unlawfully published a picture of the complainant with his partner on Facebook and… SPAIN ·aepd ·Art. 6 Social Media Controllers Processing Agreement Jan 17, 2022
€8M REWE International AG: €8,000,000 fine The Austrian DPA has imposed a fine of EUR 8 million on REWE International AG. Just in the summer of 2021, the subsidiary 'Unser Ö-Bonus Club GmbH' received a fine of EUR 2… AUSTRIA ·dsb ·Unknown Processing Agreement Human Resources Supervisory Authorities Jan 14, 2022