Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2301–2350 of 3,651 sort newestlargest fineoldest
€5,600 Physician: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined a physician. The physician had used recordings of a patient's treatment for advertising purposes. However, the patient had not consented to this.… SPAIN ·aepd ·Art. 6 Healthcare Direct Marketing Consent Apr 22, 2022
€600 DOOR2DOOR SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine on DOOR2DOOR SPAIN, S.L.. The controller had failed to implement measures repeatedly ordered by the DPA in due time. Also, the controller had… aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Apr 19, 2022
€1,800 Website operator: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine on the operator of the website link During its investigation, the DPA found numerous deficiencies on a website operated by the… SPAIN ·aepd ·Art. 6, 13, 22 Controllers Processing Agreement Consent Apr 18, 2022
€1,000 IKEA România S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on IKEA România S.R.L.. A data subject had complained to the DPA that IKEA had failed to comply with their requests to delete the… ROMANIA ·ANSPDCP ·Art. 12 Personal Data Processing Agreement Processing Apr 18, 2022
€9,000 JIMBO NETWORKS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine on JIMBO NETWORKS, S.L.. During its investigation, the DPA found numerous deficiencies on a website operated by the controller. For… SPAIN ·aepd ·Art. 6, 13, 22 Controllers Processing Agreement Law Enforcement Apr 18, 2022
€1,800 FLORAQUEEN FLOWERING THE WORLD S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined FLORAQUEEN FLOWERING THE WORLD S.L. for failing to provide information requested by the DPA during an investigation. The original fine of EUR 3,000 was… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Apr 18, 2022
€1.5M DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press… FRANCE ·CNIL ·Art. 28, 29, 32 Encryption Security Healthcare Apr 15, 2022
€8,000 RAMONA FILMS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined RAMONA FILMS, S.L. for failing to ensure that the company's privacy policy complied with the requirements of Art. 13 GDPR. Specifically, the website… SPAIN ·aepd ·Art. 13, 22 Processing Agreement Law Enforcement Supervisory Authorities Apr 13, 2022
€500 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500 on a homeowners' association. The executive board of the owners' association had publicly posted a list of defaulting owners. The DPA… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle IP Address Professional Secrecy Apr 12, 2022
€150,000 BASER COMERCIALIZADORA DE REFERENCIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has fined BASER COMERCIALIZADORA DE REFERENCIA, S.A., EUR 150,000. A customer of the company had filed a complaint with the DPA since their electricity supply… SPAIN ·aepd ·Art. 6, 32 Controllers Processing Agreement Security Apr 11, 2022
€10,000 Findomestic Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on Findomestic Banca spa. A customer had filed a complaint with the DPA regarding a breach of confidentiality related to the… ITALY ·Garante ·Art. 5 Integrity and Confidentiality Principle Personal Data IP Address Apr 7, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY ·Garante ·Art. 28 Processing Agreement IP Address Data Processor Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Video Surveillance Integrity and Confidentiality Principle IP Address Apr 7, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Storage Limitation Security Apr 7, 2022
€15,000 Rebirth s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Rebirth s.r.l. EUR 15,000. The controller had installed 14 surveillance cameras in a café it operated without, however, informing about the video… ITALY ·Garante ·Art. 5, 13, 114 +1 Video Surveillance Monitoring Controllers Apr 7, 2022
€50,000 Palumbo Superyacht Ancona s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Palumbo Superyacht Ancona s.r.l. EUR 50,000. The company had blocked an employee's company email account without permission. The employee had reported… ITALY ·Garante ·Art. 5, 12, 13 +3 Storage Limitation IP Address Employees Apr 7, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Privacy Impact Assessment Healthcare Apr 7, 2022
€10,000 E-Mac Professional s.r.l.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Apr 7, 2022
€500 Property owners' association: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined a property owners' association EUR 500 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Apr 7, 2022
€20,000 Made in Italy s.r.l.s.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on Made in Italy s.r.l.s.. A data subject had filed a complaint with the DPA after receiving promotional calls from the… Garante ·Art. 6, 7, 15 +5 ·Insufficient legal basis for data processing Controllers Processing Agreement Direct Marketing Apr 7, 2022
€463,000 Bank of Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined the Bank of Ireland EUR 463,000. The bank had reported 22 data breaches to the DPA under Article 33 GDPR. As part of its investigation, the DPA found that… Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Apr 5, 2022
€1.3M Danske Bank: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 1.3 million on Danske Bank. The DPA had opened an investigation against the bank after it informed the DPA that it had a problem with the… DENMARK ·Datatilsynet ·Art. 5 Accountability IP Address Processing Agreement Apr 5, 2022
€5,000 Mayor: Insufficient legal basis for data processing The Hellenic DPA has fined a mayor EUR 5,000. The mayor had sent documents of an employee of the municipality to third parties without the employee's consent. The DPA considered… GREECE ·HDPA ·Art. 5 IP Address Employees Processing Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 DPIA Health Data Healthcare Apr 4, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data Healthcare DPIA Apr 4, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Data Breaches Integrity and Confidentiality Principle Accuracy Apr 4, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM ·APD ·Art. 5, 6, 9 Health Data Healthcare Fines Apr 4, 2022
€7,500 Company: Insufficient fulfilment of data subjects rights The Belgian DPA has imposed a fine of EUR 7,500 on a company. A former managing director had filed a complaint against the company with the DPA. In the context of being dismissed,… BELGIUM ·APD ·Art. 5, 6, 15 +4 Personal Data Employees IP Address Apr 1, 2022
€1,300 Workshop: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,300 on a workshop. The workshop had installed a video surveillance system to protect the company's assets. However, the cameras also… HUNGARY ·NAIH ·Art. 5, 6, 13 Video Surveillance Monitoring Legitimate Interest Mar 29, 2022
€2,000 Condor SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Mar 28, 2022
€720,000 Klarna Bank AB: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 720,000 on Klarna Bank AB. Klarna is a financial company that processes a large number of personal data in various ways. As part of its… SWEDEN ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Personal Data Processing Agreement IP Address Mar 28, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK ·Datatilsynet ·Art. 36 DPIA Privacy Impact Assessment Healthcare Mar 25, 2022
€2,000 Kaufland Romania SCS: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland Romania SCS. A data subject had filed a complaint with the DPA concerning the controller's failure to comply with… ANSPDCP ·Art. 15 ·Insufficient fulfilment of data subjects rights Video Surveillance Monitoring Personal Data Mar 25, 2022
€10,000 Brav s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Brav s.r.l.. The operator of the online platform had reported a data breach to the DPA pursuant to Art. 33 GDPR. Unauthorized… ITALY ·Garante ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Security Mar 24, 2022
€490 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 490 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Mar 23, 2022
€4,000 English School Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email… Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 22, 2022
€5,000 English School staff union (ESSA): Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Mar 21, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… Art. 5, 24 Social Media Accountability Processing Agreement Mar 15, 2022
€9,700 Company: Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact… NORWAY ·Datatilsynet ·Art. 6, 13, 21 Right to Object Controllers Processing Agreement Mar 15, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare Health Data Mar 10, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Garante ·Art. 2, 5, 6 +3 Controllers Healthcare Personal Data Mar 10, 2022
€8,000 Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo: Insufficient legal basis for data processing The Italian DPA (Garante) has fined the Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo EUR 8,000. A former employee of the environmental agency had filed a complaint… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Employees Processing Mar 10, 2022
€10,000 Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 10,000 on Alfa Shipyard s.r.l.. The controller had failed to implement measures ordered by the DPA in due time. ITALY ·Garante ·Art. 58 Supervisory Authorities Supervision Controllers Mar 10, 2022
€2,000 Operatorul Briza Land S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has fined Operatorul Briza Land S.R.L. EUR 2,000. The controller failed to properly respond to a request for information. ROMANIA ·ANSPDCP ·Art. 15 Controllers Personal Data Supervisory Authorities Mar 10, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Encryption Data Breaches Notification Obligation Mar 10, 2022
€2,000 Employer: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 2,000 on an employer. An employee had filed a complaint due to the employer's failure to comply with the employee's right to object. The… GREECE ·HDPA ·Art. 5, 13 Right to Object Monitoring Audit Logs Mar 9, 2022
€2,000 Foreign language school: Insufficient fulfilment of data subjects rights The Hellenic DPA imposed a fine of EUR 2,000 on an employer (owner of a private foreign language school). An employee, who works as a language teacher in the school, had filed a… GREECE ·HDPA ·Art. 5, 13 Right to Object Education Controllers Mar 9, 2022
€7,000 Hörpu tónlistar- og ráðstefnuhúss ohf.: Non-compliance with general data processing principles The Icelandic DPA has fined Hörpu tónlistar- og ráðstefnuhúss ohf. EUR 7,000. The DPA had received a complaint regarding the concert hall's collection of ID number and date of… ICELAND ·Art. 5, 6 ·Non-compliance with general data processing principles IP Address Personal Data Cookies Mar 8, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·azop ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 8, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·azop ·Art. 15 Video Surveillance Accuracy Personal Data Mar 8, 2022