Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2301–2350 of 2,403 sort newestlargest fineoldest
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Security Personal Data Dec 10, 2019
€20,000 S CNTAR TAROM SA (Airline): Insufficient technical and organisational measures to ensure information security The Romanian data protection authority imposed a sanction on an airline because it has not taken appropriate measures to ensure that any natural person acting under its… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Dec 4, 2019
€1,500 Cerrajeria Verin S.L.: Insufficient fulfilment of information obligations The company collected personal data without providing accurate information on their data processing activities in their privacy policy published on their website. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Processing Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Dec 2, 2019
€2,500 Royal President S.R.L.: Insufficient fulfilment of data subjects rights Royal President refused a request for access to personal data pursuant to Article 15 of the GDPR and disclosed personal data without the consent of the data subjects. In addition,… ROMANIA ·ANSPDCP ·Art. 6, 15, 32 Right of Access Personal Data Security Nov 29, 2019
€500 Homeowners Association: Insufficient technical and organisational measures to ensure information security The association used video surveillance systems without proper information according to Art. 13 GDPR and without adequate security measures regarding the persons having access to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Supervision Nov 29, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance Nov 28, 2019
€75,000 Curenergía Comercializador de último recurso: Insufficient legal basis for data processing An individual filed a complaint against the company alleging that the company had used its personal data as a former customer, such as first and last name, VAT identification… SPAIN ·AEPD ·Art. 6 Personal Data Identification Processing Nov 28, 2019
€3,000 Modern Barber: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Nov 26, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Nov 25, 2019
€2,000 BNP Paribas Personal Finance S.A.: Insufficient fulfilment of data subjects rights BNP Paribas Personal Finance did not react to a request for erasure within the period set by the GDPR. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Supervision Supervisory Authorities Nov 22, 2019
€60,000 Viaqua Xestión Integral Augas de Galicia: Insufficient legal basis for data processing Processing (modification) of the personal data of a customer included in a contract by a third party without the consent of the customer. SPAIN ·AEPD ·Art. 6 Consent Personal Data Processing Nov 21, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE ·CNIL ·Art. 5, 6, 13 +4 Personal Data Supervisory Authorities Processing Nov 21, 2019
€60,000 Corporación radiotelevisión espanola: Insufficient technical and organisational measures to ensure information security CORPORACIÓN RADIOTELEVISIÓN ESPAÑOLA and the trade union have reported a security breach to the AEPD after six unencrypted USB sticks containing personal data were lost. The… SPAIN ·AEPD ·Art. 32 Encryption Security Personal Data Nov 19, 2019
€60,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security An individual complainant had received an SMS from Xfera Móviles which was to be addressed to a third party and which allowed him to access the account and personal data of this… SPAIN ·AEPD ·Art. 32 Personal Data Security Telecommunications Nov 19, 2019
€3,000 General Confederation of Labour ('CGT'): Insufficient legal basis for data processing The CGT, with the aim of convening a meeting, e-mailed personal data of the complainant, including her home address, family relationship, pregnancy status and the date of an… SPAIN ·AEPD ·Art. 6 Personal Data Consent Processing Nov 13, 2019
€900 TODOTECNICOS24H S.L.: Insufficient fulfilment of information obligations TODOTECNICOS24H had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Transparency Nov 7, 2019
€900 Cerrajero Online: Insufficient fulfilment of information obligations The company had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Transparency Nov 6, 2019
€1,770 L. Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA (UODO) imposed a fine of EUR 1,770 on L. Sp. z o.o. for the video surveillance of a residential community, which was not in compliance with the provisions of the… POLAND ·UODO ·Art. 5 Processing Personal Data Video Surveillance Nov 1, 2019
Deutsche Wohnen SE: Non-compliance with general data processing principles In addition to sanctioning violations of privacy by design principles (Art. 5 GDPR, Art. 25 GDPR - see separate entry), the Berlin data protection commissioner imposed further… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Privacy by Design Privacy by Design & Default Privacy by Default Oct 30, 2019
€511 Employer: Insufficient fulfilment of data subjects rights The pecuniary sanction of EUR 511 was imposed on an employer for refusal to grant access to the personal data of a data subject who submitted an application for access to his… BULGARIA ·CPDP ·Art. 12, 15 Personal Data Employees Oct 28, 2019
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The claimant, whose data had been provided to the company by his daughter, as authorised by him, received a call from the company offering its services, which he refused. However,… SPAIN ·AEPD ·Art. 5, 6 Consent Personal Data Processing Oct 25, 2019
€2,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Cyprus DPA ·Art. 6, 9 Types of Special Categories of Personal Data Personal Data Processing Oct 25, 2019
€10,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Cyprus DPA ·Art. 6, 9 Types of Special Categories of Personal Data Personal Data Processing Oct 25, 2019
€70,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Cyprus DPA ·Art. 6, 9 Types of Special Categories of Personal Data Personal Data Processing Oct 25, 2019
€9,380 Major of Aleksandrów Kujawski: Insufficient data processing agreement No data processing agreement has been concluded with the company whose servers contained the resources of the Public Information Bulletin (BIP) of the Municipal Office in… POLAND ·UODO ·Art. 28 Processors Personal Data Processing Oct 18, 2019
€20,000 Wind Hellas Telecommunications: Insufficient fulfilment of data subjects rights Among other things, the company has ignored objections raised by affected parties against advertising calls. GREECE ·HDPA ·Art. 21 Direct Marketing Right to Object Personal Data Oct 18, 2019
€2,500 UTTIS INDUSTRIES SRL: Insufficient fulfilment of information obligations The sanctions were applied to the controller because he could not prove that the data subjects were informed about the processing of personal data / images through the video… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Controllers Processing Oct 17, 2019
€47,000 ClickQuickNow: Non-compliance with general data processing principles The UODO imposed a fine of EUR 47000 for obstructing the exercise of the right of withdrawal for the processing of personal data. The company has not taken appropriate technical… POLAND ·UODO ·Art. 5 Personal Data Processing Right to be Forgotten Oct 16, 2019
€60,000 Xfera Moviles S.A.: Insufficient legal basis for data processing Xfera Movile has used personal data without a legal basis for the conclusion of a telephone contract and has continued to process personal data even when the data subject… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Telecommunications Oct 16, 2019
€15,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security Original fine summary: Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance Oct 9, 2019
€20,000 Vreau Credit SRL: Insufficient technical and organisational measures to ensure information security Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the platform's staff via… ROMANIA ·ANSPDCP ·Art. 32, 33 Personal Data Security Supervision Oct 9, 2019
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not meet the objection of two data subjects to the processing of their personal data for direct… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 21 Direct Marketing Right to Object Personal Data Oct 8, 2019
€5,112 The Ministry of Interior Affairs: Insufficient legal basis for data processing The fine of EUR 5,112 was imposed on the Ministry of Interior Affairs for unlawfully processing the personal data of data subject A.K. The Ministry of Interior sent the personal… BULGARIA ·CPDP ·Art. 5, 6 Personal Data Processing Public Authority Oct 8, 2019
€511 B.D.: Insufficient cooperation with supervisory authority The fine of EUR 511 was imposed on B.D. for failure to provide access to information which the Commission for Personal Data Protection needed for performance of its tasks and… BULGARIA ·CPDP ·Art. 31 Supervision Supervisory Authorities Personal Data Oct 7, 2019
€2,000 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused circumvented the law when, instead of providing social services with proper authorization, it did so… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 12, 30 Personal Data Processing Supervisory Authorities Oct 4, 2019
€9,000 Inteligo Media SA: Insufficient legal basis for data processing As part of the registration process on the webseite avocatnet.ro, the operator used an unfilled checkbox, by means of which users could declare that they did not wish to receive… ROMANIA ·ANSPDCP ·Art. 5, 6 Consent Personal Data Processing Sep 26, 2019
€195,407 Delivery Hero: Insufficient fulfilment of data subjects rights According to the findings of the Berlin data protection officer, Delivery Hero Germany GmbH had not deleted accounts of former customers in ten cases, even though those data… GERMANY ·Art. 15, 17, 21 ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Supervisory Authorities Sep 19, 2019
€10,000 Merchant: Non-compliance with general data processing principles The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's… BELGIUM ·APD/GBA ·Art. 5 Identification Personal Data Processing Sep 17, 2019
€660,000 Morele.net: Insufficient technical and organisational measures to ensure information security The Polish data protection authority imposed a fine of over PLN 2.8 million (approx. €644,780) on Morele.net for insufficient organisational and technical safeguards, which led to… POLAND ·UODO ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Sep 10, 2019
€28,100 National Revenue Agency: Insufficient legal basis for data processing The pecuniary sanction of EUR 28, 121 was imposed on the National Revenue Agency for unlawful processing of the personal data of data subject G.B.I. The personal data of G.B.I.… BULGARIA ·CPDP ·Art. 6, 58 Personal Data Supervision Integrity and Confidentiality Principle Sep 3, 2019
€1,121 Private enforcement agent: Insufficient fulfilment of data subjects rights The fine of EUR 1, 121 was imposed on a private enforcement agent for processing of the personal data of data subject through recording by technical means for video surveillance… BULGARIA ·CPDP ·Art. 12, 15 Supervision Personal Data Processing Sep 3, 2019
€5,113 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·CPDP ·Art. 6, 25 Personal Data Consent Integrity and Confidentiality Principle Sep 3, 2019
€11,760 Commercial representative of telecommunication service provider: Insufficient legal basis for data processing The pecuniary sanction of EUR 11, 760 was imposed on the commercial representative of telecommunications service provider for unlawful processing of the personal data of a data… BULGARIA ·CPDP ·Art. 6 Personal Data Representatives Integrity and Confidentiality Principle Sep 3, 2019
€1,022 Telecommunication service provide: Insufficient legal basis for data processing The pecuniary sanctions of EUR 1, 022 and EUR 5, 113 were imposed on a telecommunications service provider and its commercial representative in Bulgaria for unlawful processing of… BULGARIA ·CPDP ·Art. 6, 25 Personal Data Consent Integrity and Confidentiality Principle Sep 3, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Processors Legitimate Interest Sep 3, 2019
€2.6M National Revenue Agency: Insufficient technical and organisational measures to ensure information security Leakage of personal data in a hacking attack due to inadequate technical and organisational measures to ensure the protection of information security. It was found that personal… BULGARIA ·CPDP ·Art. 32 Security Personal Data Public Authority Aug 28, 2019
€511,000 DSK Bank: Insufficient technical and organisational measures to ensure information security Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit… BULGARIA ·CPDP ·Art. 32 Personal Data Security Insurance Aug 28, 2019
€7,000 Online Services: Insufficient fulfilment of data subjects rights A merchant who provides services in an online store has infringed the 'right to be forgotten' pursuant to Art. 17 GDPR when he was repeatedly requested by a data subject to delete… LATVIA ·DSI ·Art. 17 Right to be Forgotten Personal Data Direct Marketing Aug 26, 2019
€18,630 School in Skellefteå: Insufficient legal basis for data processing A school in Skellefteå made a trial to use facial recognition technology. The fine was imposed against the school which had used facial recognition technology to monitor the… SWEDEN ·Art. 5, 9, 35 +1 ·Insufficient legal basis for data processing Types of Special Categories of Personal Data Monitoring Personal Data Aug 20, 2019