Skip to content
Content type · 2,403 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2351–2400 of 2,403 sort newestlargest fineoldest
€60,000 AVON COSMETICS: Insufficient legal basis for data processing A consumer claimed that AVON COSMETICS had unlawfully processed his data without adequately verifying his identity, which led to his data being erroneously entered in a register… SPAIN ·AEPD ·Art. 6 Personal Data Processing Law Enforcement Aug 16, 2019
€1,715 Government Office Managing the Real Estate Register: Non-compliance with general data processing principles The owners of a real estate complained that the government office posted its decision on the change in the person of the lessee (which concluded a lease agreement with real estate… HUNGARY ·NAIH ·Art. 5, 14 Personal Data Processing Public Authority Aug 8, 2019
€150,000 PWC Business Solutions: Insufficient legal basis for data processing The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to… GREECE ·HDPA ·Art. 5, 6, 13 +1 Fairness & Transparency Legitimate Interest Controllers Jul 30, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Jul 5, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Law Enforcement Jul 2, 2019
€130,000 UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations,… ROMANIA ·ANSPDCP ·Art. 5, 25 Security Personal Data Processing Jun 27, 2019
€2,850 HUNGARY DPA: Insufficient legal basis for data processing The individual requested the deletion of his contact data (including his telephone number), however the controller further processed his contact data for claim enforcement… NAIH ·Art. 5, 6, 17 ·Insufficient legal basis for data processing Legitimate Interest Personal Data Controllers Jun 26, 2019
€15,150 HUNGARY DPA: Insufficient fulfilment of data breach notification obligations The data controller did not fulfil its data breach notification obligations when a flash memory with personal data was lost. NAIH ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Supervisory Authorities Jun 25, 2019
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not comply with the data subject's request to delete the personal data from its website, even after… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Jun 12, 2019
€2,850 Claim management company: Insufficient legal basis for data processing The complainants stated during the case that they concluded a credit agreement with the bank, which sold its claim against the complainants and transferred their respective data… HUNGARY ·NAIH ·Art. 5, 6 Legitimate Interest Controllers Consent Jun 3, 2019
€2,000 Local bank: Insufficient fulfilment of data subjects rights Customer of a local bank requested access to telephone conversation recordings as well as to CCTV recordings. The bank provided the copies of the recordings of telephone… HUNGARY ·NAIH ·Art. 12, 15, 18 Personal Data Controllers Insurance May 31, 2019
€2,000 Mayor: Insufficient legal basis for data processing The administrative fine was imposed for the misuse of personal data by a mayor for campaign purposes. BELGIUM ·APD/GBA ·Art. 5, 6 Personal Data Processing Public Authority May 28, 2019
€92,146 Organizer of SZIGET festival and VOLT festival: Insufficient legal basis for data processing The NAIH found that there were inappropriate legal bases is use and that the controller did not comply with the principle of purpose limitation. Also, information on the data… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Processing May 23, 2019
€286 Directorate of Social and Child Welfare Institutions of the Ferencvaros District of Budapest: Insufficient fulfilment of data breach notification obligations The employee of the Directorate sent by mistake 9 letters to the wrong recipient, which contained personal data of 18 data subjects (including data of children, criminal data and… HUNGARY ·NAIH ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations May 21, 2019
€1,400 Police Officer: Insufficient legal basis for data processing The police officer, using his official user ID but without reference to official duties, queried the owner data concerning the license plate of a person who he did not know well… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Public Authority May 9, 2019
€194 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights Information was not provided. ÚOOÚ (CZ) ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Processing Agreement May 6, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Right of Access Personal Data Apr 29, 2019
€12,950 Sports association: Insufficient legal basis for data processing One sports association published personal data referring to judges who were granted judicial licenses online. However, not only their names were provided, but also their exact… POLAND ·UODO ·Art. 6 Personal Data Controllers Liability Apr 25, 2019
€9,400 HUNGARY DPA: Insufficient legal basis for data processing A data controller used a, in the point of view of NAIH, wrong legal basis for processing of personal data (Art. 6.1.b) for the assignment of claims. NAIH ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing Apr 17, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Anonymization Apr 12, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA ·CPDP ·Art. 5, 6, 9 Integrity and Confidentiality Principle Personal Data Healthcare Apr 8, 2019
€1,900 HUNGARY DPA: Insufficient fulfilment of data subjects rights The data controller did not fulfil the data subject's access request. NAIH ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Right of Access Personal Data Apr 5, 2019
€220,000 Private company working with data from publicly available sources: Insufficient fulfilment of information obligations The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the… POLAND ·UODO ·Art. 14 Personal Data Controllers Supervisory Authorities Mar 26, 2019
€5,100 A.P. EOOD: Insufficient legal basis for data processing The sanction was imposed on personal data administrator A.P. EOOD for unlawful processing of personal data. The personal data of data subject D.D. was used by A.P. EOOD for… BULGARIA ·CPDP ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Processing Mar 26, 2019
€10,000 CZECH REPUBLIC DPA: Non-compliance with general data processing principles Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation') and not only kept… ÚOOÚ (CZ) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Storage Limitation Personal Data Mar 21, 2019
€3,200 Unnamed financial institution: Insufficient fulfilment of data subjects rights The fine was imposed in relation to a data subject's request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting… HUNGARY ·NAIH ·Art. 5, 6, 13 +1 Retention Period Legitimate Interest Personal Data Mar 4, 2019
€50,000 N26: Insufficient legal basis for data processing The fine was imposed against against a bank (according to a newspaper N26) that had processed 'personal data of all former customers' without permission.The Bank has acknowledged… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Security Insurance Mar 1, 2019
€170,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Public Authority Mar 1, 2019
€582 CZECH REPUBLIC DPA: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… ÚOOÚ (CZ) ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Feb 28, 2019
€776 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights Information was not provided. ÚOOÚ (CZ) ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Processing Agreement Feb 26, 2019
€27,100 Telecommunication service provider: Insufficient legal basis for data processing Repeated registration of prepaid services without the knowledge and consent of the data subject Employees of the telecommunications provider have used personal data and registered… BULGARIA ·CPDP ·Art. 5, 6 Personal Data Consent Identification Feb 26, 2019
€500 Employer: Insufficient fulfilment of data subjects rights An employee sent a request to his employer for access to personal data concerning him. The request was not answered in time and not in a complete way. BULGARIA ·CPDP ·Art. 15 Right of Access Personal Data Employees Feb 22, 2019
€1,560 Debt collector: Non-compliance with general data processing principles A data subject requested information about and erasure of the data processed, which the debt collector refused stating that it could not identify the subject. For identification… HUNGARY ·NAIH ·Art. 5 Personal Data Controllers Transparency Feb 20, 2019
€5,000 Lands Authority: Insufficient technical and organisational measures to ensure information security As a result of the lack of appropriate security measures on the Lands Authority website, over 10 gigabytes of personal data became easily accessible to the public via a simple… MALTA ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Personal Data Feb 18, 2019
€1,560 Bank: Non-compliance with general data processing principles A bank mistakenly sent SMS messages about a subject's credit card debt to the telephone number of another person. After receiving an incorrect telephone number from the client at… HUNGARY ·NAIH ·Art. 5 Personal Data Processing Insurance Feb 8, 2019
€20,000 PORTUGAL DPA: Insufficient fulfilment of data subjects rights Denial of the right to access recorded phone calls by the Data Subject CNPD (PT) ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Data Subject Rights Exercise Modalities and Procedures Feb 5, 2019
€1,165 Credit brokerage: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Feb 4, 2019
€500 Bank: Insufficient legal basis for data processing A bank gained personal data concernign a student wihtout a legal basis. BULGARIA ·CPDP ·Art. 5, 6 Personal Data Processing Insurance Jan 17, 2019
Hamburger Volksbank eG: Insufficient fulfilment of data subjects rights The company had sent a customer a newsletter with advertising content by e-mail, although this customer had previously expressly objected to the sending of further advertising… GERMANY ·HmbBfDI ·Art. 21 Direct Marketing Personal Data Insurance Jan 1, 2019
€50,000 Unknown Company: Insufficient fulfilment of data subjects rights The data controller had engaged an external company to carry out the duties of access to data according to Art. 15 GDPR. However, the engaged company conducted the correspondence… GERMANY ·Art. 15, 28 ·Insufficient fulfilment of data subjects rights Controllers Fairness & Transparency Personal Data Jan 1, 2019
€500 GERMANY DPA: Insufficient fulfilment of data subjects rights A data controller failed to comply with data subject´s request to access their personal data. Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers Jan 1, 2019
€5,000 State Hospital: Insufficient fulfilment of data subjects rights A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Cyprus DPA ·Art. 15 Personal Data Controllers Healthcare Jan 1, 2019
€21,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone had processed personal data of the claimant (bank details, name, surname and national identification number) years after the contractual relationsid had ended. The fine… SPAIN ·AEPD ·Art. 6 Personal Data Telecommunications Identification Jan 1, 2019
€30,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security Disclosure of customer personal data (i.a. purchase history) via an SMS to another customer. The initial fine of EUR 50.000 was reduced to EUR 30.000. SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Telecommunications Jan 1, 2019
€800 Police Officer: Insufficient legal basis for data processing A police officer used a witness's personal data to contact her personally. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2019
€48,000 VODAFONE ONO, S.A.U.: Insufficient technical and organisational measures to ensure information security Customers could access personal data of other customers in the customer area. The initial fine of EUR 60.000 was reduced to EUR 48.000. SPAIN ·AEPD ·Art. 32 Security Personal Data Telecommunications Jan 1, 2019
€48,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The claimant's bank account was charged by the company with two invoices for the services he had contracted, however, displaying personal data of another customer. The initial… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications Jan 1, 2019
€3,200 HUNGARY DPA: Insufficient fulfilment of data subjects rights The fine was imposed for (i) not providing a data subject with CCTV recordings, (ii) not retaining recordings for further use by the data subject, and (iii) not informing the data… NAIH ·Art. 12, 13, 15 +1 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Supervision Dec 18, 2018
€500 Bank: Insufficient legal basis for data processing A fine of 1000 BGN (or roughly 500 EUR) was imposed on a bank for calling a client for the unresolved bills of his neighbor. This provoked the client to evoke his right to be… BULGARIA ·CPDP ·Art. 5, 6 Personal Data Consent Processing Dec 4, 2018
€20,000 Knuddels.de: Insufficient technical and organisational measures to ensure information security After a hacker attack in July personal data of approx. 330.000 users, including passwords and email addresses had been revealed. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Nov 21, 2018