Skip to content
Content type · 3,594 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2401–2450 of 3,594 sort newestlargest fineoldest
€5,000 Arte del vivere S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Arte del vivere S.r.l.. A data subject filed a complaint with the DPA as his personal data had been published on the website… ITALY ·Garante ·Art. 12, 17, 157 Personal Data Controllers Supervisory Authorities Feb 10, 2022
€10,000 Costampress S.p.A.: Insufficient legal basis for data processing The company had left the e-mail account of the data subject active even after the termination of his employment and did not provide sufficient information about this. ITALY ·Garante ·Art. 5, 12, 13 Personal Data Processing Supervisory Authorities Feb 10, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Personal Data Security Supervisory Authorities Feb 10, 2022
€1,500 Studio Colli Aniene Verderocca S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,500 on Studio Colli Aniene Verderocca S.r.l.. A data subject had filed a complaint with the DPA for unsolicited telephone advertising.… ITALY ·Garante ·Art. 12, 14, 15 +2 Personal Data Direct Marketing Supervisory Authorities Feb 10, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Garante Storage Limitation Retention Period Fairness & Transparency Feb 10, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Processing Feb 10, 2022
€634,000 Budapest Bank Zrt.: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has fined Budapest Bank Zrt. EUR 634,000. NAIH reports that the bank used an artificial intelligence-driven software solution to automate the evaluation… HUNGARY ·NAIH ·Art. 5, 6, 12 +5 Right to Object Legitimate Interest Personal Data Feb 8, 2022
€10,000 PINTODIS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined PINTODIS, S.L. EUR 10,000. The controller had installed several video cameras which also covered the food areas and changing rooms of their employees.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Feb 7, 2022
€1,000 Cafe operator: Non-compliance with general data processing principles The cafe used CCTV cameras which also captured the public space outside resulting in a violation of the so called principle of data minimisation. SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Feb 7, 2022
€10,000 Εκδοτικού Οίκου Δίας: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the publisher Εκδοτικού Οίκου Δίας. A public figure had filed a complaint with the DPA. The publisher had published incorrect… CYPRUS ·Cyprus DPA ·Art. 5, 6 Personal Data Processing Telecommunications Feb 4, 2022
€2,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a private individual. The individual had published audiovisual material of a court trial on Twitter without obtaining the… SPAIN ·AEPD ·Art. 6 Consent Social Media Supervisory Authorities Feb 4, 2022
€300,000 SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS. in the amount of EUR 300,000. The data subject had received marketing emails from the controller… SPAIN ·AEPD ·Art. 6, 17, 28 Personal Data Controllers Supervisory Authorities Feb 4, 2022
€900 Private person: Non-compliance with general data processing principles Unlawful usage of video surveillance cameras which also monitored parts of the public space (violation of principle of data minimization). SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Feb 4, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 32 Security Personal Data Public Authority Feb 2, 2022
€1,000 Café owner: Non-compliance with general data processing principles The DPA from Luxembourg has imposed a fine of EUR 1,000 on a café owner. The owner had installed two video surveillance cameras in the café for the purpose of protecting company… LUXEMBOURG ·CNPD (LU) ·Art. 5, 13 Retention Period Processing Supervisory Authorities Feb 2, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +8 Fairness & Transparency Marketing Transparency Feb 2, 2022
€2,000 ASESORES DE SEGURIDAD PRIVADA, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on ASESORES DE SEGURIDAD PRIVADA, S.L.. The DPA criticized that the controller did not sufficiently inform the data subject about… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Feb 2, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Insurance Processing Agreement Feb 1, 2022
€900,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined TELEFÓNICA MÓVILES ESPAÑA, S.A.U. EUR 900,000. Four Telefónica customers had filed complaints with the DPA. In the course of its investigation, the DPA… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications Feb 1, 2022
€3.9M Vodafone España, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Vodafone España, S.A.U. EUR 3.94 million. Nine Vodafone customers had filed complaints with the DPA. In the course of its investigation, the DPA found… SPAIN ·AEPD ·Art. 5 Security Personal Data Processing Feb 1, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 1, 2022
€700,000 Orange Espagne S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined Orange Espagne S.A.U. EUR 700,000. Two Orange Espagne customers had filed complaints with the DPA. In the course of its investigation, the DPA found that… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€200,000 XFERA MÓVILES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined XFERA MÓVILES, S.A. EUR 200,000. Two Xfera customers had filed complaints with the DPA. In the course of its investigation, the DPA found that fraudsters… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€70,000 ORANGE ESPAÑA VIRTUAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined ORANGE ESPAÑA VIRTUAL, S.L. EUR 70,000. Two Orange España Virtual customers had filed complaints with the DPA. In the course of its investigation, the… SPAIN ·AEPD ·Art. 5 Personal Data Processing IP Address Feb 1, 2022
€1,500 Property Owner Community: Insufficient legal basis for data processing Use of CCTV cameras in building complex without obtaining the consent of all the property owners. SPAIN ·AEPD ·Art. 6 Consent Video Surveillance Processing Jan 31, 2022
€5,000 INCOPROSOL, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined INCOPROSOL, S.L. EUR 5,000. The controller had recorded a telephone conversation with a customer without obtaining the customer's consent. SPAIN ·AEPD ·Art. 5 Controllers Processing Consent Jan 31, 2022
€5,000 Cyrana España General S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Cyrana España General S.L. EUR 5,000. The controller had sent an invoice to the data subject although no contractual relationship existed. SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Jan 31, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +5 Fairness & Transparency Anonymization Pseudonymization Jan 27, 2022
€2,000 Private club 'Ruian': Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 2,000 on the private club 'Ruian'. The controller had installed video surveillance cameras which, among other things, also… ITALY ·Garante ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jan 27, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches Anonymization Security Jan 27, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Data Portability Recipient Personal Data Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +3 Anonymization Pseudonymization Fairness & Transparency Jan 27, 2022
€3.2M OTE Group: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 3.2 million on Cosmote subsidiary OTE Group. Among other things, OTE Group had contributed to Cosmote's security infrastructure. Cosmote… GREECE ·HDPA ·Art. 32 Data Breaches Notification Obligation Security Jan 27, 2022
€40,000 T.S.M. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on T.S.M. s.r.l.. A data subject had filed a complaint with the DPA against the company for failing to comply with their requests… ITALY ·Garante ·Art. 13, 15, 21 +2 Personal Data Supervisory Authorities Processing Jan 27, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jan 26, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·IMY ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 26, 2022
€1,200 Property Owner Community: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a property owners' community EUR 1,200. A property manager had sent a copy of the general meeting minutes to the director of the security company… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jan 21, 2022
APD/GBA · 11/2022 The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·Art. 4, 5, 7 +2 Supervisory Authorities Legitimate Interest Supervision Jan 21, 2022
€2,000 Website operator: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) imposed a fine of EUR 2,000 on a website operator for the lack of a privacy policy on its website, in violation of Art. 13 GDPR. SPAIN ·AEPD ·Art. 13 Supervisory Authorities Jan 21, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Right of Access Personal Data Controllers Jan 20, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Encryption Security Pseudonymization Jan 19, 2022
€117,000 Santander Bank Polska S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 118,000 for failing to notify data subjects of a data breach. A former employee of the bank managed to gain unauthorized… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Personal Data Jan 19, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Encryption Security Jan 19, 2022
€15,000 GARLEX SOLUTIONS, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on GARLEX SOLUTIONS, S.L.. The data subject had received a call from the company to renew their electricity supply… SPAIN ·AEPD ·Art. 6 Personal Data Consent Supervisory Authorities Jan 18, 2022
€56,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine on VODAFONE ESPAÑA, S.A.U. due to insufficient legal basis for data processing. The data subject states that two telephone connections were… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Jan 18, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
€2,000 MEETING PUERTO C.B.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on MEETING PUERTO C.B.. The data controller had unlawfully published a picture of the complainant with his partner on Facebook and… SPAIN ·AEPD ·Art. 6 Controllers Social Media Processing Jan 17, 2022
€1,500 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,500 on a private individual. The person had installed video cameras in the apartment building where he lives, which recorded, among… SPAIN ·AEPD ·Art. 5 Retention Period Processing IP Address Jan 17, 2022
€525,000 DPG Media Magazines B.V.: Insufficient fulfilment of data subjects rights The Dutch DPA has imposed a fine of EUR 525,000 on DPG Media Magazines B.V. The DPA had received several complaints regarding the way the controller handled requests from… THE NETHERLANDS ·AP ·Art. 12 Personal Data Controllers Supervisory Authorities Jan 14, 2022