Skip to content
Content type · 2,650 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2401–2450 of 2,650 sort newestlargest fineoldest
€24,000 Iberdrola Clientes: Non-compliance with general data processing principles A third person had received an electricity bill with personal details such as name, address and bank account of another customer. The reason for this was that Iberdola Clientes… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Security Personal Data Jul 2, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK ·Datatilsynet (DK) ·Art. 5, 6, 33 +1 Public Authority Data Breaches Personal Data Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE ·HDPA ·Art. 5 Personal Data Processing Education Jun 29, 2020
€7,500 Miraclia (telecommunications company): Insufficient legal basis for data processing The recording of telephone jokes via an app constitutes processing of personal data in accordance with the applicable data protection law, as the voices of individuals may… SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Jun 23, 2020
€2,000 Comunidad de propietarios demelza beach: Non-compliance with general data processing principles Illegal use of CCTV cameras due to coverage of public space and recording of passing pedestrians. Furthermore, insufficient fulfilment of information obligations. SPAIN ·AEPD ·Art. 5, 6, 13 +1 Processing Supervisory Authorities Video Surveillance Jun 22, 2020
€6,000 National Police Brigade: Insufficient legal basis for data processing Making copies of a company's business records in the context of investigations which contained data from third parties and for which there was no legal basis for processing. SPAIN ·AEPD ·Art. 5, 6 Public Authority Processing Supervisory Authorities Jun 19, 2020
Aquateknikk AS: Insufficient legal basis for data processing On June 19, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Aquateknikk AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR . This fine has been… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Processing Supervisory Authorities Supervision Jun 19, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Supervision Jun 18, 2020
€1,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The data subject repeatedly received e-mails with advertising content from a company, although the data subject had objected to the processing of his personal data and requested… APD/GBA ·Art. 17, 21, 31 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Direct Marketing Jun 16, 2020
€2,000 Café Bar: Non-compliance with general data processing principles Illegal use of CCTV cameras (recording of third parties) and insufficient fulfilment of information obligations. SPAIN ·AEPD ·Art. 5, 6, 13 +1 Processing Supervisory Authorities Video Surveillance Jun 16, 2020
€1,900 Housing Association: Non-compliance with general data processing principles Unlawful usage of surveillance cameras. In the decision, the data protection authority stressed that sound recordings have additional privacy implications, especially in a… SWEDEN ·IMY ·Art. 5, 6 Processing Video Surveillance IP Address Jun 16, 2020
€75,000 Xfera Moviles S.A.: Insufficient legal basis for data processing The data subject received a notice from a debt collection company demanding payments in connection with Xfera Móviles' services, even though the claimant had not been a customer… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Jun 15, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Jun 11, 2020
€5,000 Consulting de Seguridad e Investigacion Mira Dp Madrid S.L.: Insufficient legal basis for data processing A data subject has received marketing messages without having consented. SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Jun 9, 2020
€1,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Jun 9, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN ·AEPD ·Art. 6 Personal Data Telecommunications Representatives Jun 9, 2020
€39,000 Xfera Moviles S.A.: Insufficient legal basis for data processing A customer claimed to have received an SMS from Xfera Móviles informing about the non-payment and the resulting suspension of the service in relation to the account of another… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications Jun 9, 2020
€3,000 Salad Market S.L. (Catering Company): Insufficient fulfilment of information obligations Fines for lack of sufficient data processing information in relation to video surveillance on business premises and for insufficient information when cookies were used on its… SPAIN ·AEPD ·Art. 13, 14 Supervisory Authorities Cookies Video Surveillance Jun 9, 2020
€2,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Jun 9, 2020
€5,000 Municipal employee: Insufficient legal basis for data processing In the context of a municipal election in 2018, the data controller had sent election advertisements to a group of employees of the same municipal administration, unlawfully using… BELGIUM ·APD/GBA ·Art. 5, 6 Public Authority Controllers Processing Jun 8, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6, 35 Retention Period DPIA Profiling May 29, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ÚOOÚ (CZ) ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Controllers Processing May 26, 2020
€16,000 Kymen Vesi Oy: Non-compliance with general data processing principles Fine for failure to carry out a data protection impact assessment ('DPIA') for the processing of location data of employees with a vehicle information system FINLAND ·Deputy Data Protection Ombudsman ·Art. 35 DPIA Processing Employees May 22, 2020
€12,500 Unknown Company: Insufficient legal basis for data processing Processing of employee data without sufficient legal basis. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6 Processing Employees Human Resources May 22, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·DPC ·Art. 5, 6 Public Authority Personal Data Processing May 17, 2020
€50,000 Social Media Provider: Insufficient legal basis for data processing The company has sent invitations to contacts uploaded by its users without their consent or any other legal basis. BELGIUM ·APD/GBA ·Art. 6 Consent Social Media Processing May 14, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·IMY ·Art. 5, 6 Personal Data Public Authority Processing May 12, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance May 5, 2020
€500 Housing Association: Insufficient legal basis for data processing Fine of EUR 500 against a housing association for publishing photos showing members of the association without their consent. ESTONIA ·AKI ·Art. 6 Consent Processing Supervisory Authorities Apr 30, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS ·AP ·Art. 5, 9 Consent Personal Data Processing Apr 30, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM ·APD/GBA ·Art. 31, 37, 58 Supervisory Authorities Data Breaches Notification Obligation Apr 28, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Apr 23, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ANSPDCP ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Personal Data Healthcare Types of Special Categories of Personal Data Apr 23, 2020
€2,000 Political Party: Insufficient legal basis for data processing Forging signatures on a voters' list. BULGARIA ·CPDP ·Art. 6 Public Authority Education Processing Apr 14, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE ·HDPA ·Art. 5, 6 Retention Period Controllers Processing Apr 7, 2020
€2,890 Bank: Insufficient legal basis for data processing Due to an administrative error, the personal data of the data subject were registered and transferred to the Central Credit Information System (CCI) in connection with a loan… HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 26, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Mar 25, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Mar 25, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Mar 25, 2020
€3,000 Dante International: Insufficient legal basis for data processing The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. ROMANIA ·ANSPDCP ·Art. 6, 21 Personal Data Processing Supervision Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS ·AP ·Art. 9, 32 Security Healthcare Controllers Mar 24, 2020
€8,000 Speech and Special Education Centre - Mihou Dimitra: Insufficient fulfilment of data subjects rights The complainant had requested access to his child's data and to tax information. This request was rejected by the data controller. In addition, the data controller had violated an… GREECE ·HDPA ·Art. 15, 58 Personal Data Controllers Supervisory Authorities Mar 20, 2020
€5,800 Unknown Company: Insufficient fulfilment of data subjects rights The data controller has not complied with its obligation regarding the right of access to video recordings and was also unable to demonstrate that his data processing activities… HUNGARY ·NAIH ·Art. 6, 15 Personal Data Right of Access Controllers Mar 19, 2020
€6,000 Oliveros Ustrell, S.L.: Insufficient legal basis for data processing The company forwarded an unsigned porting contract to the operator Vodafone. However, the data controller was unable to provide evidence of the order. For this reason, the… SPAIN ·AEPD ·Art. 5, 6 Controllers Personal Data Processing Mar 19, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Mar 16, 2020
€6,000 Amalfi Servicios de Restauracion S.L.: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·AEPD ·Art. 5, 13, 14 Retention Period Processing Supervisory Authorities Mar 16, 2020
€4,000 Private Person: Insufficient legal basis for data processing On a beach, a private person secretly photographed female bathers. The incident was reported to the AEPD by the local police. SPAIN ·AEPD ·Art. 5, 6 Processing Supervisory Authorities Mar 16, 2020
€2,000 Homeowners Association: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·AEPD ·Art. 5, 13, 14 Retention Period Processing Supervisory Authorities Mar 12, 2020
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Mar 9, 2020
€870 Creditor: Insufficient legal basis for data processing Sending of SMS to a data subject as a reminder for a debt, even when the debt has already been paid. HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 9, 2020