Skip to content
Content type · 402 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 402 sort newestlargest fineoldest
€2,500 Farmacia Ardealul SRL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 2,500 on Farmacia Ardealul SRL. The controller had reported a data breach to the DPA. During its investigation, the DPA found that an… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 27, 2023
€205,000 Digi Telecommunications and Services Ltd.: Insufficient technical and organisational measures to ensure information security The Hungarian DPA has imposed a fine of EUR 205,000 against Digi Telecommunications and Services Ltd. The controller had suffered a data breach in which an unauthorized party… HUNGARY ·NAIH ·Art. 5, 32 Security Controllers Personal Data Jun 22, 2023
€8,000 Artima S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on Artima S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that employees of… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 15, 2023
€2,000 BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found… ROMANIA ·ANSPDCP ·Art. 5 Controllers Personal Data Processing Jun 15, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest Controllers Jun 8, 2023
€18,000 AUTOMOBILE BAVARIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 18,000 on AUTOMOBILE BAVARIA SRL. The data controller had notified the authority of a data breach pursuant to Art. 33 GDPR. Unknown… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default May 18, 2023
€6,700 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,700 on a municipality. The controller had reported a data breach to the DPA. During its investigation, the DPA found that the controller… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Privacy by Design & Default Controllers May 16, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers May 12, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers May 12, 2023
€2,200 Municipality: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,200 on a municipality. The controller had reported a data breach to the DPA. An employee had unauthorizedly copied a document containing… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers May 5, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Cyprus DPA ·Art. 5, 32 Security Controllers Personal Data May 2, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Retention Period Storage Limitation Security Apr 20, 2023
€7.6M TIM S.p.A.: Insufficient legal basis for data processing The Italian DPA has fined TIM S.p.A. EUR 7,631,175. The DPA had received numerous complaints about the telecommunications provider, mainly for unauthorized telemarketing… ITALY ·Garante ·Art. 5, 6, 7 +5 Personal Data Controllers Supervisory Authorities Apr 13, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Integrity and Confidentiality Principle Data Breaches Processors Mar 23, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Security Data Breaches Mar 23, 2023
€145,000 AFIANZA ASESORES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 145,000 on AFIANZA ASESORES S.L.. The controller had reported a data breach to the DPA, stating that a backpack containing a USB stick… SPAIN ·AEPD ·Art. 5, 32 Encryption Security Controllers Mar 16, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Security Encryption Right of Access Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 14, 2023
€220,000 Argon Medical Devices: Insufficient fulfilment of data breach notification obligations The Norwegian DPA has fined Argon Medical Devices EUR 220,000. The controller failed to notify the DPA of a data breach that involved personal data of all its European employees… NORWAY ·Datatilsynet (NO) ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 8, 2023
€11,100 Housing cooperative: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 11,100 on a housing cooperative. The controller had disclosed personal data of a member of the cooperative to an unauthorized person. The… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 1, 2023
€750,000 Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Data Breaches Feb 27, 2023
€40,000 Vodafone: Insufficient fulfilment of data breach notification obligations The Hellenic DPA has imposed a fine of EUR 40,000 on Vodafone. An individual had filed a complaint with the DPA because, following a request for access to records of conversations… GREECE ·HDPA ·Art. 15, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 20, 2023
€7,200 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,200 on a company. The controller had suffered a data breach that resulted in the loss of personal data. During its investigation, the… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Privacy by Design & Default Controllers Feb 8, 2023
€5,000 Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Medijobs Platform SRL. The controller had informed the DPA about a data breach according to Art. 33 GDPR. Unauthorized third… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 8, 2023
€321 Housing association: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 321 on a housing association. The controller had suffered a data breach involving the theft of documents, including a copy of a notarial… POLAND ·UODO ·Art. 5, 28, 33 +1 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 7, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA ·ANSPDCP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 31, 2023
€6,400 Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,400 on the Szczecin-Centrum District Court. The court had reported a data breach to the DPA involving the loss of three data carriers.… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Privacy by Design & Default Security Jan 19, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS ·AP ·Art. 32 Security Controllers Personal Data Jan 19, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€9,000 Magdeburg University Hospital: Insufficient fulfilment of data breach notification obligations The DPA of Sachsen-Anhalt has imposed a fine of EUR 9,000 on Magdeburg University Hospital. The clinic had failed to report to the DPA a data breach involving a former employee… GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2023
€3,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The controller had reported a data breach to the DPA according to Art. 33 GDPR. An employee had taken… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Dec 27, 2022
€100,000 VIEC Limited: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… IRELAND ·DPC ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 22, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Dec 9, 2022
€300,000 FREE SAS: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 300,000 on FREE SAS. The DPA had received several complaints from individuals experiencing difficulties in exercising their rights to… FRANCE ·CNIL ·Art. 12, 15, 17 +2 Data Breaches Personal Data Encryption Dec 8, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 25, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Personal Data Security Nov 24, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Nov 21, 2022
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Nov 16, 2022
€2,000 Romanian Post: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on the Romanian Post. The Post suffered a data breach where staff lost several mailings containing pension statements, employment… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Data Breaches Nov 7, 2022
€1,700 Mayor: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1,700 on the mayor of Dobrzyniewo Duże municipality. The mayor had reported a data breach to the DPA pursuant to Art. 33 GDPR. An… POLAND ·UODO ·Art. 5, 25, 32 Data Breaches Privacy by Design & Default Security Nov 2, 2022
DKK 500,000 Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Denmark ·Datatilsynet (DK) ·Art. 5, 9, 24 +2 Integrity and Confidentiality Principle Supervisory Authorities Encryption
€6,400 AIO E-COMMERCE, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on AIO E-COMMERCE, S.L.. The controller had suffered a data breach resulting in personal data such as bank details being siphoned off and… SPAIN ·AEPD ·Art. 5 Retention Period Security Controllers Oct 26, 2022
€5M Interserve Group Limited: Insufficient technical and organisational measures to ensure information security The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Interserve… UNITED KINGDOM ·ICO ·Art. 5, 32 Data Breaches Security Controllers Oct 19, 2022
€64,000 EVERIS SPAIN S.L: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of… AEPD ·Art. 5, 32 ·Non-compliance with general data processing principles Integrity and Confidentiality Principle Security Personal Data Oct 9, 2022
€2,000 Bitfactor SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Bitfactor SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to a malfunction of an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Sep 22, 2022
€5,000 Curtea Veche Publishing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Curtea Veche Publishing SRL. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. In the first… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Encryption Security Sep 21, 2022
€2,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Banca Comercială Română SA. The bank had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to an error in the IT… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Sep 19, 2022
€6,700 Hørsholm municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Hørsholm municipality. The municipality had reported a data breach to the DPA pursuant to Art. 33 GDPR. An employee's work… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Sep 12, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Aug 11, 2022
€285,000 Telecommunications company: Insufficient technical and organisational measures to ensure information security The Croatian DPA has fined a telecommunications company EUR 285,000. The company had suffered a data breach. Attackers had managed to access data from about 100,000 data subjects.… CROATIA ·AZOP ·Art. 25, 32 Security Personal Data Telecommunications Jul 21, 2022