Content type · 240 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY · ·Art. 5, 13 Oct 29, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA · ·Art. 5 Oct 21, 2020
€22M British Airways: Insufficient technical and organisational measures to ensure information security In July 2019, the ICO issued a notice of its intention to fine British Airways £183.39M for GDPR infringements which likely involve a breach of Art. 32 GDPR. The proposed fine… UNITED KINGDOM · ·Art. 5, 32 Oct 16, 2020
€35M H&M Hennes & Mauritz Online Shop A.B. & Co. KG: Insufficient legal basis for data processing The fashion company with seat in Hamburg operates a service center in Nuremberg. Here, according to the findings of the Hamburg data protection officer, since at least 2014… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Oct 1, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY · ·Art. 5, 32 Sep 3, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The complainant, through her attorney, requested access to her personal data. The accused failed to respond, even… CZECH REPUBLIC · ·Art. 15 Aug 31, 2020
€1,000 Supermarket: Insufficient legal basis for data processing The operator of a supermarket displayed the letter of dismissal to the personnel manager on the publicly visible notice board of the supermarket. ITALY · ·Art. 5, 6 Aug 4, 2020
HDPA (Greece) - 23/2020 The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Art. 4, 5, 12 +6 Jul 30, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA · ·Art. 17 Jul 30, 2020
€55,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing Telefónica Móviles España has processed the personal data of a data subject, such as first and last name and bank details, in order to activate three telephone lines that were… SPAIN · ·Art. 5, 6 Jul 23, 2020
€200,000 Merlini s.r.l.: Insufficient legal basis for data processing The company had carried out telemarketing activities on behalf of Wind Tre S.p.A. through a third party provider as data processor without sufficient legal basis fpr data… ITALY · ·Art. 5, 6, 7 +2 Jul 13, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY · ·Art. 32, 35 Jul 10, 2020
€3,400 East Power Sp. z o.o.: Insufficient cooperation with supervisory authority After three subpoenas to East Power, in which the latter failed to provide sufficient explanations on a direct marketing complaint, the data protection authority found that East… POLAND · ·Art. 31, 58 Jul 10, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK · ·Art. 5, 6, 33 +1 Jun 30, 2020
€12,500 Unknown Company: Insufficient legal basis for data processing Processing of employee data without sufficient legal basis. FINLAND · ·Art. 5, 6 May 22, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Apr 29, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS · ·Art. 9, 32 Mar 24, 2020
€48,000 HM Hospitales: Insufficient legal basis for data processing The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the… SPAIN · ·Art. 5, 6 Feb 25, 2020
€80,000 Iberdrola Clientes: Insufficient legal basis for data processing Iberdola Clientes, an electricity company, terminated the data subject's contract without its consent, concluded three new contracts with the data subject, processed his personal… SPAIN · ·Art. 6 Feb 14, 2020
€30,000 Sapienza Università di Roma: Insufficient technical and organisational measures to ensure information security The fine is based on the fact that, according to the data protection authority, the Sapienza Università made available online identification data of two people who had reported… ITALY · ·Art. 5, 32 Jan 23, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY · ·Art. 5, 32 Jan 23, 2020
€15,000 Allseas Marine S.A.: Non-compliance with general data processing principles The data protection supervisory authority has fined the extent to which employee data are processed by a video surveillance system in the workplace, the fact that the introduction… GREECE · ·Art. 5 Jan 13, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC · ·Art. 5, 12, 28 Jan 1, 2020
Municipality: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC · ·Art. 5, 6, 13 +1 Jan 1, 2020
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company has excessively processed the personal data of his employees through the video cameras installed in the offices and in the places where there are cabinets where the… ROMANIA · ·Art. 5, 6, 7 Dec 13, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA · ·Art. 5, 25, 32 +1 Dec 10, 2019
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone has sent the customer's invoice data to unauthorised third parties following a customer invoice complaint. Originally, a fine of EUR 75,000 was threatened, but was… SPAIN · ·Art. 6 Nov 6, 2019
€2,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Art. 6, 9 ·Insufficient legal basis for data processing Oct 25, 2019
€70,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Art. 6, 9 ·Insufficient legal basis for data processing Oct 25, 2019
€10,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Art. 6, 9 ·Insufficient legal basis for data processing Oct 25, 2019
€2,500 UTTIS INDUSTRIES SRL: Insufficient fulfilment of information obligations The sanctions were applied to the controller because he could not prove that the data subjects were informed about the processing of personal data / images through the video… ROMANIA · ·Art. 5, 6, 12 +1 Oct 17, 2019
€2,860 Unknown Company: Non-compliance with general data processing principles An employee was on sick leave when his employer checked his desktop, laptop and emails to ensure that his work-related duties were being covered in his absence. The employer then… HUNGARY · ·Art. 5, 6, 13 +2 Oct 15, 2019
€1,121 Private enforcement agent: Insufficient fulfilment of data subjects rights The fine of EUR 1, 121 was imposed on a private enforcement agent for processing of the personal data of data subject through recording by technical means for video surveillance… BULGARIA · ·Art. 12, 15 Sep 3, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA · ·Art. 32 Jul 5, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA · ·Art. 32 Jul 2, 2019
€1,400 Police Officer: Insufficient legal basis for data processing The police officer, using his official user ID but without reference to official duties, queried the owner data concerning the license plate of a person who he did not know well… GERMANY ·Art. 6 ·Insufficient legal basis for data processing May 9, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY · ·Art. 32 Apr 17, 2019
€20,000 Hamburger Verkehrsverbund GmbH (HVV GmbH): Insufficient fulfilment of data breach notification obligations On July 6, 2018, HVV GmbH was informed by a customer about a security gap on the website www.hvv.de, which was caused by an update on February 5, 2018 and concerned the so-called… GERMANY ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Jan 1, 2019
€294,000 GERMANY DPA: Non-compliance with general data processing principles A company was fined EUR 294 000 for 'unnecessarily long' storage and retention of personnel files and for 'excessive' data collection in the personnel selection process, during… Art. 5 ·Non-compliance with general data processing principles Jan 1, 2019
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL · ·Art. 5, 32 Jul 17, 2018