Skip to content
Content type · 408 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 408 sort newestlargest fineoldest
€210,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 210,000 on Piraeus Bank. During its investigation, the DPA found that the bank had processed personal data of customers in violation of… GREECE ·HDPA ·Art. 5, 6, 15 +1 Privacy by Design & Default Personal Data Security Jun 12, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest Controllers Jun 8, 2023
€20,000 RCI BANQUE, S.A. SUCURSAL EN ESPAÑA: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 RCI BANQUE, S.A. SUCURSAL EN ESPAÑA. A data subject complained that she was receiving text messages from the controller,… SPAIN ·AEPD ·Art. 17 Personal Data Controllers Supervisory Authorities Jun 7, 2023
€42,000 PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PELAYO, MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJA. An individual had filed a complaint with the DPA because the controller had disclosed… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Jun 1, 2023
€300,000 Deutsche Kreditbank: Insufficient fulfilment of data subjects rights The DPA of Berlin has imposed a fine of EUR 300,000 on Deutsche Kreditbank. A customer had filed a complaint with the DPA. The customer had submitted an application for a credit… GERMANY ·Art. 5, 15, 22 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities May 31, 2023
€10,000 Santander Consumer Bank S.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Santander Consumer Bank S.p.a. EUR 10,000 for not sufficiently fulfilling its obligation to comply with a data subject's request for access to their data. ITALY ·Garante ·Art. 12 Personal Data Supervisory Authorities Insurance May 17, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data May 12, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers May 12, 2023
€11,000 Libra Internet Bank SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 11,000 on Libra Internet Bank SA. An individual had filed a complaint against the bank due to the bank's failure to fully comply with… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Supervisory Authorities Supervision May 11, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·AZOP ·Art. 6, 13, 28 +1 Controllers Personal Data Processors May 4, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… CYPRUS ·Cyprus DPA ·Art. 5, 32 Security Controllers Personal Data May 2, 2023
€84,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. During its investigation, the DPA found that the controller had registered alleged debts of a former… SPAIN ·AEPD ·Art. 6, 15 Personal Data Controllers Supervisory Authorities Apr 4, 2023
€1,000 INMARAN ASESORES S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on INMARAN ASESORES S.L. for failing to comply with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Insurance Mar 24, 2023
€70,000 CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. The data subject had received a message from a debt collection company on behalf… SPAIN ·AEPD ·Art. 6 Personal Data Insurance Supervisory Authorities Mar 21, 2023
€145,000 AFIANZA ASESORES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 145,000 on AFIANZA ASESORES S.L.. The controller had reported a data breach to the DPA, stating that a backpack containing a USB stick… SPAIN ·AEPD ·Art. 5, 32 Encryption Security Controllers Mar 16, 2023
€10,000 Banca Cambiano 1884 S.p.A.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Insurance Mar 9, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€15,000 GRUPO NORCONSULTING, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 15,000 on GRUPO NORCONSULTING, S.L.. A data subject had filed a complaint against the controller with the DPA due to the controller's… SPAIN ·AEPD ·Art. 15, 17 Personal Data Controllers Supervisory Authorities Feb 28, 2023
€750,000 Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Data Breaches Feb 27, 2023
€4,000 Attorney: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 4,000 on an attorney. The attorney had sent a court ruling containing personal data of a data subject to several individuals via WhatsApp… SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Feb 27, 2023
€440,000 Suomen Asiakastieto Oy: Insufficient cooperation with supervisory authority The Finnish DPA has imposed a fine of EUR 440,000 on Suomen Asiakastieto Oy for failing to comply with an order issued by the DPA. During an investigation, the DPA found that the… FINLAND ·Deputy Data Protection Ombudsman ·Art. 58 Supervisory Authorities Supervision Personal Data Feb 17, 2023
€7,200 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,200 on a company. The controller had suffered a data breach that resulted in the loss of personal data. During its investigation, the… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Privacy by Design & Default Controllers Feb 8, 2023
€30,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 30,000 on Piraeus Bank. A customer had filed a complaint with the DPA because the bank had disclosed transaction and account balance… GREECE ·HDPA ·Art. 5, 33, 34 Personal Data Supervisory Authorities Processing Feb 2, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS ·AP ·Art. 32 Security Controllers Personal Data Jan 19, 2023
€56,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. An individual had filed a complaint with the DPA because the controller had disclosed their personal… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing Jan 19, 2023
€40,000 Thomas International Systems, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Thomas International Systems, S.A.. Thomas International performs psychological tests on behalf of other companies. Thomas International had… SPAIN ·AEPD ·Art. 9 Personal Data Types of Special Categories of Personal Data Controllers Jan 16, 2023
€56,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an… SPAIN ·AEPD ·Art. 6 Personal Data Consent Insurance Jan 16, 2023
Clinic: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a clinic for transmitting an unredacted treatment report on the psychiatric treatment of the data subject to an accident insurance fund… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Insurance Healthcare Jan 1, 2023
€8,000 Bank of Cyprus Public Company Ltd.: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on Bank of Cyprus Public Company Ltd.. The controller had stored inaccurate data about a data subject in its system. Cyprus DPA ·Art. 5 ·Non-compliance with general data processing principles Controllers Personal Data Processing Jan 1, 2023
€10,000 SUDREZIDENȚIAL Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on SUDREZIDENȚIAL Broker S.R.L.. An employee of the controller had unauthorizedly published an Excel spreadsheet containing… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Dec 22, 2022
€750,000 Alektum Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has fined the debt collection company Alektum Oy EUR 750 000. The DPA opened an investigation against the controller after three people filed complaints against… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 15 Personal Data Supervisory Authorities Controllers Dec 13, 2022
€8,000 Notary: Insufficient legal basis for data processing The Spanish DPA has fined a notary. The controller had consulted the land register of a property belonging to the data subject without an order requiring the consultation of this… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Dec 9, 2022
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Consent Personal Data Types of Special Categories of Personal Data Nov 30, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 25, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Nov 21, 2022
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Nov 16, 2022
€80,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANKINTER, S.A.. A person had filed a complaint with the DPA as personal data of a third person were also displayed to them when accessing… SPAIN ·AEPD ·Art. 5, 32 Security Personal Data Processing Nov 15, 2022
€48,000 Banco Bilbao Vizcaya Argentaria S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. An individual had filed a complaint with the DPA due to requesting information on one of their… SPAIN ·AEPD ·Art. 5, 32 Security Processing Privacy by Design & Default Nov 11, 2022
€2,000 Rapido Finance, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on Rapido Finance, S.L.. The data subject had received a message from a company on behalf of Rapid Finance requesting payment of… SPAIN ·AEPD ·Art. 6 Personal Data Insurance Supervisory Authorities Nov 2, 2022
€25,000 CAIXABANK S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 25,000 on CAIXABANK S.A.. The data subject had repeatedly and unsuccessfully requested that their address on file with the bank be… SPAIN ·AEPD ·Art. 16 Personal Data Supervisory Authorities Insurance Nov 2, 2022
€70,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A customer of the bank had filed a complaint with the DPA. The customer had in the past,… SPAIN ·AEPD ·Art. 5, 32 Personal Data Security Processing Oct 31, 2022
€10,000 ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP. The law firm had collected personal data from website users without obtaining their… SPAIN ·AEPD ·Art. 6, 13 Personal Data Controllers Consent Oct 26, 2022
€24,000 CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A data subject filed a complaint with the DPA. The data subject had taken… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Oct 9, 2022
€64,000 EVERIS SPAIN S.L: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of… AEPD ·Art. 5, 32 ·Non-compliance with general data processing principles Integrity and Confidentiality Principle Security Personal Data Oct 9, 2022
€72,500 Bank: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 72,500 on a bank. An individual had filed a complaint with the DPA. The bank had conducted a credit check on the individual based on a… HUNGARY ·NAIH ·Art. 5, 6, 12 Supervisory Authorities Processing Insurance Oct 5, 2022
€20,000 ALFA BANK S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on ALFA BANK S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were stored… GREECE ·HDPA ·Art. 13 Supervisory Authorities Consent Insurance Oct 3, 2022
€20,000 EUROBANK ERGASIAS S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on EUROBANK ERGASIAS S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were… GREECE ·HDPA ·Art. 13 Supervisory Authorities Consent IP Address Oct 3, 2022
€20,000 PIRAEUS BANK S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on PIRAEUS BANK S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were… GREECE ·HDPA ·Art. 13 Consent Supervisory Authorities Insurance Oct 3, 2022
€20,000 NATIONAL BANK OF GREECE S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on NATIONAL BANK OF GREECE S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions… HDPA ·Art. 13 ·Insufficient fulfilment of information obligations Supervisory Authorities Consent Insurance Oct 3, 2022