Skip to content
Content type · 394 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 394 sort newestlargest fineoldest
€70,000 CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. The data subject had received a message from a debt collection company on behalf… SPAIN ·aepd ·Art. 6 Personal Data Insurance Processing Mar 21, 2023
€145,000 AFIANZA ASESORES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 145,000 on AFIANZA ASESORES S.L.. The controller had reported a data breach to the DPA, stating that a backpack containing a USB stick… SPAIN ·aepd ·Art. 5, 32 Encryption Data Breaches Security Mar 16, 2023
€10,000 Banca Cambiano 1884 S.p.A.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Insurance Supervisory Authorities Mar 9, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Privacy by Design & Default Mar 6, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Privacy by Design & Default Mar 6, 2023
€15,000 GRUPO NORCONSULTING, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 15,000 on GRUPO NORCONSULTING, S.L.. A data subject had filed a complaint against the controller with the DPA due to the controller's… SPAIN ·aepd ·Art. 15, 17 Personal Data Controllers Processing Agreement Feb 28, 2023
€4,000 Attorney: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 4,000 on an attorney. The attorney had sent a court ruling containing personal data of a data subject to several individuals via WhatsApp… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Agreement Insurance Feb 27, 2023
€750,000 Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain… Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Feb 27, 2023
€440,000 Suomen Asiakastieto Oy: Insufficient cooperation with supervisory authority The Finnish DPA has imposed a fine of EUR 440,000 on Suomen Asiakastieto Oy for failing to comply with an order issued by the DPA. During an investigation, the DPA found that the… FINLAND ·Deputy Data Protection Ombudsman ·Art. 58 Supervisory Authorities Supervision Processing Agreement Feb 17, 2023
€7,200 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,200 on a company. The controller had suffered a data breach that resulted in the loss of personal data. During its investigation, the… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Controllers Feb 8, 2023
€30,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 30,000 on Piraeus Bank. A customer had filed a complaint with the DPA because the bank had disclosed transaction and account balance… GREECE ·HDPA ·Art. 5, 33, 34 Personal Data IP Address Insurance Feb 2, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Security Education Jan 19, 2023
€56,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. An individual had filed a complaint with the DPA because the controller had disclosed their personal… SPAIN ·aepd ·Art. 5, 32 Personal Data Controllers IP Address Jan 19, 2023
€56,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card to an… SPAIN ·aepd ·Art. 6 Insurance Processing Agreement Personal Data Jan 16, 2023
€40,000 Thomas International Systems, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Thomas International Systems, S.A.. Thomas International performs psychological tests on behalf of other companies. Thomas International had… SPAIN ·aepd ·Art. 9 Insurance Personal Data Controllers Jan 16, 2023
€8,000 Bank of Cyprus Public Company Ltd.: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on Bank of Cyprus Public Company Ltd.. The controller had stored inaccurate data about a data subject in its system. Art. 5 ·Non-compliance with general data processing principles Accuracy Controllers Personal Data Jan 1, 2023
Clinic: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a clinic for transmitting an unredacted treatment report on the psychiatric treatment of the data subject to an accident insurance fund… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Insurance Healthcare Personal Data Jan 1, 2023
€10,000 SUDREZIDENȚIAL Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on SUDREZIDENȚIAL Broker S.R.L.. An employee of the controller had unauthorizedly published an Excel spreadsheet containing… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Insurance Dec 22, 2022
€750,000 Alektum Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has fined the debt collection company Alektum Oy EUR 750 000. The DPA opened an investigation against the controller after three people filed complaints against… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 15 Controllers Personal Data Supervisory Authorities Dec 13, 2022
€8,000 Notary: Insufficient legal basis for data processing The Spanish DPA has fined a notary. The controller had consulted the land register of a property belonging to the data subject without an order requiring the consultation of this… SPAIN ·aepd ·Art. 6 Personal Data Controllers Prior Consultation Dec 9, 2022
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Health Data Social Media Insurance Nov 30, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Security Nov 25, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Nov 21, 2022
€28,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 28,000 on Raiffeisen Bank SA. The bank had reported several data breaches pursuant to Art. 33 GDPR to the DPA. During its investigation,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Nov 16, 2022
€80,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANKINTER, S.A.. A person had filed a complaint with the DPA as personal data of a third person were also displayed to them when accessing… SPAIN ·aepd ·Art. 5, 32 Personal Data Insurance IP Address Nov 15, 2022
€48,000 Banco Bilbao Vizcaya Argentaria S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. An individual had filed a complaint with the DPA due to requesting information on one of their… SPAIN ·aepd ·Art. 5, 32 Processing Agreement IP Address Security Nov 11, 2022
€2,000 Rapido Finance, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on Rapido Finance, S.L.. The data subject had received a message from a company on behalf of Rapid Finance requesting payment of… SPAIN ·aepd ·Art. 6 Personal Data Insurance Processing Agreement Nov 2, 2022
€25,000 CAIXABANK S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 25,000 on CAIXABANK S.A.. The data subject had repeatedly and unsuccessfully requested that their address on file with the bank be… SPAIN ·aepd ·Art. 16 Personal Data Processing Agreement Insurance Nov 2, 2022
€70,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A customer of the bank had filed a complaint with the DPA. The customer had in the past,… SPAIN ·aepd ·Art. 5, 32 IP Address Personal Data Processing Agreement Oct 31, 2022
€10,000 ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP. The law firm had collected personal data from website users without obtaining their… SPAIN ·aepd ·Art. 6, 13 Personal Data Controllers Processing Agreement Oct 26, 2022
€64,000 EVERIS SPAIN S.L: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EVERIS SPAIN S.L.. Everis had published information on sold data of users of an insurance company as well as records with personal data of… aepd ·Art. 5, 32 ·Non-compliance with general data processing principles Data Breaches Integrity and Confidentiality Principle Professional Secrecy Oct 9, 2022
€24,000 CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A data subject filed a complaint with the DPA. The data subject had taken… SPAIN ·aepd ·Art. 6 Insurance Personal Data Controllers Oct 9, 2022
€72,500 Bank: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 72,500 on a bank. An individual had filed a complaint with the DPA. The bank had conducted a credit check on the individual based on a… HUNGARY ·NAIH ·Art. 5, 6, 12 Insurance Processing Agreement Processing Oct 5, 2022
€20,000 PIRAEUS BANK S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on PIRAEUS BANK S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were… GREECE ·HDPA ·Art. 13 IP Address Insurance Processing Agreement Oct 3, 2022
€20,000 NATIONAL BANK OF GREECE S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on NATIONAL BANK OF GREECE S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions… HDPA ·Art. 13 ·Insufficient fulfilment of information obligations IP Address Processing Agreement Insurance Oct 3, 2022
€20,000 ALFA BANK S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on ALFA BANK S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were stored… GREECE ·HDPA ·Art. 13 IP Address Insurance Consent Oct 3, 2022
€20,000 EUROBANK ERGASIAS S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on EUROBANK ERGASIAS S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were… GREECE ·HDPA ·Art. 13 IP Address Insurance Consent Oct 3, 2022
€1,200 Health insurance provider: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This… HUNGARY ·NAIH ·Art. 5, 12, 31 Insurance Healthcare Personal Data Sep 25, 2022
€2,000 Bitfactor SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Bitfactor SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to a malfunction of an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Sep 22, 2022
€2,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Banca Comercială Română SA. The bank had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to an error in the IT… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security IP Address Sep 19, 2022
€10,000 Bper Banca S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Bper Banca S.p.A.. An individual had filed a complaint with the DPA regarding the failure to fulfill their right to erasure of… ITALY ·Garante ·Art. 12 Right to be Forgotten Data Subject Rights Exercise Modalities and Procedures Personal Data Sep 15, 2022
€2,000 SC Raiffeisen Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on SC Raiffeisen Bank SA. An individual had filed a complaint with the DPA for receiving text messages about money transfers to… ROMANIA ·ANSPDCP ·Art. 5 Insurance Personal Data IP Address Sep 9, 2022
€6,800 TIMSHEL Sp. z o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined TIMSHEL Sp. z o.o. EUR 6,800 for failing to provide information requested by the DPA during an investigation POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Processing Agreement Aug 30, 2022
€1,000 Alpha Bank Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Alpha Bank Romania SA. The bank had accidentally sent a document to the wrong recipient via WhatsApp. The document contained… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Recipient Security Processing Agreement Aug 29, 2022
€900 UNONO NET 3.0, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNONO NET 3.0, S.L.. The company had forwarded an email to numerous recipients without using the blind copy function, making it possible for… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Insurance Aug 22, 2022
€42,000 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. The company had repeatedly sent advertising messages to a data subject, although the data subject had… SPAIN ·aepd ·Art. 6 Processing Agreement Personal Data Direct Marketing Aug 2, 2022
€900,000 Hannoversche Volksbank: Insufficient legal basis for data processing The DPA of Lower Saxony has imposed a fine of EUR 900,000 on Hannoversche Volksbank. The bank had analyzed data from active and former customers without their consent. For this… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Insurance Direct Marketing Consent Jul 28, 2022
€20,000 DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A.: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A. in the amount of EUR 20,000. An individual had filed a complaint with the DPA for receiving… HDPA ·Art. 5, 6, 12 ·Insufficient fulfilment of data subjects rights Personal Data Insurance Processing Agreement Jul 19, 2022
€56,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 56,000 on BANKINTER, S.A.. The controller had inadvertently sent a report on the data subject's investment portfolio to a third party.… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Processing Agreement Jul 18, 2022
€67,200 SIRIUS (law firm): Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 67,200 on the law firm SIRIUS. The law firm had suffered a cyber attack in which hackers gained access to the firm's servers and encrypted… DENMARK ·Datatilsynet ·Art. 32 Encryption Integrity and Confidentiality Principle Data Breaches Jul 14, 2022