Skip to content
Content type · 227 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–227 of 227 sort newestlargest fineoldest
€4,200 Marbella Resorts S.L.: Insufficient data processing agreement The Spanish DPA (AEPD) has imposed a fine of EUR 7,000 on Marbella Resorts S.L.. In the case at hand, the data subject had booked a room in the hotel complex of the controller. On… SPAIN ·AEPD ·Art. 28 Controllers Personal Data Processors Jul 6, 2021
Insurance company: Insufficient fulfilment of information obligations The DPA has ex officio, without prior notice, conducted a direct supervision over an insurance company based in Zagreb. Upon inspection of its business facility for carrying out… CROATIA ·AZOP ·Art. 13, 14 Controllers Supervisory Authorities Supervision Jul 5, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Jul 5, 2021
€100,000 Vodafone España, SAU: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Vodafone España, S.A.U.. A data subject had filed a complaint with the Spanish DPA against the telecommunications… SPAIN ·AEPD ·Art. 28 Processors Controllers Personal Data May 25, 2021
EDPS: CJEU violated Regulation 2018/1725 over cookies and consent on its website A data subject complained around cookies and similar technologies used in connection to audiovisual material on the website of the Court of Justice of the European Union (CJEU),… 2019-0878 ·European Union ·Art. 7 Consent Information Provision Modalities and Communication Methods Cookies May 3, 2021
€1,500 Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A.,… ROMANIA ·ANSPDCP ·Art. 29, 32 Controllers Security Processors Apr 19, 2021
Security company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A data controller using the services of the security company reported the breach of personal data to the DPA, arising after an employee of the security company recorded the video… CROATIA ·AZOP ·Art. 32 Security Controllers Processors Feb 22, 2021
€60,000 Roma Servizi per La Mobilita S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined Roma Servizi per La Mobilita S.r.l. EUR 60,000 for failing to take adequate technical and organizational measures regarding the data of citizens… ITALY ·Garante ·Art. 32 Security Controllers Processors Feb 11, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Processors Controllers Processing Jan 14, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles Supervisory Authorities Controllers Processors Jan 1, 2021
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Healthcare Nov 19, 2020
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Controllers Pseudonymization Healthcare Nov 5, 2020
€3,000 Avata Hispania, S.L.: Insufficient legal basis for data processing Infringement of Art. 28 (3) g) GDPR, since personal data were further processed after the controller had terminated the contractual relationship with the processor. SPAIN ·AEPD ·Art. 5, 6, 28 Controllers Processors Personal Data Oct 3, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 13 +2 Processors Controllers Personal Data Sep 30, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 9 +1 Controllers Processors Personal Data Sep 30, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. Proceedings were initiated following an inspection carried out in response to a complaint. The accused processed and… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 13, 28 +1 Processors Controllers Consent Sep 25, 2020
Datatilsynet (Norway)- 20/02254 The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Datatilsynet (NO) ·Art. 57, 58 Telecommunications Supervision Supervisory Authorities Sep 7, 2020
DSB: online article about former politician is journalistic processing under Art. 85 GDPR In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that website contained wrong statements about her.… 2020-0.303.727 ·Austria ·Art. 17, 85 Right to be Forgotten Processors Personal Data Sep 1, 2020
HDPA 23/2020: Complaint against HEDNO S.A. for denial of employment certificate The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Greece ·Art. 4, 5, 12 +6 Right of Access Personal Data Processors Jul 30, 2020
€200,000 Merlini s.r.l.: Insufficient legal basis for data processing The company had carried out telemarketing activities on behalf of Wind Tre S.p.A. through a third party provider as data processor without sufficient legal basis fpr data… ITALY ·Garante ·Art. 5, 6, 7 +2 Processors Controllers Processing Jul 13, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·HmbBfDI ·Art. 26 Personal Data Processing Agreement Processors Jan 1, 2020
The complainant belongs to a political party and is a member of the city council of an Austrian municipality In November, the municipality held a meeting on the "parking space concept", to which a certain group of addressees, including the complainant, was invited. The complainant did… DSB-D123.768/0004-DSB/201 ·Austria ·DSB Public Authority Pseudonymization Anonymization Dec 18, 2019
€9,380 Major of Aleksandrów Kujawski: Insufficient data processing agreement No data processing agreement has been concluded with the company whose servers contained the resources of the Public Information Bulletin (BIP) of the Municipal Office in… POLAND ·UODO ·Art. 28 Processors Personal Data Processing Oct 18, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal ·CNPD (PT) Controllers Processors Legitimate Interest Sep 3, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Garante ·Art. 32 Controllers Processors Security Apr 17, 2019
€5,000 Kolibri Image Regina und Dirk Maass GbR: Insufficient data processing agreement Please note: According to our information this fine has been withdrawn in the meantime. Kolibri Image had send a request to the Data Protection Authority of Hessen asking how to… GERMANY ·HmbBfDI ·Art. 28 Controllers Processors Processing Dec 17, 2018
Norwegian DPA: Legelisten.no may process healthcare reviews without prior consent Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Norway ·Datatilsynet (NO) Consent Supervisory Authorities Legitimate Interest Nov 8, 2017