Skip to content
Content type · 621 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 621 sort newestlargest fineoldest
€336,000 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 336,000 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During… POLAND ·UODO ·Art. 5, 32 Security Personal Data Privacy by Design & Default May 20, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Healthcare May 9, 2024
€75,000 Azienda ospedale università di Padova: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 75,000 on Azienda ospedale università di Padova. During its investigation, the DPA found that employees had accessed patient files… ITALY ·Garante ·Art. 5, 9, 25 +1 Controllers Healthcare Processing May 9, 2024
€10,000 Azzurro Club Hotels S.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on Azzurro Club Hotels S.r.l.. The controller had sent a data subject unsolicited advertising e-mail and failed to respond… ITALY ·Garante ·Art. 6, 12, 15 +1 Personal Data Controllers Supervisory Authorities May 9, 2024
€3,000 Medical association: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the… ITALY ·Garante ·Art. 2, 5, 6 Processing Healthcare Supervisory Authorities May 9, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·AEPD ·Art. 32, 33 Data Breaches Security Personal Data May 8, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 8, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS ·AP ·Art. 5 Personal Data Controllers Processing May 2, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Security Encryption Privacy by Design & Default Apr 29, 2024
€10,000 ASSOCIACIO OASIS CULTURAL: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on ASSOCIACIO OASIS CULTURAL. A discotheque operated by the controller had published videos of dancing minors on a social media… SPAIN ·AEPD ·Art. 6 Controllers Social Media Minors Apr 26, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 25, 2024
€10,000 Azienda sanitaria locale Roma 3: Insufficient fulfilment of data breach notification obligations The Italian DPA has fined Azienda sanitaria locale Roma 3 EUR 10,000 for failing to report a data breach to the DPA in a timely manner and to properly document the data breach. ITALY ·Garante ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 21, 2024
€1,000 CLÍNICA PARÍS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on CLÍNICA PARÍS, S.L for failing to prove compliance with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Healthcare Mar 20, 2024
€1,000 DENTAL REY-GAR, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,000 on DENTAL REY-GAR, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Healthcare Mar 7, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Mar 7, 2024
€30,000 CENTRO MÉDICO SALUS BALEARES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 30,000 on CENTRO MÉDICO SALUS BALEARES, S.L.. An individual had filed a complaint with the DPA due to the clinic's use of an electronic… SPAIN ·AEPD ·Art. 5, 32 Processing Healthcare Supervisory Authorities Feb 8, 2024
€300,000 Medtronic Italia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Medtronic Italia. The controller had sent emails in an open distribution list to hundreds of individuals using the… ITALY ·Garante ·Art. 5, 9, 12 +2 Personal Data Controllers Healthcare Feb 8, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Security Personal Data Healthcare Feb 8, 2024
€5,000 Dentist: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5,000 on a dentist due to a lack of data security and a failure to respect the right of access of a data subject. FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Inspection Access Rights and Cooperation Obligations Jan 31, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Encryption Healthcare Controllers Jan 17, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2024
€3,300 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,300 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Controllers Types of Special Categories of Personal Data Jan 1, 2024
€16,000 Hotel: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 16,000 on a hotel for processing ID card data without a legal basis. GERMANY ·HmbBfDI ·Insufficient legal basis for data processing Processing Supervisory Authorities Healthcare Jan 1, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Supervisory Authorities Fines Supervision Jan 1, 2024
€2,500 Doctor´s Office: Insufficient technical and organisational measures to ensure information security The DPA of Hessen has imposed a fine of EUR 2,500 on a doctor´s office. The controller hired an office manager who worked partly from home. The manager worked with patient files,… GERMANY ·Art. 5, 6, 9 +1 ·Insufficient technical and organisational measures to ensure information security Controllers Security Healthcare Jan 1, 2024
€3,700 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,700 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Controllers Types of Special Categories of Personal Data Jan 1, 2024
€23,000 Polish Minister of Health: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 23,000 on the Polish Minister of Health. The controller had accessed information via a database relating to a physician who had prescribed… POLAND ·UODO ·Art. 25, 32, 34 Controllers Security Personal Data Dec 20, 2023
€2,000 Mushtaq Rubina Kebabish: Insufficient fulfilment of information obligations The Italian DPA has fined Mushtaq Rubina Kebabish EUR 2,000. The controller had operated video surveillance cameras in one of their premises without properly informing about the… ITALY ·Garante ·Art. 5, 13 Personal Data Controllers Processing Dec 7, 2023
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… CYPRUS ·Cyprus DPA ·Art. 5 Personal Data Processing Health Data Dec 7, 2023
€40,000 Azienda socio sanitaria territoriale nord Milano, C.F.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Azienda socio sanitaria territoriale nord Milano, C.F.. During its investigation, the DPA found that a patient's spouse had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Processing Supervisory Authorities Dec 7, 2023
€10,000 Pharmacy owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,000 on a pharmacy owner. The controller had disposed of a large number of personal documents, including medical information of data… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Processing Nov 24, 2023
€72,000 Eurocollege Oxford English Institute S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 72,000 on Eurocollege Oxford English Institute S.L. The data subject stated that they had signed a training contract with the affiliated… SPAIN ·AEPD ·Art. 5, 6, 9 Personal Data Healthcare Controllers Nov 17, 2023
€18,000 Cluster S.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 18,000 on Cluster S-r.l. A data subject had complained to the DPA because their son's health-related data and their own personal data had… ITALY ·Garante ·Art. 5, 32 Personal Data Anonymization Controllers Nov 16, 2023
€600 Hotel: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 600 on a hotel. The controller had installed video surveillance cameras which, among other things, also covered the public space and… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Nov 3, 2023
€48,000 INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P.: Non-compliance with general data processing principles The Spanish DPA has imposed a finea INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P. The controller had suffered a data breach in which personal patient and employee data had… SPAIN ·AEPD ·Art. 5, 32, 34 Data Breaches Security Controllers Nov 2, 2023
€7,000 Ophthalmologic institute: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 7,000 on a ophthalmologic institute. The controller had responded to an online review, disclosing personal data of a patient. SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing Oct 26, 2023
€2,000 UNIQUE HOTEL APARTMENT S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on UNIQUE HOTEL APARTMENT. The controller had copied identification documents for the purposes of guest registration and stored the… SPAIN ·AEPD ·Art. 5 Controllers Identification Processing Oct 18, 2023
€40,000 Azienda socio sanitaria territoriale di Lodi CF: Non-compliance with general data processing principles The Italian DPA has imposed a fine of ERU 40,000 on the health authority Azienda socio sanitaria territoriale di Lodi CF. Employees of the health authority had accessed the file… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Processing Supervisory Authorities Oct 12, 2023
€1,000 GREECE DPA: Non-compliance with general data processing principles Unlawful disclosure of health data. HDPA ·Art. 5 ·Non-compliance with general data processing principles Processing Supervisory Authorities Health Data Oct 11, 2023
€1,500 NORDETIA CLINICS MÓSTOLES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,500 on NORDETIA CLINICS MÓSTOLES S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing Supervisory Authorities Oct 10, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·AZOP ·Art. 5, 6, 12 +2 Personal Data Legitimate Interest Controllers Oct 5, 2023
€5,000 Physician: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on a physician for unlawfully disclosing patient data. ITALY ·Garante ·Art. 5, 9 Healthcare Processing Health Data Sep 28, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY ·Garante ·Art. 5, 32 Processing Health Data Healthcare Sep 28, 2023
€3,000 Palombaro s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Palombaro s.r.l. EUR 3,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects about… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Sep 28, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Personal Data Processing Sep 28, 2023
€5,000 Ministero dell'Ambiente e della Sicurezza Energetica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Ministero dell'Ambiente e della Sicurezza Energetica. The controller had published a document on its website that contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Controllers Sep 28, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·AZOP ·Art. 6, 13, 32 +1 Controllers Personal Data Encryption Sep 26, 2023
€10,000 Phyisician: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 10,000 on a physician. The physician had responded to an online review regarding their practice, disclosing personal health data of a… AUSTRIA ·DSB ·Art. 5, 9 Healthcare Types of Special Categories of Personal Data Processing Sep 26, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN ·AEPD ·Art. 9, 13 Personal Data Healthcare Controllers Sep 25, 2023