Skip to content
Content type · 2,802 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2501–2550 of 2,802 sort newestlargest fineoldest
€15,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 15,000 on a homeowners' association. The controller had publicly displayed the record of a homeowners' meeting in the elevator of the… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Mar 9, 2021
€14,900 Dragefossen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) imposed a fine of EUR 14,900 on the energy company Dragefossen AS. The latter had installed a webcam on the roof of its office building in the… NORWAY ·Datatilsynet ·Art. 5, 6 Video Surveillance Monitoring Audit Logs Mar 8, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA ·ANSPDCP ·Art. 32, 58 Personal Data Security Controllers Mar 4, 2021
€40,000 Electricity Authority of Cyprus: Insufficient legal basis for data processing The Cypriot DPA imposed a fine of EUR 40,000 on the Electricity Authority of Cyprus. The controller used an automated system based on the so-called Brad-Factor to manage, monitor… Art. 6, 9 ·Insufficient legal basis for data processing Employees Controllers Processing Mar 3, 2021
€6,000 KEPIDES: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 6,000 against KEPIDES (real estate company). The controller had submitted a list of buyers of the properties it manages to a parliamentary… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Anonymization Security Controllers Mar 3, 2021
€25,000 Hellenic Bank: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 25,000 on Hellenic Bank. The bank had closed one of its branches in the city of Nicosia in 2015. When moving out of the space, a safe… CYPRUS ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Mar 3, 2021
Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Encryption IP Address Controllers Mar 3, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Art. 12, 15, 31 +1 ·Insufficient fulfilment of information obligations Right of Access Procedures Right of Access Personal Data Mar 3, 2021
€9,000 SPAIN DPA: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 9,000 on a website operator. The controller had published photos of the data subject on its website without the consent of the data… aepd ·Art. 6, 13 ·Insufficient legal basis for data processing Personal Data Controllers Processing Agreement Mar 2, 2021
€200,000 I-DE Redes Eléctricas Inteligentes, S.A.U: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on I-DE Redes Eléctricas Inteligentes, S.A.U. The DPA received complaints from Waitum, S.L. and Servicios Aby 2018, S.L.… SPAIN ·aepd ·Art. 5, 6 Integrity and Confidentiality Principle IP Address Controllers Mar 2, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA ·VDAI ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 2, 2021
€24,400 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined a company NOK 250,000 (EUR 24,400). The controller ordered an employee to set up an automatic forwarding of his/her employee email account… Datatilsynet ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Employees Processing Agreement Mar 2, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Healthcare Health Data Feb 26, 2021
€3,000 IT sprendimai sėkmei: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 3,000 on the company 'IT sprendimai sėkmei'. The DPA had opened an investigation regarding a quarantine app introduced in Lithuania… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Privacy Impact Assessment Health Data Feb 26, 2021
€6,000 Comune di Commezzadura: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 6,000 on the municipality of Commezzadura. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare IP Address Feb 25, 2021
€6,000 Azienda Ospedaliera Universitaria Careggi: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Azienda Ospedaliera Universitaria Careggi for a breach of Art. 5 GDPR and Art. 9 GDPR. Azienda Ospedaliera… ITALY ·Garante ·Art. 5, 9 Data Breaches Healthcare Health Data Feb 25, 2021
€4,000 Ministero dell’Istruzione, Ufficio Scolastico Regionale per il Lazio: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the Lazio Region School Authority. A parent had filed a complaint against the school authority for forwarding data of… ITALY ·Garante ·Art. 5, 6, 9 Education Healthcare Public Authority Feb 25, 2021
€2,000 Comune di Conflenti: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 2,000 on the municipality of Conflenti. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Feb 25, 2021
€20,000 Gedi Gruppo Editoriale S.p.A.: Insufficient legal basis for data processing The Italian DPA (Garante) has fined Gedi Gruppo Editoriale S.p.A. 20,000 euros. The controller had published photos in its newspaper of people who were in custody in connection… ITALY ·Garante ·Art. 5 Controllers Consent Processing Feb 25, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY ·Garante ·Art. 5, 25, 35 Fairness & Transparency Privacy Impact Assessment DPIA Feb 25, 2021
€12,000 Avilon Center 2016 S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 20,000 on Avilon Center 2016 S.L. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·aepd ·Art. 21, 23, 48 Personal Data Controllers Direct Marketing Feb 24, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Right to Object Personal Data Processing Feb 23, 2021
Security company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A data controller using the services of the security company reported the breach of personal data to the DPA, arising after an employee of the security company recorded the video… CROATIA ·azop ·Art. 32 Security Controllers Processors Feb 22, 2021
€1,000 The Washpoint S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) imposed a fine of EUR 1,000 on The Washpoint S.L. for the lack of a privacy policy on its website, in violation of Art. 13 GDPR. SPAIN ·aepd ·Art. 13 Processing Agreement Supervisory Authorities Feb 16, 2021
€1,600 Ripobruna 207, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 2,000 against Ripobruna 207, S.L. (restaurant) for the unauthorized use of two video surveillance cameras that also recorded parts of… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Feb 12, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet ·Art. 5 Fines Administrative Fines on Union Institutions, Bodies, Offices and Agencies Storage Limitation Feb 12, 2021
€120,000 Vodafone España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A former customer had received e-mails containing electronic bills even after he had terminated his… SPAIN ·aepd ·Art. 5, 6 Personal Data Controllers Telecommunications Feb 12, 2021
€3,000 AUSTRIA DPA: Insufficient cooperation with supervisory authority The Austrian DPA has fined a company EUR 3,000 for failing to provide information requested by the DPA during an investigation. dsb ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Feb 12, 2021
€440,000 OLVG: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) imposed a fine of EUR 440,000 on the Amsterdam hospital OLVG. The controller had taken insufficient measures between 2018 and 2020 to prevent access by… THE NETHERLANDS ·AP ·Art. 32 Healthcare Health Data Healthcare Feb 11, 2021
€60,000 Roma Servizi per La Mobilita S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined Roma Servizi per La Mobilita S.r.l. EUR 60,000 for failing to take adequate technical and organizational measures regarding the data of citizens… ITALY ·Garante ·Art. 32 Security Controllers Processors Feb 11, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Prior Consultation IP Address Public Authority Feb 11, 2021
€5,000 Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da Pietrelcina: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Foundation for Religion and Worship 'Casa sollievo della sofferenza' Opera di San Pio da Pietrelcina. On January… ITALY ·Garante ·Art. 5, 9 Notification Obligation Data Breaches Personal Data Feb 11, 2021
€45,000 Istituti ospedalieri bergamaschi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 45,000 on Istituti ospedalieri bergamaschi. The DPA initiated an investigation against the controller after it reported a data… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare Healthcare Feb 11, 2021
€350,000 Roma Capitale: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined the city of Rome EUR 350,000 for failing to take adequate technical and organizational measures regarding the data of citizens who had obtained… ITALY ·Garante ·Art. 5, 6, 28 +1 Security Privacy by Design & Default Education Feb 11, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Data Breaches Integrity and Confidentiality Principle Security Feb 11, 2021
€24,000 Vamavi Phone S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Vamavi Phone S.L.. The data subject had received an advertising call from the controller made on behalf of Vodafone España,… SPAIN ·aepd ·Art. 21, 23, 28 +1 Direct Marketing Personal Data Controllers Feb 11, 2021
€1,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine of EUR 1,000 on ING Bank N.V. Amsterdam - Bucharest Branch. It was found that the controller had sent files to a contractual partner in… ROMANIA ·ANSPDCP ·Art. 29, 32 Integrity and Confidentiality Principle Professional Secrecy Audit Logs Feb 10, 2021
€65,000 Lursoft IT SIA: Insufficient legal basis for data processing The Latvian DPA (DSI) fined Lursoft IT SIA EUR 65,000 for the illegal processing of personal data by publishing documents containing personal data on its website 'www.lursoft.lv'.… LATVIA ·DSI ·Art. 6 Personal Data Controllers Processing Feb 9, 2021
€3,000 Patio Ancestral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on Patio Ancestral S.L.. The complainant worked for a construction company and had carried out some renovation work for the… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Feb 8, 2021
€5,000 Private Person: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 5,000 for illegal camera surveillance. The data subject had rented two rooms in the apartment of the controller. The… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Feb 8, 2021
€12,000 Orthodontic Clinic: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined an orthodontic clinic EUR 12,000. The web form that new patients used to sign up contained mandatory fields for all sorts of patient personal data.… THE NETHERLANDS ·AP ·Art. 32 Encryption Healthcare Security Feb 4, 2021
€100,000 Iberdrola Clientes: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 100,000 on Iberdrola Clientes, SAU. The data subject had terminated an existing contract with the controller due to a move and… SPAIN ·aepd ·Art. 5, 17 Personal Data Controllers Processing Agreement Feb 3, 2021
€19,300 Cyberbook AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Cyberbook AS NOK 200,000 (EUR 19,300) for the illegal automatic forwarding of e-mails from a former employee. The forwarding took place for… NORWAY ·Datatilsynet ·Art. 5, 6 Personal Data Employees Processing Agreement Feb 3, 2021
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Right to Object Personal Data Processing Feb 2, 2021
€80 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 80 on a legal person. The accused was sending commercial communications to the complainant, despite their objection to the processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Right to Object Personal Data Processing Feb 1, 2021
€24,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Xfera Móviles S.A.. The data subject claimed a violation of its right to information to the AEPD. The AEPD then issued a… SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision Feb 1, 2021
€3,000 IDFINANCE Spain, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on IDFINANCE Spain S.L.. A person had received a debt collection email from IDFinance that contained a link for the payment of… aepd ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Controllers Personal Data Insurance Feb 1, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Education IP Address Jan 27, 2021
€50,000 Family Service / N.D.P.K. nv.: Insufficient legal basis for data processing The Belgian DPA imposed a fine of EUR 50,000 on Family Service / N.D.P.K. nv. The controller is an advertising agency that, among other things, sends expectant mothers gift boxes… BELGIUM ·APD ·Art. 5, 6, 7 +4 IP Address Controllers Personal Data Jan 27, 2021
€75,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Data Breaches Access Controls Jan 27, 2021