Skip to content
Content type · 3,833 documents in this view · 3,838 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2651–2700 of 3,833 sort newestlargest fineoldest
€5,000 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on DW Dynamic Works LIMITED. The controller operated as a processor for Hermes Airport Ltd.. Hermes had suffered a cyberattack… CYPRUS ·Cyprus DPA ·Art. 32 Controllers Security Processors Jan 1, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Personal Data Jan 1, 2022
Supermarket: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a supermarket. A store detective had taken a photo of the data subject on the occasion of an alleged theft and transmitted it via the… GERMANY ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Processing Jan 1, 2022
€1,400 Dentist: Non-compliance with general data processing principles The Hungarian DPA has fined a dentist EUR 1,300. The controller had installed several surveillance cameras in their practice, which permanently recorded employees and patients.… HUNGARY ·NAIH ·Non-compliance with general data processing principles Video Surveillance Monitoring Personal Data Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Cyprus DPA ·Art. 28, 32 Security Controllers Processors Jan 1, 2022
€1,000 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records of positive and negative Covid-19 Antigen Rapid test results from patients in a public waste disposal site. GERMANY ·HmbBfDI ·Art. 32 Security Healthcare Supervisory Authorities Jan 1, 2022
€5,000 Cyprus Electricity Authority: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Cyprus DPA ·Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Privacy by Design & Default Jan 1, 2022
Physician: Insufficient legal basis for data processing The DPA of Bremen imposed a fine on a physician for using a patient's contact details to contact them privately without their consent. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Healthcare Processing Jan 1, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… CYPRUS ·Cyprus DPA ·Art. 24, 32 Controllers Security Processors Jan 1, 2022
€6,500 Pharmacy: Non-compliance with general data processing principles The DPA of Baden-Württemberg imposed a fine of EUR 6,500 on a pharmacy. The pharmacy had disposed of a large number of personal documents, including diagnoses and medical… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Personal Data Processing Healthcare Jan 1, 2022
€500 The DPA from Baden-Württemberg imposed a fine of EUR 500 on a restaurant The owner had disposed of a large quantity of Covid contact forms in the forest. Restaurant: €500 fine ·GERMANY ·Unknown Supervisory Authorities Healthcare Jan 1, 2022
Company: Insufficient fulfilment of data subjects rights The DPA of Bremen imposed a fine on a company for failing to respond to a data subject's request for access to their data in a timely manner. GERMANY ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Jan 1, 2022
Physician: Insufficient legal basis for data processing The DPA of Bremen imposed a fine on a physician for transmitting patient's data to a billing office without their consent. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Processing Agreement Healthcare Jan 1, 2022
Private individual: Insufficient legal basis for data processing The DPA of Bremen imposed a fine on a private individual. The individual who worked in a restaurant, had contacted a restaurant visitor privately using the contact information… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Processing Supervisory Authorities Jan 1, 2022
Company: Non-compliance with general data processing principles The DPA of Bremen has imposed a five-digit fine on a company. The controller had unlawfully used GPS software in its company vehicles, allowing unrestricted monitoring of its… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Controllers Processing Monitoring Jan 1, 2022
Company: Insufficient legal basis for data processing The DPA of Bremen has imposed a five-digit fine on a company. The company had sent an unredacted social plan to all affected employees in the context of dismissals due to… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Types of Special Categories of Personal Data Employees Jan 1, 2022
Company: Insufficient legal basis for data processing The DPA of Bremen has imposed a five-digit fine on a company. The company had transferred the pay slips of its employees without their consent to another company, which was to… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Employees International Transfer Jan 1, 2022
Company: Insufficient fulfilment of data breach notification obligations The DPA from Bremen has fined a company for failing to inform the DPA pursuant to Art. 33 GDPR that an employee's business email account had been hacked. GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2022
Medical care center: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a medical care center for having scanned a customer's ID card against their will and stored the copy. Once the customer complained, they… GERMANY ·Insufficient legal basis for data processing Personal Data Right to Object Healthcare Jan 1, 2022
Logistics company: Insufficient technical and organisational measures to ensure information security A logistics company had disposed of delivery lists in a public waste paper container. The lists contained a large amount of detailed information, such as the first and last names… GERMANY ·HmbBfDI ·Art. 32, 33 Data Breaches Personal Data Security Jan 1, 2022
€2,700 Covid-19 test center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them… GERMANY ·HmbBfDI ·Art. 32 Encryption Security Personal Data Jan 1, 2022
€1,400 Covid-19 test center: Insufficient legal basis for data processing The DPA from Hamburg has imposed a fine of EUR 1,400 on a Covid-19 test center. The controller intended to fulfill its statutory documentation obligations and scanned the front… GERMANY ·HmbBfDI ·Art. 6 Controllers Personal Data Healthcare Jan 1, 2022
€3,400 Company: Insufficient legal basis for data processing The Czech DPA imposed a fine of EUR 3,400 on a company. The data subject had concluded an energy supply contract with the controller in the past, but then duly terminated it.… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Insufficient legal basis for data processing Controllers Processors Personal Data Jan 1, 2022
€16,400 Covid-19 test center: Insufficient legal basis for data processing The DPA of Hessen has fined a Covid-19 test center EUR 16,400. The controller had sent an e-mail containing personal data to several recipients in an open distribution list. The… GERMANY ·Art. 6, 33 ·Insufficient legal basis for data processing Data Breaches Personal Data Controllers Jan 1, 2022
€1,800 Covid-19 test center: Non-compliance with general data processing principles The DPA of Hessen imposed a fine of EUR 1,800 on a Covid-19 test center. An employee had taken an adhesive label from the trash, written the test center's e-mail address on it and… GERMANY ·Art. 5, 6 ·Non-compliance with general data processing principles Personal Data Processing Healthcare Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a five-figure fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Consent Processing Jan 1, 2022
€80,700 Beauty salon: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 80,700 on a beauty salon. The controller had installed video cameras in all its premises, which permanently recorded customers and… HUNGARY ·NAIH ·Insufficient legal basis for data processing Video Surveillance Direct Marketing Controllers Jan 1, 2022
€12,800 Political party: Insufficient legal basis for data processing The Bulgarian DPA has imposed a fine of EUR 12,800 on a political party. Several individuals had filed a complaint with the DPA because their personal data had been added to voter… BULGARIA ·CPDP ·Art. 6 Personal Data Consent Supervisory Authorities Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Berlin has imposed a fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with their personal data… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Controllers Processing Jan 1, 2022
Sports photography company: Insufficient legal basis for data processing The DPA of Berlin has imposed a fine on a sports photography company. A sports photographer had published over 16,000 photos of minors who had taken part in a swimming competition… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Consent Processing Minors Jan 1, 2022
€50,000 Company: Insufficient fulfilment of data subjects rights The DPA of Niedersachsen has imposed a fine of EUR 50,000 on a company. The company sent out a newsletter by e-mail that could not be unsubscribed from due to technical… GERMANY ·Art. 15, 21 ·Insufficient fulfilment of data subjects rights Personal Data Right to Object Supervisory Authorities Jan 1, 2022
€8,900 Company: Insufficient technical and organisational measures to ensure information security The DPA of Niedersachsen imposed a fine of EUR 8,900 on a company. The company had a customer database on the Internet with thousands of entries. During its investigation, the DPA… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2022
Credit agency: Insufficient fulfilment of data subjects rights The DPA of Berlin imposed a fine on a credit agency. In the course of its investigation, the DPA found that the controller had stored 27 false addresses and 13 false dates of… GERMANY ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Five fines for failing to comply with orders issued by the DPA. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Fines Jan 1, 2022
Company: Insufficient legal basis for data processing The Latvian DPA has fined a company for issuing loyalty cards to customers without a valid legal basis. LATVIA ·DSI ·Art. 5, 6 Processing Supervisory Authorities Jan 1, 2022
€60M Google Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Google Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Telecommunications Dec 31, 2021
€90M Google LLC: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 90,000,000 on GOOGLE LLC. The CNIL received several complaints regarding the manner in which cookies could be… FRANCE ·CNIL ·Art. 82 Cookies Direct Marketing Telecommunications Dec 31, 2021
€60M Facebook Ireland Ltd.: Insufficient legal basis for data processing On December 31, 2021, the French DPA (CNIL) imposed a fine of EUR 60,000,000 on Facebook Ireland Ltd. The CNIL received several complaints regarding the manner in which cookies… FRANCE ·CNIL ·Art. 82 Social Media Cookies Direct Marketing Dec 31, 2021
€25,000 PLUS REAL ADVERTISEMENT: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 25,000 on PLUS REAL ADVERTISEMENT. The controller had conducted advertising calls without the consent of the data subjects. In addition,… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Controllers Consent Dec 31, 2021
€150M Google LLC is a subsidiary owned wholly by Alphabet Inc Google Ireland Limited ('GIL') "presents itself" as the headquarters for the Google group's operations in the EEA and Switzerland. In March 2020 the French DPA (CNIL) carried out… SAN-2021-023 ·France ·CNIL Material scope (GDPR) Supervision Supervisory Authorities Dec 31, 2021
€30,000 INFO COMMUNICATION SERVICES: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 30,000 on INFO COMMUNICATION SERVICES. The controller had conducted advertising calls without the consent of the data subjects. In… GREECE ·HDPA ·Art. 11, 13, 14 Personal Data Controllers Supervisory Authorities Dec 31, 2021
€75,000 Greek Ministry of Tourism: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 75,000 on the Greek Ministry of Tourism. A data breach had occurred at the authority. According to the DPA, an attempt by a citizen to… GREECE ·HDPA ·Art. 13, 32, 33 +1 Data Breaches Notification Obligation Public Authority Dec 29, 2021
€2,000 VENTANAS MAKE YOURSELF, S.L.: Insufficient fulfilment of information obligations The corporate website did not present a privacy policy on its main page. SPAIN ·AEPD ·Art. 13 Supervisory Authorities Dec 28, 2021
€6,000 REAL CLUB NÁUTICO DE RIBADEO: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on REAL CLUB NÁUTICO DE RIBADEO. The controller had uploaded links to court decisions containing personal data of the data… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Social Media Dec 28, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Personal Data Dec 28, 2021
€300,000 FREE MOBILE: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has imposed a fine of EUR 300,000 on FREEE MOBILE. The CNIL had received numerous complaints regarding the company's failure to comply with data subjects'… FRANCE ·CNIL ·Art. 12, 15, 21 +2 Personal Data Right to Object Privacy by Design & Default Dec 28, 2021
€2,000 Call shop manager: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on the manager of a call shop. In the context of a job vacancy, the manager had set up a stand where applicants could submit their… SPAIN ·AEPD ·Art. 13 Personal Data Supervisory Authorities Processing Dec 28, 2021
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Controllers Processing Dec 26, 2021
€1,500 LA OFICINA BAR: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined LA OFICINA BAR. The bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. The… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Dec 23, 2021