Skip to content
Content type · 3,833 documents in this view · 3,838 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2701–2750 of 3,833 sort newestlargest fineoldest
€5,000 Sfam España General s.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Sfam España General s.l.. A data subject had filed a complaint with the DPA against the controller for charging her… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Dec 22, 2021
€5,000 HUBSIDE IBÉRICA S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 HUBSIDE IBÉRICA S.L.. A data subject had filed a complaint with the DPA against the controller for charging her several… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Supervisory Authorities Dec 22, 2021
€2,000 FUNDACION ESPANOLA DE MEDICINA ESTETICA Y LONGEVIDAD: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on FUNDACION ESPANOLA DE MEDICINA ESTETICA Y LONGEVIDAD. The DPA criticized that the data protection notice of the controller did… SPAIN ·AEPD ·Art. 7, 13 Controllers Consent Supervisory Authorities Dec 21, 2021
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 6,000 on a private individual. The person had shared a video on Twitter showing images of a sexual assault by a man on a woman. The… SPAIN ·AEPD ·Art. 6 Legitimate Interest Social Media Supervisory Authorities Dec 21, 2021
€1.3M Lisbon City Council: Insufficient legal basis for data processing The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since… PORTUGAL ·CNPD (PT) ·Art. 5, 6, 9 +2 Public Authority Personal Data DPIA Dec 21, 2021
€2,000 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a private individual EUR 2,000. The data controller had installed video cameras in such a way that they could record images of the public space and… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Dec 17, 2021
€2,000 Online retailer: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on an online retailer. The data subject bought a product from the controller's online store via eBay and paid with Paypal. However,… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Consent Dec 17, 2021
€4,000 CLUB DEPORTIVO RITMO DE ANDALUCÍA: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on CLUB DEPORTIVO RITMO DE ANDALUCÍA. The DPA criticized that the data protection notice of the controller did not comply with the… SPAIN ·AEPD ·Art. 7, 13 Controllers Consent Supervisory Authorities Dec 17, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY ·Garante ·Art. 5, 6, 9 Healthcare Personal Data Controllers Dec 17, 2021
€3,900 T. Stene Transport AS: €3,900 fine The Norwegian DPA has fined T. Stene Transport AS EUR 3,900 due to an unfair credit check on a data subject. NORWAY ·Datatilsynet (NO) ·Unknown Personal Data Supervisory Authorities Supervision Dec 17, 2021
€6,500 Travel agency: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 6,500 on a travel agency. A customer of the travel agency informed the DPA to suspect that the company might not process the data of its… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 17, 25 +1 Personal Data Security Processing Dec 16, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Privacy by Design & Default Controllers Dec 16, 2021
€20,000 Corradi s.r.l.: Non-compliance with general data processing principles The company had left the e-mail account of the data subject active even after the termination of his employment and had automatically forwarded incoming e-mails. The company did… ITALY ·Garante ·Art. 5, 13, 157 Personal Data Processing Supervisory Authorities Dec 16, 2021
Enel Energia S.p.A: Insufficient legal basis for data processing Originial fine summary: The Italian DPA has fined Enel Energia S.p.A EUR 26.5 million for numerous breaches of the GDPR. Following a complex preliminary investigation launched… ITALY ·Garante ·Art. 5, 6, 12 +7 Direct Marketing Personal Data Controllers Dec 16, 2021
€1,200 Private individual: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined a private individual EUR 1,200 for failing to provide sufficient information about a video surveillance system installed at their property. SPAIN ·AEPD ·Art. 13 Supervisory Authorities Video Surveillance Monitoring Dec 16, 2021
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Dec 16, 2021
€60,000 Banco Bilbao Vizcaya Argentaria S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria S.A.. A data subject filed a complaint with the DPA due to the fact that the controller repeatedly… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Dec 16, 2021
€75,000 Bank: Insufficient involvement of data protection officer The Belgian DPA has imposed a fine of EUR 75,000 on a bank. The DPA identified a conflict of interest regarding the data protection officer. In addition to his work as data… BELGIUM ·APD/GBA ·Art. 38 Supervisory Authorities Scientific Panel Independence Notified Body Independence Dec 16, 2021
€52,000 Motor insurance center: Non-compliance with general data processing principles The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25 Retention Period Controllers Insurance Dec 16, 2021
€20,000 FCA Italy s.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined FCA Italy s.p.a. EUR 20,000. A former customer of the controller had asked the controller to provide him with the transcripts of telephone conversations… Garante ·Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Dec 16, 2021
€1,000 Università Telematica Internazionale Uninettuno: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,000 on Università Telematica Internazionale Uninettuno. A professor had filed a complaint with the DPA against the educational… ITALY ·Garante ·Art. 5 Retention Period Personal Data Processing Dec 16, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Garante ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2021
€50,000 IZA OBRAS Y PROMOCIONES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IZA OBRAS Y PROMOCIONES, S.A. EUR 50,000. An employee had filed a complaint with the DPA against the company, alleging that the controller had… SPAIN ·AEPD ·Art. 5 Personal Data Retention Period Controllers Dec 14, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY ·Datatilsynet (NO) ·Art. 6, 9 Personal Data Types of Special Categories of Personal Data Consent Dec 13, 2021
€2,000 SC Nobiotic Pharma SRL: Insufficient cooperation with supervisory authority Failure to provide requested information to the Romanian DPA within the required timeframe in violation of Art. 58 GDPR. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Dec 13, 2021
€20,000 Elektro & Automasjon Systemer AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Elektro & Automasjon Systemer AS EUR 20,000. The controller had carried out a credit check on an individual, although there was no legal… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Processing Supervisory Authorities Dec 13, 2021
€10,000 Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Warsaw University of Technology EUR 10,000. The university had reported a data breach to the authority pursuant to Art. 33 GDPR. One of the… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Privacy by Design & Default Dec 9, 2021
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·DPC ·Art. 12, 13, 15 Personal Data Right of Access Controllers Dec 9, 2021
€30,000 One Way Private Company: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 30,000 on One Way Private Company. The DPA received 17 complaints regarding illegal telephone calls for the purpose of advertising. The… GREECE ·HDPA ·Art. 11, 28, 32 Security Controllers Personal Data Dec 8, 2021
€10,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA has imposed a fine of EUR 10,000 against a company. The data subject had repeatedly received mail with advertising content from a company, although he had objected… APD/GBA ·Art. 12, 14, 15 +2 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Direct Marketing Dec 8, 2021
€24,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U.. A data subject filed a complaint with the DPA against the company after they had denied him a financial transaction due to… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Dec 7, 2021
€608,000 Psykoterapiakeskus Vastaamo: Non-compliance with general data processing principles The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 33, 34 Integrity and Confidentiality Principle Personal Data Controllers Dec 7, 2021
€6,000 Telekom Romania Communications SA: Non-compliance with general data processing principles The Romanian DPA (ANSPDCP) imposed a fine of EUR 6,000 on Telekom Romania Communications SA. A data subject had complained that the controller had sent invoices and messages to… ANSPDCP ·Art. 5, 17 ·Non-compliance with general data processing principles Personal Data Controllers Processing Dec 6, 2021
€843 Lawyer: Insufficient legal basis for data processing The Hungarian DPA imposed a fine of EUR 843 on a lawyer for having unauthorizedly disclosed documents containing personal data of his client in the course of criminal proceedings. HUNGARY ·NAIH ·Art. 5, 6, 9 Personal Data Processing Insurance Dec 3, 2021
€1,000 Store owner: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined a store owner EUR 1,000 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN ·AEPD ·Art. 13 Supervisory Authorities Video Surveillance Monitoring Dec 3, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€2,000 IMAGINA FRAN SPORT, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined IMAGINA FRAN SPORT, S.L. EUR 2,000 due to the fact that its privacy policy did not comply with the requirements of Art. 13 GDPR. For instance, the… SPAIN ·AEPD ·Art. 13 Supervisory Authorities Dec 2, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY ·Garante ·Art. 5, 32 Security Personal Data Privacy by Design & Default Dec 2, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€5,000 Azienda USL di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda USL di Parma EUR 5,000. A patient filed a complaint with the DPA because she had mistakenly received two reports of diagnostic tests on two… ITALY ·Garante ·Art. 5, 9 Healthcare Processing Health Data Dec 2, 2021
€60,000 Irish Teacher Council: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 60,000 on the Irish Teaching Council. The Council notified the DPA of a data breach under Art. 33 of the GDPR. Accordingly, two employees… IRELAND ·DPC ·Art. 5, 32, 33 Data Breaches Personal Data Security Dec 2, 2021
€5,000 INTRODUCTION BUSINESS CAPITAL MEDIA, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on INTRODUCTION BUSINESS CAPITAL MEDIA, S.L.. The data subject had received advertising calls from the controller, although the… SPAIN ·AEPD ·Art. 21, 23, 48 Personal Data Direct Marketing Controllers Dec 1, 2021
€6,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 6,800 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Controllers Dec 1, 2021
€4,000 Pactum Poland Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Data Breaches Dec 1, 2021
€1,500 Neighborhood community: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a neighborhood community. The controller had installed video cameras on their private property in such a way that they could capture images of the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Nov 30, 2021
€20,000 DAVISER SERVICIOS, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 on DAVISER SERVICIOS, S.L.. The company had been processing biometric data (fingerprints) of employees for access to… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Nov 30, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Processing Nov 30, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Processing Nov 30, 2021
€4,000 TIGERS MARKET, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 4,000 on TIGERS MARKET, S.L.. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·AEPD ·Art. 21, 23, 48 Personal Data Direct Marketing Controllers Nov 29, 2021
€1,000 Restaurant owner: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined a restaurant owner EUR 1,000 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN ·AEPD ·Art. 13 Supervisory Authorities Video Surveillance Monitoring Nov 29, 2021