Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2701–2750 of 3,446 sort newestlargest fineoldest
€5,000 KARIERA A.E.: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 5,000 on ΚARIERA A.E.. A data subject had filed a complaint with the DPA against the controller due to the fact that the controller… GREECE ·HDPA ·Art. 17, 21, 25 Personal Data Controllers Processing Agreement May 12, 2021
€5,000 A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ: Non-compliance with general data processing principles The Hellenic DPA has fined A. ΕΠΙΛΟΓΗ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ EUR 5,000. The controller had not responded to requests for information and deletion from the data subject.… GREECE ·HDPA ·Art. 5, 12, 15 +1 Personal Data Controllers IP Address May 12, 2021
€1,000 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,000 on a company. The controller had installed a video surveillance system with the purposes of the protection of… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Video Surveillance IP Address Accountability May 12, 2021
€1,900 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 1,900 on a company. The controller had installed a video surveillance system to protect the company's assets and prevent… CNPD ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Accountability IP Address May 12, 2021
€2,000 World Class România S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on World Class România S.A.. The controller had published the termination letter of an employee in a WhatsApp group used… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Personal Data May 7, 2021
Disqus Inc.: Insufficient legal basis for data processing On May 5, 2021, the Norwegian DPA (Datatilsynet) announced that it intents to fine Disqus Inc. EUR 2, 500, 000 for violations of Art. 5 (1), (2) GDPR, Art. 6 GDPR, Art. 12 GDPR… NORWAY ·Datatilsynet ·Art. 5, 6, 12 +1 Telecommunications Processing Agreement Processing May 5, 2021
€1.5M EDP Comercializadora, S.A.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Comercializadora, S.A.U.. The decision follows, in particular, several complaints received for processing… SPAIN ·aepd ·Art. 13, 25 Controllers Personal Data Processing Agreement May 4, 2021
€1.5M EDP Energía, S.A.U: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500,000 on EDP Energía, S.A.U.. The decision follows, in particular, several complaints received for processing personal data… SPAIN ·aepd ·Art. 13, 25 Controllers Personal Data Processing Agreement May 4, 2021
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement Apr 29, 2021
€2,000 Santa Ninfa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Santa Ninfa municipality. The municipality had published a resolution on its website that contained personal information… ITALY ·Garante ·Art. 2, 5, 6 Personal Data IP Address Education Apr 29, 2021
€5,050 PNP S.A.: Insufficient cooperation with supervisory authority The controller failed to provide information requested by the Polish DPA (UODO) for investigative purposes. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Controllers Apr 27, 2021
€15,000 Anytime Fitness Iberia S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 15,000 on Anytime Fitness Iberia S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact… SPAIN ·aepd ·Art. 17, 21 Personal Data Controllers Processing Agreement Apr 27, 2021
€1,400 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,400 on a company. In the course of his professional activities, a data subject had made a telephone call to the controller on… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Accountability Personal Data Apr 27, 2021
€3,000 Pagamastarde S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Pagamastarde S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·aepd ·Art. 17, 21 Controllers Personal Data Processing Agreement Apr 27, 2021
€570 Company: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 570 on a company. In the course of his professional activities, a data subject had made a telephone call to a company on… HUNGARY ·NAIH ·Art. 5, 6, 13 IP Address Controllers Accountability Apr 27, 2021
€100,000 Financial company: Insufficient technical and organisational measures to ensure information security The Belgian DPA (APD) has imposed a fine of EUR 100,000 on a financial company. A data subject had filed two complaints with the APD against the company. They were based on 20… BELGIUM ·APD ·Art. 5, 32 Personal Data Security Controllers Apr 26, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·aepd ·Art. 5, 6, 14 Fairness & Transparency Integrity and Confidentiality Principle IP Address Apr 23, 2021
€4,000 HazteOir.Org: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on HazteOir.Org. The controller had published a brochure on sex education in schools which unlawfully contained the photos… SPAIN ·aepd ·Art. 6 Education Consent Personal Data Apr 22, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Recipient Security Apr 22, 2021
€1,500 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on a private individual. The controller had installed a surveillance camera on his property, which recorded, among other… SPAIN ·aepd ·Art. 5 Audit Logs Monitoring IP Address Apr 22, 2021
€15,000 Fondazione Policlinico Tor Vergata di Roma: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Fondazione Policlinico Tor Vergata di Roma. In February 2020, a data subject filed a complaint with Garante alleging… ITALY ·Garante ·Art. 5, 13, 25 +1 Healthcare Personal Data Healthcare Apr 21, 2021
€75,000 ParkkiPate Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 75,000 on ParkkiPate Oy. A number of people had been issued parking tickets by the controller and had thereupon requested information… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 14 +3 Retention Period Storage Limitation Personal Data Apr 21, 2021
€8,000 Highcliffe Estates Marbella S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 8,000 on Highcliffe Estates Marbella S.L.. The controller had published a photo of the data subject on its website without his… SPAIN ·aepd ·Art. 6 Controllers Personal Data Consent Apr 20, 2021
€2,800 Website operator: Non-compliance with general data processing principles The Hungarian DPA (NAIH) has imposed a fine of EUR 2,800 on a website operator. The controller had failed to prove the lawfulness of its processing of personal data upon request… HUNGARY ·NAIH ·Art. 5, 24 Accountability Controllers IP Address Apr 20, 2021
€1,500 Pub owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the owner of a pub EUR 1,500 due to the unauthorized use of two video surveillance cameras covering parts of the public space. SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring Apr 19, 2021
€1,500 Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A.,… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Processors Controllers Apr 19, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Education Controllers Apr 16, 2021
€5,000 S.C. Tip Top Food Industry S.R.L: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined S.C. Tip Top Food Industry S.R.L. EUR 5,000. The controller had installed several video cameras in the food areas and changing rooms to… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Video Surveillance Employees IP Address Apr 15, 2021
€2,000 Società triveneta di chirurgia: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Società triveneta di chirurgia. A physician had shown slides of a clinical case at a congress, which were subsequently… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Healthcare Apr 15, 2021
€3,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller resides on the 1st floor of an apartment building, where he is the owner of… SPAIN ·aepd ·Art. 5, 13 Audit Logs IP Address Controllers Apr 15, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Security Personal Data Apr 15, 2021
€12,000 Istituto Nazionale Previdenza Sociale (INPS): Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 12,000 on the Italian National Institute for Social Security (Istituto Nazionale della Previdenza Sociale). That fine was based… ITALY ·Garante ·Art. 5, 12, 15 Personal Data Education Controllers Apr 15, 2021
€5,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on… ITALY ·Garante ·Art. 5, 6, 9 Healthcare Healthcare Personal Data Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·aepd ·Art. 6 Controllers IP Address Telecommunications Apr 13, 2021
€3,400 Miljø- og Kvalitetsledelse AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 3,400 on Miljø- og Kvalitetsledelse AS. At one of the carwashes operated by the controller, incidents of vandalism had… NORWAY ·Datatilsynet ·Art. 5, 6 Controllers Processing Agreement Monitoring Apr 9, 2021
€750,000 TikTok: Insufficient fulfilment of information obligations The Dutch DPA (AP) has fined the video portal TikTok EUR 750,000 for violating the privacy of young children. The information that Dutch users - mostly young children - received… THE NETHERLANDS ·AP ·Art. 12 Minors Social Media Personal Data Apr 9, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD ·Art. 5, 13 ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Apr 8, 2021
€60,000 Kutxabank, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request… SPAIN ·aepd ·Art. 17 Right to be Forgotten Personal Data Data Subject Rights Exercise Modalities and Procedures Apr 8, 2021
€2,400 Promotech Digital S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined Promotech Digital S.L. EUR 2,400 for repeatedly sending the data subject advertising SMS, even though he never subscribed or agreed to receive… SPAIN ·aepd ·Art. 21 Direct Marketing Controllers Personal Data Apr 6, 2021
€4,000 Stockhunters S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Stockhunters S.L.. The controller was not able to answer the data subject's requests regarding the use of his personal… SPAIN ·aepd ·Art. 13 Personal Data Controllers Processing Agreement Apr 5, 2021
€3,000 Electrotecnica Bastida S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Electrotecnica Bastida S.L. EUR 3,000. Police officers had found 29 envelopes addressed to the controllers' respective employees on a vacant lot… SPAIN ·aepd ·Art. 32 Security Controllers Privacy by Design & Default Apr 5, 2021
€3,000 Kukimbia S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Kukimbia S.L. EUR 3,000. The controller is a company that stores, transports and distributes goods. Documents containing personal data about the… SPAIN ·aepd ·Art. 32 Controllers Processing Agreement Security Apr 5, 2021
€10,000 Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security The Romania DPA (ANSPDCP) has fined Telekom Romania Mobile Communications S.A. EUR 10,000 for failing to implement adequate security measures to ensure the security of personal… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Data Breaches Security Mar 30, 2021
€4,000 Comune di Castellanza: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the municipality of Castellanza. The municipality had uploaded documents containing personal data of the data subject… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Education Mar 25, 2021
€30,000 OneDirect Srl: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 30,000 on OneDirect Srl. A data subject had filed two complaints with the DPA after receiving advertisements by e-mail from the… ITALY ·Garante ·Art. 6, 7, 30 +1 Right to Object Controllers Personal Data Mar 25, 2021
€1,425 Operator of a care facility: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,425 on the operator of a care facility. The operator had installed a total of 25 cameras in all rooms of the facility, with… HUNGARY ·NAIH ·Art. 5, 6, 13 Video Surveillance Healthcare Monitoring Mar 25, 2021
€7,000 TECNOMEDICAL S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 7,000 on TECNOMEDICAL S.r.l.. A data subject filed a complaint with the DPA after the controller failed to properly respond to… ITALY ·Garante ·Art. 12, 15 Healthcare Health Data Personal Data Mar 25, 2021
€4.5M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Fastweb S.p.A. EUR 4,500,000 for aggressive telemarketing. Following a complex preliminary investigation launched after hundreds of reports and… ITALY ·Garante ·Art. 5, 6, 7 +8 IP Address Telecommunications Direct Marketing Mar 25, 2021
€20,000 GEDI News Network Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on GEDI News Network Spa. A data subject filed a complaint with the Italian DPA against the controller regarding an… ITALY ·Garante ·Art. 12 Personal Data Controllers Telecommunications Mar 25, 2021
€6,000 Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (boarding school): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (CE) boarding school. The boarding school had published a document… ITALY ·Garante ·Art. 2, 5, 6 Education Personal Data Processing Agreement Mar 25, 2021