Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2751–2800 of 3,446 sort newestlargest fineoldest
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY ·NAIH ·Art. 32, 33, 34 Encryption Integrity and Confidentiality Principle Healthcare Mar 24, 2021
€90,000 Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 90,000 on Irish Credit Bureau (ICB). The fine follows a data breach reported by the controller to the DPA on August 31, 2018. The… IRELAND ·Art. 5, 24, 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Accuracy Mar 23, 2021
€1,000 Laboratorio Octogón, S.L.: Non-compliance with general data processing principles Usage of CCTV camera systems that were also monitoring public space (breach of principle of data minimization). SPAIN ·aepd ·Art. 5 Video Surveillance Audit Logs Monitoring Mar 23, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Healthcare Mar 23, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Education Controllers Mar 22, 2021
€19,900 Basaren Drift AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 19,900 on Basaren Drift AS. The controller had installed video cameras in its premises which recorded both its employees… NORWAY ·Datatilsynet ·Art. 5, 6, 13 Video Surveillance Controllers Monitoring Mar 21, 2021
€4,900 Funeda Sp. z o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined Funeda Sp. z o.o. EUR 4,900 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Processing Agreement Mar 19, 2021
€3,000 Asesoría Alpi-Clúa S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 3,000 on Asesoría Alpi-Clúa S.L.. A client had requested documents from the controller to submit them to the tax authorities. The… SPAIN ·aepd ·Art. 5, 32 IP Address Controllers Processing Agreement Mar 18, 2021
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 60,000 on Vodafone Spain. The data subject had been a customer of the controller several years ago. After receiving payment reminders… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Mar 16, 2021
€1,000 School: Insufficient legal basis for data processing The Belgian DPA (APD) fined a school EUR 1,000. The controller had conducted a survey on student well-being via a smartschooling system. The DPA states that the controller did not… BELGIUM ·APD ·Art. 5, 6, 8 Education Consent IP Address Mar 15, 2021
€2,000 Heredad de Urueña S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Heredad de Urueña S.A. EUR 2,000 because its personal data processing policy did not comply with the requirements of Art. 13 GDPR. In addition, the… SPAIN ·aepd ·Art. 13 Personal Data Controllers Processing Agreement Mar 15, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data Accuracy Controllers Mar 15, 2021
€600,000 Air Europa Lineas Aereas, SA.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) fined Air Europa Lineas Aereas, SA. EUR 600,000 after a serious data breach involving unauthorized access to contact details and bank accounts was reported… SPAIN ·aepd ·Art. 32, 33 Data Breaches Integrity and Confidentiality Principle Security Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet ·Art. 5, 6, 24 +1 Data Breaches Public Authority Education Mar 15, 2021
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY ·Datatilsynet ·Art. 24, 32, 35 DPIA Data Breaches Security Mar 15, 2021
€3,000 Cultural association: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 3,000 on a cultural association. The controller had published pictures of a four-year-old child on various groups of the Chinese… SPAIN ·aepd ·Art. 6 Controllers Consent Processing Agreement Mar 15, 2021
€12,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U. EUR 20,000. An identity thief had obtained the data of a third party without authorization and applied for a microcredit… SPAIN ·aepd ·Art. 6 IP Address Controllers Recipient Mar 12, 2021
€1,500 Private Person: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a private individual EUR 1,500. The controller had installed a video surveillance camera facing a public thoroughfare and covering parts of the… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers Mar 12, 2021
€3,000 Comune di San Marco in Lamis: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,000 on the municipality of San Marco in Lamis. The municipality had uploaded documents containing personal data of the data… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Mar 11, 2021
€80,000 Planet Group Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 80,000 on Planet Group Spa. The controller made promotional calls on behalf of TIM s.p.a.. Several of these calls were made… ITALY ·Garante ·Art. 5, 6, 12 +2 Right to Object Data Subject Rights Exercise Modalities and Procedures Direct Marketing Mar 11, 2021
€15,000 Mediacom s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Mediacom s.r.l.. The controller carried out advertising calls on behalf of TIM s.p.a.. Several of the calls were made… ITALY ·Garante ·Art. 5, 6 Direct Marketing Controllers Processing Agreement Mar 11, 2021
€600,000 Municipality of Enschede: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the municipality of Enschede EUR 600,000. In 2017, the municipality decided to install special measurement boxes to measure crowds in the city center… THE NETHERLANDS ·AP ·Art. 5, 6 IP Address Education Public Authority Mar 11, 2021
€8.2M Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Since 2018, the Spanish DPA (AEPD) had received a total of 191 complaints against Vodafone España, S.A.U. The data subjects complained about advertising calls and messages (e-mail… SPAIN ·aepd ·Art. 21, 23, 24 +3 Right to Object Fines Direct Marketing Mar 11, 2021
€200 Self Employed Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 200 on a self employed person. The accused obtained scans of identity cards from foreign subjects who booked accommodation there and kept… CZECH REPUBLIC ·UOOU ·Art. 5, 6, 12 +4 Personal Data Consent Processing Mar 10, 2021
€10,000 Hospital Campogrande DE: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 10,000 on Hospital Campogrande DE. A patient filed a complaint against the controller with the DPA. The controller had performed an… SPAIN ·aepd ·Art. 5 Healthcare Healthcare IP Address Mar 10, 2021
€8,000 Filigrana Comunicación S.L.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Filigrana Comunicación S.L.U. EUR 8,000. The controller operates a website that provides information on internships offered by the Spanish Ministry of… SPAIN ·aepd ·Art. 6, 13, 14 IP Address Controllers Personal Data Mar 10, 2021
€300,000 VfB Stuttgart 1893 AG: Non-compliance with general data processing principles The DPA from Baden-Württemberg has imposed a fine of EUR 300,000 on the soccer club VfB Stuttgart 1893 AG for negligent breach of data protection accountability under Art. 5 (2)… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Accountability IP Address Controllers Mar 10, 2021
€90,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 150,000 on Xfera Móviles S.A.. The DPA had received two complaints from a data subject. The first complaint concerned the sending of… SPAIN ·aepd ·Art. 5, 17, 32 Telecommunications Controllers Personal Data Mar 10, 2021
€50,000 Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Equifax Iberica S.L. EUR 50,000 for a violation of Art. 6 (1) f) GDPR. The controller had added the data subject to a debtor register without… SPAIN ·aepd ·Art. 6 Legitimate Interest Personal Data Controllers Mar 10, 2021
€15,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 15,000 on a homeowners' association. The controller had publicly displayed the record of a homeowners' meeting in the elevator of the… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle IP Address Professional Secrecy Mar 9, 2021
€14,900 Dragefossen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) imposed a fine of EUR 14,900 on the energy company Dragefossen AS. The latter had installed a webcam on the roof of its office building in the… NORWAY ·Datatilsynet ·Art. 5, 6 Video Surveillance Monitoring Audit Logs Mar 8, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA ·ANSPDCP ·Art. 32, 58 Personal Data Security Controllers Mar 4, 2021
€25,000 Hellenic Bank: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 25,000 on Hellenic Bank. The bank had closed one of its branches in the city of Nicosia in 2015. When moving out of the space, a safe… CYPRUS ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Mar 3, 2021
Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles IP Address Encryption Controllers Mar 3, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Art. 12, 15, 31 +1 ·Insufficient fulfilment of information obligations Right of Access Procedures Right of Access Inspection Access Rights and Cooperation Obligations Mar 3, 2021
€40,000 Electricity Authority of Cyprus: Insufficient legal basis for data processing The Cypriot DPA imposed a fine of EUR 40,000 on the Electricity Authority of Cyprus. The controller used an automated system based on the so-called Brad-Factor to manage, monitor… Art. 6, 9 ·Insufficient legal basis for data processing Employees Controllers Personal Data Mar 3, 2021
€6,000 KEPIDES: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 6,000 against KEPIDES (real estate company). The controller had submitted a list of buyers of the properties it manages to a parliamentary… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Anonymization Controllers Security Mar 3, 2021
€9,000 SPAIN DPA: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 9,000 on a website operator. The controller had published photos of the data subject on its website without the consent of the data… aepd ·Art. 6, 13 ·Insufficient legal basis for data processing Personal Data Controllers Processing Agreement Mar 2, 2021
€200,000 I-DE Redes Eléctricas Inteligentes, S.A.U: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 200,000 on I-DE Redes Eléctricas Inteligentes, S.A.U. The DPA received complaints from Waitum, S.L. and Servicios Aby 2018, S.L.… SPAIN ·aepd ·Art. 5, 6 Integrity and Confidentiality Principle Controllers IP Address Mar 2, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA ·VDAI ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 2, 2021
€24,400 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined a company NOK 250,000 (EUR 24,400). The controller ordered an employee to set up an automatic forwarding of his/her employee email account… Datatilsynet ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Processing Agreement Employees Mar 2, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Healthcare Health Data Feb 26, 2021
€3,000 IT sprendimai sėkmei: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 3,000 on the company 'IT sprendimai sėkmei'. The DPA had opened an investigation regarding a quarantine app introduced in Lithuania… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Privacy Impact Assessment Health Data Feb 26, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY ·Garante ·Art. 5, 25, 35 Fairness & Transparency Privacy Impact Assessment DPIA Feb 25, 2021
€6,000 Comune di Commezzadura: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 6,000 on the municipality of Commezzadura. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare IP Address Feb 25, 2021
€4,000 Ministero dell’Istruzione, Ufficio Scolastico Regionale per il Lazio: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the Lazio Region School Authority. A parent had filed a complaint against the school authority for forwarding data of… ITALY ·Garante ·Art. 5, 6, 9 Education Healthcare Public Authority Feb 25, 2021
€2,000 Comune di Conflenti: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 2,000 on the municipality of Conflenti. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Feb 25, 2021
€6,000 Azienda Ospedaliera Universitaria Careggi: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Azienda Ospedaliera Universitaria Careggi for a breach of Art. 5 GDPR and Art. 9 GDPR. Azienda Ospedaliera… ITALY ·Garante ·Art. 5, 9 Data Breaches Healthcare Health Data Feb 25, 2021
€20,000 Gedi Gruppo Editoriale S.p.A.: Insufficient legal basis for data processing The Italian DPA (Garante) has fined Gedi Gruppo Editoriale S.p.A. 20,000 euros. The controller had published photos in its newspaper of people who were in custody in connection… ITALY ·Garante ·Art. 5 Controllers Consent Processing Feb 25, 2021
€12,000 Avilon Center 2016 S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) imposed a fine of EUR 20,000 on Avilon Center 2016 S.L. The data subject had received advertising calls from the controller, although the data subject was… SPAIN ·aepd ·Art. 21, 23, 48 Direct Marketing Personal Data Controllers Feb 24, 2021