Skip to content
Content type · 3,610 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2801–2850 of 3,610 sort newestlargest fineoldest
€10,000 TNT EXPRESS WORLDWIDE SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 10,000 on TNT EXPRESS WORLDWIDE SPAIN, S.L.. The data subject had placed a private order with the controller and had entered the… AEPD ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers Processing Jun 22, 2021
€24,800 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 14,800 on a company. The background to the case is a complaint by a former employee who learned that the company's… Datatilsynet (NO) ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Supervisory Authorities Right to Object Controllers Jun 22, 2021
€1.6M Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has fined Storstockholms Lokaltrafik (Stockholm Local Transport Company) EUR 1,600,000. The controller had equipped ticket inspectors with body-worn cameras, which… SWEDEN ·IMY ·Art. 5, 6, 13 Retention Period Identification Fairness & Transparency Jun 21, 2021
€20,000 UAB VS FITNESS: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) has imposed a fine of EUR 20,000 on UAB VS FITNESS. After receiving a notification from an individual stating that scanning a fingerprint was necessary… LITHUANIA ·VDAI ·Art. 5, 9, 13 +2 DPIA Controllers Identification Jun 21, 2021
€35,300 Sopockie Towarzystwo Ubezpieczeń ERGO Hestia S.A.: Insufficient fulfilment of data breach notification obligations The controller had sent an email to that contained personal data of a customer to the wrong recipient. The leaked data included data such as the name, postal address of the data… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 21, 2021
€28,400 Magyar Telekom Nyrt.: Insufficient fulfilment of data subjects rights The Hungarian DPA (NAIH) has imposed a fine of EUR 28,400 on Magyar Telekom Nyrt. The controller had mistakenly sent an e-mail newsletter to the data subject. This occurred due to… HUNGARY ·NAIH ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Jun 18, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Jun 16, 2021
€34,000 Huppuís ehf: Non-compliance with general data processing principles The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 34,000 on Huppuís ehf. A former employee filed a complaint against the controller with the DPA. The reason for this was… ICELAND ·Persónuvernd ·Art. 5, 6, 12 +1 Legitimate Interest Controllers Supervisory Authorities Jun 15, 2021
€1,200 Inmopiso Zaragoza S.L.: Insufficient fulfilment of information obligations The controller failed to provide accurate information about the data collection in accordance with Art. 13 GDPR. The original fine of EUR 2,000 was reduced to EUR 1,200 due to… SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Jun 14, 2021
€500,000 BRICO PRIVÉ: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 500,000 on BRICO PRIVÉ. CNIL conducted three inspections at BRICO PRIVÉ between 2018 and 2021 and identified several deficiencies… FRANCE ·CNIL ·Art. 5, 13, 17 +2 Storage Limitation Retention Period Personal Data Jun 14, 2021
€7,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,600 on a company. This company had installed a video surveillance system for the purpose of protecting the company's… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Accountability Jun 11, 2021
€15,000 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA of Luxembourg (CNPD) has imposed a fine of EUR 15,000 on a company. During an investigation, the DPA found that the controller had not sufficiently involved the data… CNPD (LU) ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Personal Data Jun 11, 2021
€7,200 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,200 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD (LU) ·Art. 5, 13, 32 ·Non-compliance with general data processing principles Supervisory Authorities Storage Limitation Retention Period Jun 11, 2021
€20,000 Dentist: Insufficient legal basis for data processing The Italian DPA (Garante) has fined a dentist EUR 20,000. A data subject filed a complaint with the DPA against the dentist for refusing to treat him after the data subject had… ITALY ·Garante ·Art. 5 Personal Data Processing Healthcare Jun 10, 2021
€40,000 aiComply S.r.l.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 28, 32 Encryption Security Controllers Jun 10, 2021
€2.6M Foodinho s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Foodinho s.r.l. EUR 2,600,000. Foodinho is an Italian food delivery service. The investigation against Foodinho mainly focused on the drivers… ITALY ·Garante ·Art. 5, 13, 22 +5 Retention Period Privacy by Design & Default DPIA Jun 10, 2021
€40,000 Aeroporto Guglielmo Marconi di Bologna S.p.a.: Insufficient technical and organisational measures to ensure information security The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Encryption Security Jun 10, 2021
€34,800 Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 34,800 on the directorate of the Östra Skaraborg Rescue Service. The DPA had received information that several fire stations in Östra… SWEDEN ·IMY ·Art. 5, 32 Controllers Processing Video Surveillance Jun 9, 2021
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused did not respond to the subject's request to disclose what information the accused was processing about… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jun 9, 2021
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused did not respond to the complainant's repeated requests to provide access to personal data and to… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Right of Access Personal Data Supervisory Authorities Jun 9, 2021
€2,000 La Santrade S.R.L.: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined La Santrade S.R.L. EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 31, 58 Supervisory Authorities Supervision Personal Data Jun 9, 2021
€2,000 S.C. Dreamtime Call S.R.L.: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined S.C. Dreamtime Call S.R.L. EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Jun 9, 2021
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUr 2,000 on a legal person. The accused did not respond to the subject's request to disclose what information the accused was processing about… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Jun 9, 2021
€2,000 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on an unknown controller. The accused did not respond to the subject's request to disclose what information the accused was… ÚOOÚ (CZ) ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers Jun 9, 2021
€50,000 Region Stockholm: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13, 14 Supervisory Authorities Personal Data Security Jun 7, 2021
€20,000 Master Distancia S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 25,000 on Master Distancia S.A.. The controller had included personal data of the data subject in a credit report register without… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Public Authority Jun 7, 2021
€25,000 Region Värmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Värmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·IMY ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Encryption Personal Data Jun 7, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jun 7, 2021
€19,600 Radiotelevisión del principado de Asturias: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 26,000 on Radiotelevisión del principado de Asturias. The fine consists of EUR 20,000 due to a violation of Art. 5 (1) c) GDPR and… SPAIN ·AEPD ·Art. 5, 12 Retention Period Controllers Supervisory Authorities Jun 7, 2021
€25,000 Region Sörmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Sörmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€49,200 Moss municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Personal Data Public Authority Jun 4, 2021
€6,000 Creator Energy S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on Creator Energy S.L.. The controller had used the personal data of the data subject without his consent to conclude… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 4, 2021
€15,000 PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ: Non-compliance with general data processing principles The Hellenic DPA has fined PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ EUR 15,000 due to the illegal installation and operation of a video surveillance system. The controller had installed a video… GREECE ·HDPA ·Art. 5 Accountability Controllers Transparency Jun 3, 2021
€4,000 Avalos Consultores, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Avalos Consultores, S.L.. The data subject, who was a client of the controller, filed a complaint with the AEPD because… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Consent Jun 2, 2021
€18,000 LUXEMBOURG DPA: Insufficient involvement of data protection officer The DPA of Luxembourg has imposed a fine of EUR 18,000 on a company. According to the DPA, the controller firstly failed to involve the data protection officer in all matters… CNPD (LU) ·Art. 38, 39 ·Insufficient involvement of data protection officer Supervisory Authorities Controllers Personal Data May 31, 2021
€450,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has fined UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen) EUR 450,000. The UWV had not properly secured the… THE NETHERLANDS ·AP ·Art. 32 Security Insurance Healthcare May 31, 2021
€39,700 BRAbank ASA: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,700 on BRAbank ASA. The controller had reported a data breach to the DPA on September 6, 2019. On the controller's… NORWAY ·Datatilsynet (NO) ·Art. 24, 32 Security Controllers Personal Data May 28, 2021
€120,000 Azienda Usl della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Usl della Romagna EUR 120,000. The local health authority of Romagna had accidentally transmitted a patient's report regarding an… ITALY ·Garante ·Art. 5, 9 Healthcare Processing International Transfer May 27, 2021
€2,000 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 2,000 on a private individual for the unauthorized use of video surveillance cameras, which also recorded parts of public space… SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Monitoring May 27, 2021
€150,000 Azienda Provinciale per i Servizi Sanitari di Trento: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda Provinciale per i Servizi Sanitari di Trento EUR 150,000. The controller had accidentally forwarded 293 medical reports of 175 patients… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Processing May 27, 2021
€3,000 Vodafone España, S.A.U.: Insufficient cooperation with supervisory authority Failure to provide information to the Spanish DPA (AEPD) within the required timeframe in violation of Art. 58 GDPR. The original fine of EUR 5,000 was reduced by 20% EUR 3,000… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Telecommunications May 26, 2021
€900 Managing Director of a company: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 1,500 on the managing director of a company. A data subject filed a complaint with the AEPD against the controller with whom he… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities May 25, 2021
€4,000 Alava Norte, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Alava Norte, S.L. EUR 4,000. The controller had installed three 360° video surveillance cameras on the facade of one of its buildings to secure… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Security May 25, 2021
€100,000 Vodafone España, SAU: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Vodafone España, S.A.U.. A data subject had filed a complaint with the Spanish DPA against the telecommunications… SPAIN ·AEPD ·Art. 28 Processors Controllers Personal Data May 25, 2021
€6,000 Desolasol Restauración, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined Desolasol Restauración S.L. EUR 6,000. The data subject had submitted a consumer complaint form to the restaurant because he was unable to… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing May 25, 2021
€45,000 Telefónica de España, S.A.U: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 75,000 on Telefonica de España, S.A.U.. A data subject had filed a complaint with the AEPD against the telecommunications company.… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications May 21, 2021
€3,000 Physician: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined a physician EUR 3,000. The controller had left his/her former clinic and started working in a new clinic. The complainant had taken over the… SPAIN ·AEPD ·Art. 6 Controllers Healthcare Supervisory Authorities May 21, 2021
€3,000 Homeowners Association: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·AEPD ·Art. 5, 12 Retention Period Processing Supervisory Authorities May 21, 2021
€39,000 Municipality of Oslo: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,000 on the Municipality of Oslo. On a website of the controller a subpoena from the public prosecutor's office… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Personal Data Types of Special Categories of Personal Data Controllers May 20, 2021