Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2851–2900 of 3,446 sort newestlargest fineoldest
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY ·Garante ·Art. 5, 32 Security Education Controllers Jan 14, 2021
€2M Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Caixabank S.A. EUR 6,000,000 for violations of Art. 6 GDPR, Art. 13 GDPR and Art. 14 GDPR. Customers of the bank were supposed to accept new privacy… SPAIN ·aepd ·Art. 6, 13, 14 Legitimate Interest Processing Agreement Controllers Jan 13, 2021
€10,000 BELGIUM DPA: Insufficient legal basis for data processing Managing a fan page on Facebook without the data subject's permission and failing to comply with the data subject's request after exercising his or her right to object. APD ·Art. 6, 12, 21 ·Insufficient legal basis for data processing Right to Object Social Media Data Subject Rights Exercise Modalities and Procedures Jan 12, 2021
€38,600 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined a company NOK 400,000 (EUR 38,600) for the illegal automatic forwarding of an employee's email inbox. The automatic forwarding was activated… Datatilsynet ·Art. 5, 6 ·Insufficient legal basis for data processing Employees Processing Agreement Processing Jan 12, 2021
€30,000 Enea S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information… POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 11, 2021
€10M notebooksbilliger.de: Insufficient legal basis for data processing The DPA of Lower Saxony (LfD Niedersachsen) imposed a fine of EUR 10,4 million on the electronics retailer notebooksbilliger.de.The company had video-monitored its employees for… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Monitoring Employees Jan 8, 2021
€7,250 Gveik AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Gveik AS EUR 7,250. The controller had carried out a credit check on an individual, although there was no legal basis for doing so. NORWAY ·Datatilsynet ·Art. 5, 6 Controllers Insurance Processing Agreement Jan 7, 2021
€9,700 Lindstrand Trading AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined Lindstrand Trading AS EUR 9,700. The controller had carried out four credit checks on individuals and individual companies, although… NORWAY ·Datatilsynet ·Art. 5, 6 Controllers Insurance Processing Agreement Jan 6, 2021
€19,000 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of EUR 19,000 on a hospital operator. A former employee had unlawfully copied the personal data of 100 patients from the hospital's computer… UODO ·Art. 34, 58 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 5, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 5, 2021
€20,000 Nestor SAS: Insufficient fulfilment of information obligations The French DPA (CNIL) fined the company Nestor EUR 20,000. The CNIL notes that the privacy policy provided during the registration process on the company´s website did not contain… FRANCE ·CNIL ·Art. 12, 13 Controllers Processing Agreement Processing Jan 5, 2021
€118,500 CZECH REPUBLIC DPA: Insufficient legal basis for data processing The Czech DPA (UOOU) fined 11 companies a total of EUR 118,500 for sending unrequested postal advertising messages to the mailboxes of various citizens. Based on a decision by the… UOOU ·Art. 6, 14 ·Insufficient legal basis for data processing Direct Marketing Processing Agreement Personal Data Jan 4, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out four credit checks on the data… NORWAY ·Datatilsynet ·Art. 5, 6 Insurance Controllers Personal Data Jan 4, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN ·aepd ·Art. 5 Accuracy Personal Data Telecommunications Jan 4, 2021
Physician: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a four-digit fine on a doctor of child and adolescent psychotherapy. The doctor had set up a Whatsgroup with 230 participants to communicate… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Healthcare Consent IP Address Jan 1, 2021
Private individual: Non-compliance with general data processing principles A private individual had installed video surveillance cameras which, among other things, also covered the public space GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jan 1, 2021
Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of patient records in a waste paper container used by several offices. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Security Supervisory Authorities Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully accessed data in a police database. For this reason, the DPA of Brandenburg imposed a fine for a violation of § 32 (1) BbgDSG. The Brandenburg Data… GERMANY ·Insufficient legal basis for data processing Public Authority Education Public Sector Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried his stepson's investigative process in order to prepare him for… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
€12,500 Energy supplier: €12,500 fine The DPA of Hamburg has imposed a fine of EUR 12,5000 on an energy supplier. The company had outsourced and sold its heating energy division. Customers affected by the transfer… GERMANY ·Unknown Right to Object Processing Agreement Personal Data Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer used a witness's personal data to contact her personally. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer accused in a criminal case intended to use the information from the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
€600 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes in order to obtain information about his ex-wife's new address. He discovered where his… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
€170 Restaurant: Non-compliance with general data processing principles In order to identify a guest who had not paid, several visitors were contacted by employees of a restaurant. For this purpose, the telephone numbers provided by the guests as part… GERMANY ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Agreement Healthcare Jan 1, 2021
€12,500 Energy supplier: €12,500 fine The DPA of Hamburg has imposed a fine of EUR 12,5000 on an energy supplier. The company had outsourced and sold its heating energy division. Customers affected by the transfer… GERMANY ·Unknown Right to Object Processing Agreement Data Subject Rights Exercise Modalities and Procedures Jan 1, 2021
€500 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes in order to obtain information about a colleague. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
€600 Private individual: Non-compliance with general data processing principles The Austrian DPA imposed a fine of EUR 600 on a private individual. The individual had contacted a public institution to draw their attention to the fact that the statement of a… AUSTRIA ·dsb ·Art. 5, 9 Personal Data Integrity and Confidentiality Principle Healthcare Jan 1, 2021
Restaurant: Insufficient technical and organisational measures to ensure information security A restaurant had disposed of 120 completed guest registration forms for contact tracing purposes during the Covid-19 pandemic in a publicly-accessible dumpster. During its… GERMANY ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Processing Agreement Jan 1, 2021
Political organization: Data Protection Authority of Saarland An employee of a political organization had sent an e-mail to 400 people in an open distribution list. This not only made the e-mail addresses of all recipients visible to the… GERMANY ·Unknown IP Address Supervisory Authorities Law Enforcement Jan 1, 2021
€16,000 Electronics store: Non-compliance with general data processing principles The DPA from Lower Saxony has imposed a fine of EUR 16,000 on an electronics store. The company had installed a video surveillance system which permanently recorded employees,… GERMANY ·Art. 5, 17, 35 ·Non-compliance with general data processing principles Video Surveillance DPIA IP Address Jan 1, 2021
Real estate agent: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a fine on a real estate agent. The real estate agent had contacted an individual and offered him to sell a property he owned. Since the… GERMANY ·Art. 6, 12 ·Insufficient legal basis for data processing Personal Data Data Subject Rights Exercise Modalities and Procedures Processing Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security A company had stored telecommunications hardware, a server and backup technology in a guest bathroom. The server cabinet, which did not have an intact lock, also served as a… GERMANY ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Human Resources Jan 1, 2021
€10,100 Car trading group: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 10,110 on a car trading group. The company had informed the customer base that the reasons for the restructuring there was the absence… GERMANY ·Insufficient legal basis for data processing Healthcare Health Data Processing Agreement Jan 1, 2021
Job center employee: Insufficient legal basis for data processing A job center employee had accessed data in social database systems and in the civil register for private research purposes. The employee wanted to prove that two of her colleagues… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing IP Address Scientific Research Processing Jan 1, 2021
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-digit fine on a company employee. The employee had forwarded application documents received by his employer from his work e-mail address… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Anonymization Processing Agreement Processing Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine in the six-digit range on a Hamburg-based company operating in the healthcare sector. The company had failed to take appropriate technical… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Recipient Jan 1, 2021
€500 SLOVAKIA DPA: Insufficient cooperation with supervisory authority The Slovak DPA has imposed a fine of EUR 500 on a controller for failing to cooperate with the DPA. Slovak Data Protection Office ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Jan 1, 2021
€5,000 Private individual: Insufficient legal basis for data processing The DPA of Hamburg imposed a fine of EUR 5,000 on a private individual. The individual had filmed numerous young women in public. Some of the recorded female persons were… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Consent Processing Jan 1, 2021
€700,000 Customer loyalty program: €700,000 fine According to the newspaper 'Der Standard', the Austrian DPA has imposed a fine of EUR 1.2 million on a customer loyalty program in 2021. Further information has not yet been… AUSTRIA ·dsb ·Unknown Processing Agreement Controllers Supervisory Authorities Jan 1, 2021
€4M Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… AUSTRIA ·dsb ·Art. 5, 32 Data Breaches Encryption Integrity and Confidentiality Principle Jan 1, 2021
Private individual: Insufficient legal basis for data processing Nineteen fines between EUR 100 and EUR 1,000 for unlawful use of a dashcam. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Fines Processing Supervisory Authorities Jan 1, 2021
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a cemetery had put out an open list in which visitors had to enter their contact data. A cemetery employee obtained first names, last… Unknown Personal Data IP Address Education Jan 1, 2021
Beverage retailer: Data Protection Authority of Berlin The DPA from Berlin imposed a fine against a beverage retailer. The retailer operated a video surveillance system in which the observation angle of the cameras extended into the… GERMANY ·Unknown Video Surveillance Monitoring Supervisory Authorities Jan 1, 2021
GERMANY DPA: Data Protection Authority of Schleswig-Holstein An employee at a Covid testing center had used a test subject's phone number to contact them privately. Unknown Healthcare Supervisory Authorities Processing Agreement Jan 1, 2021
€400 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes. The officer had purchased a notebook for private use on an Internet platform. Since the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Scientific Research Processing Jan 1, 2021
GERMANY DPA: Insufficient technical and organisational measures to ensure information security The camera images of a store were distributed without the knowledge and intention of the controller due to a faulty configuration. The distribution involved recordings of… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processing Agreement Jan 1, 2021
GERMANY DPA: Insufficient technical and organisational measures to ensure information security Live video surveillance which was accessible via the Internet and, due to a lack of sufficient pixelation or redaction, allowed persons to be recognized. Art. 32 ·Insufficient technical and organisational measures to ensure information security Video Surveillance Security Monitoring Jan 1, 2021
Bank employee: Insufficient legal basis for data processing An employee of a bank had regularly accessed the bank account data of a bank customer for private purposes over a period of about a year. GERMANY ·Insufficient legal basis for data processing Insurance Processing Supervisory Authorities Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer had queried the new partner of a friend's ex-wife because he feared that… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Personal Data Public Authority Education Jan 1, 2021