Skip to content
Content type · 3,615 documents in this view · 3,836 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2901–2950 of 3,615 sort newestlargest fineoldest
€5,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Controllers Healthcare Apr 15, 2021
€90,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 150,000 on Vodafone España S.A.U.. Three data subjects had filed complaints with the AEPD against the controller. They complained… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications Apr 13, 2021
€750,000 TikTok: Insufficient fulfilment of information obligations The Dutch DPA (AP) has fined the video portal TikTok EUR 750,000 for violating the privacy of young children. The information that Dutch users - mostly young children - received… THE NETHERLANDS ·AP ·Art. 12 Personal Data Supervisory Authorities Supervision Apr 9, 2021
€3,400 Miljø- og Kvalitetsledelse AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 3,400 on Miljø- og Kvalitetsledelse AS. At one of the carwashes operated by the controller, incidents of vandalism had… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Processing Video Surveillance Apr 9, 2021
€60,000 Kutxabank, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine of EUR 100,000 on Kutxabank, S.A.. Following a complaint from a former customer, claiming that the bank did not comply with his request… SPAIN ·AEPD ·Art. 17 Personal Data Right to be Forgotten Controllers Apr 8, 2021
€2,800 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 2,800 on a company. The controller had installed location sensors on a number of cars in its fleet. The purpose of this… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Storage Limitation Retention Period Apr 8, 2021
€2,400 Promotech Digital S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined Promotech Digital S.L. EUR 2,400 for repeatedly sending the data subject advertising SMS, even though he never subscribed or agreed to receive… SPAIN ·AEPD ·Art. 21 Personal Data Direct Marketing Controllers Apr 6, 2021
€4,000 Stockhunters S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on Stockhunters S.L.. The controller was not able to answer the data subject's requests regarding the use of his personal… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Apr 5, 2021
€3,000 Kukimbia S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Kukimbia S.L. EUR 3,000. The controller is a company that stores, transports and distributes goods. Documents containing personal data about the… SPAIN ·AEPD ·Art. 32 Controllers Security Personal Data Apr 5, 2021
€3,000 Electrotecnica Bastida S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Electrotecnica Bastida S.L. EUR 3,000. Police officers had found 29 envelopes addressed to the controllers' respective employees on a vacant lot… SPAIN ·AEPD ·Art. 32 Security Controllers Personal Data Apr 5, 2021
€10,000 Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security The Romania DPA (ANSPDCP) has fined Telekom Romania Mobile Communications S.A. EUR 10,000 for failing to implement adequate security measures to ensure the security of personal… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Controllers Mar 30, 2021
€4,000 Comune di Castellanza: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the municipality of Castellanza. The municipality had uploaded documents containing personal data of the data subject… ITALY ·Garante ·Art. 5, 6 Public Authority Personal Data Processing Mar 25, 2021
€20,000 GEDI News Network Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on GEDI News Network Spa. A data subject filed a complaint with the Italian DPA against the controller regarding an… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Mar 25, 2021
€1,425 Operator of a care facility: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has imposed a fine of EUR 1,425 on the operator of a care facility. The operator had installed a total of 25 cameras in all rooms of the facility, with… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Processing Mar 25, 2021
€4.5M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Fastweb S.p.A. EUR 4,500,000 for aggressive telemarketing. Following a complex preliminary investigation launched after hundreds of reports and… ITALY ·Garante ·Art. 5, 6, 7 +8 Direct Marketing Personal Data Controllers Mar 25, 2021
€6,000 Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (boarding school): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (CE) boarding school. The boarding school had published a document… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Public Authority Processing Mar 25, 2021
€30,000 OneDirect Srl: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 30,000 on OneDirect Srl. A data subject had filed two complaints with the DPA after receiving advertisements by e-mail from the… ITALY ·Garante ·Art. 6, 7, 30 +1 Personal Data Controllers Processing Mar 25, 2021
€7,000 TECNOMEDICAL S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 7,000 on TECNOMEDICAL S.r.l.. A data subject filed a complaint with the DPA after the controller failed to properly respond to… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Mar 25, 2021
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY ·NAIH ·Art. 32, 33, 34 Encryption Personal Data Security Mar 24, 2021
€90,000 Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 90,000 on Irish Credit Bureau (ICB). The fine follows a data breach reported by the controller to the DPA on August 31, 2018. The… IRELAND ·DPC ·Art. 5, 24, 25 Controllers Security Data Breaches Mar 23, 2021
€1,000 Laboratorio Octogón, S.L.: Non-compliance with general data processing principles Usage of CCTV camera systems that were also monitoring public space (breach of principle of data minimization). SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Mar 23, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Controllers Mar 23, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Controllers Supervisory Authorities Mar 22, 2021
€19,900 Basaren Drift AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 19,900 on Basaren Drift AS. The controller had installed video cameras in its premises which recorded both its employees… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Mar 21, 2021
€4,900 Funeda Sp. z o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined Funeda Sp. z o.o. EUR 4,900 for failing to provide information requested by the DPA during an investigation. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Mar 19, 2021
€3,000 Asesoría Alpi-Clúa S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 3,000 on Asesoría Alpi-Clúa S.L.. A client had requested documents from the controller to submit them to the tax authorities. The… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing Insurance Mar 18, 2021
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 60,000 on Vodafone Spain. The data subject had been a customer of the controller several years ago. After receiving payment reminders… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Telecommunications Mar 16, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Mar 15, 2021
€3,000 Cultural association: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 3,000 on a cultural association. The controller had published pictures of a four-year-old child on various groups of the Chinese… SPAIN ·AEPD ·Art. 6 Controllers Consent Supervisory Authorities Mar 15, 2021
€1,000 School: Insufficient legal basis for data processing The Belgian DPA (APD) fined a school EUR 1,000. The controller had conducted a survey on student well-being via a smartschooling system. The DPA states that the controller did not… BELGIUM ·APD/GBA ·Art. 5, 6, 8 Retention Period Controllers Consent Mar 15, 2021
€600,000 Air Europa Lineas Aereas, SA.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) fined Air Europa Lineas Aereas, SA. EUR 600,000 after a serious data breach involving unauthorized access to contact details and bank accounts was reported… SPAIN ·AEPD ·Art. 32, 33 Data Breaches Security Controllers Mar 15, 2021
€2,000 Heredad de Urueña S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Heredad de Urueña S.A. EUR 2,000 because its personal data processing policy did not comply with the requirements of Art. 13 GDPR. In addition, the… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 24 +1 Public Authority Personal Data Security Mar 15, 2021
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY ·Datatilsynet (NO) ·Art. 24, 32, 35 DPIA Security Monitoring Mar 15, 2021
€1,500 Private Person: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a private individual EUR 1,500. The controller had installed a video surveillance camera facing a public thoroughfare and covering parts of the… SPAIN ·AEPD ·Art. 5 Controllers Processing Video Surveillance Mar 12, 2021
€12,000 NBQ Technology, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined NBQ Technology, S.A.U. EUR 20,000. An identity thief had obtained the data of a third party without authorization and applied for a microcredit… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Recipient Mar 12, 2021
€15,000 Mediacom s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 15,000 on Mediacom s.r.l.. The controller carried out advertising calls on behalf of TIM s.p.a.. Several of the calls were made… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Consent Mar 11, 2021
€8.2M Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Since 2018, the Spanish DPA (AEPD) had received a total of 191 complaints against Vodafone España, S.A.U. The data subjects complained about advertising calls and messages (e-mail… SPAIN ·AEPD ·Art. 21, 23, 24 +3 Personal Data Right to Object Direct Marketing Mar 11, 2021
€3,000 Comune di San Marco in Lamis: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,000 on the municipality of San Marco in Lamis. The municipality had uploaded documents containing personal data of the data… ITALY ·Garante ·Art. 5, 6 Public Authority Personal Data Processing Mar 11, 2021
€600,000 Municipality of Enschede: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the municipality of Enschede EUR 600,000. In 2017, the municipality decided to install special measurement boxes to measure crowds in the city center… THE NETHERLANDS ·AP ·Art. 5, 6 Public Authority Processing IP Address Mar 11, 2021
€80,000 Planet Group Spa: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 80,000 on Planet Group Spa. The controller made promotional calls on behalf of TIM s.p.a.. Several of these calls were made… ITALY ·Garante ·Art. 5, 6, 12 +2 Right to Object Direct Marketing Personal Data Mar 11, 2021
€8,000 Filigrana Comunicación S.L.U.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Filigrana Comunicación S.L.U. EUR 8,000. The controller operates a website that provides information on internships offered by the Spanish Ministry of… SPAIN ·AEPD ·Art. 6, 13, 14 Personal Data Controllers Consent Mar 10, 2021
€200 Self Employed Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 200 on a self employed person. The accused obtained scans of identity cards from foreign subjects who booked accommodation there and kept… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 12 +4 Personal Data Consent Processing Mar 10, 2021
€300,000 VfB Stuttgart 1893 AG: Non-compliance with general data processing principles The DPA from Baden-Württemberg has imposed a fine of EUR 300,000 on the soccer club VfB Stuttgart 1893 AG for negligent breach of data protection accountability under Art. 5 (2)… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Controllers Accountability Processing Mar 10, 2021
€10,000 Hospital Campogrande DE: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 10,000 on Hospital Campogrande DE. A patient filed a complaint against the controller with the DPA. The controller had performed an… SPAIN ·AEPD ·Art. 5 Controllers Processing Healthcare Mar 10, 2021
€90,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 150,000 on Xfera Móviles S.A.. The DPA had received two complaints from a data subject. The first complaint concerned the sending of… SPAIN ·AEPD ·Art. 5, 17, 32 Personal Data Controllers Security Mar 10, 2021
€50,000 Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Equifax Iberica S.L. EUR 50,000 for a violation of Art. 6 (1) f) GDPR. The controller had added the data subject to a debtor register without… SPAIN ·AEPD ·Art. 6 Legitimate Interest Personal Data Controllers Mar 10, 2021
€15,000 Homeowners Association: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 15,000 on a homeowners' association. The controller had publicly displayed the record of a homeowners' meeting in the elevator of the… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Mar 9, 2021
€14,900 Dragefossen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) imposed a fine of EUR 14,900 on the energy company Dragefossen AS. The latter had installed a webcam on the roof of its office building in the… NORWAY ·Datatilsynet (NO) ·Art. 5, 6 Controllers Personal Data Processing Mar 8, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA ·ANSPDCP ·Art. 32, 58 Security Personal Data Controllers Mar 4, 2021