Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2901–2950 of 3,446 sort newestlargest fineoldest
€100 SLOVAKIA DPA: €100 fine Unlawful video surveillance in a garden community. Slovak Data Protection Office ·Unknown Video Surveillance Monitoring Supervisory Authorities Jan 1, 2021
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. A restaurant employee obtained first names, last… Unknown IP Address Personal Data Healthcare Jan 1, 2021
Clinic: Insufficient involvement of data protection officer The DPA from Berlin has imposed a fine on a clinic. The clinic had appointed the clinic manager, who was also a shareholder of the clinic, as the data protection officer. A data… GERMANY ·Insufficient involvement of data protection officer Notified Body Responsibilities and Operational Obligations Supervisory Authorities Notified Body Independence Jan 1, 2021
Physician: Insufficient technical and organisational measures to ensure information security A physician had stored patient records in an open carport and not in a locked room. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Security Supervisory Authorities Jan 1, 2021
Private individual: Data Protection Authority of Saxony A resident of a residential building had unlawfully made video recordings which, among other things, covered parts of the jointly used inner courtyard. GERMANY ·Unknown Supervisory Authorities Jan 1, 2021
Private individual: Non-compliance with general data processing principles The Austrian DPA has fined a private individual. The individual had installed a video surveillance system which, among other things, also recorded the public space and stored the… AUSTRIA ·dsb ·Art. 5 Video Surveillance Monitoring IP Address Jan 1, 2021
Company: Data Protection Authority of Brandenburg The DPA of Brandenburg has imposed a fine on a company. An individual had filed a complaint with the DPA based on the fact that the company produced a video recording in which the… GERMANY ·Unknown Supervisory Authorities Law Enforcement Processing Agreement Jan 1, 2021
Private individual: Insufficient legal basis for data processing The DPA from Brandenburg imposed a three-digit fine on a company employee. The individual had sent an Excel spreadsheet with employee data of 56 employees to her private e-mail… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Employees Processing Agreement Human Resources Jan 1, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles DPIA Accountability Controllers Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried the investigation process of a friend against the background of a… GERMANY ·Insufficient legal basis for data processing Public Authority Education Public Sector Jan 1, 2021
Attorney: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on an attorney. The attorney had been in dispute with a client for several years over a monetary claim. For two years, he published the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Insurance Personal Data Processing Jan 1, 2021
€1,800 Police officer: Insufficient legal basis for data processing A police officer repeatedly had accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
Private individual: Data Protection Authority of Saxony A private individual had taken secret video recordings during a court hearing with their mobile phone. GERMANY ·Unknown Supervisory Authorities Jan 1, 2021
Physician: Insufficient legal basis for data processing The DPA of Brandenburg imposed a fine on a physician. The father of a minor patient had filed a complaint with the DPA because the physician had transmitted numerous data on his… GERMANY ·Art. 6, 9 ·Insufficient legal basis for data processing Healthcare Insurance Healthcare Jan 1, 2021
Gym owner: Data Protection Authority of Saxony The owner of a gym had apologized for the late opening of the gym, but at the same time shifted the responsibility to an employee who was named. As a result, their personal data… GERMANY ·Unknown Personal Data Supervisory Authorities Employees Jan 1, 2021
Police officer: Insufficient legal basis for data processing A police officer repeatedly had accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
Job center employee: Insufficient legal basis for data processing A job center employee had accessed data in social database systems and in the civil register for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2021
Medical clinic: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on a medical clinic. The clinic had installed 21 cameras in its premises for the purpose of protection against crime and property damage.… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Healthcare Healthcare Jan 1, 2021
€3,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) fined ING Bank N.V. Amsterdam - Bucharest office in the amount of EUR 3,000. The bank had contacted the data subject by e-mail for the purpose of… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers IP Address Dec 30, 2020
€1,000 Qualitance QBS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Qualitance QBS SA EUR 1,000 for a violation of Art. 32 GDPR. The company had sent information by email to 295 individuals, disclosing the email… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Security Professional Secrecy Dec 29, 2020
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND ·UODO ·Art. 33, 34 Data Breaches Notification Obligation Notified Body Reporting and Notification Obligations Dec 28, 2020
€50,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 50,000 on a company for several violations of the GDPR. The controller is a company that carries out parking ticket controls. The… APD ·Art. 5, 12, 14 +2 ·Insufficient fulfilment of data subjects rights Personal Data IP Address Controllers Dec 23, 2020
€15,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 15,000 on a company due to insufficient fulfilment of data subject rights. The controller is a debt collection agency which was… APD ·Art. 5, 6, 12 +2 ·Insufficient fulfilment of data subjects rights Personal Data Data Subject Rights Exercise Modalities and Procedures Controllers Dec 23, 2020
€6,000 Iberdrola Clientes, SAU: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) fined Iberdrola Clientes, SAU EUR 6,000. The data subject had received promotional calls from two different telephone numbers of the controller although the… SPAIN ·aepd ·Art. 21, 23, 48 Personal Data Controllers Direct Marketing Dec 22, 2020
€2,000 S.C. C&V Water Control S.A.: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) fined S.C. C&V Water Control S.A. EUR 2,000 for failure to comply with the data protection authority's request for information in the course of an… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 22, 2020
€36,000 Banco Bilbao Vizcaya Argentaria, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data… SPAIN ·aepd ·Art. 5 Personal Data Controllers Insurance Dec 21, 2020
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives IP Address Personal Data Dec 20, 2020
€8,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,800 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€11,830 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€8,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,800 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€10,070 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€8,340 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€9,420 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€26,710 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€8,100 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,100 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 200 on a legal person. The accused sent the data subject, despite his objection and therefore his disagreement with further processing of… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Right to Object Direct Marketing Dec 18, 2020
€12,910 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Dec 18, 2020
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 Health Data DPIA Healthcare Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Dec 17, 2020
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… UODO ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Privacy by Design & Default Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Personal Data IP Address Dec 17, 2020
€3,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 3,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data as MRI and X-ray images as well as… FRANCE ·CNIL ·Art. 32, 33 Healthcare Healthcare Security Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Garante ·Art. 12 Personal Data Education Controllers Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Retention Period Storage Limitation Healthcare Dec 17, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 17, 2020
€6,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well… FRANCE ·CNIL ·Art. 32, 33 Healthcare Healthcare Security Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority IP Address Controllers Dec 17, 2020