Skip to content
Content type · 402 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 402 sort newestlargest fineoldest
€67,200 SIRIUS (law firm): Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 67,200 on the law firm SIRIUS. The law firm had suffered a cyber attack in which hackers gained access to the firm's servers and encrypted… DENMARK ·Datatilsynet (DK) ·Art. 32 Encryption Security Integrity and Confidentiality Principle Jul 14, 2022
€132,000 DKV Seguros y Reaseguros, S.A.E.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DKV Seguros y Reaseguros, S.A.E.. An individual had filed a complaint with the DPA after receiving multiple e-mails from the controller… SPAIN ·AEPD ·Art. 5, 32, 33 Data Breaches Security Controllers Jul 13, 2022
€202,000 Manx Care Ltd: Non-compliance with general data processing principles The DPA of Isle of Man has imposed a fine of EUR 202,000 on Manx Care Ltd. Manx Care had emailed an unsecured attachment containing a patient's confidential health information to… ISLE OF MAN ·Art. 5, 24, 25 +3 ·Non-compliance with general data processing principles Data Breaches Retention Period Privacy by Design & Default Jul 13, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Data Breaches Personal Data Healthcare Jul 7, 2022
€12,450 Głównego Geodetę Kraju: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 12,450 on the public cartography institute Głównego Geodetę Kraju. The institute had suffered a data breach in which numerous land… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 6, 2022
€2,120 University Hospital of the Medical University of Warsaw: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 2,120 on the University Hospital of the Medical University of Warsaw. The university hospital had suffered a data breach in which a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 6, 2022
€2,000 Continental Automotive Romania SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Continental Automotive Romania SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jun 30, 2022
€1,600 URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.: Insufficient fulfilment of data breach notification obligations The spanish DPA has fined URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.for failing to report a data breach to the DPA in a timely manner. The original fine of EUR 2,000 was reduced to… SPAIN ·AEPD ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 22, 2022
€3,500 Esselmann Technika Pojazdowa Sp. z o.o. Sp. k.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Esselmann Technika Pojazdowa Sp. z o.o. Sp. k. EUR 3,500. The controller had suffered a data breach during which a certificate of employment containing… POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 6, 2022
€2,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Kaufland România SCS. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. An employee who… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jun 3, 2022
€5,000 Kredyt Inkaso Investments RO S.A: Insufficient legal basis for data processing The Romanian DPA has fined Kredyt Inkaso Investments RO S.A. EUR 5,000. A data subject had filed a complaint with the DPA against the controller for having disclosed their… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +1 Data Breaches Personal Data Controllers May 18, 2022
€4,000 INSEKT FOOD S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 4,000 on INSEKT FOOD S.L.. A data subject hat filed a complain with the DPA against the controller due to the fact that the… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Integrity and Confidentiality Principle May 17, 2022
€13,400 Civilstyrelsen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 13,400 on the Danish agency Civilstyrelsen. A Civilstyrelsen USB stick containing more than 800 pages of sensitive and confidential… DENMARK ·Datatilsynet (DK) ·Art. 32, 33 Encryption Data Breaches Security May 12, 2022
€500,000 Bulgarian Post EAD: Insufficient technical and organisational measures to ensure information security The Bulgarian DPA has imposed a fine of EUR 500,000 on Bulgarian Posts EAD. The controller had suffered a hacking attack, during which the attackers managed to access the… BULGARIA ·CPDP ·Art. 32 Security Controllers Personal Data May 4, 2022
€36,000 City of Reykjavík: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 36,000 on the City of Reykjavík. The city had used the digital education system 'Seesaw' at several schools. The student system… ICELAND ·Persónuvernd ·Art. 5, 6, 32 Retention Period Personal Data Security May 3, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Data Breaches Security Apr 28, 2022
€50,000 Istituto Nazionale Assicurazione Infortuni sul Lavoro: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Istituto Nazionale Assicurazione Infortuni sul Lavoro (Public Accident Insurance for workers) EUR 50,000. As part of its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +2 Security Personal Data Data Breaches Apr 28, 2022
€1,000 ASST di Lodi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 1,000 on ASST di Lodi. The healthcare facility had reported a data breach to the DPA pursuant to Art. 33 GDPR. A patient had… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Personal Data Security Apr 26, 2022
€463,000 Bank of Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined the Bank of Ireland EUR 463,000. The bank had reported 22 data breaches to the DPA under Article 33 GDPR. As part of its investigation, the DPA found that… DPC ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Apr 5, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Integrity and Confidentiality Principle Data Breaches Personal Data Apr 4, 2022
€2,000 Condor SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Mar 28, 2022
€10,000 Brav s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Brav s.r.l.. The operator of the online platform had reported a data breach to the DPA pursuant to Art. 33 GDPR. Unauthorized… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Mar 24, 2022
€4,000 English School Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email… Cyprus DPA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data Mar 22, 2022
€5,000 English School staff union (ESSA): Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a… CYPRUS ·Cyprus DPA ·Art. 32 Data Breaches Security Personal Data Mar 21, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… DPC ·Art. 5, 24 Accountability Supervision Security Mar 15, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Security Personal Data Processing Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Security Healthcare Mar 10, 2022
€89,250 Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security A retail company, i.e. the data controller, reported the breach of personal data to the DPA informing that its employees have recorded video surveillance footage via mobile phone… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Mar 8, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Identification Mar 4, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Processing Feb 10, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Personal Data Supervisory Authorities Feb 10, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 32 Security Personal Data Public Authority Feb 2, 2022
€6M Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 6 million on Cosmote Mobile Telecommunications S.A.. Cosmote had reported a data breach to the DPA pursuant to Art. 33 GDPR. A hacker… GREECE ·HDPA ·Art. 5, 13, 14 +4 Data Breaches Anonymization Security Jan 27, 2022
€3.2M OTE Group: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 3.2 million on Cosmote subsidiary OTE Group. Among other things, OTE Group had contributed to Cosmote's security infrastructure. Cosmote… GREECE ·HDPA ·Art. 32 Data Breaches Notification Obligation Security Jan 27, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jan 26, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·IMY ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 26, 2022
€53,000 PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined PIKA Sp. z o.o. in the amount of EUR 53,000. The fine is related to a fine imposed on Fortum Marketing and Sales Polska S.A.. PIKA was acting as a… POLAND ·UODO ·Art. 28, 32 Security Encryption Pseudonymization Jan 19, 2022
€1M Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR.… POLAND ·UODO ·Art. 5, 24, 25 +2 Data Breaches Security Encryption Jan 19, 2022
€117,000 Santander Bank Polska S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 118,000 for failing to notify data subjects of a data breach. A former employee of the bank managed to gain unauthorized… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Personal Data Jan 19, 2022
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 1, 2022
Logistics company: Insufficient technical and organisational measures to ensure information security A logistics company had disposed of delivery lists in a public waste paper container. The lists contained a large amount of detailed information, such as the first and last names… GERMANY ·HmbBfDI ·Art. 32, 33 Data Breaches Personal Data Security Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Cyprus DPA ·Art. 24, 28 Controllers Processors Processing Jan 1, 2022
Company: Insufficient fulfilment of data breach notification obligations The DPA from Bremen has fined a company for failing to inform the DPA pursuant to Art. 33 GDPR that an employee's business email account had been hacked. GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2022
€16,400 Covid-19 test center: Insufficient legal basis for data processing The DPA of Hessen has fined a Covid-19 test center EUR 16,400. The controller had sent an e-mail containing personal data to several recipients in an open distribution list. The… GERMANY ·Art. 6, 33 ·Insufficient legal basis for data processing Data Breaches Controllers Personal Data Jan 1, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processors Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Cyprus DPA ·Art. 28, 32 Security Processors Controllers Jan 1, 2022
€75,000 Greek Ministry of Tourism: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 75,000 on the Greek Ministry of Tourism. A data breach had occurred at the authority. According to the DPA, an attempt by a citizen to… GREECE ·HDPA ·Art. 13, 32, 33 +1 Data Breaches Notification Obligation Public Authority Dec 29, 2021
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Personal Data Dec 28, 2021