Skip to content
Content type · 277 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–277 of 277 sort newestlargest fineoldest
€2,000 Istituto Comprensivo Statale Crucoli Torretta: Insufficient technical and organisational measures to ensure information security Publication of personal data of students on the website of the Institute with, inter alia, notes about health and progress in school due to technical failure. ITALY ·Garante ·Art. 5, 32 Personal Data Security Education Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Personal Data Security Public Authority Sep 3, 2020
€2,000 School: Insufficient legal basis for data processing Placing personal data of pupils on a public notice board. ITALY ·Garante ·Art. 5, 6 Personal Data Processing Education Aug 5, 2020
€5,000 National Institute for Social Security - Department of the Province of Brescia: Insufficient fulfilment of data subjects rights ⇄ Failure to graint access to personal health data of a data subject according to Art. 15 GDPR. ITALY ·Garante ·Art. 15 Healthcare Personal Data Health Data Aug 4, 2020
€22,300 Office for geodesy and cartography: Insufficient cooperation with supervisory authority Refusal of access to the premises by the supervisory authority in the course of an audit. POLAND ·UODO ·Art. 31, 58 Supervision Supervisory Authorities Personal Data Jul 15, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet (NO) ·Art. 32, 35 DPIA Security Types of Special Categories of Personal Data Jul 10, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK ·Datatilsynet (DK) ·Art. 5, 6, 33 +1 Data Breaches Personal Data Types of Special Categories of Personal Data Jun 30, 2020
€40,000 Tusla Child and Family Agency: Insufficient fulfilment of data breach notification obligations The organization sent a letter with abuse allegations to a third party who then uploaded it to social networks. IRELAND ·DPC ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE ·HDPA ·Art. 5 Personal Data Processing Education Jun 29, 2020
€13,500 Department of Home Affairs: Insufficient fulfilment of data subjects rights Fines for failure to comply with the right of access to personal data under Articles 12 and 15 GDPR. The Isle of Man has declared the GDPR - although it is not an EU state - to be… ISLE OF MAN ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Inspection Access Rights and Cooperation Obligations Jun 25, 2020
€2,000 Political Party: Insufficient legal basis for data processing Forging signatures on a voters' list. BULGARIA ·CPDP ·Art. 6 Education Public Authority Processing Apr 14, 2020
€5,000 Centro De Estudio Dirigidos Delta, S.L.: Non-compliance with general data processing principles Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Accountability Mar 16, 2020
€9,000 Breiðholt Upper Secondary School: Insufficient technical and organisational measures to ensure information security In violation of Art. 32 GDPR, a teacher had sent an e-mail to his students and their parents with an attachment containing data on their well-being, academic performance and… ICELAND ·Persónuvernd ·Art. 5, 32 Security Education Public Authority Mar 10, 2020
€4,000 Liceo Artistico Statale di Napoli: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information in the teacher rankings published on the Institute's website. This… ITALY ·Garante ·Art. 5, 6, 9 Retention Period Fairness & Transparency Healthcare Mar 6, 2020
€4,000 Liceo Scientifico Nobel di Torre del Greco: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information of more than 2000 teachers in the teacher rankings published on the… ITALY ·Garante ·Art. 5, 6, 9 Retention Period Fairness & Transparency Healthcare Mar 6, 2020
School in Gdansk (Danzig) (fine imposed against town of Gdansk): Insufficient legal basis for data processing Original summary: A school in Gdansk used biometric fingerprint scanners to authenticate students for the payment process in the school canteen. Although the parents had given… POLAND ·UODO ·Art. 5, 9 Consent Personal Data Processing Mar 4, 2020
Rælingen Municipality: Insufficient technical and organisational measures to ensure information security On February 26, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Rælingen Municipality EUR 73,600 for violations of Art. 5 (1) f) GDPR and Art. 32 GDPR .… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Public Authority Education Feb 26, 2020
€3,000 Colegio Arenales Carabanchel (School): Insufficient legal basis for data processing The decision of the data protection authority states that the school transferred pictures (and therefore personal data) to third parties, who published them without legal basis. SPAIN ·AEPD ·Art. 6 Personal Data Education Public Authority Feb 14, 2020
€30,000 Sapienza Università di Roma: Insufficient technical and organisational measures to ensure information security The fine is based on the fact that, according to the data protection authority, the Sapienza Università made available online identification data of two people who had reported… ITALY ·Garante ·Art. 5, 32 Security Identification Education Jan 23, 2020
Operator of a ballet school: Insufficient legal basis for data processing The operator of a ballet school had published photos of underage students on their website and Facebook page without the consent of the legal guardians. GERMANY ·Art. 5, 6, 7 ·Insufficient legal basis for data processing Consent Processing Education Jan 1, 2020
Municipality: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 13 +1 Public Authority Processing Education Jan 1, 2020
Public university: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 13 Personal Data Education Public Authority Jan 1, 2020
€15,100 Town of Kerepes: Insufficient legal basis for data processing The city based its video surveillance practice on its legitimate interests (Art. 6 (1) f GDPR). However, accordingt to Art. 6 (1) subparagraph 2 this legal basis shall not apply… HUNGARY ·NAIH ·Art. 6 Legitimate Interest Public Authority Video Surveillance Oct 1, 2019
€28,100 National Revenue Agency: Insufficient legal basis for data processing The pecuniary sanction of EUR 28, 121 was imposed on the National Revenue Agency for unlawful processing of the personal data of data subject G.B.I. The personal data of G.B.I.… BULGARIA ·CPDP ·Art. 6, 58 Personal Data Supervision Integrity and Confidentiality Principle Sep 3, 2019
€18,630 School in Skellefteå: Insufficient legal basis for data processing A school in Skellefteå made a trial to use facial recognition technology. The fine was imposed against the school which had used facial recognition technology to monitor the… SWEDEN ·Art. 5, 9, 35 +1 ·Insufficient legal basis for data processing Types of Special Categories of Personal Data Monitoring Personal Data Aug 20, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Right of Access Personal Data Apr 29, 2019
€170,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Public Authority Mar 1, 2019