Skip to content
Content type · 332 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 332 sort newestlargest fineoldest
€19,900 Basaren Drift AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 19,900 on Basaren Drift AS. The controller had installed video cameras in its premises which recorded both its employees… NORWAY ·Datatilsynet ·Art. 5, 6, 13 Video Surveillance Controllers Monitoring Mar 21, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data Accuracy Education Mar 15, 2021
€10,000 Hospital Campogrande DE: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 10,000 on Hospital Campogrande DE. A patient filed a complaint against the controller with the DPA. The controller had performed an… SPAIN ·aepd ·Art. 5 Healthcare Healthcare Insurance Mar 10, 2021
€200 Self Employed Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 200 on a self employed person. The accused obtained scans of identity cards from foreign subjects who booked accommodation there and kept… CZECH REPUBLIC ·UOOU ·Art. 5, 6, 12 +4 Personal Data Consent Processing Mar 10, 2021
€6,000 Azienda Ospedaliera Universitaria Careggi: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Azienda Ospedaliera Universitaria Careggi for a breach of Art. 5 GDPR and Art. 9 GDPR. Azienda Ospedaliera… ITALY ·Garante ·Art. 5, 9 Data Breaches Healthcare Health Data Feb 25, 2021
€1,600 Ripobruna 207, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of EUR 2,000 against Ripobruna 207, S.L. (restaurant) for the unauthorized use of two video surveillance cameras that also recorded parts of… SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Feb 12, 2021
€440,000 OLVG: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) imposed a fine of EUR 440,000 on the Amsterdam hospital OLVG. The controller had taken insufficient measures between 2018 and 2020 to prevent access by… THE NETHERLANDS ·AP ·Art. 32 Healthcare Health Data Healthcare Feb 11, 2021
€45,000 Istituti ospedalieri bergamaschi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 45,000 on Istituti ospedalieri bergamaschi. The DPA initiated an investigation against the controller after it reported a data… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare Healthcare Feb 11, 2021
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Prior Consultation Jan 27, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY ·Garante ·Art. 5, 9 Healthcare Health Data Healthcare Jan 27, 2021
€50,000 Azienda USL della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 50,000 on Azienda USL della Romagna. Upon her arrival at the gynecology unit of a hospital operated by the controller (for the… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Healthcare Jan 27, 2021
€18,000 Azienda Usl di Bologna: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Usl di Bologna EUR 18,000. In a hospital operated by the controller, 49 patients in the oncology ward received discharge letters with… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Controllers Jan 14, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Controllers Processors Processing Agreement Jan 14, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 5, 2021
€19,000 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of EUR 19,000 on a hospital operator. A former employee had unlawfully copied the personal data of 100 patients from the hospital's computer… UODO ·Art. 34, 58 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 5, 2021
€170 Restaurant: Non-compliance with general data processing principles In order to identify a guest who had not paid, several visitors were contacted by employees of a restaurant. For this purpose, the telephone numbers provided by the guests as part… GERMANY ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Agreement Healthcare Jan 1, 2021
Medical clinic: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on a medical clinic. The clinic had installed 21 cameras in its premises for the purpose of protection against crime and property damage.… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Healthcare Monitoring Jan 1, 2021
Clinic: Insufficient involvement of data protection officer The DPA from Berlin has imposed a fine on a clinic. The clinic had appointed the clinic manager, who was also a shareholder of the clinic, as the data protection officer. A data… GERMANY ·Insufficient involvement of data protection officer Notified Body Responsibilities and Operational Obligations Supervisory Authorities Notified Body Independence Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine in the six-digit range on a Hamburg-based company operating in the healthcare sector. The company had failed to take appropriate technical… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Jan 1, 2021
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. A restaurant employee obtained first names, last… Unknown IP Address Personal Data Supervisory Authorities Jan 1, 2021
Restaurant: Insufficient technical and organisational measures to ensure information security A restaurant had disposed of 120 completed guest registration forms for contact tracing purposes during the Covid-19 pandemic in a publicly-accessible dumpster. During its… GERMANY ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Processing Agreement Jan 1, 2021
Physician: Insufficient legal basis for data processing The DPA of Brandenburg imposed a fine on a physician. The father of a minor patient had filed a complaint with the DPA because the physician had transmitted numerous data on his… GERMANY ·Art. 6, 9 ·Insufficient legal basis for data processing Healthcare Insurance Healthcare Jan 1, 2021
€3,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 3,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data as MRI and X-ray images as well as… FRANCE ·CNIL ·Art. 32, 33 Healthcare Healthcare Privacy by Design & Default Dec 17, 2020
€6,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well… FRANCE ·CNIL ·Art. 32, 33 Healthcare Security Healthcare Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Health Data Healthcare Dec 17, 2020
€3,250 Cosmetic Medical Limited: Insufficient cooperation with supervisory authority The DPA of Isle of Man has imposed a fine of EUR 3,250 on Cosmetic Medical Limited. A data subject had filed a complaint with the DPA regarding the controller's failure to comply… ISLE OF MAN ·Art. 31 ·Insufficient cooperation with supervisory authority Right of Access Right of Access Procedures Supervisory Authorities Dec 11, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 10, 2020
€243,800 Östergötland Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Östergötland Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Health Data Security Healthcare Dec 3, 2020
€2.9M Capio St. Göran AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Capio St. Göran AB SEK 30,000,000 (EUR 2,900,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Health Data Healthcare Dec 3, 2020
€390,100 Karolinska University Hospital of Solna: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Karolinska University Hospital of Solna SEK 4,000,000 (EUR 390,100) for failing to implement adequate technical and… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Health Data Security Healthcare Dec 3, 2020
€243,800 Västerbotten Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Västerbotten Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2020
€341,300 Sahlgrenska University Hospital: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Sahlgrenska University Hospital SEK 3,500,000 (EUR 341,300) for failing to implement adequate technical and organizational… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Health Data Healthcare Healthcare Dec 3, 2020
€1.2M Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Aleris Sjukvård AB SEK 12,000,000 (EUR 1,168,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Health Data Dec 3, 2020
€1.5M Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Aleris Sjukvård AB SEK 15,000,000 (EUR 1,463,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Security Healthcare Dec 3, 2020
€3,000 Charly Mike s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Charly Mike s.r.l.. The controller is the hotel operator of the Hotel Olimpo in Alberobello. Garante received a complaint… ITALY ·Garante ·Art. 5, 13 Video Surveillance Monitoring Controllers Nov 26, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Health Data Fairness & Transparency Nov 19, 2020
€20M Marriott International, Inc: Insufficient technical and organisational measures to ensure information security Original Summary: The ICO issued a notice of its intention to fine Marriott International Inc due to a cyber incident which was notified to the ICO by Marriott in November 2018. A… UNITED KINGDOM ·ICO ·Art. 32 Fines Security Healthcare Oct 30, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY ·Garante ·Art. 5, 9 Notification Obligation Data Breaches Healthcare Oct 26, 2020
€600 Private Individual: Insufficient legal basis for data processing Between February and June 2020, a private individual published information about patients on his personal Facebook page. The information included health data in terms of Art. 4… AUSTRIA ·dsb ·Art. 5, 9 Healthcare Health Data Healthcare Oct 19, 2020
€50,000 Centro de Investigación y Estudio para la Obesidad, SL: Insufficient legal basis for data processing Fines for the transfer of the data subject's personal data to Evo Finance EFC, SA in the course of processing a health insurance application, without a sufficient legal basis for… SPAIN ·aepd ·Art. 5, 6 Fines Personal Data Insurance Oct 9, 2020
€900 Café Restaurante B.B.B: Non-compliance with general data processing principles The cafe used CCTV cameras which also captured the public space outside resulting in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Oct 9, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 9 +1 Healthcare Personal Data Controllers Sep 30, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 13 +2 Healthcare Processors Healthcare Sep 30, 2020
€65,000 Cork University Maternity Hospital: Insufficient technical and organisational measures to ensure information security The „Data Protection Authority of Ireland“ imposed a fine on Cork University Maternity Hospital (CUMH) after the personal data of 78 patients was discovered disposed of in a… IRELAND ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Health Data Healthcare Healthcare Aug 18, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Installation of CCTV surveillance cameras that were also monitoring the public space and without proper information. SPAIN ·aepd ·Art. 5, 12, 13 Video Surveillance Monitoring Audit Logs Aug 5, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK ·Datatilsynet ·Art. 5 Retention Period Personal Data IP Address Jul 28, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY ·Datatilsynet ·Art. 32 Healthcare Health Data Healthcare Jun 22, 2020
€2,000 Café Bar: Non-compliance with general data processing principles Illegal use of CCTV cameras (recording of third parties) and insufficient fulfilment of information obligations. SPAIN ·aepd ·Art. 5, 6, 13 +1 Video Surveillance IP Address Healthcare Jun 16, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Healthcare Healthcare May 12, 2020
€6,000 Amalfi Servicios de Restauracion S.L.: Non-compliance with general data processing principles Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has… SPAIN ·aepd ·Art. 5, 13, 14 Video Surveillance Monitoring IP Address Mar 16, 2020