Skip to content
Content type · 408 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 408 sort newestlargest fineoldest
€1,200 Health insurance provider: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This… HUNGARY ·NAIH ·Art. 5, 12, 31 Personal Data Insurance Supervisory Authorities Sep 25, 2022
€2,000 Bitfactor SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Bitfactor SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to a malfunction of an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Sep 22, 2022
€2,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Banca Comercială Română SA. The bank had notified the DPA of a data breach pursuant to Art. 33 GDPR. Due to an error in the IT… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Sep 19, 2022
€10,000 Bper Banca S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Bper Banca S.p.A.. An individual had filed a complaint with the DPA regarding the failure to fulfill their right to erasure of… ITALY ·Garante ·Art. 12 Personal Data Supervisory Authorities Right to be Forgotten Sep 15, 2022
€2,000 SC Raiffeisen Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on SC Raiffeisen Bank SA. An individual had filed a complaint with the DPA for receiving text messages about money transfers to… ROMANIA ·ANSPDCP ·Art. 5 Personal Data Processing Insurance Sep 9, 2022
€6,800 TIMSHEL Sp. z o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined TIMSHEL Sp. z o.o. EUR 6,800 for failing to provide information requested by the DPA during an investigation POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Personal Data Aug 30, 2022
€1,000 Alpha Bank Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Alpha Bank Romania SA. The bank had accidentally sent a document to the wrong recipient via WhatsApp. The document contained… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Recipient Aug 29, 2022
€900 UNONO NET 3.0, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNONO NET 3.0, S.L.. The company had forwarded an email to numerous recipients without using the blind copy function, making it possible for… SPAIN ·AEPD ·Art. 5, 32 Processing Insurance Supervisory Authorities Aug 22, 2022
€42,000 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on Banco Bilbao Vizcaya Argentaria, S.A.. The company had repeatedly sent advertising messages to a data subject, although the data subject had… SPAIN ·AEPD ·Art. 6 Personal Data Direct Marketing Insurance Aug 2, 2022
€900,000 Hannoversche Volksbank: Insufficient legal basis for data processing The DPA of Lower Saxony has imposed a fine of EUR 900,000 on Hannoversche Volksbank. The bank had analyzed data from active and former customers without their consent. For this… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Direct Marketing Insurance Jul 28, 2022
€20,000 DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A.: Insufficient fulfilment of data subjects rights The Hellenic DPA has fined DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A. in the amount of EUR 20,000. An individual had filed a complaint with the DPA for receiving… HDPA ·Art. 5, 6, 12 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Processing Jul 19, 2022
€56,000 BANKINTER, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 56,000 on BANKINTER, S.A.. The controller had inadvertently sent a report on the data subject's investment portfolio to a third party.… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Jul 18, 2022
€67,200 SIRIUS (law firm): Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 67,200 on the law firm SIRIUS. The law firm had suffered a cyber attack in which hackers gained access to the firm's servers and encrypted… DENMARK ·Datatilsynet (DK) ·Art. 32 Encryption Security Integrity and Confidentiality Principle Jul 14, 2022
€132,000 DKV Seguros y Reaseguros, S.A.E.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DKV Seguros y Reaseguros, S.A.E.. An individual had filed a complaint with the DPA after receiving multiple e-mails from the controller… SPAIN ·AEPD ·Art. 5, 32, 33 Data Breaches Security Controllers Jul 13, 2022
€20,000 Intesa Sanpaolo Vita S.p.a.: Non-compliance with general data processing principles The Italian DPA has fined Intesa Sanpaolo Vita S.p.a. EUR 20,000. The data subject, who had taken out a life insurance policy with the controller, had filed a complaint with the… ITALY ·Garante ·Art. 5 Personal Data Controllers Processing Jul 7, 2022
€1,600 URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.: Insufficient fulfilment of data breach notification obligations The spanish DPA has fined URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.for failing to report a data breach to the DPA in a timely manner. The original fine of EUR 2,000 was reduced to… SPAIN ·AEPD ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 22, 2022
€20,000 Deutsche Bank S.p.A.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Insurance Jun 16, 2022
€10,000 Cribis Credit Management s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Cribis Credit Management s.r.l. EUR 10,000. The company had inadvertently sent an e-mail about late payments on a subscription to the head of the data… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Insurance Jun 9, 2022
DSB · 2021-0.643.804 The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·Art. 6, 55 Legitimate Interest Controllers Pseudonymization Jun 9, 2022
€100,000 Intesa Sanpaolo S.p.A: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 100,000 on Intesa Sanpaolo S.p.A.. The bank had unlawfully disclosed data of the data subject to unauthorized third parties (the father… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Insurance May 26, 2022
€5,000 Kredyt Inkaso Investments RO S.A: Insufficient legal basis for data processing The Romanian DPA has fined Kredyt Inkaso Investments RO S.A. EUR 5,000. A data subject had filed a complaint with the DPA against the controller for having disclosed their… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +1 Data Breaches Personal Data Controllers May 18, 2022
€4,000 Concordia Capital IFN S.A.: Insufficient legal basis for data processing The Romanian DPA has fined Concordia Capital IFN S.A. EUR 4,000. The controller had unlawfully installed audio and video cameras in the offices of its employees. The video… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Processing Personal Data May 4, 2022
€50,000 Istituto Nazionale Assicurazione Infortuni sul Lavoro: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Istituto Nazionale Assicurazione Infortuni sul Lavoro (Public Accident Insurance for workers) EUR 50,000. As part of its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +2 Security Personal Data Data Breaches Apr 28, 2022
€40,000 Working Capital Management España, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 40,000 on the credit information agency Working Capital Management España, S.L.. A data subject had filed a complaint with the… SPAIN ·AEPD ·Art. 6 Personal Data Consent Insurance Apr 28, 2022
€10,000 Findomestic Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on Findomestic Banca spa. A customer had filed a complaint with the DPA regarding a breach of confidentiality related to the… ITALY ·Garante ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Apr 7, 2022
€463,000 Bank of Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined the Bank of Ireland EUR 463,000. The bank had reported 22 data breaches to the DPA under Article 33 GDPR. As part of its investigation, the DPA found that… DPC ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Apr 5, 2022
€1.3M Danske Bank: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 1.3 million on Danske Bank. The DPA had opened an investigation against the bank after it informed the DPA that it had a problem with the… DENMARK ·Datatilsynet (DK) ·Art. 5 Accountability Personal Data Processing Apr 5, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Integrity and Confidentiality Principle Data Breaches Personal Data Apr 4, 2022
€720,000 Klarna Bank AB: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 720,000 on Klarna Bank AB. Klarna is a financial company that processes a large number of personal data in various ways. As part of its… SWEDEN ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Personal Data International Transfer Supervisory Authorities Mar 28, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Security Personal Data Processing Mar 10, 2022
€1,000 Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Consent Feb 22, 2022
€1,600 RECLAMADOR, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine RECLAMADOR, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the controller continued… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Feb 14, 2022
€634,000 Budapest Bank Zrt.: Insufficient legal basis for data processing The Hungarian DPA (NAIH) has fined Budapest Bank Zrt. EUR 634,000. NAIH reports that the bank used an artificial intelligence-driven software solution to automate the evaluation… HUNGARY ·NAIH ·Art. 5, 6, 12 +5 Right to Object Legitimate Interest Personal Data Feb 8, 2022
€300,000 SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined SEGURCAIXA ADESLAS, S.A. DE SEGUROS Y REASEGUROS. in the amount of EUR 300,000. The data subject had received marketing emails from the controller… SPAIN ·AEPD ·Art. 6, 17, 28 Personal Data Controllers Supervisory Authorities Feb 4, 2022
€2,000 ASESORES DE SEGURIDAD PRIVADA, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 2,000 on ASESORES DE SEGURIDAD PRIVADA, S.L.. The DPA criticized that the controller did not sufficiently inform the data subject about… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Feb 2, 2022
€5,000 Etterforsker1 Gruppen AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Etterforsker1 Gruppen AS EUR 5,000. The controller had carried out a credit check on an individual, although there was no legal basis for… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Insurance Processing Agreement Feb 1, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
€117,000 Santander Bank Polska S. A.: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined Santander Bank Polska S.A. EUR 118,000 for failing to notify data subjects of a data breach. A former employee of the bank managed to gain unauthorized… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Personal Data Jan 19, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… CYPRUS ·Cyprus DPA ·Art. 28, 32 Security Processors Controllers Jan 1, 2022
Credit agency: Insufficient fulfilment of data subjects rights The DPA of Berlin imposed a fine on a credit agency. In the course of its investigation, the DPA found that the controller had stored 27 false addresses and 13 false dates of… GERMANY ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Jan 1, 2022
Debt collection company: Insufficient legal basis for data processing The DPA from Baden-Württemberg has imposed a fine on a debt collection company. The debt collection company had received investor information from an employee of an insolvent… GERMANY ·Art. 6, 14 ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Insurance Jan 1, 2022
Bank: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-digit fine on a bank. The bank had installed a video surveillance system that covered parts of the foyer of the branch with ATMs, the… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processors Jan 1, 2022
€2,700 Credit institution: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 2,700 on a credit institution. Several individuals had filed a complaint with the DPA due to the fact that the controller had… HUNGARY ·NAIH ·Art. 5, 6 Controllers Consent Processing Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… CYPRUS ·Cyprus DPA ·Art. 24, 28 Controllers Processors Processing Jan 1, 2022
€17,000 Bank of Cyprus Public Company Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Cyprus DPA ·Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Privacy by Design & Default Jan 1, 2022
€180,000 SLIMPAY: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 180,000 on the payment institution SLIMPAY. In 2015, SLIMPAY conducted an internal research project in which it processed personal… FRANCE ·CNIL ·Art. 28, 32, 34 Data Breaches Security Personal Data Dec 28, 2021
€5,000 Sfam España General s.l.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Sfam España General s.l.. A data subject had filed a complaint with the DPA against the controller for charging her… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Dec 22, 2021
€60,000 Banco Bilbao Vizcaya Argentaria S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine on Banco Bilbao Vizcaya Argentaria S.A.. A data subject filed a complaint with the DPA due to the fact that the controller repeatedly… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Insurance Dec 16, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Garante ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2021
€52,000 Motor insurance center: Non-compliance with general data processing principles The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25 Retention Period Insurance Controllers Dec 16, 2021