Skip to content
Content type · 749 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 749 sort newestlargest fineoldest
€1,000 Office Nova Concept SRL: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Right of Access Personal Data Right to Object NL Apr 14, 2025
€1,000 Office Nova Concept SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Office Nova Concept SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Controllers Personal Data Supervisory Authorities Apr 14, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Apr 11, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on NEW GAMBLING SOLUTIONS S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Apr 11, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 15,000 on Tensa Art Design S.A. The controller contacted a data for direct marketing purposes without consent. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Direct Marketing Marketing Controllers Apr 10, 2025
€15,000 Tensa Art Design S.A.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 15.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Marketing Processing NL Apr 10, 2025
€360 SINDICAT CATAC-CTSC: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of on SINDICAT CATAC-CTSC. The controller failed to react to a communication attempt by the AEPD. The original fine of EUR 600 was reduced to EUR… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Apr 4, 2025
€360 SINDICAT CATAC-CTSC: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 360 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision NL Apr 4, 2025
€5,000 Banca Transilvania S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Data Controller Personal Data NL Apr 3, 2025
€5,000 Banca Transilvania S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on Banca Transilvania S.A. The controller forwarded client data to an insurance company without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Insurance Processing Agreement Controllers Apr 3, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Telecommunications Apr 2, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Telecommunications NL Apr 2, 2025
€25,000 NTT DATA ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on NTT DATA ROMANIA S.A. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Mar 25, 2025
€25,000 NTT DATA ROMANIA S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers NL Mar 25, 2025
€1,000 Bucharest Down Town Hotel SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Bucharest Down Town Hotel SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 13, 15 Personal Data Controllers Processing Agreement Mar 21, 2025
€4,800 TECNOCRÃTICA CENTRO DE DATOS S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 4,800 on TECNOCRÃTICA CENTRO DE DATOS S.L. The controller failed to reply to an information request by the AEPD within the given… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Mar 20, 2025
€2,000 ONE UNITED PROPERTIES S.A: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on ONE UNITED PROPERTIES S.A. The controller contacted a data subject multiple times for direct marketing purposes without… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Direct Marketing Controllers Personal Data Mar 20, 2025
€5,000 Automobilus International S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Automobilus International S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Mar 12, 2025
€1,000 Noy Business Tranzactions SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Noy Business Tranzactions SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Processing Agreement Mar 11, 2025
€338,000 Telenor ASA.: Non-compliance with general data processing principles The Norwegian DPA has imposed a fine of EUR 333,800 on Telenor ASA. During its investigation, the DPA found that the company had not conducted sufficient assessments and… NORWAY ·Datatilsynet ·Art. 24, 37, 38 Supervisory Authorities IP Address Telecommunications Mar 10, 2025
€2,000 SHOPBAG GROUP ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 2,000 onSHOPBAG GROUP ONLINE SRL. The controller failed to respond to a request made by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers Mar 6, 2025
€20,000 WEBRASOFT SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on WEBRASOFT SRL. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Mar 4, 2025
€10,000 BEKO ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BEKO ROMANIA SA. The controller failed to implement sufficient technical and organisational measures to provide data security,… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Mar 3, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA ·ANSPDCP ·Art. 12, 15 Health Data Healthcare Personal Data Feb 27, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA ·ANSPDCP ·Art. 32 Healthcare Security Health Data Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 Healthcare Health Data Personal Data Feb 17, 2025
herhaaldelijk De AP heeft herhaaldelijk aangegeven dat het van mening is dat de wet zodanig zou moeten worden aangepast dat alle boetebesluiten standaard gepubliceerd worden. Enforcement Supervision NL Feb 12, 2025
€3,000 PPC Energie Muntenia SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on PPC Energie Muntenia SA. The controller forwarded customer data to a third company, which then contacted the data subjects for… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Controllers Personal Data Processing Agreement Feb 10, 2025
€3,000 Omniasig Vienna Insurance Group S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Omniasig Vienna Insurance Group S.A. The controller failed to implement sufficient technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance Feb 6, 2025
€5,000 FARMEC SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on FARMEC SA. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Processing Agreement Feb 5, 2025
€10,000 V&M Contab & Management SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on V&M Contab & Management SRL. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32, 58 Data Breaches Security Controllers Feb 4, 2025
€15,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 25 Data Breaches Security Controllers Feb 3, 2025
€15,000 S.P.E.E.H. HIDROELECTRICA S.A: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on S.P.E.E.H. HIDROELECTRICA S.A. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 25 Data Breaches Security Controllers Jan 31, 2025
€40,000 Orange Romania SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 40,000 on Orange Romania SA. The controller failed to fulfil a request for the erasure of data. The controller also execsevly stored and… ANSPDCP ·Art. 5, 6, 7 +2 ·Non-compliance with general data processing principles IP Address Controllers Personal Data Jan 27, 2025
€5,000 Softehnica S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Softehnica S.R.L. The controller had suffered a ransomware attack, which allowed unauthorized third parties to gain access to… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default Controllers Jan 23, 2025
€15,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Vodafone Romania S.A. Personal data such as names, email addresses and customer numbers were repeatedly disclosed due to… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Privacy by Design & Default Jan 20, 2025
€2,000 DELIVERY SOLUTIONS S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on DELIVERY SOLUTIONS S.A. A security incident led to the unauthorized disclosure of personal data (name, address, telephone… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Privacy by Design & Default Jan 17, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA ·ANSPDCP ·Art. 24, 32 Healthcare Healthcare Security Jan 3, 2025
€15,000 HSSERVICE LIZCON SOLUTIONS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 15,000 on HSSERVICE LIZCON SOLUTIONS, S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€600 ENERGY WINNER, S.L.: Insufficient cooperation with supervisory authority Fine of EUR 600 for failure to provide information to the Spanish DPA within the required timeframe SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€40,000 Coolblue B.V: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of €40,000 on Coolblue. The company collected personal data via cookies without users' explicit consent, relying on pre-ticked consent boxes. THE NETHERLANDS ·AP ·Art. 5, 6 Cookies Consent Processing Agreement Dec 23, 2024
€2,000 AUTOMOCIÓN 1972, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 2,000 on AUTOMOCIÓN 1972, S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€9,000 CRIDOLMA BARCELONA S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 9,000 on CRIDOLMA BARCELONA S.L. for failing to prove compliance with an order issued by the DPA SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Dec 23, 2024
€4.8M Netflix International B.V.: Insufficient fulfilment of information obligations The Dutch DPA has imposed a fine of EUR 4.75 million on Netflix. This fine is based on a complaint filed by the Austrian organization 'noyb'. During its investigation, the DPA… THE NETHERLANDS ·AP ·Art. 5, 12, 13 +1 Telecommunications Personal Data Processing Nov 26, 2024
€1,000 Blackcab Systems SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Blackcab Systems SRL. A individual lodged a complaint with the DPA, alleging that the controller had failed to properly respond… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 4, 2024
€12,000 NEGOCIOS R&R 2020 S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined NEGOCIOS R&R 2020 S.L. EUR 12,000 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€4,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined GESTIÓN DE VENTAS IBERIA S.L. EUR 4000 for failing to provide information requested by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€900 RIVENDELL TECHNOLOGY, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 900 on RIVENDELL TECHNOLOGY, S.L. for failing to prove compliance with an order issued by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Processing Agreement Oct 31, 2024
€15,000 Untold SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Untold SRL. During its investigation, the DPA found that the controller had failed to properly comply with a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Processing Agreement Oct 30, 2024
€5,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA fined Vodafone Romania S.A. EUR 5,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Telecommunications Security IP Address Oct 28, 2024