Content type · 472 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
Datatilsynet (Denmark) - 2020-422-0026 The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Art. 5 Sep 28, 2022
€1,200 Health insurance provider: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This… HUNGARY · ·Art. 5, 12, 31 Sep 25, 2022
€100,000 Lazio Region: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Lazio Region. An individual had filed a complaint with the DPA because she had received an invitation from the regional health… ITALY · ·Art. 5, 6, 9 +4 Sep 15, 2022
€20,000 Medical laboratory: Insufficient technical and organisational measures to ensure information security The Belgian DPA imposed a fine of EUR 20,000 on a medical laboratory. During its investigation, the DPA found that the laboratory had failed to conduct a data protection impact… BELGIUM · ·Art. 5, 12, 13 +3 Aug 19, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK · ·Art. 32 Aug 11, 2022
€30,000 Private Polyclinic and Diagnostic Centre of Pyle Axiou: Non-compliance with general data processing principles The Hellenic DPA has fined Private Polyclinic and Diagnostic Centre of Pyle Axiou EUR 30,000. A patient had requested access to data from an imaging examination. Due to lack of… GREECE · ·Art. 5 Aug 3, 2022
€9,600 LAST LAP, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on LAST LAP, S.L.. Last Lap organizes the San Silvestre road running race. Race participants were required to show their vaccination certificate… SPAIN · ·Art. 6, 9 Aug 1, 2022
€3,000 Azienda Socio Sanitaria Territoriale Rhodense: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Socio Sanitaria Territoriale Rhodense EUR 3,000. The healthcare facility had reported the loss of a patient's medical record. The file contained… ITALY · ·Art. 5, 32 Jul 21, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Jul 19, 2022
€202,000 Manx Care Ltd: Non-compliance with general data processing principles The DPA of Isle of Man has imposed a fine of EUR 202,000 on Manx Care Ltd. Manx Care had emailed an unsecured attachment containing a patient's confidential health information to… ISLE OF MAN ·Art. 5, 24, 25 +3 ·Non-compliance with general data processing principles Jul 13, 2022
€1,500 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,500 on a physician. A patient had asked the doctor to send her complete medical records, such as imaging records as well as consent… HUNGARY · ·Art. 5, 12, 13 Jul 8, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY · ·Art. 5, 6, 7 +4 Jul 7, 2022
€2,120 University Hospital of the Medical University of Warsaw: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 2,120 on the University Hospital of the Medical University of Warsaw. The university hospital had suffered a data breach in which a… POLAND · ·Art. 33, 34 Jul 6, 2022
€3,000 Pediatric psychologist: Insufficient cooperation with supervisory authority The Hellenic DPA has fined a pediatric psychologist EUR 3,000. The psychologist had not properly cooperated with the DPA during an investigation. GREECE · ·Art. 31 Jun 29, 2022
€91,000 Tavistock & Portman NHS Foundation Trust: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Tavistock and Portman NHS Foundation Trust EUR 91,000. The Tavistock and Portman NHS Foundation Trust is a mental health specialist trust located in… UNITED KINGDOM · ·Art. 5, 32 Jun 9, 2022
€2,100 Stołeczny Ośrodek dla Osób Nietrzeźwych: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 2,100 on 'Stołeczny Ośrodek dla Osób Nietrzeźwych', a center for people suffering from alcoholism. During its investigation, the DPA found… POLAND · ·Art. 5, 6 May 31, 2022
€50,000 Azienda sanitaria universitaria Friuli Occidentale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed… ITALY · ·Art. 5, 9, 25 +1 May 26, 2022
€46,000 Azienda Sanitaria Locale Roma: Insufficient legal basis for data processing The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most… ITALY · ·Art. 2, 5, 6 +1 May 26, 2022
€70,000 Azienda sanitaria universitaria Friuli Centrale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 70,000 on the healthcare facility Azienda sanitaria universitaria Friuli Centrale. Employees of the healthcare facility had accessed… ITALY · ·Art. 5, 9, 25 +1 May 26, 2022
€5,000 MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on MED LIFE S.A.. The company had disposed of documents containing sensitive patient data in a publicly accessible garbage can. An… ROMANIA · ·Art. 32 May 24, 2022
€7,000 Azienda Socio Sanitaria Territoriale Dei Sette Laghi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the healthcare facility Azienda Socio Sanitaria Territoriale Dei Sette Laghi. A patient had mistakenly received… ITALY · ·Art. 5, 9, 32 May 22, 2022
€10,600 HEI – Medical Travel: Insufficient fulfilment of data subjects rights The Icelandic DPA has imposed a fine of EUR 10,600 on HEI - Medical Travel. A data subject had filed a complaint with the DPA against the controller. The controller had gained… ICELAND ·Art. 9, 15, 17 ·Insufficient fulfilment of data subjects rights May 3, 2022
€4,200 CLÍNICA DENTAL SAN FRANCISCO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine on CLÍNICA DENTAL SAN FRANCISCO, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN · ·Art. 17, 21 Apr 29, 2022
€16,000 LABORATORIOS GONZÁLEZ, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined LABORATORIOS GONZÁLEZ, S.L.. The laboratory had sent the results of a Covid-19 test that the data subject had taken not only to them but also to… SPAIN · ·Art. 5 Apr 29, 2022
€1,500 Direzione Didattica Statale 1° Circolo-Eboli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on the school 'Direzione Didattica Statale 1° Circolo-Eboli'. The educational institution had sent a document containing the names… ITALY · ·Art. 2, 5, 6 +1 Apr 28, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY · ·Art. 5, 9 Apr 28, 2022
€10,000 Italian Ministry of Defense: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Italian Ministry of Defense. An employee of the ministry had filed a complaint with the DPA. During its investigation, the… ITALY · ·Art. 2, 5, 6 +2 Apr 28, 2022
€2,500 'Isabella Gonzaga' high school: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the 'Isabella Gonzaga' high school. The school had published a document, which also contained personal health data of some… ITALY · ·Art. 2, 5, 6 +1 Apr 28, 2022
€1,000 ASST di Lodi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 1,000 on ASST di Lodi. The healthcare facility had reported a data breach to the DPA pursuant to Art. 33 GDPR. A patient had… ITALY · ·Art. 5, 9, 32 Apr 26, 2022
€5,600 Physician: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined a physician. The physician had used recordings of a patient's treatment for advertising purposes. However, the patient had not consented to this.… SPAIN · ·Art. 6 Apr 22, 2022
€1.5M DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press… FRANCE · ·Art. 28, 29, 32 Apr 15, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY · ·Art. 28 Apr 7, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY · ·Art. 5, 13, 14 +4 Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY · ·Art. 5, 13, 29 +2 Apr 7, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS · ·Art. 5, 6, 32 +1 Apr 7, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM · ·Art. 5, 6, 9 +3 Apr 4, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM · ·Art. 5, 6, 9 Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM · ·Art. 5, 6, 9 +3 Apr 4, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK · ·Art. 36 Mar 25, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY · ·Art. 2, 5, 6 +3 Mar 10, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM · ·Art. 5 Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY · ·Art. 5, 9, 32 Mar 10, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY · ·Art. 5, 32 Mar 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Mar 3, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY · ·Art. 5, 9 Feb 10, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA · ·Art. 6, 9 Feb 1, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 26, 2022
€2,400 PHARMA TALENTS, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's… SPAIN · ·Art. 5, 32 Jan 14, 2022
€1,000 Villa Masi Residenza per anziani: Insufficient fulfilment of information obligations Inexistence of signalization regarding the use of CCTV systems in a nursing care facility. ITALY · ·Art. 13 Jan 13, 2022