Skip to content
Content type · 472 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 472 sort newestlargest fineoldest
Datatilsynet (Denmark) - 2020-422-0026 The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Art. 5 Controllers Processors Processing Sep 28, 2022
€1,200 Health insurance provider: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This… HUNGARY ·NAIH ·Art. 5, 12, 31 Insurance Healthcare Personal Data Sep 25, 2022
€100,000 Lazio Region: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Lazio Region. An individual had filed a complaint with the DPA because she had received an invitation from the regional health… ITALY ·Garante ·Art. 5, 6, 9 +4 Accuracy Personal Data IP Address Sep 15, 2022
€20,000 Medical laboratory: Insufficient technical and organisational measures to ensure information security The Belgian DPA imposed a fine of EUR 20,000 on a medical laboratory. During its investigation, the DPA found that the laboratory had failed to conduct a data protection impact… BELGIUM ·APD ·Art. 5, 12, 13 +3 DPIA Encryption Privacy Impact Assessment Aug 19, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Security Health Data Aug 11, 2022
€30,000 Private Polyclinic and Diagnostic Centre of Pyle Axiou: Non-compliance with general data processing principles The Hellenic DPA has fined Private Polyclinic and Diagnostic Centre of Pyle Axiou EUR 30,000. A patient had requested access to data from an imaging examination. Due to lack of… GREECE ·HDPA ·Art. 5 Healthcare IP Address Processing Agreement Aug 3, 2022
€9,600 LAST LAP, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on LAST LAP, S.L.. Last Lap organizes the San Silvestre road running race. Race participants were required to show their vaccination certificate… SPAIN ·aepd ·Art. 6, 9 Health Data Healthcare IP Address Aug 1, 2022
€3,000 Azienda Socio Sanitaria Territoriale Rhodense: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Socio Sanitaria Territoriale Rhodense EUR 3,000. The healthcare facility had reported the loss of a patient's medical record. The file contained… ITALY ·Garante ·Art. 5, 32 Healthcare Security Healthcare Jul 21, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Controllers Lawful Basis Jul 19, 2022
€202,000 Manx Care Ltd: Non-compliance with general data processing principles The DPA of Isle of Man has imposed a fine of EUR 202,000 on Manx Care Ltd. Manx Care had emailed an unsecured attachment containing a patient's confidential health information to… ISLE OF MAN ·Art. 5, 24, 25 +3 ·Non-compliance with general data processing principles Data Breaches Healthcare Processing Agreement Jul 13, 2022
€1,500 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,500 on a physician. A patient had asked the doctor to send her complete medical records, such as imaging records as well as consent… HUNGARY ·NAIH ·Art. 5, 12, 13 Healthcare Health Data Healthcare Jul 8, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Data Breaches Health Data Audit Logs Jul 7, 2022
€2,120 University Hospital of the Medical University of Warsaw: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 2,120 on the University Hospital of the Medical University of Warsaw. The university hospital had suffered a data breach in which a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jul 6, 2022
€3,000 Pediatric psychologist: Insufficient cooperation with supervisory authority The Hellenic DPA has fined a pediatric psychologist EUR 3,000. The psychologist had not properly cooperated with the DPA during an investigation. GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Processing Agreement Jun 29, 2022
€91,000 Tavistock & Portman NHS Foundation Trust: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Tavistock and Portman NHS Foundation Trust EUR 91,000. The Tavistock and Portman NHS Foundation Trust is a mental health specialist trust located in… UNITED KINGDOM ·ICO ·Art. 5, 32 Healthcare Security IP Address Jun 9, 2022
€2,100 Stołeczny Ośrodek dla Osób Nietrzeźwych: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 2,100 on 'Stołeczny Ośrodek dla Osób Nietrzeźwych', a center for people suffering from alcoholism. During its investigation, the DPA found… POLAND ·UODO ·Art. 5, 6 Video Surveillance Healthcare Monitoring May 31, 2022
€50,000 Azienda sanitaria universitaria Friuli Occidentale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Health Data Healthcare Healthcare May 26, 2022
€46,000 Azienda Sanitaria Locale Roma: Insufficient legal basis for data processing The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Health Data Healthcare May 26, 2022
€70,000 Azienda sanitaria universitaria Friuli Centrale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 70,000 on the healthcare facility Azienda sanitaria universitaria Friuli Centrale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare May 26, 2022
€5,000 MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on MED LIFE S.A.. The company had disposed of documents containing sensitive patient data in a publicly accessible garbage can. An… ROMANIA ·ANSPDCP ·Art. 32 Healthcare Health Data Security May 24, 2022
€7,000 Azienda Socio Sanitaria Territoriale Dei Sette Laghi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the healthcare facility Azienda Socio Sanitaria Territoriale Dei Sette Laghi. A patient had mistakenly received… ITALY ·Garante ·Art. 5, 9, 32 Health Data Healthcare Healthcare May 22, 2022
€10,600 HEI – Medical Travel: Insufficient fulfilment of data subjects rights The Icelandic DPA has imposed a fine of EUR 10,600 on HEI - Medical Travel. A data subject had filed a complaint with the DPA against the controller. The controller had gained… ICELAND ·Art. 9, 15, 17 ·Insufficient fulfilment of data subjects rights Healthcare Personal Data Healthcare May 3, 2022
€4,200 CLÍNICA DENTAL SAN FRANCISCO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine on CLÍNICA DENTAL SAN FRANCISCO, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·aepd ·Art. 17, 21 Healthcare Personal Data Controllers Apr 29, 2022
€16,000 LABORATORIOS GONZÁLEZ, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined LABORATORIOS GONZÁLEZ, S.L.. The laboratory had sent the results of a Covid-19 test that the data subject had taken not only to them but also to… SPAIN ·aepd ·Art. 5 Healthcare Personal Data IP Address Apr 29, 2022
€1,500 Direzione Didattica Statale 1° Circolo-Eboli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on the school 'Direzione Didattica Statale 1° Circolo-Eboli'. The educational institution had sent a document containing the names… ITALY ·Garante ·Art. 2, 5, 6 +1 Education Healthcare Health Data Apr 28, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Data Breaches Health Data Apr 28, 2022
€10,000 Italian Ministry of Defense: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Italian Ministry of Defense. An employee of the ministry had filed a complaint with the DPA. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 +2 Healthcare Personal Data Processing Agreement Apr 28, 2022
€2,500 'Isabella Gonzaga' high school: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the 'Isabella Gonzaga' high school. The school had published a document, which also contained personal health data of some… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Health Data Education Apr 28, 2022
€1,000 ASST di Lodi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 1,000 on ASST di Lodi. The healthcare facility had reported a data breach to the DPA pursuant to Art. 33 GDPR. A patient had… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare Healthcare Apr 26, 2022
€5,600 Physician: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined a physician. The physician had used recordings of a patient's treatment for advertising purposes. However, the patient had not consented to this.… SPAIN ·aepd ·Art. 6 Healthcare Direct Marketing Consent Apr 22, 2022
€1.5M DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press… FRANCE ·CNIL ·Art. 28, 29, 32 Encryption Security Healthcare Apr 15, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY ·Garante ·Art. 28 Processing Agreement IP Address Data Processor Apr 7, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Privacy Impact Assessment Healthcare Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Video Surveillance Integrity and Confidentiality Principle IP Address Apr 7, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Storage Limitation Security Apr 7, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data DPIA Healthcare Apr 4, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM ·APD ·Art. 5, 6, 9 Health Data Healthcare Fines Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD ·Art. 5, 6, 9 +3 Health Data DPIA Audit Logs Apr 4, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK ·Datatilsynet ·Art. 36 DPIA Privacy Impact Assessment Healthcare Mar 25, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Garante ·Art. 2, 5, 6 +3 Healthcare Personal Data Controllers Mar 10, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Data Breaches Encryption Notification Obligation Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Healthcare Health Data Mar 10, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Access Controls Security Mar 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Controllers Personal Data Mar 3, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Garante ·Art. 5, 9 Data Breaches Healthcare Health Data Feb 10, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Controllers Processing Agreement Feb 1, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Healthcare Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Data Breaches Jan 26, 2022
€2,400 PHARMA TALENTS, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's… SPAIN ·aepd ·Art. 5, 32 Security Healthcare Personal Data Jan 14, 2022
€1,000 Villa Masi Residenza per anziani: Insufficient fulfilment of information obligations Inexistence of signalization regarding the use of CCTV systems in a nursing care facility. ITALY ·Garante ·Art. 13 Video Surveillance Healthcare Supervisory Authorities Jan 13, 2022