Skip to content
Content type · 621 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 621 sort newestlargest fineoldest
€1,600 Company: Insufficient fulfilment of data subjects rights The Finnish DPA has imposed a fine of EUR 1,600 on a company providing psychotherapy services. A customer had submitted a request for access to their stored personal data.… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 15 Personal Data Supervisory Authorities Healthcare Sep 4, 2023
€10,000 Mednow Medical Center di Giugni Marco: Non-compliance with general data processing principles The Italian DPA has fined Mednow Medical Center di Giugni Marco EUR 10,000. An individual had filed a complaint with the DPA because the controller had inadvertently sent the… ITALY ·Garante ·Art. 5, 9, 12 +5 Recipient Personal Data Controllers Aug 31, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Personal Data Identification Aug 28, 2023
€2,000 Med Life SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Med Life SA. The controller had refused to disclose certain video recordings of the reception of a hospital to the data… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Aug 3, 2023
€10,000 GYMOOGIMNASIOS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined GYMOOGIMNASIOS S.L. EUR 10,000. The controller had installed a reservation system where data subjects had to consent to the processing of health-related… SPAIN ·AEPD ·Art. 5, 7 Retention Period Controllers Consent Aug 2, 2023
€12,000 Azienda Socio Sanitaria Territoriale Ovest Milanese: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of… ITALY ·Garante ·Art. 5, 9, 32 Controllers Healthcare Personal Data Jul 18, 2023
€15,000 RCL CRUISES LTD: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 15,000 on RCL CRUISES LTD. An individual had filed a complaint with the DPA. The individual, after requesting information about a cruise… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Jul 7, 2023
€5,000 Ristorante Francesco srl: Non-compliance with general data processing principles The Italian DPA has fined Ristorante Francesco srl EUR 5,000. The controller had operated video surveillance cameras in its premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Jul 6, 2023
€500 EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L. EUR 500. The controller had installed video surveillance cameras which, among other things, also… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jul 4, 2023
€81,000 Heilsuveru: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has fined Heilsuveru EUR 81,000. The controller had reported a data breach to the DPA, as two unauthorized persons had managed to view personal data. During its… ICELAND ·Persónuvernd ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Jul 3, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Persónuvernd ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Jun 28, 2023
€22,500 Irish Departement of Health: Non-compliance with general data processing principles The Irish DPA (DPC) has fined the Irish Department of Health EUR 22,500. The DPA launched an investigation into the department following public allegations that the department… IRELAND ·DPC ·Art. 5, 6, 9 Retention Period Healthcare Personal Data Jun 16, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest Controllers Jun 8, 2023
€5,000 Azienda Tutela della Salute della Sardegna: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Azienda Tutela della Salute della Sardegna. The health authority had placed a sign at the gate of a physician's practice… ITALY ·Garante ·Art. 2, 5, 9 Healthcare Processing Supervisory Authorities Jun 7, 2023
€10,000 Camedi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Camedi s.r.l. Medical Center. A person had filed a complaint with the DPA because they had received invoices as well as… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Security Supervisory Authorities Jun 1, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY ·Garante ·Art. 2, 5, 9 +1 Healthcare Personal Data Controllers Jun 1, 2023
€15,000 Thin Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Thin Srl. The authority took action following a complaint from a GP who alleged that the company had breached data protection… ITALY ·Garante ·Art. 5, 9, 13 Healthcare Personal Data International Transfer Jun 1, 2023
€300 CBHNOS S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CBHNOS S.L.. The controller had installed video surveillance cameras which, among other things, also covered a public road. The DPA… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing May 29, 2023
€3,000 NORDETIA CLINICS IBERIA, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined NORDETIA CLINICS IBERIA, S.L. EUR 3,000 for failing to provide information requested by the DPA during an investigation. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Healthcare May 24, 2023
€10,000 Azienda ULSS 6 Euganea: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Azienda ULSS 6 Euganea. The controller had mistakenly sent documents containing personal data to the wrong patients. The DPA… ITALY ·Garante ·Art. 5, 6, 32 Security Controllers Personal Data May 17, 2023
€15,000 Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Apr 27, 2023
€15,000 Citynews S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Citynews S.p.A. EUR 15,000. The controller had published an article in a newspaper reporting on the arrest of an individual, including health data of the… ITALY ·Garante ·Art. 5, 9 Personal Data Types of Special Categories of Personal Data Controllers Apr 14, 2023
€13,000 Azienda socio sanitaria locale n. 3 di Nuoro: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 13,000 on Azienda socio sanitaria locale n. 3 di Nuoro. An individual had filed a complaint with the DPA because the health authority had… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Personal Data Controllers Apr 13, 2023
€3,000 Comune di Cogollo del Cengio: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on Comune di Cogollo del Cengio. A former employee had filed a complaint with the DPA due to the fact, that the municipality had… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Apr 13, 2023
€4,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 4,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 9, 32 Security Personal Data Healthcare Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Integrity and Confidentiality Principle Data Breaches Processors Mar 23, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Security Data Breaches Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€220,000 Argon Medical Devices: Insufficient fulfilment of data breach notification obligations The Norwegian DPA has fined Argon Medical Devices EUR 220,000. The controller failed to notify the DPA of a data breach that involved personal data of all its European employees… NORWAY ·Datatilsynet (NO) ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Mar 8, 2023
€50,000 Azienda sanitaria locale di Bari: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda sanitaria locale di Bari. The healthcare facility had published reviews of former patients on the Internet and provided… ITALY ·Garante ·Art. 5, 9, 25 Healthcare Processing Health Data Mar 2, 2023
€80,500 I&S Limited Kft: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 80,500 on the spa operator, 'I&S Limited Kft'. During its investigation, the DPA found that the controller had installed video… HUNGARY ·NAIH ·Art. 5, 6, 9 +3 Controllers Personal Data Supervisory Authorities Feb 6, 2023
€600 HOTEL VILLA SORO, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on HOTEL VILLA SORO, S.L.. The controller had installed a video surveillance system without providing the required information according to Art.… SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Monitoring Feb 3, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA ·ANSPDCP ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 31, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA ·ANSPDCP ·Art. 6, 9 Healthcare Consent Controllers Jan 31, 2023
€5,000 Azienda ULSS n.5 Polesana: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 5,000 on Azienda ULSS n.5 Polesana. The healthcare facility had mistakenly sent a patient medical record to the wrong patient. The DPA… ITALY ·Garante ·Art. 5, 9, 32 Security Healthcare Personal Data Jan 26, 2023
€7,000 Azienda Ospedaliera Bianchi Melacrino Morelli: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 7,000 on Azienda Ospedaliera Bianchi Melacrino Morelli. The controller had mistakenly sent a document containing health data of the data… ITALY ·Garante ·Art. 5, 32, 75 Security Personal Data Controllers Jan 26, 2023
€8,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has fined a company EUR 8, 000. The controller failed ot properly fulfil the data subject's right to access their personal data processed by the company. The… LITHUANIA ·VDAI ·Art. 5, 15 Personal Data Retention Period Storage Limitation Jan 24, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·DPC ·Art. 5, 32 Security Controllers Personal Data Jan 23, 2023
€17,900 Dalarna Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a… SWEDEN ·IMY ·Art. 32 Security Personal Data Privacy by Design & Default Jan 17, 2023
€50,000 DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Legitimate Interest Controllers Personal Data Jan 16, 2023
€6,000 Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Jan 11, 2023
€2,500 Azienda Sanitaria Locale di Brindisi: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,500 on Azienda Sanitaria Locale di Brindisi. A data subject had filed a complaint with the DPA due to the health authority's failure to… ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Healthcare Jan 11, 2023
€5,000 Azienda Ospedale-Università Padova: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Azienda Ospedale-Università Padova. The controller had sent an email containing consent forms for participation in a clinical… ITALY ·Garante ·Art. 5, 9 Controllers Healthcare Consent Jan 11, 2023
€3,600 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records containing patient data in a public waste disposal site. GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Jan 1, 2023
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on six private individuals. The individuals, who worked in a hospital, had accessed the medical records of a colleague who… GERMANY ·Insufficient legal basis for data processing Health Data Healthcare Human Resources Jan 1, 2023
Pizza delivery service: Non-compliance with general data processing principles The DPA of Baden-Wuerttemberg has imposed a four-digit fine on a pizza delivery service. The controller had disposed of receipts containing customers' personal data at a public… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Controllers Personal Data Processing Jan 1, 2023
Physician: Non-compliance with general data processing principles The DPA of Bavaria has imposed a fine in the four figure range on a physician. The physician had responded to an online review regarding their practice, disclosing personal health… GERMANY ·Non-compliance with general data processing principles Health Data Healthcare Types of Special Categories of Personal Data Jan 1, 2023
€9,000 Magdeburg University Hospital: Insufficient fulfilment of data breach notification obligations The DPA of Sachsen-Anhalt has imposed a fine of EUR 9,000 on Magdeburg University Hospital. The clinic had failed to report to the DPA a data breach involving a former employee… GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2023
€2,000 Private individual: Insufficient legal basis for data processing The DPA of Baden-Wuerttemberg has imposed a fine of EUR 2,000 on a clinic employee. The employee had unlawfully accessed a patient administration system in order to find out more… GERMANY ·Art. 6, 9 ·Insufficient legal basis for data processing Personal Data Healthcare Processing Jan 1, 2023