Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

2951–3000 of 3,651 sort newestlargest fineoldest
€3,000 IDFINANCE Spain, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on IDFINANCE Spain S.L.. A person had received a debt collection email from IDFinance that contained a link for the payment of… aepd ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Controllers Personal Data Security Feb 1, 2021
€50,000 Azienda USL della Romagna: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 50,000 on Azienda USL della Romagna. Upon her arrival at the gynecology unit of a hospital operated by the controller (for the… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Healthcare Jan 27, 2021
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Prior Consultation Jan 27, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY ·Garante ·Art. 5, 9 Healthcare Health Data Data Breaches Jan 27, 2021
€50,000 Family Service / N.D.P.K. nv.: Insufficient legal basis for data processing The Belgian DPA imposed a fine of EUR 50,000 on Family Service / N.D.P.K. nv. The controller is an advertising agency that, among other things, sends expectant mothers gift boxes… BELGIUM ·APD ·Art. 5, 6, 7 +4 Controllers IP Address Personal Data Jan 27, 2021
€75,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Data Breaches Access Controls Jan 27, 2021
€150,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Data Breaches Access Controls Jan 27, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Education Personal Data IP Address Jan 27, 2021
€25,000 BELGIUM DPA: Insufficient technical and organisational measures to ensure information security The Belgian DPA fined a mobile operator EUR 25,000. The controller had assigned the data subject's phone number to an unauthorized third party, causing the data subject to lose… APD ·Art. 5, 24, 32 +2 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Social Media Jan 22, 2021
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 75,000 on Telefónica Móviles España, SAU. The controller had assigned five telephone lines with five numbers to the data subject as… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Jan 21, 2021
€50,000 Alterna Operador Integral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 50,000 on Alterna Operador Integral S.L.. A switch of the electricity supplier had taken place without the consent of the data… SPAIN ·aepd ·Art. 6 Personal Data Controllers Processing Agreement Jan 21, 2021
€1,200 Individual: Non-compliance with general data processing principles The controller installed cameras on his building, which were directed towards parts of the public space. However, no recording took place, as the cameras only served as a… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Controllers Jan 20, 2021
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Jan 20, 2021
€26,710 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·UOOU ·Art. 6, 14 Direct Marketing Processing Agreement Processing Jan 20, 2021
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent unsolicited commercial communications to the complainant and failed to respond to their repeated… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Processing Supervisory Authorities Jan 19, 2021
€9,700 Aquateknikk AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Aquateknikk AS NOK 100,000 (EUR 9,700). The controller had carried out a credit rating on an individual without there being a customer… NORWAY ·Datatilsynet ·Art. 5, 6 Personal Data Controllers IP Address Jan 19, 2021
€4,600 Anwara Sp. z.o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) fined the company Anwara Sp. z.o.o. EUR 4,600. The controller had not cooperated with the DPA and had not provided it with all the information necessary for… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Public Sector Jan 15, 2021
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY ·Garante ·Art. 5, 32 Security Education Personal Data Jan 14, 2021
€38,600 Coop Finnmark SA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Coop Finnmark SA NOK 400,000 (EUR 38,600). The manager of the store in question recorded CCTV footage with a mobile phone and shared the… NORWAY ·Datatilsynet ·Art. 5, 6 Video Surveillance Processing Agreement Processing Jan 14, 2021
€30,000 Azienda sanitaria provinciale di Enna: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 30,000 on Azienda sanitaria provinciale di Enna. The controller processed biometric data of employees for the purpose of… ITALY ·Garante ·Art. 5, 6, 9 Biometric Data Special Categories of Data Biometric Data Jan 14, 2021
€18,000 Azienda Usl di Bologna: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Usl di Bologna EUR 18,000. In a hospital operated by the controller, 49 patients in the oncology ward received discharge letters with… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare IP Address Jan 14, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Controllers Processors Processing Agreement Jan 14, 2021
€2,000 Poliambulatorio Talenti S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) fined Poliambulatorio Talenti S.r.l. EUR 2,000 for failing to respond to the data subject's request for access to his and his daughters' data in a timely… ITALY ·Garante ·Art. 12, 15 Personal Data Healthcare Supervisory Authorities Jan 14, 2021
€2M Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined Caixabank S.A. EUR 6,000,000 for violations of Art. 6 GDPR, Art. 13 GDPR and Art. 14 GDPR. Customers of the bank were supposed to accept new privacy… SPAIN ·aepd ·Art. 6, 13, 14 Legitimate Interest Processing Agreement Controllers Jan 13, 2021
€10,000 BELGIUM DPA: Insufficient legal basis for data processing Managing a fan page on Facebook without the data subject's permission and failing to comply with the data subject's request after exercising his or her right to object. APD ·Art. 6, 12, 21 ·Insufficient legal basis for data processing Right to Object Social Media Data Subject Rights Exercise Modalities and Procedures Jan 12, 2021
€38,600 NORWAY DPA: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined a company NOK 400,000 (EUR 38,600) for the illegal automatic forwarding of an employee's email inbox. The automatic forwarding was activated… Datatilsynet ·Art. 5, 6 ·Insufficient legal basis for data processing Employees Processing Agreement Processing Jan 12, 2021
€30,000 Enea S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information… POLAND ·UODO ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 11, 2021
€10M notebooksbilliger.de: Insufficient legal basis for data processing The DPA of Lower Saxony (LfD Niedersachsen) imposed a fine of EUR 10,4 million on the electronics retailer notebooksbilliger.de.The company had video-monitored its employees for… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Monitoring Employees Jan 8, 2021
€7,250 Gveik AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined Gveik AS EUR 7,250. The controller had carried out a credit check on an individual, although there was no legal basis for doing so. NORWAY ·Datatilsynet ·Art. 5, 6 Controllers Insurance Processing Agreement Jan 7, 2021
€9,700 Lindstrand Trading AS: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined Lindstrand Trading AS EUR 9,700. The controller had carried out four credit checks on individuals and individual companies, although… NORWAY ·Datatilsynet ·Art. 5, 6 Controllers Insurance Processing Agreement Jan 6, 2021
€20,000 Nestor SAS: Insufficient fulfilment of information obligations The French DPA (CNIL) fined the company Nestor EUR 20,000. The CNIL notes that the privacy policy provided during the registration process on the company´s website did not contain… FRANCE ·CNIL ·Art. 12, 13 Controllers Processing Agreement Processing Jan 5, 2021
€19,000 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of EUR 19,000 on a hospital operator. A former employee had unlawfully copied the personal data of 100 patients from the hospital's computer… UODO ·Art. 34, 58 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 5, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 5, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN ·aepd ·Art. 5 Accuracy Personal Data Controllers Jan 4, 2021
€118,500 CZECH REPUBLIC DPA: Insufficient legal basis for data processing The Czech DPA (UOOU) fined 11 companies a total of EUR 118,500 for sending unrequested postal advertising messages to the mailboxes of various citizens. Based on a decision by the… UOOU ·Art. 6, 14 ·Insufficient legal basis for data processing Direct Marketing Processing Agreement Personal Data Jan 4, 2021
€95,500 Innovasjon Norge: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) fined the national development bank Innovasjon Norge NOK 1,000,000 (EUR 95,500). The controller had carried out four credit checks on the data… NORWAY ·Datatilsynet ·Art. 5, 6 Controllers Insurance Personal Data Jan 4, 2021
Political organization: Data Protection Authority of Saarland An employee of a political organization had sent an e-mail to 400 people in an open distribution list. This not only made the e-mail addresses of all recipients visible to the… GERMANY ·Unknown IP Address Supervisory Authorities Law Enforcement Jan 1, 2021
€600 Private individual: Non-compliance with general data processing principles The Austrian DPA imposed a fine of EUR 600 on a private individual. The individual had contacted a public institution to draw their attention to the fact that the statement of a… AUSTRIA ·dsb ·Art. 5, 9 Personal Data Integrity and Confidentiality Principle Healthcare Jan 1, 2021
€4M Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… AUSTRIA ·dsb ·Art. 5, 32 Data Breaches Encryption Integrity and Confidentiality Principle Jan 1, 2021
Clinic: Insufficient involvement of data protection officer The DPA from Berlin has imposed a fine on a clinic. The clinic had appointed the clinic manager, who was also a shareholder of the clinic, as the data protection officer. A data… GERMANY ·Insufficient involvement of data protection officer Notified Body Responsibilities and Operational Obligations Supervisory Authorities Scientific Panel Independence Jan 1, 2021
€700,000 Customer loyalty program: €700,000 fine According to the newspaper 'Der Standard', the Austrian DPA has imposed a fine of EUR 1.2 million on a customer loyalty program in 2021. Further information has not yet been… AUSTRIA ·dsb ·Unknown Processing Agreement Controllers Supervisory Authorities Jan 1, 2021
Physician: Insufficient technical and organisational measures to ensure information security A physician had stored patient records in an open carport and not in a locked room. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Security Supervisory Authorities Jan 1, 2021
GERMANY DPA: Insufficient technical and organisational measures to ensure information security The camera images of a store were distributed without the knowledge and intention of the controller due to a faulty configuration. The distribution involved recordings of… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processing Agreement Jan 1, 2021
GERMANY DPA: Insufficient technical and organisational measures to ensure information security Live video surveillance which was accessible via the Internet and, due to a lack of sufficient pixelation or redaction, allowed persons to be recognized. Art. 32 ·Insufficient technical and organisational measures to ensure information security Video Surveillance Security Monitoring Jan 1, 2021
Physician: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a four-digit fine on a doctor of child and adolescent psychotherapy. The doctor had set up a Whatsgroup with 230 participants to communicate… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Healthcare Consent IP Address Jan 1, 2021
Private individual: Insufficient legal basis for data processing The DPA from Brandenburg imposed a three-digit fine on a company employee. The individual had sent an Excel spreadsheet with employee data of 56 employees to her private e-mail… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Employees Processing Agreement Human Resources Jan 1, 2021
Private individual: Data Protection Authority of Saxony A private individual had taken secret video recordings during a court hearing with their mobile phone. GERMANY ·Unknown Supervisory Authorities Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine in the six-digit range on a Hamburg-based company operating in the healthcare sector. The company had failed to take appropriate technical… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Recipient Jan 1, 2021
Private individual: Insufficient legal basis for data processing Nineteen fines between EUR 100 and EUR 1,000 for unlawful use of a dashcam. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Fines Processing Supervisory Authorities Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security A company had stored telecommunications hardware, a server and backup technology in a guest bathroom. The server cabinet, which did not have an intact lock, also served as a… GERMANY ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Human Resources Jan 1, 2021