Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3101–3150 of 3,651 sort newestlargest fineoldest
€390,100 Karolinska University Hospital of Solna: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Karolinska University Hospital of Solna SEK 4,000,000 (EUR 390,100) for failing to implement adequate technical and… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Health Data Security Dec 3, 2020
€2.9M Capio St. Göran AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Capio St. Göran AB SEK 30,000,000 (EUR 2,900,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Health Data Security Dec 3, 2020
€243,800 Östergötland Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Östergötland Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Dec 3, 2020
€6,000 Servicio de Alojamientos Responsables, S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine in the amount of EUR 6,000 against the controller for unauthorized conclusion of a contract in the name of the data subject without his/her… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Dec 2, 2020
€5,000 Asociación de Víctimas por Arbitrariedades Judiciales, (JAVA): Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on the association for publishing the personal data of the data subjects on its website. The data had been unlawfully recorded… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Dec 2, 2020
€3,000 Comercio Online Levante, S.L.: Insufficient technical and organisational measures to ensure information security A woman filed a complaint with the Spanish DPA (AEPD) against Comercio Online Levante, S.L. due to the fact that she was shown the personal data of another user when trying to… SPAIN ·aepd ·Art. 5, 32 Controllers Security Personal Data Dec 2, 2020
€10,000 Losada Advocats S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine on Losada Advocats S.L. for sending an e-mail to dozens of recipients without putting them on the Blind Carbon Copy (BCC) list, thus… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Security Dec 2, 2020
€800 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 800 on a legal person. The complainant had worked with the accused over the years as an employee, collaborator, author, licensor, and… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Supervisory Authorities Processing Agreement Dec 1, 2020
€100,000 Südameapteegi e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Consent Dec 1, 2020
€100,000 Azeta.ee e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Consent Dec 1, 2020
€100,000 Apotheka e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Consent Dec 1, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of Eur 2,000 on a legal person. The accused failed to comply with the request to erase the auction notice with the personal data and failed to… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Processing Agreement Supervisory Authorities Nov 30, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The accused sent the subject a commercial offer via SMS after assuring the data subject that their data was… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Processing Agreement Supervisory Authorities Nov 30, 2020
€1,200 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine in the amount of EUR 1,200 on a private individual for impersonating a third party on the social networks Tinder and WhatsApp by using images… SPAIN ·aepd ·Art. 5 IP Address Personal Data Consent Nov 27, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Garante ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Health Data Integrity and Confidentiality Principle Nov 26, 2020
€3,000 Charly Mike s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Charly Mike s.r.l.. The controller is the hotel operator of the Hotel Olimpo in Alberobello. Garante received a complaint… ITALY ·Garante ·Art. 5, 13 Video Surveillance Monitoring Controllers Nov 26, 2020
€10,000 Reti Televisive Italiane S.p.a.: Non-compliance with general data processing principles The television station broadcasted a documentary about the link between emissions from a local ceramics plant and health problems in the population, in which the person… ITALY ·Garante ·Art. 5 Healthcare IP Address Telecommunications Nov 26, 2020
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·aepd ·Art. 6, 13, 14 Recipient Personal Data IP Address Nov 25, 2020
€1,500 Private Individual: Insufficient legal basis for data processing The Belgian DPA (APD) imposed a fine against private individuals. The controllers installed video cameras on their private property, two of which were positioned in a way that… BELGIUM ·APD ·Art. 6, 25 Controllers Processing Processing Agreement Nov 25, 2020
€19,500 Gnosjö Municipality: Insufficient legal basis for data processing The Swedish DPA imposed a fine on the municipality of Gnosjö for illegal video surveillance in a care home for persons with certain functional disabilities. SWEDEN ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Video Surveillance Healthcare Monitoring Nov 25, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Privacy by Design & Default Personal Data Nov 24, 2020
€394,000 City of Stockholm: Insufficient technical and organisational measures to ensure information security The Swedish DPA imposed a fine on the City of Stockholm for data breaches on a school education platform. The platform consists of different subsystems, including a system for… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Audit Logs Education Nov 24, 2020
€12,000 Recambios Villalegre S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined the company for posting photos of a person on Facebook and WhatsApp and accusing the individual of theft in related posts. The photos were obtained… SPAIN ·aepd ·Art. 6, 13 Video Surveillance Social Media Monitoring Nov 23, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY ·Garante ·Art. 5, 13 Personal Data IP Address Employees Nov 23, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Telecommunications Processing Agreement Nov 23, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Right of Access Procedures Fairness & Transparency Nov 19, 2020
€4,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 4,800 on a legal person. In the course of the business activities, the accused contacted business entities, owners of industrial rights,… CZECH REPUBLIC ·UOOU ·Art. 6, 12 Processing Processing Agreement Supervisory Authorities Nov 19, 2020
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis. The company had sent an invoice to a data subject without being able to prove that it had a contract… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Nov 19, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… NAIH ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers IP Address Nov 18, 2020
€2,000 Anmavas 61, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning… SPAIN ·aepd ·Art. 58 Right to be Forgotten Data Subject Rights Exercise Modalities and Procedures Supervisory Authorities Nov 18, 2020
€800,000 Carrefour Banque: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine on Carrefour Banque for violation of its obligation to process data fairly (Article 5 (1) GDPR). If a person who subscribed to the Pass card… FRANCE ·CNIL ·Art. 5 IP Address Processing Agreement Insurance Nov 18, 2020
€2.3M Carrefour France: Non-compliance with general data processing principles The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that… CNIL ·Art. 5, 12, 13 +5 ·Non-compliance with general data processing principles Processing Agreement IP Address Personal Data Nov 18, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY ·Garante ·Art. 9 Personal Data Healthcare Education Nov 17, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY ·Garante ·Art. 12, 13, 14 Video Surveillance Personal Data Public Authority Nov 17, 2020
€1,600 Homeowners Association: Non-compliance with general data processing principles Usage of CCTV camera systems that were also monitoring public space (breach of principle of data minimization). SPAIN ·aepd ·Art. 5 Video Surveillance Audit Logs Monitoring Nov 16, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing In 2019, after an arbitration procedure, the company agreed to the early termination of a contract with the data subject and to the deletion of the personal data concerned.… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Nov 16, 2020
€1.4M Ticketmaster UK Limited: Insufficient technical and organisational measures to ensure information security Ticketmaster UK Limited has been fined GBP 1.25 million (approximately EUR 1.405 million) for failing to protect the personal data of its customers with adequate security… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Processing Agreement Personal Data Nov 13, 2020
€1,500 BELGIUM DPA: Non-compliance with general data processing principles The Belgian DPA (APD/GBA) imposed a fine of EUR 1,500 on a social housing company for non-compliance with several principles of the GDPR such as data processing as well as the… APD ·Art. 5, 6, 12 +3 ·Non-compliance with general data processing principles Video Surveillance Fairness & Transparency IP Address Nov 13, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY ·Garante ·Art. 5, 6, 7 +7 IP Address Telecommunications Security Nov 12, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The company ported a telephone number of the data subject without their consent (missing signature on the porting contract). SPAIN ·aepd ·Art. 5, 6 Consent Personal Data Telecommunications Nov 11, 2020
€900,000 Telecoms provider (1&1 Telecom GmbH): Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's… GERMANY ·BfDI ·Art. 32 Telecommunications IP Address Controllers Nov 11, 2020
€3,000 Miguel Ibáñez Bezanilla, S.L.: Insufficient technical and organisational measures to ensure information security The company's website (license plate seller) requested personal information such as first and last name, copy of ID card and driver's license, and the car's VIN number, but… SPAIN ·aepd ·Art. 13, 32 Encryption Security Processing Nov 10, 2020
€20,000 Xfera Moviles S.A.: Insufficient legal basis for data processing Xfera Móviles had failed to cooperate with the AEPD in the investigation of privacy violations. Xfera Móviles had neither responded to the request for information nor provided any… SPAIN ·aepd ·Art. 31 Telecommunications Processing Supervisory Authorities Nov 6, 2020
DSB (Austria) - DSB-D124.1749 The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… DSB-D124.1749 ·Art. 4, 9 Personal Data Healthcare Insurance Nov 5, 2020
€75,000 Telefonica Moviles Espana, S.A.U.: Insufficient legal basis for data processing Processing of personal data of the data subject without sufficient legal basis. The company had issued several invoices to the data subject and collected invoice amounts from his… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Nov 5, 2020
€30,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis due to errors in the correct assignment of customer contracts. In this case, Vodafone demanded a debt… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Nov 3, 2020
€20M Marriott International, Inc: Insufficient technical and organisational measures to ensure information security Original Summary: The ICO issued a notice of its intention to fine Marriott International Inc due to a cyber incident which was notified to the ICO by Marriott in November 2018. A… UNITED KINGDOM ·ICO ·Art. 32 Fines Security Healthcare Oct 30, 2020
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY ·Garante ·Art. 5, 13 Video Surveillance Controllers Personal Data Oct 29, 2020
€1,000 American College of Greece: Insufficient fulfilment of information obligations The Hellenic DPA (HDPA) imposed a fine of EUR 1,000 against the American College of Greece for violations of the right of access and the right to erasure of personal data. HDPA ·Art. 12 ·Insufficient fulfilment of information obligations Right to be Forgotten Right of Access Procedures Right of Access Oct 29, 2020
€20,000 Gaypa s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee's email account active and had access to the data subject's… ITALY ·Garante ·Art. 5, 12, 13 Personal Data Controllers IP Address Oct 29, 2020