Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3151–3200 of 3,446 sort newestlargest fineoldest
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Insurance Healthcare Security Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE ·HDPA ·Art. 5 Personal Data Education IP Address Jun 29, 2020
€7,500 Miraclia (telecommunications company): Insufficient legal basis for data processing The recording of telephone jokes via an app constitutes processing of personal data in accordance with the applicable data protection law, as the voices of individuals may… SPAIN ·aepd ·Art. 5, 6 Consent Personal Data Processing Jun 23, 2020
€2,000 Comunidad de propietarios demelza beach: Non-compliance with general data processing principles Illegal use of CCTV cameras due to coverage of public space and recording of passing pedestrians. Furthermore, insufficient fulfilment of information obligations. SPAIN ·aepd ·Art. 5, 6, 13 +1 Video Surveillance IP Address Processing Jun 22, 2020
€112,000 Østfold HF Hospital: Insufficient technical and organisational measures to ensure information security It was found that Østfold HF Hospital had stored patient data, including sensitive data such as the reason for hospitalisation, during the period 2013-2019 without controlling… NORWAY ·Datatilsynet ·Art. 32 Healthcare Health Data Healthcare Jun 22, 2020
€10,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The company sent an e-mail to the person concerned without his consent. Thereupon the person concerned requested timely information about the entries in the database concerning… APD ·Art. 5, 6, 15 ·Insufficient fulfilment of data subjects rights Personal Data Consent Processing Agreement Jun 19, 2020
€6,000 National Police Brigade: Insufficient legal basis for data processing Making copies of a company's business records in the context of investigations which contained data from third parties and for which there was no legal basis for processing. SPAIN ·aepd ·Art. 5, 6 Public Authority Education Processing Jun 19, 2020
Aquateknikk AS: Insufficient legal basis for data processing On June 19, 2020, the Norwegian DPA (Datatilsynet) announced that it intents to fine Aquateknikk AS EUR 28,000 for violations of Art. 5 GDPR and Art. 6 GDPR . This fine has been… NORWAY ·Datatilsynet ·Art. 5, 6 Processing Agreement Processing Supervisory Authorities Jun 19, 2020
€4,000 Enel Energie: Insufficient technical and organisational measures to ensure information security Failure to take adequate measures to prevent unauthorised disclosure of personal data. The fine was preceded by a complaint about the disclosure of personal data of the data… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Security Processing Jun 18, 2020
€2,000 Café Bar: Non-compliance with general data processing principles Illegal use of CCTV cameras (recording of third parties) and insufficient fulfilment of information obligations. SPAIN ·aepd ·Art. 5, 6, 13 +1 Video Surveillance IP Address Healthcare Jun 16, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 16, 2020
€1,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The data subject repeatedly received e-mails with advertising content from a company, although the data subject had objected to the processing of his personal data and requested… APD ·Art. 17, 21, 31 ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Processing Agreement Jun 16, 2020
€1,900 Housing Association: Non-compliance with general data processing principles Unlawful usage of surveillance cameras. In the decision, the data protection authority stressed that sound recordings have additional privacy implications, especially in a… SWEDEN ·Art. 5, 6 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jun 16, 2020
€75,000 Xfera Moviles S.A.: Insufficient legal basis for data processing The data subject received a notice from a debt collection company demanding payments in connection with Xfera Móviles' services, even though the claimant had not been a customer… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Jun 15, 2020
€4,010 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 4,010 on a legal person. The order was issued based on the carried out inspection. The accused failed to respond to numerous requests to… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Supervisory Authorities Processing Agreement Jun 11, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Telecommunications Jun 11, 2020
€2,000 Attorney: Insufficient technical and organisational measures to ensure information security In the course of proceedings, an attorney submitted documents whose backs contained personal data of other parties. SPAIN ·aepd ·Art. 32 Security Insurance Personal Data Jun 9, 2020
€1,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Jun 9, 2020
€3,000 Salad Market S.L. (Catering Company): Insufficient fulfilment of information obligations Fines for lack of sufficient data processing information in relation to video surveillance on business premises and for insufficient information when cookies were used on its… SPAIN ·aepd ·Art. 13, 14 Video Surveillance Fines Monitoring Jun 9, 2020
€40,000 TELEFONICA MOVILES ESPAÑA, S.A.U.: Insufficient legal basis for data processing A sales representative failed to carefully check the identity of a claimant so that he could appear in the name of the data subject and order a telephone connection for four… SPAIN ·aepd ·Art. 6 Representatives Personal Data Telecommunications Jun 9, 2020
€5,000 Consulting de Seguridad e Investigacion Mira Dp Madrid S.L.: Insufficient legal basis for data processing A data subject has received marketing messages without having consented. SPAIN ·aepd ·Art. 5, 6 Insurance Direct Marketing Personal Data Jun 9, 2020
€540 Chenming Ye (Bazar Real): Insufficient fulfilment of information obligations Usage of CCTV camera in a shop without proper information. SPAIN ·aepd ·Art. 13, 14 Video Surveillance Supervisory Authorities Jun 9, 2020
€39,000 Xfera Moviles S.A.: Insufficient legal basis for data processing A customer claimed to have received an SMS from Xfera Móviles informing about the non-payment and the resulting suspension of the service in relation to the account of another… SPAIN ·aepd ·Art. 5 Personal Data Telecommunications Processing Jun 9, 2020
€75,000 Equifax Iberica, S.L.: Insufficient fulfilment of data subjects rights The Data Subject has requested by e-mail the deletion of his data from the file of the National Association of Financial Credit Institutions ('ASNEF'). Equifax Iberica had replied… SPAIN ·aepd ·Art. 15 Personal Data Insurance Supervisory Authorities Jun 9, 2020
€2,000 Property Owner: Non-compliance with general data processing principles Usage of CCTV camera which also captured the public roads outside in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Jun 9, 2020
€25,000 Glovoapp23: Insufficient involvement of data protection officer The company had not appointed a Data Protection Officer ('DPO') to whom requests from data subjects could be addressed, and the company's website did not contain information about… SPAIN ·aepd ·Art. 37 Supervisory Authorities Personal Data Jun 9, 2020
€5,000 Municipal employee: Insufficient legal basis for data processing In the context of a municipal election in 2018, the data controller had sent election advertisements to a group of employees of the same municipal administration, unlawfully using… BELGIUM ·APD ·Art. 5, 6 Controllers Education IP Address Jun 8, 2020
€4,000 Iberdrola Clientes: Insufficient cooperation with supervisory authority The company was asked to provide the AEPD with specific information in relation to a complaint. However, the company had not replied to the data protection authorities request for… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Jun 4, 2020
€1,168 Entrepreneur running a non-public nursery and pre-school: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. POLAND ·UODO ·Art. 31, 58 Data Breaches Supervisory Authorities Supervision Jun 3, 2020
€1,000 Non-profit organisation: Insufficient fulfilment of data subjects rights The Belgian data protection authority has imposed a fine of EUR 1000 on a non-profit organisation for sending out direct marketing messages, despite the fact that data subjects… BELGIUM ·APD ·Art. 6, 21 Right to Object Right to be Forgotten Legitimate Interest May 29, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Insurance May 26, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Education Public Authority May 17, 2020
€6,700 JobTeam A/S DKK: Insufficient fulfilment of data subjects rights The company has deleted personal data affected by a request for access without legal reason. DENMARK ·Datatilsynet ·Art. 15 Personal Data Employees Supervisory Authorities May 15, 2020
€50,000 Social Media Provider: Insufficient legal basis for data processing The company has sent invitations to contacts uploaded by its users without their consent or any other legal basis. BELGIUM ·APD ·Art. 6 Social Media Consent Processing May 14, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Healthcare Healthcare May 12, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Personal Data May 5, 2020
€134,000 Telenor Norge AS: Insufficient technical and organisational measures to ensure information security Fines for security breaches in a voice mailbox function. NORWAY ·Datatilsynet ·Art. 32 Telecommunications Security Fines May 3, 2020
€500 Housing Association: Insufficient legal basis for data processing Fine of EUR 500 against a housing association for publishing photos showing members of the association without their consent. ESTONIA ·AKI ·Art. 6 Consent Processing Supervisory Authorities Apr 30, 2020
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS ·AP ·Art. 5, 9 Consent Employees Biometric Data Apr 30, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 29, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM ·APD ·Art. 31, 37, 58 Notified Body Responsibilities and Operational Obligations Supervisory Authorities Scientific Panel Independence Apr 28, 2020
€3,000 Estee Lauder Romania: Insufficient legal basis for data processing Processing of personal data without sufficient legal basis including health data. ANSPDCP ·Art. 6, 7, 9 ·Insufficient legal basis for data processing Healthcare Health Data Personal Data Apr 23, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Accuracy Security Telecommunications Apr 23, 2020
€2,000 Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε.: Non-compliance with general data processing principles The Hellenic DPA (HDPA) has imposed a fine of EUR 2,000 on Ιγνατιάδης Νικόλαος και ΣΙΑ Ε.Ε. The controller had installed surveillance cameras covering areas where its employees… GREECE ·HDPA ·Art. 5, 6 Video Surveillance IP Address Monitoring Apr 7, 2020
€2,000 SOS Infertility Association: Insufficient cooperation with supervisory authority The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient… ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Healthcare Mar 25, 2020
€3,000 Enel Energie: Insufficient technical and organisational measures to ensure information security The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Law Enforcement Mar 25, 2020
€3,000 Dante International: Insufficient legal basis for data processing The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. ROMANIA ·ANSPDCP ·Art. 6, 21 Personal Data Processing Supervisory Authorities Mar 25, 2020
€4,150 Vodafone Romania: Insufficient technical and organisational measures to ensure information security The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Telecommunications Security Personal Data Mar 25, 2020
€5,000 Xfera Moviles S.A.: Insufficient cooperation with supervisory authority The company did not provide the data protection authority with the requested information in a timely manner. The AEPD's request was preceded by a request from a data subject for… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Personal Data Mar 25, 2020
€15,000 CP&A: Insufficient technical and organisational measures to ensure information security The Dutch DPA (AP) has imposed a fine of EUR 15,000 on CP&A. The controller had documented both the causes of illness and specific complaints of the data subjects as part of the… THE NETHERLANDS ·AP ·Art. 9, 32 Health Data Healthcare Access Controls Mar 24, 2020