Skip to content
Content type · 3,833 documents in this view · 3,838 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3201–3250 of 3,833 sort newestlargest fineoldest
Attorney: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on an attorney. The attorney had been in dispute with a client for several years over a monetary claim. For two years, he published the… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Insurance Jan 1, 2021
Clinic: Insufficient involvement of data protection officer The DPA from Berlin has imposed a fine on a clinic. The clinic had appointed the clinic manager, who was also a shareholder of the clinic, as the data protection officer. A data… GERMANY ·Insufficient involvement of data protection officer Supervisory Authorities Notified Body Independence Scientific Panel Independence Jan 1, 2021
Company: Data Protection Authority of Brandenburg The DPA of Brandenburg has imposed a fine on a company. An individual had filed a complaint with the DPA based on the fact that the company produced a video recording in which the… GERMANY ·Unknown Supervisory Authorities Jan 1, 2021
Real estate agent: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a fine on a real estate agent. The real estate agent had contacted an individual and offered him to sell a property he owned. Since the… GERMANY ·Art. 6, 12 ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Data Subject Rights Exercise Modalities and Procedures Jan 1, 2021
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-digit fine on a company employee. The employee had forwarded application documents received by his employer from his work e-mail address… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Anonymization Human Resources Processing Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried the investigation process of a friend against the background of a… GERMANY ·Insufficient legal basis for data processing Public Authority Scientific Research Human Resources Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Public Authority Personal Data Supervisory Authorities Jan 1, 2021
€10,100 Car trading group: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine of EUR 10,110 on a car trading group. The company had informed the customer base that the reasons for the restructuring there was the absence… GERMANY ·HmbBfDI ·Insufficient legal basis for data processing Health Data International Transfer Types of Special Categories of Personal Data Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security A company had stored telecommunications hardware, a server and backup technology in a guest bathroom. The server cabinet, which did not have an intact lock, also served as a… GERMANY ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Human Resources Jan 1, 2021
Private individual: Non-compliance with general data processing principles A private individual had installed video surveillance cameras which, among other things, also covered the public space GERMANY ·Art. 5 ·Non-compliance with general data processing principles Processing Video Surveillance Monitoring Jan 1, 2021
Bank employee: Insufficient legal basis for data processing An employee of a bank had regularly accessed the bank account data of a bank customer for private purposes over a period of about a year. GERMANY ·Insufficient legal basis for data processing Insurance Processing Supervisory Authorities Jan 1, 2021
€500 SLOVAKIA DPA: Insufficient cooperation with supervisory authority The Slovak DPA has imposed a fine of EUR 500 on a controller for failing to cooperate with the DPA. Slovak Data Protection Office ·Art. 31 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Jan 1, 2021
€100 SLOVAKIA DPA: €100 fine Unlawful video surveillance in a garden community. Slovak Data Protection Office ·Unknown Supervisory Authorities Video Surveillance Monitoring Jan 1, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles Supervisory Authorities Controllers Processors Jan 1, 2021
Private individual: Non-compliance with general data processing principles The Austrian DPA has fined a private individual. The individual had installed a video surveillance system which, among other things, also recorded the public space and stored the… AUSTRIA ·DSB ·Art. 5 Processing Video Surveillance Monitoring Jan 1, 2021
€500 Police officer: Insufficient legal basis for data processing A police officer had accessed data in police databases for private research purposes in order to obtain information about a colleague. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2021
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine in the six-digit range on a Hamburg-based company operating in the healthcare sector. The company had failed to take appropriate technical… GERMANY ·HmbBfDI ·Art. 32 Security Privacy by Design & Default Recipient Jan 1, 2021
Private individual: Insufficient legal basis for data processing Nineteen fines between EUR 100 and EUR 1,000 for unlawful use of a dashcam. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Fines Processing Supervisory Authorities Jan 1, 2021
Physician: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a four-digit fine on a doctor of child and adolescent psychotherapy. The doctor had set up a Whatsgroup with 230 participants to communicate… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Healthcare Minors Jan 1, 2021
GERMANY DPA: Insufficient technical and organisational measures to ensure information security The camera images of a store were distributed without the knowledge and intention of the controller due to a faulty configuration. The distribution involved recordings of… Art. 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Supervisory Authorities Jan 1, 2021
Physician: Insufficient technical and organisational measures to ensure information security A physician had stored patient records in an open carport and not in a locked room. GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2021
€4M Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… AUSTRIA ·DSB ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 1, 2021
€3,000 ING Bank N.V. Amsterdam - Bucharest office: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) fined ING Bank N.V. Amsterdam - Bucharest office in the amount of EUR 3,000. The bank had contacted the data subject by e-mail for the purpose of… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing Dec 30, 2020
€1,000 Qualitance QBS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Qualitance QBS SA EUR 1,000 for a violation of Art. 32 GDPR. The company had sent information by email to 295 individuals, disclosing the email… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Integrity and Confidentiality Principle Dec 29, 2020
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 28, 2020
€15,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 15,000 on a company due to insufficient fulfilment of data subject rights. The controller is a debt collection agency which was… APD/GBA ·Art. 5, 6, 12 +2 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Dec 23, 2020
€50,000 BELGIUM DPA: Insufficient fulfilment of data subjects rights The Belgian DPA (APD) imposed a fine of EUR 50,000 on a company for several violations of the GDPR. The controller is a company that carries out parking ticket controls. The… APD/GBA ·Art. 5, 12, 14 +2 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Dec 23, 2020
€6,000 Iberdrola Clientes, SAU: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) fined Iberdrola Clientes, SAU EUR 6,000. The data subject had received promotional calls from two different telephone numbers of the controller although the… SPAIN ·AEPD ·Art. 21, 23, 48 Personal Data Direct Marketing Controllers Dec 22, 2020
€2,000 S.C. C&V Water Control S.A.: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) fined S.C. C&V Water Control S.A. EUR 2,000 for failure to comply with the data protection authority's request for information in the course of an… ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Personal Data Dec 22, 2020
€36,000 Banco Bilbao Vizcaya Argentaria, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Dec 21, 2020
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Personal Data Representatives Supervisory Authorities Dec 20, 2020
€10,070 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€11,830 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 200 on a legal person. The accused sent the data subject, despite his objection and therefore his disagreement with further processing of… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 17 Personal Data Direct Marketing Right to Object Dec 18, 2020
€8,340 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€8,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,800 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€8,100 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,100 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€9,420 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€8,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,800 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€26,710 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 11,430 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€12,910 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€11,430 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 8,340 on a legal person. During the state of emergency (COVID-19 pandemic), the accused sent unsolicited marketing communications for a… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 14 Marketing Supervisory Authorities Direct Marketing Dec 18, 2020
€6,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well… FRANCE ·CNIL ·Art. 32, 33 Security Controllers Personal Data Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Storage Limitation Retention Period Controllers Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Dec 17, 2020
€3,000 Doctor: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a doctor EUR 3,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data as MRI and X-ray images as well as… FRANCE ·CNIL ·Art. 32, 33 Security Controllers Personal Data Dec 17, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Dec 17, 2020
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… UODO ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Privacy by Design & Default Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Personal Data Controllers Dec 17, 2020