Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3201–3250 of 3,651 sort newestlargest fineoldest
€5,000 Former mayor of a community: Insufficient legal basis for data processing Originial fine summary: Sending election advertising to citizens without sufficient legal basis. Update: On January 27th, 2021, the Brussels Court of Appeal overturned the fine of… BELGIUM ·APD ·Art. 5, 6 Direct Marketing Education Public Authority Sep 7, 2020
€3,000 Barcelona Airport Security Guard Association ('AVSAB'): Non-compliance with general data processing principles A member of the AVSAB security committee used WhatsApp to send messages to private phone numbers containing personal information about employees. This was a violation of the… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Controllers Sep 7, 2020
€2,000 Istituto Comprensivo Statale Crucoli Torretta: Insufficient technical and organisational measures to ensure information security Publication of personal data of students on the website of the Institute with, inter alia, notes about health and progress in school due to technical failure. ITALY ·Garante ·Art. 5, 32 Education Healthcare Security Sep 7, 2020
GBP 130,000 ICO - CPS Advisory Limited CPS Advisory Limited (CPSAL) conducted direct marketing calls in relation to personal pensions. The data CPSAL used to conduct the calls had been purchased from third party data… United Kingdom ·UK ·Art. 55A Direct Marketing Consent Marketing Sep 4, 2020
€2,000 Comune di Casaloldo: Insufficient legal basis for data processing Publication of personal data on the website of the community. ITALY ·Garante ·Art. 5, 6 Personal Data Education Processing Sep 3, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Education Security Sep 3, 2020
€75,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing According to the supervisory authority, the company processed personal data without sufficient legal basis, with the result that the data subject received several hundred… SPAIN ·aepd ·Art. 5, 6 Personal Data Telecommunications Processing Sep 1, 2020
€500 Apartment building owners association: Insufficient legal basis for data processing Export of a still image from a video surveillance system and posting of the image on the billboard of the building without sufficient legal basis. In addition, violation of the… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +3 Video Surveillance Personal Data Monitoring Sep 1, 2020
DSB (Austria) - 2020-0.303.727 In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that website contained wrong statements about her.… 2020-0.303.727 ·Art. 17, 85 Right to be Forgotten Personal Data Controllers Sep 1, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The complainant, through her attorney, requested access to her personal data. The accused failed to respond, even… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Supervisory Authorities Human Resources Aug 31, 2020
€22,700 Surveyor General of Poland ('GKK'): Insufficient legal basis for data processing Processing of personal data on the GEOPORTAL2 platform in the form of land and mortgage registers (including names, surnames and other personal data) without sufficient legal… UODO ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Education Processing Aug 31, 2020
€5,000 Basketball Federation of Castilla and Leon: Insufficient legal basis for data processing The Basketball Association transmitted personal data to third parties, which were subsequently published on the Internet without consent of the data subjects. In addition, the… SPAIN ·aepd ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Professional Secrecy Aug 28, 2020
€50,000 Bankia S.A.: Non-compliance with general data processing principles The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this… SPAIN ·aepd ·Art. 5 Personal Data Insurance IP Address Aug 28, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. Despite the objection raised by the data subject (the owner of the industrial rights) against the processing and… CZECH REPUBLIC ·UOOU ·Art. 12 Right to Object Personal Data Processing Aug 28, 2020
€65,000 Cork University Maternity Hospital: Insufficient technical and organisational measures to ensure information security The „Data Protection Authority of Ireland“ imposed a fine on Cork University Maternity Hospital (CUMH) after the personal data of 78 patients was discovered disposed of in a… IRELAND ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Health Data Healthcare Aug 18, 2020
€56 Health care worker: Insufficient legal basis for data processing Acess to personal data in a health database for private research activities. ESTONIA ·AKI ·Art. 5, 6 Scientific Research Healthcare Health Data Aug 17, 2020
€48 Police Officer: Insufficient legal basis for data processing Acess to personal data in a police database for private research activities. ESTONIA ·AKI ·Art. 5, 6 Scientific Research Personal Data Processing Aug 17, 2020
€5,000 Party of the Socialists of Catalonia: Non-compliance with general data processing principles The Socialist Party of Catalonia has used the personal data provided by a professional doctor to send a letter to the complainant's relative asking for political support. This… SPAIN ·aepd ·Art. 5 Personal Data IP Address Education Aug 17, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Data Breaches Security Aug 12, 2020
€10,000 Cavauto S.R.L.: Insufficient legal basis for data processing Access to personal data of a former employee (containing his browser history) on his work computer. ITALY ·Garante ·Art. 5, 6, 7 Right of Access Personal Data Processing Aug 10, 2020
€10,000 Community of Baronissi: Insufficient legal basis for data processing The community published on its website personal data of data subjects including names, birth dates, place of birth, place of residence, etc. ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Aug 10, 2020
€3,000 GTL S.R.L.: Insufficient fulfilment of data subjects rights Failure to graint access to personal data of a data subject according to Art. 15 GDPR. ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Supervisory Authorities Aug 6, 2020
€3,000 Just Landed S.L.: Insufficient fulfilment of information obligations Just Landed was fined with EUR 3000 for insufficient cookie information according to national data protection laws and at the same time warned due to insufficient fulfilment of… SPAIN ·aepd ·Art. 13 Supervisory Authorities Aug 6, 2020
€3,000 GROW BEATS SL: Insufficient fulfilment of information obligations The company had published a cookie policy on its website, which on the one hand contained no information about the purpose of the use of cookies and on the other hand no… SPAIN ·aepd ·Art. 12, 13, 14 Cookies IP Address Law Enforcement Aug 6, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Installation of CCTV surveillance cameras that were also monitoring the public space and without proper information. SPAIN ·aepd ·Art. 5, 12, 13 Video Surveillance Monitoring Audit Logs Aug 5, 2020
€2,000 School: Insufficient legal basis for data processing Placing personal data of pupils on a public notice board. ITALY ·Garante ·Art. 5, 6 Education Personal Data Processing Aug 5, 2020
€7,000 Acc Consulting Varsinais-Suomi: Insufficient legal basis for data processing Unsolicited marketing SMS without prior consent FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6 Direct Marketing Consent Insurance Aug 5, 2020
€100 Bank: Insufficient legal basis for data processing A bank employee made a copy of the identity card of a bank client who wanted to exchange EUR 100 in foreign currency and justified this with money laundering charges. However,… AUSTRIA ·dsb ·Art. 5, 6 Insurance Processing Supervisory Authorities Aug 5, 2020
€250,000 Spartoo: Non-compliance with general data processing principles A fine of EUR 250000 was imposed on the online retailer Spartoo. The reason for this was that the company, which has its headquarters in France but supplies a large number of… FRANCE ·CNIL ·Art. 5, 13, 14 IP Address Encryption Personal Data Aug 5, 2020
€60,000 Vodafone España, SAU: Insufficient legal basis for data processing The data subject received confirmation from Vodafone of a number porting, which the latter had never commissioned. SPAIN ·aepd ·Art. 5, 6 Personal Data Telecommunications Processing Aug 4, 2020
€15,000 Mapei S.p.A.: Insufficient legal basis for data processing The company had left the e-mail account of the data subject active even after the termination of his employment and had automatically forwarded incoming e-mails. The company did… ITALY ·Garante ·Art. 5, 6, 12 +3 Personal Data Processing Employees Aug 4, 2020
€5,000 National Institute for Social Security - Department of the Province of Brescia: Insufficient fulfilment of data subjects rights Failure to graint access to personal health data of a data subject according to Art. 15 GDPR. ITALY ·Garante ·Art. 15 Healthcare Health Data Personal Data Aug 4, 2020
€1,000 Supermarket: Insufficient legal basis for data processing The operator of a supermarket displayed the letter of dismissal to the personnel manager on the publicly visible notice board of the supermarket. ITALY ·Garante ·Art. 5, 6 Processing Human Resources Supervisory Authorities Aug 4, 2020
€20,100 PrivatBo A.M.B.A.: Insufficient technical and organisational measures to ensure information security The company had distributed USB sticks to tenants in the context of a sale of real estate, which contained not only non-personal information on the real estate objects in question… DENMARK ·Datatilsynet ·Art. 5, 32 Security Personal Data Supervisory Authorities Aug 4, 2020
€3,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The data subject received telephone calls regarding a candidacy for parliamentary elections. When the data subject made use of its right to access according to Art. 15 GDPR, it… GREECE ·HDPA ·Art. 15 Personal Data Education Data Subject Rights Exercise Modalities and Procedures Aug 3, 2020
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. Following the delivery of the goods with the invoice, the accused did not respond to the request of the OA for… CZECH REPUBLIC ·UOOU ·Art. 15 Right of Access Personal Data Supervisory Authorities Aug 3, 2020
€1,500 Tour & People Max S.L.: Insufficient fulfilment of data subjects rights Unsolicited marketing calls though data subjects had expressed their objection to data processing. In addition to the GDPR, this was also seen as a violation of Article 48(1)(b)… SPAIN ·aepd ·Art. 21 Right to Object Direct Marketing Personal Data Jul 31, 2020
€45,000 Vodafone España SAU: Insufficient legal basis for data processing Unlawfull processing of a telephone number for marketing purposes even after the data subject had exercised its right to erasure SPAIN ·aepd ·Art. 5, 6 Right to be Forgotten Personal Data Direct Marketing Jul 31, 2020
€2,000 Romanian Post National Company: Insufficient technical and organisational measures to ensure information security Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and… ROMANIA ·ANSPDCP ·Art. 32 Controllers Anonymization Personal Data Jul 30, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Insurance Processing Jul 30, 2020
€2,000 Community of Manduria: Insufficient legal basis for data processing The community transmitted personal data of a community employee to the press without sufficient legal basis. ITALY ·Garante ·Art. 5, 6 Personal Data Employees Processing Jul 30, 2020
HDPA (Greece) - 23/2020 The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Art. 4, 5, 12 +6 Personal Data Controllers Processors Jul 30, 2020
€3,000 Community of San Giorgio Jonico: Insufficient legal basis for data processing Publication of personal data on the municipal website with regard to legal proceedings. ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Jul 29, 2020
€4,000 Region of Campania: Insufficient legal basis for data processing Publication of an enforcement order in civil proceedings on the Region's website. The document listed the names and place of residence and the amount of the claim. ITALY ·Garante ·Art. 5, 6 Education Public Authority Processing Jul 29, 2020
€3,000 Communal political association: Insufficient legal basis for data processing A local political association has sent out election advertisements to the residents of the municipality for the local elections in 2018. For this purpose, the association used the… BELGIUM ·APD ·Art. 5, 6, 14 IP Address Education Public Authority Jul 28, 2020
€147,800 Arp Hansen Hotel Group A/S: Non-compliance with general data processing principles During an inspection, the supervisory authority reviewed a number of IT systems to examine whether Arp-Hansen had sufficient procedures in place to ensure that personal data were… DENMARK ·Datatilsynet ·Art. 5 Retention Period Personal Data IP Address Jul 28, 2020
€5,000 SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security Unauthorised disclosure of the data of five Tarom passengers due to inadequate technical and organisational measures for secure data processing. Among other things, the company… ROMANIA ·ANSPDCP ·Art. 32 Notified Body Responsibilities and Operational Obligations Security Notified Body Assessment Procedures Jul 27, 2020
€55,000 Telefónica Móviles España, SAU: Insufficient legal basis for data processing Telefónica Móviles España has processed the personal data of a data subject, such as first and last name and bank details, in order to activate three telephone lines that were… SPAIN ·aepd ·Art. 5, 6 Personal Data IP Address Telecommunications Jul 23, 2020
€1,700 Employer: Insufficient fulfilment of data subjects rights Failure to change the private address of an employee to his new address and to delete the old address as well as insufficient enabling of the employer to exercise his/her rights. HUNGARY ·NAIH ·Art. 12, 15, 17 Personal Data Employees Jul 23, 2020
€560 Forbes Hungary: Insufficient legal basis for data processing Fine imposed on Forbes Hungary for publishing a list of the 50 wealthiest Hungarians and a list of the largest family businesses without a sufficient balance of interests (Art. 6… NAIH ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Telecommunications Jul 23, 2020