Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3251–3300 of 3,446 sort newestlargest fineoldest
€60,000 Xfera Moviles S.A.: Insufficient legal basis for data processing According to the data protection authority, XFERA MOVILES has violated Article 6(1) of the GDPR, as the company has unlawfully processed data, including bank details, customer… SPAIN ·aepd ·Art. 5, 6 Personal Data Telecommunications Processing Feb 3, 2020
€5,000 Queseria Artesenal Ameco S.L.: Insufficient legal basis for data processing The company processed personal data of customers without required consent. SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Consent Feb 3, 2020
€20,000 Iberia Lineas Aereas de Espana, S.A. Operadora Unipersonal: Insufficient legal basis for data processing Iberia continued to send e-mails to the data subject, despite the data subject had requested the withdrawal of his consent and the erasure of his personal data and that the… SPAIN ·aepd ·Art. 5, 6, 21 Personal Data IP Address Consent Feb 3, 2020
€800 Automoción: Insufficient legal basis for data processing An employee created a fake profile about a female colleague on an erotic portal, which contained, among other things, her contact details, a photo of her and information about her… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Supervisory Authorities Feb 3, 2020
€4,000 Comune di Colledara: Insufficient legal basis for data processing Publication of documents relating to a public tender with personal data on a website ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Jan 30, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Jan 23, 2020
€30,000 Sapienza Università di Roma: Insufficient technical and organisational measures to ensure information security The fine is based on the fact that, according to the data protection authority, the Sapienza Università made available online identification data of two people who had reported… ITALY ·Garante ·Art. 5, 32 Security Education Access Controls Jan 23, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Garante ·Art. 5, 6, 17 +2 Telecommunications Integrity and Confidentiality Principle Direct Marketing Jan 15, 2020
€10,000 Community of Francavilla Fontana: Insufficient legal basis for data processing The community published on its website information about a court trial, including personal data such as health data about a data subject. ITALY ·Garante ·Art. 5, 6 Healthcare Health Data Personal Data Jan 15, 2020
€3,600 Zhang Bordeta 2006, S.L. (Store and Restaurant): Non-compliance with general data processing principles The store and restaurant owner installed a video surveillance system which, among others, also took pictures of the sidewalk and thus of the public space, which violates the… SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Jan 14, 2020
€15,000 Allseas Marine S.A.: Non-compliance with general data processing principles The data protection supervisory authority has fined the extent to which employee data are processed by a video surveillance system in the workplace, the fact that the introduction… GREECE ·HDPA ·Art. 5 Video Surveillance Monitoring Employees Jan 13, 2020
€3,000 Vodafone España, S.A.U.: Insufficient cooperation with supervisory authority Failure to provide information to the AEPD within the required timeframe in violation of Article 58 SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Telecommunications Jan 9, 2020
€10,000 Asociación de Médicos Demócratas: Insufficient legal basis for data processing The Asociación de Médicos Demócratas has processed personal data of its members, despite having been warned by the AEPD that it carried out the processing without the consent of… SPAIN ·aepd ·Art. 6 Healthcare Consent Personal Data Jan 7, 2020
€44,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The company had sent a contract with personal data, including the applicant's name, address and telephone number, to the wrong recipient. SPAIN ·aepd ·Art. 5 Recipient Personal Data IP Address Jan 7, 2020
€75,000 EDP Comercializadora, S.A.U.: Insufficient legal basis for data processing The company processed personal data in connection with a gas contract without the consent of the applicant. The decision finds that the applicant received an invoice for a gas… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Jan 7, 2020
€75,000 EDP España S.A.U.: Insufficient legal basis for data processing The company processed personal data such as first and last name, tax number, address and mobile phone number without the consent of the data subject SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Jan 7, 2020
Police officer: Insufficient legal basis for data processing Several cases in which police officers have accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC ·UOOU ·Art. 24, 32 Healthcare Health Data Security Jan 1, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5 ·Insufficient legal basis for data processing Employees Processing Processing Agreement Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€300 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€2,700 Mall.tv: Insufficient legal basis for data processing The Czech DPA (UOOU) fined Mall.tv EUR 2,700 for recording parts of the public space without a legal basis. The subject of the DPA's investigation was the operation of two cameras… CZECH REPUBLIC ·UOOU ·Art. 5, 6 Telecommunications Processing Identification Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
€19,200 CZECH REPUBLIC DPA: Non-compliance with general data processing principles A company copied personal data from public registers, which was considered illegal by the Czech DPA, as it was not deemed necessary. UOOU ·Art. 5, 6, 12 +8 ·Non-compliance with general data processing principles Personal Data IP Address Processing Agreement Jan 1, 2020
€7,000 GERMANY DPA: Insufficient cooperation with supervisory authority The Bavarian DPA has imposed a fine on a company. The controller had refused access to the business premises and data processing equipment during an on-site inspection carried out… Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Inspection Access Rights and Cooperation Obligations Jan 1, 2020
€4,100 LIECHTENSTEIN DPA: Non-compliance with general data processing principles Unlawful operation of a video surveillance system. Non-compliance with general data processing principles Video Surveillance Monitoring Supervisory Authorities Jan 1, 2020
€1,900 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights A person had received an invoice for ordered goods, which, however, came from a different company than the one from which she had ordered the goods. Therefore, the data subject… UOOU ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Data Controller Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers IP Address Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·Art. 6, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Processing Agreement Jan 1, 2020
€10,000 Clearview AI Inc.: Insufficient cooperation with supervisory authority The DPA from Hamburg has fined Clearview AI Inc. EUR 10,000 for failing to provide information requested by the DPA during an investigation. GERMANY ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Jan 1, 2020
Ski rental company: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 5, 6, 7 +9 IP Address Controllers Personal Data Jan 1, 2020
Corporation: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. GERMANY ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Jan 1, 2020
Medical assistant: Insufficient legal basis for data processing A medical assistant at a doctor's office stored a patient's telephone number in her mobile phone and then contacted him for private purposes. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Healthcare Processing Supervisory Authorities Jan 1, 2020
Operator of a ballet school: Insufficient legal basis for data processing The operator of a ballet school had published photos of underage students on their website and Facebook page without the consent of the legal guardians. GERMANY ·Art. 5, 6, 7 ·Insufficient legal basis for data processing Social Media Consent Education Jan 1, 2020
€400 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€10,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jan 1, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·Art. 26 ·Insufficient data processing agreement Processing Agreement IP Address Data Processor Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Fairness & Transparency Personal Data Controllers Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers IP Address Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security Accidental loss of personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Processing Agreement Jan 1, 2020
€8,000 LITHUANIA DPA: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) fined a company EUR 8,000 for conducting sound recordings on public transport buses in violation of Article 5 GDPR, Article 13 GDPR, Article 24 GDPR and… VDAI ·Art. 5, 13, 24 +1 ·Non-compliance with general data processing principles DPIA Privacy Impact Assessment IP Address Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2020
CZECH REPUBLIC DPA: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Agreement Processing Jan 1, 2020