Content type · 3,833 documents in this view · 3,838 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filter by Topic Supervisory Authorities 3612 Processing 2650 Personal Data 2423 Controllers 2035 Processing Agreement 1116 Security 1021 Supervision 865 Healthcare 623 Public Authority 573 Law Enforcement 572 Monitoring 550 Consent 509
€1,500 Private Individual: Insufficient legal basis for data processing The Belgian DPA (APD) imposed a fine against private individuals. The controllers installed video cameras on their private property, two of which were positioned in a way that… BELGIUM · ·Art. 6, 25 Nov 25, 2020
€19,500 Gnosjö Municipality: Insufficient legal basis for data processing The Swedish DPA imposed a fine on the municipality of Gnosjö for illegal video surveillance in a care home for persons with certain functional disabilities. SWEDEN · ·Art. 5, 6, 13 +2 Nov 25, 2020
€394,000 City of Stockholm: Insufficient technical and organisational measures to ensure information security The Swedish DPA imposed a fine on the City of Stockholm for data breaches on a school education platform. The platform consists of different subsystems, including a system for… SWEDEN · ·Art. 5, 32 Nov 24, 2020
€5,000 Dada Creation S.R.L.: Insufficient technical and organisational measures to ensure information security Due to inadequate technical and organizational measures, the company disclosed the order, delivery and personal data of over 1000 customers via its web store. The data was… ROMANIA · ·Art. 32, 33 Nov 24, 2020
€4,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 4,000 on Vodafone România SA. The fine was imposed as a result of complaints alleging that the operator failed to… ROMANIA · ·Art. 12, 15, 17 Nov 23, 2020
€12,000 Recambios Villalegre S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) fined the company for posting photos of a person on Facebook and WhatsApp and accusing the individual of theft in related posts. The photos were obtained… SPAIN · ·Art. 6, 13 Nov 23, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY · ·Art. 5, 13 Nov 23, 2020
€4,800 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 4,800 on a legal person. In the course of the business activities, the accused contacted business entities, owners of industrial rights,… CZECH REPUBLIC · ·Art. 6, 12 Nov 19, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Nov 19, 2020
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis. The company had sent an invoice to a data subject without being able to prove that it had a contract… SPAIN · ·Art. 5, 6 Nov 19, 2020
€800,000 Carrefour Banque: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine on Carrefour Banque for violation of its obligation to process data fairly (Article 5 (1) GDPR). If a person who subscribed to the Pass card… FRANCE · ·Art. 5 Nov 18, 2020
€2.3M Carrefour France: Non-compliance with general data processing principles The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that… ·Art. 5, 12, 13 +5 ·Non-compliance with general data processing principles Nov 18, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… ·Art. 5 ·Non-compliance with general data processing principles Nov 18, 2020
€2,000 Anmavas 61, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA (AEPD) imposed a fine on Anmavas 61, S.L. for neither granting nor justifiably denying the right to erasure to the data subject, even after receiving a warning… SPAIN · ·Art. 58 Nov 18, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY · ·Art. 9 Nov 17, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY · ·Art. 12, 13, 14 Nov 17, 2020
€1,600 Homeowners Association: Non-compliance with general data processing principles Usage of CCTV camera systems that were also monitoring public space (breach of principle of data minimization). SPAIN · ·Art. 5 Nov 16, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing In 2019, after an arbitration procedure, the company agreed to the early termination of a contract with the data subject and to the deletion of the personal data concerned.… SPAIN · ·Art. 5, 6 Nov 16, 2020
€1.4M Ticketmaster UK Limited: Insufficient technical and organisational measures to ensure information security Ticketmaster UK Limited has been fined GBP 1.25 million (approximately EUR 1.405 million) for failing to protect the personal data of its customers with adequate security… UNITED KINGDOM · ·Art. 5, 32 Nov 13, 2020
€1,500 BELGIUM DPA: Non-compliance with general data processing principles The Belgian DPA (APD/GBA) imposed a fine of EUR 1,500 on a social housing company for non-compliance with several principles of the GDPR such as data processing as well as the… ·Art. 5, 6, 12 +3 ·Non-compliance with general data processing principles Nov 13, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY · ·Art. 5, 6, 7 +7 Nov 12, 2020
€900,000 Telecoms provider (1&1 Telecom GmbH): Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's… GERMANY · ·Art. 32 Nov 11, 2020
€42,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The company ported a telephone number of the data subject without their consent (missing signature on the porting contract). SPAIN · ·Art. 5, 6 Nov 11, 2020
€3,000 Miguel Ibáñez Bezanilla, S.L.: Insufficient technical and organisational measures to ensure information security The company's website (license plate seller) requested personal information such as first and last name, copy of ID card and driver's license, and the car's VIN number, but… SPAIN · ·Art. 13, 32 Nov 10, 2020
€20,000 Xfera Moviles S.A.: Insufficient legal basis for data processing Xfera Móviles had failed to cooperate with the AEPD in the investigation of privacy violations. Xfera Móviles had neither responded to the request for information nor provided any… SPAIN · ·Art. 31 Nov 6, 2020
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Nov 5, 2020
€75,000 Telefonica Moviles Espana, S.A.U.: Insufficient legal basis for data processing Processing of personal data of the data subject without sufficient legal basis. The company had issued several invoices to the data subject and collected invoice amounts from his… SPAIN · ·Art. 5, 6 Nov 5, 2020
€30,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis due to errors in the correct assignment of customer contracts. In this case, Vodafone demanded a debt… SPAIN · ·Art. 5, 6 Nov 3, 2020
€20M Marriott International, Inc: Insufficient technical and organisational measures to ensure information security Original Summary: The ICO issued a notice of its intention to fine Marriott International Inc due to a cyber incident which was notified to the ICO by Marriott in November 2018. A… UNITED KINGDOM · ·Art. 32 Oct 30, 2020
€20,000 Gaypa s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee's email account active and had access to the data subject's… ITALY · ·Art. 5, 12, 13 Oct 29, 2020
€1,000 American College of Greece: Insufficient fulfilment of information obligations The Hellenic DPA (HDPA) imposed a fine of EUR 1,000 against the American College of Greece for violations of the right of access and the right to erasure of personal data. ·Art. 12 ·Insufficient fulfilment of information obligations Oct 29, 2020
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY · ·Art. 5, 13 Oct 29, 2020
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Processing of personal data of a data subject without sufficient legal basis due to errors in the correct assignment of customer contracts. SPAIN · ·Art. 5, 6 Oct 28, 2020
€4,000 Play Orenes, S.L.: Non-compliance with general data processing principles The company used CCTV cameras outside its premises which also captured the public space resulting in a violation of the principle of data minimisation. SPAIN · ·Art. 5 Oct 28, 2020
€50,000 Conseguridad SL: Insufficient involvement of data protection officer The company (private security company for video surveillance systems) did not have a data protection officer in breach of Art. 37 GDPR. SPAIN · ·Art. 37 Oct 26, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY · ·Art. 5, 9 Oct 26, 2020
€4,000 Organic Natur 03 S.L.: Insufficient fulfilment of information obligations Use of a membership contract containing pre-defined privacy clauses, which prevents effective negotiation and the express consent of the signing client. SPAIN · ·Art. 13 Oct 26, 2020
€200 Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Oct 24, 2020
€54,800 Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak: Insufficient fulfilment of data subjects rights The data controller denied the data subject access to the video material recorded by CCTV in a local store, with which the data subject wanted to prove that he or she had not… HUNGARY · ·Art. 12, 15, 18 +1 Oct 23, 2020
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Oct 22, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA · ·Art. 5 Oct 21, 2020
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company had not provided the ANSPDCP with requested information. ROMANIA · ·Art. 58 Oct 20, 2020
€150 Private Individual: Insufficient legal basis for data processing The private individual recorded a female person while she was using one of the WC cabins by placing a cell phone (smartphone with camera function) under the WC cabin partition… AUSTRIA · ·Art. 5, 6 Oct 19, 2020
€600 Private Individual: Insufficient legal basis for data processing Between February and June 2020, a private individual published information about patients on his personal Facebook page. The information included health data in terms of Art. 4… AUSTRIA · ·Art. 5, 9 Oct 19, 2020
€1,000 Grant Ideas Ltd: Insufficient legal basis for data processing Sending emails to data subjects without sufficient legal basis. CYPRUS · ·Art. 5, 6 Oct 19, 2020
€15,000 Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found… ·Art. 5, 15, 32 +1 ·Insufficient technical and organisational measures to ensure information security Oct 19, 2020
€22M British Airways: Insufficient technical and organisational measures to ensure information security In July 2019, the ICO issued a notice of its intention to fine British Airways £183.39M for GDPR infringements which likely involve a breach of Art. 32 GDPR. The proposed fine… UNITED KINGDOM · ·Art. 5, 32 Oct 16, 2020
€30,000 PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Spain · ·Art. 22 Oct 16, 2020
€3,000 S.C. Marsorom S.R.L.: Insufficient technical and organisational measures to ensure information security Disclosure of personal data of customers on the companies website due to inadequate technical and organisational measures to ensure information security. ROMANIA · ·Art. 32 Oct 15, 2020
€12,030 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 12,030 on a legal person. The accused did not comply with the complainant's request to erase their data. The company implemented an… CZECH REPUBLIC · ·Art. 6, 12 Oct 14, 2020