Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3301–3350 of 3,446 sort newestlargest fineoldest
€300 Employee at a Covid 19 testing center: Non-compliance with general data processing principles An employee at a Covid 19 testing center used the data of a tested person to contact them via WhatsApp for private purposes. GERMANY ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Supervisory Authorities Jan 1, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Controllers Fairness & Transparency Personal Data Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
€2,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security A third party has gained unauthorized access to another person's account. Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Security Jan 1, 2020
€150,000 Aegean Marine Petroleum Network Inc.: Insufficient technical and organisational measures to ensure information security Companies outside the Aegean Marine Petroleum Group had access to its servers containing personal data and copied the contents of the servers, since Aegean Marine Petroleum failed… GREECE ·HDPA ·Art. 5, 6, 32 Security Privacy by Design & Default Processing Agreement Dec 19, 2019
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Telecommunications Security Dec 18, 2019
DSB (Austria) - D123.768/0004-DSB/2019 The complainant belongs to a political party and is a member of the city council of an Austrian municipality. In November, the municipality held a meeting on the "parking space… DSB-D123.768/0004-DSB/201 ·Art. 4, 85 Personal Data Legitimate Interest Social Media Dec 18, 2019
€2,000 Nursing Care Organisation: Insufficient fulfilment of data subjects rights The company failed to act on requests from the data subject to get access to his data and to have his data erased. BELGIUM ·APD ·Art. 12, 15, 17 Personal Data Supervisory Authorities Law Enforcement Dec 17, 2019
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM ·APD ·Art. 6, 12, 13 Personal Data Fairness & Transparency IP Address Dec 17, 2019
€6,000 SC Enel Energie S.A. (Electricity Distributor): Insufficient legal basis for data processing The sanctions were imposed following a complaint alleging that Enel Energie had unlawfully processed an individual's personal data and was unable to prove that it had obtained the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Right to Object Fines Personal Data Dec 16, 2019
€35,000 Nusvar AB: Insufficient legal basis for data processing Nusvar AB, operator of the website Mrkoll.se, which provides information on all Swedes over 16 years of age, had published information on people who are overdue. SWEDEN ·Art. 6 ·Insufficient legal basis for data processing Processing Supervisory Authorities Dec 16, 2019
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Dec 16, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company has excessively processed the personal data of his employees through the video cameras installed in the offices and in the places where there are cabinets where the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 IP Address Employees Personal Data Dec 13, 2019
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused provided the data subject with access to their personal data only after being requested to do so by… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Supervisory Authorities Processing Agreement Dec 13, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company processed biometric data (fingerprints) of the employees for access to certain rooms tough less intrusive means for the privacy of the data subjects could be used… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Special Categories of Data Employees Types of Special Categories of Personal Data Dec 13, 2019
€8.5M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6, 17 +1 Fines Integrity and Confidentiality Principle Personal Data Dec 11, 2019
€3M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6 Fines Integrity and Confidentiality Principle Personal Data Dec 11, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Fines Security Dec 10, 2019
€5,000 Shop Macoyn, S.L.: Insufficient technical and organisational measures to ensure information security The company has sent advertising e-mails to several recipients where the e-mail addresses of all other recipients were visible to all recipients, because the recipient addresses… SPAIN ·aepd ·Art. 32 Recipient IP Address Direct Marketing Dec 10, 2019
€1,600 Megastar SL: Non-compliance with general data processing principles The company operated a video surveillance system in which the observation angle of the cameras extended unnecessarily far into the public traffic area. Furthermore, no sign with… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Monitoring IP Address Dec 10, 2019
€10,000 Rapidata GmbH: Insufficient involvement of data protection officer Despite repeated requests of the BfDI the company (an internet provider) did not comply with its legal obligation under Article 37 GDPR to appoint a data protection officer. GERMANY ·BfDI ·Art. 37 Telecommunications Supervisory Authorities Dec 9, 2019
€20,000 S CNTAR TAROM SA (Airline): Insufficient technical and organisational measures to ensure information security The Romanian data protection authority imposed a sanction on an airline because it has not taken appropriate measures to ensure that any natural person acting under its… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Dec 4, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2019
€5,000 Linea Directa Aseguradora: Insufficient legal basis for data processing The insurance company has sent advertising e-mails for the 'Reto Nuez' platform without the required consent. SPAIN ·aepd ·Art. 6 Insurance Direct Marketing Consent Dec 3, 2019
€1,500 Cerrajeria Verin S.L.: Insufficient fulfilment of information obligations The company collected personal data without providing accurate information on their data processing activities in their privacy policy published on their website. SPAIN ·aepd ·Art. 13 Personal Data Processing Supervisory Authorities Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Healthcare Dec 2, 2019
€2,500 Royal President S.R.L.: Insufficient fulfilment of data subjects rights Royal President refused a request for access to personal data pursuant to Article 15 of the GDPR and disclosed personal data without the consent of the data subjects. In addition,… ROMANIA ·ANSPDCP ·Art. 6, 15, 32 Right of Access Personal Data Security Nov 29, 2019
€500 Homeowners Association: Insufficient technical and organisational measures to ensure information security The association used video surveillance systems without proper information according to Art. 13 GDPR and without adequate security measures regarding the persons having access to… ROMANIA ·ANSPDCP ·Art. 32 Video Surveillance Security Monitoring Nov 29, 2019
€75,000 Curenergía Comercializador de último recurso: Insufficient legal basis for data processing An individual filed a complaint against the company alleging that the company had used its personal data as a former customer, such as first and last name, VAT identification… SPAIN ·aepd ·Art. 6 Personal Data Processing Identification Nov 28, 2019
€5,000 Municipal alderman: Insufficient legal basis for data processing Fine for sending election mailings without a sufficient legal basis. The e-mail addresses used have not been collected for this purpose. BELGIUM ·APD ·Art. 6 Education IP Address Public Authority Nov 28, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Personal Data Nov 28, 2019
€5,000 Mayor: Insufficient legal basis for data processing Fine for sending election mailings without a sufficient legal basis. The e-mail addresses used have not been collected for this purpose. BELGIUM ·APD ·Art. 6 Education Public Authority Processing Nov 28, 2019
€3,000 Modern Barber: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Nov 26, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA ·ANSPDCP ·Art. 32 Right of Access Security Controllers Nov 25, 2019
€2,000 BNP Paribas Personal Finance S.A.: Insufficient fulfilment of data subjects rights BNP Paribas Personal Finance did not react to a request for erasure within the period set by the GDPR. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Insurance Processing Nov 22, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE ·CNIL ·Art. 5, 6, 13 +4 Personal Data Healthcare Processing Nov 21, 2019
€60,000 Viaqua Xestión Integral Augas de Galicia: Insufficient legal basis for data processing Processing (modification) of the personal data of a customer included in a contract by a third party without the consent of the customer. SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Nov 21, 2019
€60,000 Corporación radiotelevisión espanola: Insufficient technical and organisational measures to ensure information security CORPORACIÓN RADIOTELEVISIÓN ESPAÑOLA and the trade union have reported a security breach to the AEPD after six unencrypted USB sticks containing personal data were lost. The… SPAIN ·aepd ·Art. 32 Encryption Healthcare Criminal Data Nov 19, 2019
€6,000 Sports Bar: Non-compliance with general data processing principles The sports bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Nov 19, 2019
€60,000 Xfera Moviles S.A.: Insufficient technical and organisational measures to ensure information security An individual complainant had received an SMS from Xfera Móviles which was to be addressed to a third party and which allowed him to access the account and personal data of this… SPAIN ·aepd ·Art. 32 Telecommunications Security Personal Data Nov 19, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN ·aepd ·Art. 5 Accuracy IP Address Telecommunications Nov 14, 2019
€3,000 General Confederation of Labour ('CGT'): Insufficient legal basis for data processing The CGT, with the aim of convening a meeting, e-mailed personal data of the complainant, including her home address, family relationship, pregnancy status and the date of an… SPAIN ·aepd ·Art. 6 Personal Data IP Address Consent Nov 13, 2019
€900 TODOTECNICOS24H S.L.: Insufficient fulfilment of information obligations TODOTECNICOS24H had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·aepd ·Art. 13 Personal Data Transparency Supervisory Authorities Nov 7, 2019
€900 Cerrajero Online: Insufficient fulfilment of information obligations The company had collected personal data without providing accurate information about data collection in its data protection declaration pursuant to Article 13 of the GDPR. SPAIN ·aepd ·Art. 13 Personal Data Transparency Supervisory Authorities Nov 6, 2019
€60,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing Vodafone has sent the customer's invoice data to unauthorised third parties following a customer invoice complaint. Originally, a fine of EUR 75,000 was threatened, but was… SPAIN ·aepd ·Art. 6 Telecommunications Processing Human Resources Nov 6, 2019
€1,770 L. Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA (UODO) imposed a fine of EUR 1,770 on L. Sp. z o.o. for the video surveillance of a residential community, which was not in compliance with the provisions of the… POLAND ·UODO ·Art. 5 Video Surveillance Monitoring IP Address Nov 1, 2019
€150,000 LATVIA DPA: Insufficient legal basis for data processing Unlawful data processing. No further information available yet. DSI ·Art. 6 ·Insufficient legal basis for data processing Processing Processing Agreement Supervisory Authorities Nov 1, 2019
€5,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Nov 1, 2019
€50,000 Menzis (Health Insurance Company): Non-compliance with general data processing principles Marketing staff had access to patient data. Among other things, this violated the purpose limitation principle. THE NETHERLANDS ·AP ·Art. 5 Insurance Health Data Healthcare Oct 31, 2019