Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3351–3400 of 3,446 sort newestlargest fineoldest
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS ·AP ·Art. 32 Access Controls Security Health Data Oct 31, 2019
€6,000 Jocker Premium Invex: Insufficient legal basis for data processing After registering for a local census, Jocker Premium Invex had sent the applicant postal advertisements and commercial offers, although data such as first name, surname and postal… SPAIN ·aepd ·Art. 6 Processing Public Authority Public Sector Oct 31, 2019
Deutsche Wohnen SE: Non-compliance with general data processing principles In addition to sanctioning violations of privacy by design principles (Art. 5 GDPR, Art. 25 GDPR - see separate entry), the Berlin data protection commissioner imposed further… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Privacy by Default Privacy by Design Fines Oct 30, 2019
€16M Austrian Post: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 16,000,000 on the Austrian Post. The controller had sold information regarding the political affinity to third parties without a… AUSTRIA ·dsb ·Art. 5, 6 Controllers Processing Agreement Processing Oct 29, 2019
€36,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The claimant, whose data had been provided to the company by his daughter, as authorised by him, received a call from the company offering its services, which he refused. However,… SPAIN ·aepd ·Art. 5, 6 Personal Data Consent Telecommunications Oct 25, 2019
€100,000 Food company: Insufficient technical and organisational measures to ensure information security The company had set up an applicant portal on its website where interested parties could submit their application documents online. However, the company did not offer an encrypted… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Inspection Access Rights and Cooperation Obligations Oct 24, 2019
€60,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles Vodafone sent an invoice history to the subscriber as part of the invoice complaint by the subscriber. The history also contained invoice data of an unknown third party. SPAIN ·aepd ·Art. 5 Telecommunications IP Address Processing Oct 23, 2019
€20,000 Wind Hellas Telecommunications: Insufficient fulfilment of data subjects rights Among other things, the company has ignored objections raised by affected parties against advertising calls. GREECE ·HDPA ·Art. 21 Right to Object Telecommunications Direct Marketing Oct 18, 2019
€2,500 UTTIS INDUSTRIES SRL: Insufficient fulfilment of information obligations The sanctions were applied to the controller because he could not prove that the data subjects were informed about the processing of personal data / images through the video… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Video Surveillance Personal Data Controllers Oct 17, 2019
€8,000 Iberdrola Clientes: Insufficient cooperation with supervisory authority Iberdrola Clientes, an electricity company, had refused to make a request to a person to change its electricity supplier because it claimed that its data would be included in the… SPAIN ·aepd ·Art. 31 Supervision Supervisory Authorities Oct 16, 2019
€60,000 Xfera Moviles S.A.: Insufficient legal basis for data processing Xfera Movile has used personal data without a legal basis for the conclusion of a telephone contract and has continued to process personal data even when the data subject… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Oct 16, 2019
€15,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security Original fine summary: Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Personal Data Oct 9, 2019
€20,000 Vreau Credit SRL: Insufficient technical and organisational measures to ensure information security Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the platform's staff via… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Insurance Personal Data Oct 9, 2019
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not meet the objection of two data subjects to the processing of their personal data for direct… CZECH REPUBLIC ·UOOU ·Art. 21 Right to Object Personal Data Marketing Oct 8, 2019
€200,000 Telecommunication Service Provider: Non-compliance with general data processing principles Inappropriate technical measures resulted in the data of 8,000 customers not being deleted upon request. GREECE ·HDPA ·Art. 21, 25 Telecommunications IP Address Privacy by Design & Default Oct 7, 2019
€200,000 Telecommunication Service Provider: Non-compliance with general data processing principles A large number of customers were subject to telemarketing calls, although they had declared an opt-out for this. This was ignored due to technical errors. GREECE ·HDPA ·Art. 5, 25 Direct Marketing Telecommunications IP Address Oct 7, 2019
€511 B.D.: Insufficient cooperation with supervisory authority The fine of EUR 511 was imposed on B.D. for failure to provide access to information which the Commission for Personal Data Protection needed for performance of its tasks and… BULGARIA ·KZLD ·Art. 31 Supervision Supervisory Authorities Personal Data Oct 7, 2019
€2,000 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused circumvented the law when, instead of providing social services with proper authorization, it did so… CZECH REPUBLIC ·UOOU ·Art. 5, 12, 30 Personal Data Healthcare Processing Oct 4, 2019
€30,000 Vueling Airlines: Insufficient legal basis for data processing The Spanish Data Protection Agency (AEPD) has sanctioned Vueling Airlines with 30,000 euros for not giving users the ability to refuse their cookies and force them to use them if… SPAIN ·aepd ·Art. 5, 6 Cookies Processing Supervisory Authorities Oct 1, 2019
€9,000 Inteligo Media SA: Insufficient legal basis for data processing As part of the registration process on the webseite avocatnet.ro, the operator used an unfilled checkbox, by means of which users could declare that they did not wish to receive… ROMANIA ·ANSPDCP ·Art. 5, 6 Consent Right to Object Telecommunications Sep 26, 2019
€195,407 Delivery Hero: Insufficient fulfilment of data subjects rights According to the findings of the Berlin data protection officer, Delivery Hero Germany GmbH had not deleted accounts of former customers in ten cases, even though those data… GERMANY ·Art. 15, 17, 21 ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Healthcare Sep 19, 2019
€10,000 Merchant: Non-compliance with general data processing principles The Belgian data protection authority has imposed a fine of 10,000 euros on a merchant who wanted to use an electronic identity card (eID) to create a customer card. The DPA's… BELGIUM ·APD ·Art. 5 Personal Data IP Address Right of Access Sep 17, 2019
€660,000 Morele.net: Insufficient technical and organisational measures to ensure information security The Polish data protection authority imposed a fine of over PLN 2.8 million (approx. €644,780) on Morele.net for insufficient organisational and technical safeguards, which led to… POLAND ·UODO ·Art. 32 Security Law Enforcement Personal Data Sep 10, 2019
CNPD (Portugal) - Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Art. 2, 3, 5 +8 Controllers Personal Data Processing Sep 3, 2019
€18,630 School in Skellefteå: Insufficient legal basis for data processing A school in Skellefteå made a trial to use facial recognition technology. The fine was imposed against the school which had used facial recognition technology to monitor the… SWEDEN ·Art. 5, 9, 35 +1 ·Insufficient legal basis for data processing Biometric Data Biometric Data Monitoring Aug 20, 2019
€60,000 AVON COSMETICS: Insufficient legal basis for data processing A consumer claimed that AVON COSMETICS had unlawfully processed his data without adequately verifying his identity, which led to his data being erroneously entered in a register… SPAIN ·aepd ·Art. 6 Personal Data Processing Supervisory Authorities Aug 16, 2019
€200 Private person (YouTube-Channel): Insufficient legal basis for data processing The private person used a dashcam to make recordings of public road traffic and then published them on YouTube as a compilation. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Supervisory Authorities Aug 5, 2019
€25,000 Company in the medical sector: Insufficient fulfilment of information obligations The (none-final) fine was imposed on a company in the medical sector for non-compliance with information obligations and for not appointing a data protection officer. Update: The… AUSTRIA ·dsb ·Art. 13, 35, 37 Healthcare Healthcare Supervisory Authorities Aug 1, 2019
€150,000 PWC Business Solutions: Insufficient legal basis for data processing The processing of employee personal data was based on consent. The HDPA found that consent as legal basis was inappropriate, as the processing of personal data was intended to… GREECE ·HDPA ·Art. 5, 6, 13 +1 Legitimate Interest Fairness & Transparency Personal Data Jul 30, 2019
€180,000 ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had… FRANCE ·CNIL ·Art. 32 Insurance Integrity and Confidentiality Principle Data Breaches Jul 25, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 5, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA ·ANSPDCP ·Art. 32 Security Healthcare Personal Data Jul 2, 2019
€11,000 Private person (soccer coach): Insufficient legal basis for data processing The fine was imposed on a soccer coach who had secretly filmed female players while they were naked in the shower cubicle for years. AUSTRIA ·dsb ·Art. 6 Processing Supervisory Authorities Jul 1, 2019
€130,000 UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations,… ROMANIA ·ANSPDCP ·Art. 5, 25 Security Insurance Personal Data Jun 27, 2019
€2,850 HUNGARY DPA: Insufficient legal basis for data processing The individual requested the deletion of his contact data (including his telephone number), however the controller further processed his contact data for claim enforcement… NAIH ·Art. 5, 6, 17 ·Insufficient legal basis for data processing Legitimate Interest Controllers Personal Data Jun 26, 2019
€15,150 HUNGARY DPA: Insufficient fulfilment of data breach notification obligations The data controller did not fulfil its data breach notification obligations when a flash memory with personal data was lost. NAIH ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 25, 2019
€350,000 Haga Hospital: Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data… THE NETHERLANDS ·AP ·Art. 32 Healthcare Health Data Healthcare Jun 18, 2019
€20,000 Employer UNIONTRAD COMPANY: Insufficient legal basis for data processing Between 2013 and 2017, the CNIL received complaints from several employees of the company who were filmed at their workstation. On two occasions, it alerted the company to the… FRANCE ·CNIL ·Art. 5, 12, 13 +1 Video Surveillance Employees Processing Jun 13, 2019
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not comply with the data subject's request to delete the personal data from its website, even after… CZECH REPUBLIC ·UOOU ·Art. 17 Personal Data Processing Agreement Supervisory Authorities Jun 12, 2019
€250,000 Professional Football League (LaLiga): Insufficient fulfilment of information obligations The national Football League (LaLiga) was fined for offering an app which once per minute accessed the microphone of users' mobile phones in order to detect pubs screening… SPAIN ·aepd ·Art. 5, 7 Consent Supervisory Authorities Jun 11, 2019
€2,000 Mayor: Insufficient legal basis for data processing The administrative fine was imposed for the misuse of personal data by a mayor for campaign purposes. BELGIUM ·APD ·Art. 5, 6 Education Personal Data Public Authority May 28, 2019
€400,000 SERGIC (Real Estate): Insufficient technical and organisational measures to ensure information security The CNIL based the penalty on two grounds: Lack of basic security measures and excessive data storage. As to the first, sensitive user documents uploaded by rental candidates… FRANCE ·CNIL ·Art. 5 Security Access Controls Healthcare May 28, 2019
€61,500 Payment service provider UAB MisterTango: Insufficient fulfilment of data breach notification obligations During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a… LITHUANIA ·VDAI ·Art. 5, 32, 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction May 16, 2019
€1,400 Police Officer: Insufficient legal basis for data processing The police officer, using his official user ID but without reference to official duties, queried the owner data concerning the license plate of a person who he did not know well… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Public Authority Personal Data Processing May 9, 2019
€194 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights Information was not provided. UOOU ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Processing Agreement May 6, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet ·Art. 32 Security Education Right of Access Apr 29, 2019
€12,950 Sports association: Insufficient legal basis for data processing One sports association published personal data referring to judges who were granted judicial licenses online. However, not only their names were provided, but also their exact… POLAND ·UODO ·Art. 6 Personal Data Liability Controllers Apr 25, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Garante ·Art. 32 Controllers Processors Data Breaches Apr 17, 2019
€9,400 HUNGARY DPA: Insufficient legal basis for data processing A data controller used a, in the point of view of NAIH, wrong legal basis for processing of personal data (Art. 6.1.b) for the assignment of claims. NAIH ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing Apr 17, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Professional Secrecy Anonymization Apr 12, 2019