Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3401–3450 of 3,651 sort newestlargest fineoldest
€75,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The fine preceded the complaint by the data subject, who argued that Vodafone España had signed a contract for the transfer of a telephone subscription with a third party without… SPAIN ·aepd ·Art. 5, 6 IP Address Personal Data Consent Feb 3, 2020
€60,000 Xfera Moviles S.A.: Insufficient legal basis for data processing According to the data protection authority, XFERA MOVILES has violated Article 6(1) of the GDPR, as the company has unlawfully processed data, including bank details, customer… SPAIN ·aepd ·Art. 5, 6 Personal Data Processing Telecommunications Feb 3, 2020
€5,000 Queseria Artesenal Ameco S.L.: Insufficient legal basis for data processing The company processed personal data of customers without required consent. SPAIN ·aepd ·Art. 5, 6 Personal Data Consent Processing Feb 3, 2020
€20,000 Iberia Lineas Aereas de Espana, S.A. Operadora Unipersonal: Insufficient legal basis for data processing Iberia continued to send e-mails to the data subject, despite the data subject had requested the withdrawal of his consent and the erasure of his personal data and that the… SPAIN ·aepd ·Art. 5, 6, 21 Personal Data IP Address Consent Feb 3, 2020
€4,000 Comune di Colledara: Insufficient legal basis for data processing Publication of documents relating to a public tender with personal data on a website ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Jan 30, 2020
€1,450 Accounting firm: Insufficient technical and organisational measures to ensure information security A printed customer list of an accounting firm, which also contained personal data, could be accessed by unauthorized persons. HUNGARY ·NAIH ·Art. 24, 32 Security Personal Data Insurance Jan 24, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Jan 23, 2020
€30,000 Sapienza Università di Roma: Insufficient technical and organisational measures to ensure information security The fine is based on the fact that, according to the data protection authority, the Sapienza Università made available online identification data of two people who had reported… ITALY ·Garante ·Art. 5, 32 Security Access Controls Education Jan 23, 2020
€10,000 Community of Francavilla Fontana: Insufficient legal basis for data processing The community published on its website information about a court trial, including personal data such as health data about a data subject. ITALY ·Garante ·Art. 5, 6 Healthcare Health Data Personal Data Jan 15, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Garante ·Art. 5, 6, 17 +2 Integrity and Confidentiality Principle Telecommunications Direct Marketing Jan 15, 2020
€3,600 Zhang Bordeta 2006, S.L. (Store and Restaurant): Non-compliance with general data processing principles The store and restaurant owner installed a video surveillance system which, among others, also took pictures of the sidewalk and thus of the public space, which violates the… SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Jan 14, 2020
€1,000 eShop for Sports (M.L. PRO.FIT SOLUTIONS LTD): Insufficient legal basis for data processing Sending SMS marketing messages without consent. In particular, no appropriate measures were taken, such as the possibility for telephone users to block marketing messages from the… CYPRUS ·Art. 6 ·Insufficient legal basis for data processing Direct Marketing Consent Marketing Jan 13, 2020
€15,000 Allseas Marine S.A.: Non-compliance with general data processing principles The data protection supervisory authority has fined the extent to which employee data are processed by a video surveillance system in the workplace, the fact that the introduction… GREECE ·HDPA ·Art. 5 Video Surveillance Monitoring Employees Jan 13, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Right of Access Security Insurance Jan 13, 2020
€3,000 Vodafone España, S.A.U.: Insufficient cooperation with supervisory authority Failure to provide information to the AEPD within the required timeframe in violation of Article 58 SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Telecommunications Jan 9, 2020
€44,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The company had sent a contract with personal data, including the applicant's name, address and telephone number, to the wrong recipient. SPAIN ·aepd ·Art. 5 Recipient Personal Data IP Address Jan 7, 2020
€75,000 EDP Comercializadora, S.A.U.: Insufficient legal basis for data processing The company processed personal data in connection with a gas contract without the consent of the applicant. The decision finds that the applicant received an invoice for a gas… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Jan 7, 2020
€75,000 EDP España S.A.U.: Insufficient legal basis for data processing The company processed personal data such as first and last name, tax number, address and mobile phone number without the consent of the data subject SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Jan 7, 2020
€10,000 Asociación de Médicos Demócratas: Insufficient legal basis for data processing The Asociación de Médicos Demócratas has processed personal data of its members, despite having been warned by the AEPD that it carried out the processing without the consent of… SPAIN ·aepd ·Art. 6 Healthcare Consent Personal Data Jan 7, 2020
€5,110 Utility Company: Insufficient legal basis for data processing The fine of EUR ca. 5,113 was imposed on a Bulgarian utility company for unlawful processing of the personal data of the data subject V.V. The personal data of V.V. was unlawfully… BULGARIA ·KZLD ·Art. 6 Integrity and Confidentiality Principle Personal Data Processing Jan 6, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·Art. 6, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Processing Agreement Jan 1, 2020
€300 Employee at a Covid 19 testing center: Non-compliance with general data processing principles An employee at a Covid 19 testing center used the data of a tested person to contact them via WhatsApp for private purposes. GERMANY ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Supervisory Authorities Jan 1, 2020
€7,000 GERMANY DPA: Insufficient cooperation with supervisory authority The Bavarian DPA has imposed a fine on a company. The controller had refused access to the business premises and data processing equipment during an on-site inspection carried out… Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Inspection Access Rights and Cooperation Obligations Jan 1, 2020
Police officer: Insufficient legal basis for data processing Several cases in which police officers have accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
€4,100 LIECHTENSTEIN DPA: Non-compliance with general data processing principles Unlawful operation of a video surveillance system. Non-compliance with general data processing principles Video Surveillance Monitoring Supervisory Authorities Jan 1, 2020
Public university: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 6, 13 Personal Data Education Processing Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Fairness & Transparency Personal Data Controllers Jan 1, 2020
Bank: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 21, 23, 48 IP Address Insurance Processing Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Controllers Security Jan 1, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Controllers Fairness & Transparency Personal Data Jan 1, 2020
CZECH REPUBLIC DPA: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Agreement Processing Jan 1, 2020
€3,850 Television broadcaster: Insufficient fulfilment of information obligations A TV broadcaster had provided information on its website about the processing of personal data, which was however hidden and inaccurate (links to outdated legal provisions). CZECH REPUBLIC ·UOOU ·Art. 12 Personal Data Accuracy Telecommunications Jan 1, 2020
€19,200 CZECH REPUBLIC DPA: Non-compliance with general data processing principles A company copied personal data from public registers, which was considered illegal by the Czech DPA, as it was not deemed necessary. UOOU ·Art. 5, 6, 12 +8 ·Non-compliance with general data processing principles Personal Data IP Address Processing Agreement Jan 1, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5 ·Insufficient legal basis for data processing Employees Processing Processing Agreement Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
€400 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€300 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
Operator of a ballet school: Insufficient legal basis for data processing The operator of a ballet school had published photos of underage students on their website and Facebook page without the consent of the legal guardians. GERMANY ·Art. 5, 6, 7 ·Insufficient legal basis for data processing Education Social Media Consent Jan 1, 2020
€2,700 Mall.tv: Insufficient legal basis for data processing The Czech DPA (UOOU) fined Mall.tv EUR 2,700 for recording parts of the public space without a legal basis. The subject of the DPA's investigation was the operation of two cameras… CZECH REPUBLIC ·UOOU ·Art. 5, 6 Telecommunications Processing Identification Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC ·UOOU ·Art. 24, 32 Healthcare Health Data Security Jan 1, 2020
Medical assistant: Insufficient legal basis for data processing A medical assistant at a doctor's office stored a patient's telephone number in her mobile phone and then contacted him for private purposes. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Healthcare Processing Supervisory Authorities Jan 1, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·Art. 26 ·Insufficient data processing agreement Processing Agreement IP Address Data Processor Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Supervisory Authorities Jan 1, 2020
€1,900 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights A person had received an invoice for ordered goods, which, however, came from a different company than the one from which she had ordered the goods. Therefore, the data subject… UOOU ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Data Controller Jan 1, 2020
€8,000 LITHUANIA DPA: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) fined a company EUR 8,000 for conducting sound recordings on public transport buses in violation of Article 5 GDPR, Article 13 GDPR, Article 24 GDPR and… VDAI ·Art. 5, 13, 24 +1 ·Non-compliance with general data processing principles DPIA IP Address Privacy Impact Assessment Jan 1, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2020