Skip to content
Content type · 402 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 402 sort newestlargest fineoldest
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Dec 16, 2021
€10,000 Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Warsaw University of Technology EUR 10,000. The university had reported a data breach to the authority pursuant to Art. 33 GDPR. One of the… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Privacy by Design & Default Dec 9, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€60,000 Irish Teacher Council: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 60,000 on the Irish Teaching Council. The Council notified the DPA of a data breach under Art. 33 of the GDPR. Accordingly, two employees… IRELAND ·DPC ·Art. 5, 32, 33 Data Breaches Personal Data Security Dec 2, 2021
€4,000 Pactum Poland Sp. z o.o.: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. UODO ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Data Breaches Dec 1, 2021
€110,000 UAB Prime Leasing: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has fined UAB Prime Leasing, the operator of the short-term car rental platform CityBee, EUR 110,000. The DPA conducted the investigation on its own initiative… LITHUANIA ·VDAI ·Art. 32 Data Breaches Notification Obligation Encryption Nov 29, 2021
€2,000 Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on Valoris Center S.R.L.. The controller notified the DPA of a data breach pursuant to Art. 33 GDPR. A call center… ROMANIA ·ANSPDCP ·Art. 29, 32 Data Breaches Security Right of Access Nov 26, 2021
€6,000 Società H San Raffaele Resnati s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. The DPA initiated an investigation against the health care provider after it… ITALY ·Garante ·Art. 5, 9 Healthcare Processing Data Breaches Nov 25, 2021
€585,000 Cabinet Office: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Cabinet Office EUR 585,000. On December 27, 2019, the Cabinet Office published a file on GOV.UK containing the names and uncensored addresses of… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Personal Data Data Breaches Nov 25, 2021
€98,000 Norwegian State Pension Fund (SPK): Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 98,000 on the Norwegian State Pension Fund (SPK). The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 9 Data Breaches Controllers Healthcare Nov 24, 2021
€2,900 Vodafone România SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,900 on VODAFONE România S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. In the… ROMANIA ·ANSPDCP ·Art. 3, 32 Data Breaches Security Personal Data Nov 14, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS ·AP ·Art. 32 Security Personal Data Data Breaches Nov 12, 2021
€1,000 IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,000 on IKEA ROMÂNIA SA. The controller had sent a notification to the DPA about a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Nov 1, 2021
€5,000 S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Nov 1, 2021
€78,000 Bank Millennium S.A: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 78,000 on Bank Millennium S.A.. The UODO had become aware of a data protection breach following a complaint against the bank. It… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 14, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 29, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet (NO) ·Art. 32 Data Breaches Security Personal Data Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 17, 2021
€10,000 Favrskov municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 16, 2021
€5,000 Ciechi Ardizzone Gioeni di Catania: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Ciechi Ardizzone Gioeni di Catania residential home for blind people. A visitor to the residence filed a complaint… ITALY ·Garante ·Art. 5, 12, 13 +1 Integrity and Confidentiality Principle Retention Period Monitoring Sep 16, 2021
€3,000 Actamedica SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has fined Actamedica SRL EUR 3,000. The controller had informed a private individual about the loss of her biological samples and a sum of money sent… ROMANIA ·ANSPDCP ·Art. 28, 32, 33 Data Breaches Security Controllers Aug 24, 2021
€1,500 MOVE Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data Aug 20, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND ·UODO ·Art. 5, 25, 32 Encryption Security Personal Data Aug 13, 2021
€135,000 Insurance company: Insufficient technical and organisational measures to ensure information security The DPA of Luxembourg has imposed a fine of EUR 135,000 on an insurance company. On October 19, 2018, an employee of the controller had sent an e-mail to an uninvolved third party… LUXEMBOURG ·CNPD (LU) ·Art. 5, 32, 33 Data Breaches Security Controllers Aug 5, 2021
€3,000 UST GLOBAL ESPAÑA, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on UST GLOBAL ESPAÑA, S.A.. An employee filed a complaint against the controller with the DPA. UST GLOBAL ESPAÑA, S.A. was… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Security Jul 27, 2021
€67,900 Region of Syddanmark: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has fined the Region of Syddanmark EUR 67,900 for failing to comply with its obligation as a data controller to implement adequate security measures.… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Controllers Personal Data Jul 16, 2021
€29,000 Mermaids: Insufficient technical and organisational measures to ensure information security The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR.… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Encryption Pseudonymization Jul 5, 2021
IT services company: Insufficient technical and organisational measures to ensure information security A Croatian IT company provides IT services to entities such as mobile operators, banks and state institutions in Croatia, as well as to companies abroad (USA, Great Britain, the… CROATIA ·AZOP ·Art. 32 Controllers Security Processors Jul 5, 2021
€3,000 Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 30, 2021
€35,300 Sopockie Towarzystwo Ubezpieczeń ERGO Hestia S.A.: Insufficient fulfilment of data breach notification obligations The controller had sent an email to that contained personal data of a customer to the wrong recipient. The leaked data included data such as the name, postal address of the data… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 21, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Supervisory Authorities Jun 16, 2021
€64,500 Voice Integrate Nordic AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 64,500 on Voice Integrate Nordic AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jun 7, 2021
€50,000 Region Stockholm: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13, 14 Supervisory Authorities Personal Data Security Jun 7, 2021
€25,000 Region Värmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Värmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€1.2M MedHelp AB: Non-compliance with general data processing principles The Swedish DPA has imposed a fine of EUR 1,200,000 on MedHelp AB. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of… SWEDEN ·IMY ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Personal Data Encryption Jun 7, 2021
€25,000 Region Sörmland: Insufficient fulfilment of information obligations The Swedish DPA has imposed a fine of EUR 25,000 on Region Sörmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions… SWEDEN ·IMY ·Art. 5, 13 Supervisory Authorities Personal Data Security Jun 7, 2021
€49,200 Moss municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Personal Data Public Authority Jun 4, 2021
€39,700 BRAbank ASA: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,700 on BRAbank ASA. The controller had reported a data breach to the DPA on September 6, 2019. On the controller's… NORWAY ·Datatilsynet (NO) ·Art. 24, 32 Security Controllers Personal Data May 28, 2021
€2,000 World Class România S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) has imposed a fine of EUR 2,000 on World Class România S.A.. The controller had published the termination letter of an employee in a WhatsApp group used… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Controllers Security May 7, 2021
€23,100 InfoMentor ehf: Insufficient technical and organisational measures to ensure information security The Icelandic DPA (Persónuvernd) has imposed a fine of EUR 23,100 on InfoMentor ehf. Previously, the controller had reported a data breach according to Art. 33 GDPR. The incident… ICELAND ·Persónuvernd ·Art. 32 Data Breaches Security Controllers Apr 29, 2021
€245,000 Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Cyfrowy Polsat S.A. EUR 245,000. The fine was based on a large number of data breaches reported by the controller to the DPA. Frequently, postal… POLAND ·UODO ·Art. 24, 32, 34 Data Breaches Security Controllers Apr 22, 2021
€10,000 Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security The Romania DPA (ANSPDCP) has fined Telekom Romania Mobile Communications S.A. EUR 10,000 for failing to implement adequate security measures to ensure the security of personal… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 30, 2021
€2,000 S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security In February, the Romanian DPA (ANSPDCP) closed an investigation against S.C. Medicover S.R.L. and found a violation of Art. 32 (1) b), (2), (4) GDPR. The DPA imposed a fine of EUR… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Right of Access Mar 23, 2021
€90,000 Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 90,000 on Irish Credit Bureau (ICB). The fine follows a data breach reported by the controller to the DPA on August 31, 2018. The… IRELAND ·DPC ·Art. 5, 24, 25 Controllers Security Data Breaches Mar 23, 2021
€600,000 Air Europa Lineas Aereas, SA.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) fined Air Europa Lineas Aereas, SA. EUR 600,000 after a serious data breach involving unauthorized access to contact details and bank accounts was reported… SPAIN ·AEPD ·Art. 32, 33 Data Breaches Security Controllers Mar 15, 2021
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY ·Datatilsynet (NO) ·Art. 24, 32, 35 DPIA Security Monitoring Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 24 +1 Personal Data Security Public Authority Mar 15, 2021
€25,000 Hellenic Bank: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 25,000 on Hellenic Bank. The bank had closed one of its branches in the city of Nicosia in 2015. When moving out of the space, a safe… CYPRUS ·Cyprus DPA ·Art. 5, 32, 33 Data Breaches Controllers Security Mar 3, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA ·VDAI ·Art. 32 Security Personal Data Controllers Mar 2, 2021