Content type · 332 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN · ·Art. 5 Mar 9, 2020
€6,000 Casa Gracio Operation: Non-compliance with general data processing principles The company used CCTV cameras in the premises of a hotel which also captured the public roads outside the hotel resulting in a violation of the so called principle of data… SPAIN · ·Art. 5 Feb 25, 2020
€48,000 HM Hospitales: Insufficient legal basis for data processing The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the… SPAIN · ·Art. 5, 6 Feb 25, 2020
€1,500 Cafetería Nagasaki: Insufficient legal basis for data processing The AEPD found that the Nagasaki Cafetería did not comply with its obligations under the GDPR, as it placed its surveillance cameras in such a way as to monitor the public space… SPAIN · ·Art. 5, 6 Feb 4, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY · ·Art. 5, 32 Jan 23, 2020
€3,600 Zhang Bordeta 2006, S.L. (Store and Restaurant): Non-compliance with general data processing principles The store and restaurant owner installed a video surveillance system which, among others, also took pictures of the sidewalk and thus of the public space, which violates the… SPAIN · ·Art. 5 Jan 14, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC · ·Art. 5, 12, 28 Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€10,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
Medical assistant: Insufficient legal basis for data processing A medical assistant at a doctor's office stored a patient's telephone number in her mobile phone and then contacted him for private purposes. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC · ·Art. 24, 32 Jan 1, 2020
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM · ·Art. 32 Dec 17, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA · ·Art. 58 Dec 2, 2019
€6,000 Sports Bar: Non-compliance with general data processing principles The sports bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. SPAIN · ·Art. 5 Nov 19, 2019
€5,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Nov 1, 2019
€100,000 Food company: Insufficient technical and organisational measures to ensure information security The company had set up an applicant portal on its website where interested parties could submit their application documents online. However, the company did not offer an encrypted… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Oct 24, 2019
€7,400 Military Hospital: Insufficient fulfilment of data breach notification obligations A military hospital did not meet the reporting deadline for data breaches. Another part of the fine relates to a lack of technical and organisational measures. HUNGARY · ·Art. 32, 33 Oct 24, 2019
€195,407 Delivery Hero: Insufficient fulfilment of data subjects rights According to the findings of the Berlin data protection officer, Delivery Hero Germany GmbH had not deleted accounts of former customers in ten cases, even though those data… GERMANY ·Art. 15, 17, 21 ·Insufficient fulfilment of data subjects rights Sep 19, 2019
€25,000 Company in the medical sector: Insufficient fulfilment of information obligations The (none-final) fine was imposed on a company in the medical sector for non-compliance with information obligations and for not appointing a data protection officer. Update: The… AUSTRIA · ·Art. 13, 35, 37 Aug 1, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA · ·Art. 32 Jul 2, 2019
€350,000 Haga Hospital: Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data… THE NETHERLANDS · ·Art. 32 Jun 18, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA · ·Art. 5, 6, 9 Apr 8, 2019
€14,000 Doctor: Insufficient legal basis for data processing A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2019
€2,000 Restaurant: Non-compliance with general data processing principles Video surveillance cameras have been used in violation of principle of data minimisation (monitoring also of customer areas in restaurants). GERMANY ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2019
€5,000 State Hospital: Insufficient fulfilment of data subjects rights A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Art. 15 ·Insufficient fulfilment of data subjects rights Jan 1, 2019
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL · ·Art. 5, 32 Jul 17, 2018
€1,800 Kebab restaurant: Insufficient legal basis for data processing CCTV was unlawfully used. Sufficient information about the video surveillance was missing. In addition, the storage period of 14 days was too long and therefore against the… AUSTRIA · ·Art. 5, 13, 14 Jan 1, 2018
Datatilsynet (Norway) - 15/01355 Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Art. 4, 5, 6 +3 Nov 8, 2017