Skip to content
Content type · 332 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–332 of 332 sort newestlargest fineoldest
€15,000 Gesthotel Activos Balagares: Non-compliance with general data processing principles The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered,… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Mar 9, 2020
€6,000 Casa Gracio Operation: Non-compliance with general data processing principles The company used CCTV cameras in the premises of a hotel which also captured the public roads outside the hotel resulting in a violation of the so called principle of data… SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Feb 25, 2020
€48,000 HM Hospitales: Insufficient legal basis for data processing The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the… SPAIN ·aepd ·Art. 5, 6 Consent Healthcare Healthcare Feb 25, 2020
€1,500 Cafetería Nagasaki: Insufficient legal basis for data processing The AEPD found that the Nagasaki Cafetería did not comply with its obligations under the GDPR, as it placed its surveillance cameras in such a way as to monitor the public space… SPAIN ·aepd ·Art. 5, 6 Video Surveillance Monitoring Processing Feb 4, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Jan 23, 2020
€3,600 Zhang Bordeta 2006, S.L. (Store and Restaurant): Non-compliance with general data processing principles The store and restaurant owner installed a video surveillance system which, among others, also took pictures of the sidewalk and thus of the public space, which violates the… SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Jan 14, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 5, 12, 28 Health Data Healthcare Healthcare Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
€10,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
Medical assistant: Insufficient legal basis for data processing A medical assistant at a doctor's office stored a patient's telephone number in her mobile phone and then contacted him for private purposes. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Healthcare Processing Supervisory Authorities Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC ·UOOU ·Art. 24, 32 Healthcare Health Data Healthcare Jan 1, 2020
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM ·ICO ·Art. 32 Healthcare Healthcare Security Dec 17, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Healthcare Dec 2, 2019
€6,000 Sports Bar: Non-compliance with general data processing principles The sports bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Nov 19, 2019
€5,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Nov 1, 2019
€100,000 Food company: Insufficient technical and organisational measures to ensure information security The company had set up an applicant portal on its website where interested parties could submit their application documents online. However, the company did not offer an encrypted… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Inspection Access Rights and Cooperation Obligations Oct 24, 2019
€7,400 Military Hospital: Insufficient fulfilment of data breach notification obligations A military hospital did not meet the reporting deadline for data breaches. Another part of the fine relates to a lack of technical and organisational measures. HUNGARY ·NAIH ·Art. 32, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 24, 2019
€195,407 Delivery Hero: Insufficient fulfilment of data subjects rights According to the findings of the Berlin data protection officer, Delivery Hero Germany GmbH had not deleted accounts of former customers in ten cases, even though those data… GERMANY ·Art. 15, 17, 21 ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Healthcare Sep 19, 2019
€25,000 Company in the medical sector: Insufficient fulfilment of information obligations The (none-final) fine was imposed on a company in the medical sector for non-compliance with information obligations and for not appointing a data protection officer. Update: The… AUSTRIA ·dsb ·Art. 13, 35, 37 Healthcare Healthcare Supervisory Authorities Aug 1, 2019
€15,000 WORLD TRADE CENTER BUCHAREST SA: Insufficient technical and organisational measures to ensure information security The breach of data security was that a printed paper list used to check breakfast customers and containing personal data of 46 clients who stayed at the hotel's WORLD TRADE CENTER… ROMANIA ·ANSPDCP ·Art. 32 Security Healthcare Personal Data Jul 2, 2019
€350,000 Haga Hospital: Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data… THE NETHERLANDS ·AP ·Art. 32 Healthcare Health Data Healthcare Jun 18, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA ·KZLD ·Art. 5, 6, 9 Healthcare Healthcare Integrity and Confidentiality Principle Apr 8, 2019
€14,000 Doctor: Insufficient legal basis for data processing A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Art. 5, 6 ·Insufficient legal basis for data processing Healthcare Healthcare Controllers Jan 1, 2019
€2,000 Restaurant: Non-compliance with general data processing principles Video surveillance cameras have been used in violation of principle of data minimisation (monitoring also of customer areas in restaurants). GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring Audit Logs Jan 1, 2019
€5,000 State Hospital: Insufficient fulfilment of data subjects rights A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Art. 15 ·Insufficient fulfilment of data subjects rights Healthcare Healthcare Personal Data Jan 1, 2019
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL ·CNPD ·Art. 5, 32 Health Data Healthcare Healthcare Jul 17, 2018
€1,800 Kebab restaurant: Insufficient legal basis for data processing CCTV was unlawfully used. Sufficient information about the video surveillance was missing. In addition, the storage period of 14 days was too long and therefore against the… AUSTRIA ·dsb ·Art. 5, 13, 14 Video Surveillance Monitoring IP Address Jan 1, 2018
Datatilsynet (Norway) - 15/01355 Legelisten.no AS is a Norwegian limited liability company running a website where people anonymously can post reviews about dentists, doctors, psychologists and other healthcare… 15/01355 ·Art. 4, 5, 6 +3 Legitimate Interest Healthcare Personal Data Nov 8, 2017