Skip to content
Content type · 427 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 427 sort newestlargest fineoldest
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·DPC ·Art. 5, 13, 24 +3 Security Controllers Personal Data Nov 13, 2024
€2,500 COYARE SLU: Non-compliance with general data processing principles The Spanish DPA fined COYARE SLU EUR 2,500 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the unauthorized… SPAIN ·AEPD ·Art. 5, 32 Processing IP Address Processing Agreement Nov 13, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Nov 11, 2024
€2,000 KAFFA KOFFEE ORGANISATION, S.L.: Non-compliance with general data processing principles The Spanish DPA fined KAFFA KOFFEE ORGANISATION, S.L. EUR 2,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This… SPAIN ·AEPD ·Art. 5, 32 Processing IP Address Processing Agreement Nov 7, 2024
€1,000 MINAS DE VALDECASTILLO, S.A..: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on MINAS DE VALDECASTILLO, S.A.. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Nov 6, 2024
€15M OpenAI OpCo LLC: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15 million on OpenAI in connection with the operation of the generative AI chatbot “ChatGPT”. The DPA found that OpenAI had violated… ITALY ·Garante ·Art. 5, 6, 12 +4 Transparency Fairness & Transparency Personal Data Nov 2, 2024
€5,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA fined Vodafone Romania S.A. EUR 5,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Oct 28, 2024
€180,000 IBERCAJA BANCO, S.A.: Insufficient legal basis for data processing The Spanish DPA has fined IBERCAJA BANCO, S.A. for unlawfully accessing a customer’s credit file after the termination of their contractual relationship. The DPA concluded that… SPAIN ·AEPD ·Art. 6 Insurance IP Address Supervisory Authorities Oct 22, 2024
€20,800 Grue municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA fined Grue municipality EUR 20,800 following the municipality's notification of a data breach. The municipality reported that personal data of students had been… NORWAY ·Datatilsynet (NO) ·Art. 24, 32 Security Personal Data Public Authority Oct 21, 2024
€9,000 Vilnius District Municipality Administration: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has imposed a fine of EUR 1,000 on the Vilnius District Municipality Administration. The Municipality Administration had been hacked. The attack resulted in… LITHUANIA ·VDAI ·Art. 5, 32, 34 Personal Data Security Supervisory Authorities Oct 18, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers Consent Processing Sep 26, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·AEPD ·Art. 5 Controllers Security Personal Data Sep 26, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers Consent Processing Sep 26, 2024
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE ·CNIL ·Art. 5, 66 Identification Supervisory Authorities Processing Sep 12, 2024
€270,000 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA. An individual who provided services to the controller filed a complaint with the DPA due to the fact… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Aug 12, 2024
€80,000 Selectra S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access… ITALY ·Garante ·Art. 5, 13, 88 +1 Storage Limitation Retention Period Controllers Jul 17, 2024
€5M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5 million on Hera Comm S.p.A. The investigation was launched following numerous complaints. The energy supplier had failed to take… ITALY ·Garante ·Art. 5, 12, 15 +3 Controllers Personal Data Supervisory Authorities Jul 17, 2024
€600 ASSOCIACIO CANNABICA DEL MARESME ACANNAM: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on ASSOCIACIO CANNABICA DEL MARESME ACANNAM. The controller had installed video surveillance cameras which, among other… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jul 11, 2024
€1M Fastweb S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1 million on Fastweb S.p.A. due to unauthorized telemarketing, the unlawful storage of customer data after contract termination, and… ITALY ·Garante ·Art. 5, 6, 7 +13 Direct Marketing Storage Limitation Right to Object Jun 20, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which also recorded the entrance area of the… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance May 14, 2024
€8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers IP Address Apr 30, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Mar 25, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·AEPD ·Art. 5, 32 Controllers Personal Data Security Mar 21, 2024
€3M IBERDROLA, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although… SPAIN ·AEPD ·Art. 5, 32 Security Processing Law Enforcement Feb 7, 2024
€5M ENERGYA VM GESTIÓN DE ENERGÍA, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined ENERGYA VM GESTIÓN DE ENERGÍA, S.L. EUR 5 million following an investigation into unlawful personal data processing by Nivalco, a company… SPAIN ·AEPD ·Art. 5 Controllers Processing Personal Data Feb 6, 2024
€3.5M I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3.5 million on I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U. The controller had suffered a cyber attack on its GEA web application resulting… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Feb 5, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Encryption Healthcare Controllers Jan 17, 2024
€2,500 Doctor´s Office: Insufficient technical and organisational measures to ensure information security The DPA of Hessen has imposed a fine of EUR 2,500 on a doctor´s office. The controller hired an office manager who worked partly from home. The manager worked with patient files,… GERMANY ·Art. 5, 6, 9 +1 ·Insufficient technical and organisational measures to ensure information security Controllers Security Healthcare Jan 1, 2024
€200 Civic Association: Insufficient legal basis for data processing The Slovak DPA has imposed a fine of EUR 200 on a civic association. The controller violated the principle of lawfulness of processing. SLOVAKIA ·Slovak Data Protection Office ·Insufficient legal basis for data processing Controllers IP Address Supervisory Authorities Jan 1, 2024
€496,000 Company: Non-compliance with general data processing principles The DPA of Hessen has imposed a fine of EUR 496,000 on a company. The DPA identified several GDPR violations, including transmitting customer data to the incorrect recipient and… GERMANY ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Recipient Supervisory Authorities Processing Jan 1, 2024
Multiple Police Officers: Data Protection Authority of Berlin The DPA of Berlin imposed fined 23 police officers. The police officers misused their access to the police information system for private purposes. GERMANY ·Unknown Supervisory Authorities Public Authority Education Jan 1, 2024
€7,500 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 7,500 on an unknown controller. The controller violated the principle of lawfulness, the principle of transparency and the principle of… Slovak Data Protection Office ·Non-compliance with general data processing principles Supervisory Authorities Accountability Controllers Jan 1, 2024
€1,000 GREECE DPA: Non-compliance with general data processing principles Unlawful disclosure of health data. HDPA ·Art. 5 ·Non-compliance with general data processing principles Processing Supervisory Authorities Health Data Oct 11, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN ·AEPD ·Art. 9, 13 Personal Data Healthcare Controllers Sep 25, 2023
Multiple website operators: Czech Data Protection Auhtority (UOOU) In the period from January 2023 to July 2023, the Czech DPA imposed fines totaling EUR 178,000, with the highest fine being EUR 36,000. These fines were imposed due to unlawful… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Unknown Integrity and Confidentiality Principle Cookies Fines Aug 2, 2023
€600 Private individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a private individual. The controller had installed video surveillance cameras which, among other things, covered a neighbor… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Jun 30, 2023
€210,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 210,000 on Piraeus Bank. During its investigation, the DPA found that the bank had processed personal data of customers in violation of… GREECE ·HDPA ·Art. 5, 6, 15 +1 Privacy by Design & Default Personal Data Security Jun 12, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY ·Garante ·Art. 2, 5, 9 +1 Healthcare Personal Data Controllers Jun 1, 2023
€1,020 Telecommunications Operator: Non-compliance with general data processing principles The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient identification methodes, resulting in a customer… BULGARIA ·CPDP ·Art. 5 Identification Controllers Personal Data Mar 16, 2023
€1,020 Telecommunications Operator: Non-compliance with general data processing principles The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient technical and organisational measures to ensure… BULGARIA ·CPDP ·Art. 5, 6 Security Controllers Telecommunications Jan 17, 2023
€28,000 Political party: €28,000 fine The Austrian DPA has imposed a fine of EUR 50,700 on a political party. The controller had sent two emails in an open distribution list. This allowed the recipients to view the… AUSTRIA ·DSB ·Unknown Political Opinions Education IP Address Jan 1, 2023
€3M VOODOO ('provider') was a mobile game developer The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of the provider's mobile applications on iOS, in… SAN-2022-026 ·France ·CNIL IP Address Transparency Personal Data Dec 29, 2022
€5,000 Comune di Borgia: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 5,000 on Comune di Borgia. The municipality processed biometric data of employees for the purpose of registering their attendance.… ITALY ·Garante ·Art. 5, 6, 9 +1 Types of Special Categories of Personal Data Public Authority Personal Data Dec 15, 2022
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide access to information about the purpose of the processing, the storage period, the… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Controllers Supervisory Authorities Nov 9, 2022
€525,000 TECHPUMP SOLUTIONS S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Techpump Solutions S.L. EUR 525,000. Techpump operates several websites with adult content. The DPA found several violations of data protection law… SPAIN ·AEPD ·Art. 5, 6, 8 +5 Retention Period Personal Data Storage Limitation Oct 31, 2022
€9,000 EL RACO DEL PIS INVERSIONES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 9,000 on EL RACO DEL PIS INVERSIONES S.L.. The controller had sent an e-mail in an open distribution list, making the email addresses of… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing IP Address Oct 25, 2022
€7,000 I.S.P.R.O.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the oncology health care facility I.S.P.R.O.. An individual had mistakenly received medical records from another… ITALY ·Garante ·Art. 5, 9 Healthcare Processing Health Data Oct 20, 2022
€20,000 EUROBANK ERGASIAS S.A.: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 20,000 on EUROBANK ERGASIAS S.A.. In the context of the use of certain debit/credit cards, information of the last 10 transactions were… GREECE ·HDPA ·Art. 13 Supervisory Authorities Consent IP Address Oct 3, 2022
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·Datatilsynet (DK) DPIA Controllers Prior Consultation
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022