Skip to content
Content type · 1,529 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 1,529 sort newestlargest fineoldest
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN ·aepd ·Art. 15, 35 Personal Data Biometric Data Employees Nov 22, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security IP Address Public Authority Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN ·aepd ·Art. 15, 35 DPIA Privacy Impact Assessment Employees Nov 22, 2024
€4,700 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4,700 on a subcontractor that was contracted to redesign the website of another company. This fine is linked to ETid-2491. Due to an error… UODO ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processing Agreement Nov 20, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period Monitoring Nov 20, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individua had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6 Telecommunications Personal Data Processing Agreement Nov 19, 2024
€5M Foodinho Srl: Non-compliance with general data processing principles The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the… ITALY ·Garante ·Art. 2, 5, 6 +11 IP Address Employees Personal Data Nov 13, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Video Surveillance Security IP Address Nov 13, 2024
€2.4M Posti Jakelu Oy: Insufficient legal basis for data processing The Finnish DPA imposed a fine of EUR 2.4 million on Posti Jakelu Oy following an investigation. It was found that Posti had automatically set up an electronic mailbox for… FINLAND ·Deputy Data Protection Ombudsman ·Art. 6 Consent Processing Agreement Processing Nov 13, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Nov 12, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN ·aepd ·Art. 5, 32 Security Privacy by Design & Default IP Address Nov 11, 2024
€1,000 MINAS DE VALDECASTILLO, S.A..: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on MINAS DE VALDECASTILLO, S.A.. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers IP Address Nov 6, 2024
€1,000 Blackcab Systems SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Blackcab Systems SRL. A individual lodged a complaint with the DPA, alleging that the controller had failed to properly respond… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Processing Agreement Nov 4, 2024
€15,000 Untold SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Untold SRL. During its investigation, the DPA found that the controller had failed to properly comply with a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Data Controller Oct 30, 2024
€310M LinkedIn: Insufficient legal basis for data processing The Irish DPA (DPC) has fined LinkedIn EUR 310 million. This decision is related to an investigation following a complaint in 2018 from the French NGO 'La Quadrature Du Net'. In… Art. 60 Social Media Direct Marketing Processing Agreement Oct 24, 2024
€5,800 POLAND DPA: Insufficient involvement of data protection officer The Polish DPA has imposed a fine of EUR 5,800 on a data controller. The controller failed to appoint a data protection officer and to provide the DPA with the contact details in… UODO ·Art. 37 ·Insufficient involvement of data protection officer Controllers Supervisory Authorities Processing Oct 18, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individual had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·aepd ·Art. 6 Telecommunications Personal Data Processing Agreement Oct 18, 2024
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Your Consulting SRL. The controller had suffered a data breach involving the unauthorized disclosure of personal data. During… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Oct 16, 2024
Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·APD/GBA Cookies Direct Marketing Legitimate Interest Oct 11, 2024
€91M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 91 million on Meta Platforms Ireland Limited (MPIL). The DPC had initiated an investigation after MPIL reported that user passwords… Encryption Data Breaches Security Sep 27, 2024
€904,000 Police Service of Northern Ireland: Insufficient technical and organisational measures to ensure information security The ICO fined the Police Service of Northern Ireland £750,000 (EUR 904,000) after accidentally publishing personal data of 9,483 police officers and staff on the internet. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Personal Data Public Authority Sep 26, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·aepd ·Art. 5 Telecommunications IP Address Security Sep 26, 2024
€1,400 Attorney: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 1,400 on an attorney. An individual had filed a complaint with the DPA because the controller did not adequately respond to their… GREECE ·HDPA ·Art. 12, 31 Personal Data Controllers Supervisory Authorities Sep 23, 2024
€3,000 Constanța South Container Terminal SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Constanța South Container Terminal SRL. The controller had suffered a data breach in which personal data of employees had been… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Sep 17, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·azop ·Art. 5, 6, 12 +4 Data Breaches Healthcare Healthcare Sep 13, 2024
€5,000 Top Quality Corporation s.r.l.s.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Top Quality Corporation s.r.l.s. A data subject (former emplyee) had filed a complaint with the DPA due to the controller's… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Employees Sep 12, 2024
€400 Private individual: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 400 on a private individual. The individual had installed video surveillance cameras, which however also recorded parts of neighboring… ITALY ·Garante ·Art. 5, 6 Video Surveillance Monitoring Processing Sep 12, 2024
€842,062 Sky Italia S.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Sky Italia EUR 842,062 for unlawful telemarketing. The investigation revealed that Sky contacted individuals without proper consent, including those… ITALY ·Garante ·Art. 5, 6, 130 Direct Marketing Right to Object Processing Agreement Sep 12, 2024
€12,700 University of Agder: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the University of Agder (UiA) EUR 12,700. An employee of UiA had discovered that documents containing personal data of employees, students and external… NORWAY ·Datatilsynet ·Art. 24, 32 Personal Data Security Education Sep 4, 2024
€19,800 National Prosecutor's Office: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 19,800 on the National Prosecutor's Office. During a press conference, the public prosecutor's office disclosed an individual's personal… POLAND ·UODO ·Art. 6, 9, 33 +1 Data Breaches Personal Data Public Authority Sep 2, 2024
€698,000 Apohem AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 698,000 on Apohem AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Social Media Security Privacy by Design & Default Aug 29, 2024
€3.2M Apoteket AB.: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 3.2 million on Apoteket AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Social Media Security Healthcare Aug 29, 2024
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Aug 20, 2024
€940,000 mBank: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined mBank EUR 940,000. The bank had suffered a data breach in which an employee of the controller sent documents containing customer data to the wrong… POLAND ·UODO ·Art. 34 Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Aug 20, 2024
€1.5M IKEA: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 1,500,000 on IKEA. The controller used excessive video surveillance, including in public spaces and the checkout area. Additionally, the… AUSTRIA ·dsb ·Art. 5, 6 Video Surveillance Monitoring Controllers Aug 16, 2024
€1.5M Company: €1,500,000 fine The Austrian DPA has imposed a fine of EUR 1,500,000 on a company, that is part of a group. The controller installed video surveillance devices that did not comply with the GDPR,… AUSTRIA ·dsb ·Unknown Video Surveillance Monitoring Supervisory Authorities Aug 16, 2024
€270,000 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA. An individual who provided services to the controller filed a complaint with the DPA due to the fact… SPAIN ·aepd ·Art. 5, 32 Personal Data Controllers Employees Aug 12, 2024
€10,000 LOCAL VERTICALS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has fined LOCAL VERTICALS, S.L. EUR 10,000. An individual filed a complaint with the DPA because they could not access the privacy policy during the registration… SPAIN ·aepd ·Art. 13 Controllers Personal Data Processing Agreement Aug 6, 2024
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… Autoriteit Persoonsgegevens Privacy Shield Processing Agreement IP Address Jul 22, 2024
€600 DIGIMAN ALICANTE S.L.: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on DIGIMAN ALICANTE S.L.. The data controller had installed a video surveillance system without adequately providing information for data… SPAIN ·aepd ·Art. 13 Video Surveillance Controllers Monitoring Jul 17, 2024
€5M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5 million on Hera Comm S.p.A. The investigation was launched following numerous complaints. The energy supplier had failed to take… ITALY ·Garante ·Art. 5, 12, 15 +3 Data Subject Rights Exercise Modalities and Procedures IP Address Processing Agreement Jul 17, 2024
€30,000 Pere Sihtkapital SA: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 30,000 on Pere Sihtkapital SA. The controller conducted a survey on childless families. In the process, the controller failed to take all… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Security Controllers Privacy by Design & Default Jul 15, 2024
€600 ASSOCIACIO CANNABICA DEL MARESME ACANNAM: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on ASSOCIACIO CANNABICA DEL MARESME ACANNAM. The controller had installed video surveillance cameras which, among other… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Monitoring Jul 11, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which also recorded parts of a neighbouring… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Processing Agreement Jul 4, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Criminal Data Security Healthcare Jul 4, 2024
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA ·VDAI ·Art. 5, 12 Inspection Access Rights and Cooperation Obligations Fairness & Transparency Right of Access Procedures Jul 2, 2024
€50,000 METRO SA: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 50,000 on METRO SA. A former employee had sent text messages to the private mobile phone of a customer who had a user account in the… GREECE ·HDPA ·Art. 15, 17, 24 +2 Security Controllers Processing Agreement Jun 27, 2024
€600 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a Homeowners' association. The association had installed video surveillance cameras which, among other things, also covered the public space.… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jun 26, 2024
€3,000 Rețele Electrice Muntenia SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Rețele Electrice Muntenia SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default Controllers Jun 25, 2024
€150,000 BANCO CETELEM, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO CETELEM, S.A.. A person had filed a complaint against the controller with the DPA due to the fact that debits had been made from their… SPAIN ·aepd ·Art. 6, 17 Controllers IP Address Personal Data Jun 25, 2024