Skip to content
Content type · 539 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 539 sort newestlargest fineoldest
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Security Data Breaches Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Integrity and Confidentiality Principle Data Breaches Processors Mar 23, 2023
€5,000 Misterbianco municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Misterbianco municipality. An employee had filed a complaint with the DPA due to the fact, that the municipality had published a… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Public Authority Jan 26, 2023
€6,400 Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,400 on the Szczecin-Centrum District Court. The court had reported a data breach to the DPA involving the loss of three data carriers.… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Privacy by Design & Default Security Jan 19, 2023
€150,000 Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on the Dutch Social Insurance Institution (SVB). The controller had suffered a data breach in which a client's data had been leaked… THE NETHERLANDS ·AP ·Art. 32 Security Controllers Personal Data Jan 19, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€6,000 Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia. The school board had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Jan 11, 2023
Daycare center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a four-figure fine on a daycare center that had disposed of documents containing personal data of children and their parents in a publicly… GERMANY ·HmbBfDI ·Art. 32 Security Personal Data Education Jan 1, 2023
€8,000 Cypriot Ministry of the Interior: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on the Cypriot Ministry of the Interior. The Ministry of Interior had unlawfully transmitted personal data of employees to the… CYPRUS ·Cyprus DPA ·Art. 5 Personal Data Processing Public Authority Jan 1, 2023
€28,000 Political party: €28,000 fine The Austrian DPA has imposed a fine of EUR 50,700 on a political party. The controller had sent two emails in an open distribution list. This allowed the recipients to view the… AUSTRIA ·DSB ·Unknown Political Opinions Education IP Address Jan 1, 2023
€3M VOODOO ('provider') was a mobile game developer The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of the provider's mobile applications on iOS, in… SAN-2022-026 ·France ·CNIL IP Address Transparency Personal Data Dec 29, 2022
€6,000 Comune di Bracciano: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Comune di Bracciano. A former employee had filed a complaint with the DPA due to the fact, that the municipality had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Dec 15, 2022
€3,000 Scuola Statale Secondaria di I^ grado 'Bianco-Pascol': Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the school 'Scuola Statale Secondaria di I^ grado 'Bianco-Pascoli', di Fasano (BR)'. The educational institution had published a… ITALY ·Garante ·Art. 2, 5, 6 +2 Types of Special Categories of Personal Data Healthcare Supervisory Authorities Dec 15, 2022
€5,000 Comune di Borgia: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 5,000 on Comune di Borgia. The municipality processed biometric data of employees for the purpose of registering their attendance.… ITALY ·Garante ·Art. 5, 6, 9 +1 Types of Special Categories of Personal Data Public Authority Personal Data Dec 15, 2022
€8,000 Comune di Vicchio: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 8,000 on Comune di Vicchio. The municipality processed biometric data of employees for the purpose of registering their attendance.… ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Personal Data Processing Dec 15, 2022
€4,000 Villafranca di Verona municipality: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on Villafranca di Verona municipality. The municipality had published a document containing personal data of an employee on… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Public Authority Nov 10, 2022
€5,000 Cisterna di Latina Municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Cisterna di Latina Municipality. An individual had filed a complaint with the DPA. The individual had submitted a request to the… ITALY ·Garante ·Art. 5, 12, 37 Public Authority Personal Data Supervisory Authorities Nov 10, 2022
€6,000 Conservatorio di Musica S. Cecilia di Roma: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on 'Conservatorio di Musica S. Cecilia di Roma'. A student of the educational institution had filed a complaint with the DPA for… ITALY ·Garante ·Art. 2, 5, 6 +1 Supervisory Authorities Controllers Personal Data Nov 10, 2022
€5,000 Cisterna di Latina municipality: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Cisterna di Latina municipality. An individual had filed a complaint with the DPA because the municipality had not responded to… ITALY ·Garante ·Art. 5, 12, 37 Public Authority Personal Data Supervisory Authorities Nov 10, 2022
€180,000 Setúbal municipality: Non-compliance with general data processing principles The Portuguese DPA has imposed a fine of EUR 170,000 on Setúbal municipality. The DPA found data protection violations regarding the collection of personal data from Ukrainian… PORTUGAL ·CNPD (PT) ·Art. 5, 13, 37 Public Authority Retention Period Personal Data Nov 2, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD (PT) ·Art. 5, 9, 12 +5 Privacy Shield Controllers DPIA Nov 2, 2022
€1,700 Mayor: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 1,700 on the mayor of Dobrzyniewo Duże municipality. The mayor had reported a data breach to the DPA pursuant to Art. 33 GDPR. An… POLAND ·UODO ·Art. 5, 25, 32 Data Breaches Privacy by Design & Default Security Nov 2, 2022
€12,000 Comune di Salento: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on Comune di Salento. An individual had lodged a complaint with the DPA for being recorded by a CCTV camera, which proved that he… ITALY ·Garante ·Art. 5, 6, 12 +3 Personal Data Processing Supervisory Authorities Oct 20, 2022
€900 Istituto di Istruzione Superiore G. Renda di Polistena, Reggio Calabria: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 900 on the educational institution 'Istituto di Istruzione Superiore G. Renda di Polistena, Reggio Calabria'. A former employee of the… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Oct 20, 2022
€12,000 SEAN SERIOS S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 12,000 on SEAN SERIOS S.L. The controller had published the results of a selection procedure on a website. This included, among other… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Education Oct 14, 2022
€100,000 Veneto region: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 100,000 on the Veneto Region. The DPA had received a complaint from dozens of medical and nursing staff. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 Processing Public Authority Healthcare Oct 6, 2022
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·Datatilsynet (DK) DPIA Controllers Prior Consultation
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022
€3,000 Thiene municipality: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Thiene municipality. A former employee of the municipality filed a complaint with the DPA because a document containing… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Public Authority Sep 15, 2022
€250,000 GIE INFOGREFFE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 250,000 on GIE INFOGREFFE. The portal operates a website where people can access legal information about companies and order documents… FRANCE ·CNIL ·Art. 5, 32 Security Encryption Personal Data Sep 13, 2022
€6,700 Hørsholm municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Hørsholm municipality. The municipality had reported a data breach to the DPA pursuant to Art. 33 GDPR. An employee's work… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Sep 12, 2022
€15,000 School: Non-compliance with general data processing principles The Hellenic DPA has fined a school EUR 15,000. The school had installed several video surveillance cameras on the building, which permanently recorded students, teachers and… GREECE ·HDPA ·Art. 5, 6, 12 +2 Legitimate Interest Controllers Personal Data Sep 9, 2022
€4,000 Liceo Statale 'Edoardo Amaldi”: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the school 'Edoardo Amaldi'. The school had published a circular on the school website about the summer vacations which… ITALY ·Garante ·Art. 2, 5, 6 +1 Processing Education Public Authority Sep 1, 2022
€3,000 COLEGIO VILLAEUROPA, S.C.L: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine on COLEGIO VILLAEUROPA, S.C.L. The school did not provide sufficient information on the video surveillence, as required by Art. 13 GDPR. The… SPAIN ·AEPD ·Art. 13 Controllers Personal Data Supervisory Authorities Aug 30, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Aug 11, 2022
€26,000 Policoro municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 26,000 on Policoro municipality. The municipality had installed a video surveillance system without, however, providing sufficient… ITALY ·Garante ·Art. 5, 12, 13 +2 Retention Period Storage Limitation Supervisory Authorities Aug 1, 2022
€3,000 ESTUDIOS EUROPEOS DE POSTGRADO Y EMPRESA, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3,000 on ESTUDIOS EUROPEOS DE POSTGRADO Y EMPRESA, S.L.. An employee had filed a complaint with the DPA. The employee stated that she had… SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Jul 29, 2022
€5,000 Ginosa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Ginosa municipality. The fine is related to the fine against Clio S.r.l.. Clio provides and manages a whistleblowing reporting… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Supervisory Authorities Public Authority Jul 21, 2022
Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022) During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Belgium ·APD/GBA Health Data Healthcare Types of Special Categories of Personal Data Jul 19, 2022
€12,450 Głównego Geodetę Kraju: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 12,450 on the public cartography institute Głównego Geodetę Kraju. The institute had suffered a data breach in which numerous land… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 6, 2022
Icelandic DPA: genetic research company violated DPO independence under Art. 38(3) GDPR The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Iceland ·Persónuvernd Supervisory Authorities Controllers Prior Consultation Jun 29, 2022
€2,000 Parliamentary election candidate: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 2,000 on a parliamentary election candidate. A data subject had filed a complaint with the DPA because of receiving unsolicited election… GREECE ·HDPA ·Art. 11, 12 Personal Data Supervisory Authorities Direct Marketing Jun 24, 2022
€26,000 Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Italy ·Garante ·Art. 5, 12, 13 +3 Public Authority Supervisory Authorities Storage Limitation Jun 9, 2022
€91,000 Tavistock & Portman NHS Foundation Trust: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Tavistock and Portman NHS Foundation Trust EUR 91,000. The Tavistock and Portman NHS Foundation Trust is a mental health specialist trust located in… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Privacy by Design & Default Public Authority Jun 9, 2022
€10,000 Afragola municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on Afragola municipality. A former employee of the municipality had filed a complaint with the DPA because the municipality had… ITALY ·Garante ·Art. 2, 5, 12 Personal Data Supervisory Authorities Processing May 26, 2022
€16,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 16,000 on the Region of Tuscany. The region had published documents on its website containing information on professionals from the… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education May 26, 2022
€12,000 Comune di Napoli Corpo di Polizia Municipale: Insufficient legal basis for data processing The Italian DPA has fined the police authority 'Comune di Napoli Corpo di Polizia Municipale' EUR 12,000. The police authority had sent a list of names, addresses, tax numbers,… ITALY ·Garante ·Art. 5, 6, 88 +1 Consent Processing Education May 22, 2022
€14,500 Arbeidstilsynet: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has fined the Norwegian Labor Inspectorate 'Arbeidstilsynet' EUR 14,500. The controller had carried out a credit check on the data subject without… NORWAY ·Datatilsynet (NO) ·Art. 6 Controllers Personal Data Public Authority May 16, 2022
€13,400 Civilstyrelsen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 13,400 on the Danish agency Civilstyrelsen. A Civilstyrelsen USB stick containing more than 800 pages of sensitive and confidential… DENMARK ·Datatilsynet (DK) ·Art. 32, 33 Encryption Data Breaches Security May 12, 2022
€6,000 Villabate municipality: Non-compliance with general data processing principles The Italian DPA has fined Villabate municipality EUR 6,000. The municipality had disclosed personal data of a former employee to unauthorized third parties without a valid legal… ITALY ·Garante ·Art. 5, 6, 37 +1 Public Authority Personal Data Supervisory Authorities May 12, 2022