Skip to content
Content type · 441 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 441 sort newestlargest fineoldest
€2,000 Istituto Comprensivo - IC Cosenza III “V. Negroni”: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo - IC Cosenza III “V. Negroni”. The educational institution had published a document, which also contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Health Data Education Healthcare Sep 21, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet ·Art. 32 Data Breaches Health Data Security Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Notification Obligation Healthcare Sep 17, 2021
€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Garante ·Art. 2, 5, 6 +6 Audit Logs Fairness & Transparency Privacy Shield Sep 16, 2021
€10,000 Favrskov municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Encryption Notification Obligation Sep 16, 2021
€5,000 Comune di Montalbano Jonico: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the municipality of Montalbano Jonico. An individual had filed a complaint against the municipality with the DPA. He… ITALY ·Garante ·Art. 2, 5, 6 +1 Education Personal Data IP Address Sep 16, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet ·Art. 32 Security Healthcare Health Data Sep 8, 2021
€20,100 Danish Immigration Agency: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 20,100 on the Danish Immigration Agency. Media reports brought the DPA's attention to possible logging errors in one of the agency's IT… DENMARK ·Datatilsynet ·Art. 5, 32 Security Audit Logs Public Sector Aug 17, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND ·UODO ·Art. 5, 25, 32 Encryption Data Breaches Security Aug 13, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·dsb ·Art. 9 Personal Data Genetic Data Processors Aug 5, 2021
€600 DSB Austria: sharing medical assessment with municipality lacked Art. 9(2) legal basis Person A is employed at a municipality and has been on sick leave for several weeks in 2013 and 2014. In September 2014, the municipality concluded that Person A's sickness had… Art. 4, 5, 9 +1 Personal Data Healthcare Healthcare Aug 5, 2021
€3,000 UNIVERSIDAD A DISTANCIA DE MADRID, S.A.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine on UNIVERSIDAD A DISTANCIA DE MADRID, S.A.. A data subject had filed a complaint against the distance learning university. He stated that… SPAIN ·aepd ·Art. 17, 21 Personal Data Education Controllers Jul 29, 2021
€2,400 PODEMOS PARTIDO POLÍTICO: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on the political party PODEMOS PARTIDO POLÍTICO. The controller had installed video surveillance cameras which, among other things, also… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Jul 27, 2021
€200,000 Regione Lombardia: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on the Region of Lombardy. The region had published on its website the personal data of more than 100,000 students who… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Education Jul 22, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Controllers Fines Processors Jul 22, 2021
€3,000 Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal… POLAND ·UODO ·Art. 33, 34 Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 30, 2021
€27,000 Vejle Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA (Datatilsynet) has imposed a fine of EUR 27,000 on Vejle municipality. The Danish DPA had started investigations against the municipality after it had reported a… DENMARK ·Datatilsynet ·Art. 32 Data Breaches Security Public Authority Jun 16, 2021
€20,000 Master Distancia S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 25,000 on Master Distancia S.A.. The controller had included personal data of the data subject in a credit report register without… SPAIN ·aepd ·Art. 6 Personal Data Controllers Education Jun 7, 2021
€39,000 Municipality of Oslo: Insufficient legal basis for data processing The Norwegian DPA (Datatilsynet) has imposed a fine of EUR 39,000 on the Municipality of Oslo. On a website of the controller a subpoena from the public prosecutor's office… NORWAY ·Datatilsynet ·Art. 5, 6 Health Data Healthcare Public Authority May 20, 2021
€2,000 Santa Ninfa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Santa Ninfa municipality. The municipality had published a resolution on its website that contained personal information… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Public Authority IP Address Apr 29, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Education Controllers Apr 16, 2021
€12,000 Istituto Nazionale Previdenza Sociale (INPS): Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 12,000 on the Italian National Institute for Social Security (Istituto Nazionale della Previdenza Sociale). That fine was based… ITALY ·Garante ·Art. 5, 12, 15 Personal Data Education Controllers Apr 15, 2021
€40,000 Comune di Palermo: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of… ITALY ·Garante ·Art. 5, 25, 32 Integrity and Confidentiality Principle Personal Data Security Apr 15, 2021
€6,000 Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (boarding school): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Convitto Nazionale Statale 'Giordano Bruno' di Maddaloni (CE) boarding school. The boarding school had published a document… ITALY ·Garante ·Art. 2, 5, 6 Education Personal Data Processing Agreement Mar 25, 2021
€4,000 Comune di Castellanza: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the municipality of Castellanza. The municipality had uploaded documents containing personal data of the data subject… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Education Mar 25, 2021
€27,700 Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) has fined the XI District Office of the Government of Budapest EUR 27,700.The controller had emailed health data regarding Covid-19 rapid tests, as well… HUNGARY ·NAIH ·Art. 32, 33, 34 Encryption Integrity and Confidentiality Principle Health Data Mar 24, 2021
€2,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The Greek DPA (HDPA) has fined a parliamentary candidate EUR 2,000. The data subject had received a call from the controller on her private mobile number prior to the Greek… GREECE ·HDPA ·Art. 11, 15 Personal Data Education Controllers Mar 22, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data IP Address Education Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet ·Art. 5, 6, 24 +1 Data Breaches Public Authority IP Address Mar 15, 2021
€1,000 School: Insufficient legal basis for data processing The Belgian DPA (APD) fined a school EUR 1,000. The controller had conducted a survey on student well-being via a smartschooling system. The DPA states that the controller did not… BELGIUM ·APD ·Art. 5, 6, 8 Education IP Address Consent Mar 15, 2021
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY ·Datatilsynet ·Art. 24, 32, 35 DPIA Data Breaches Privacy Impact Assessment Mar 15, 2021
€600,000 Municipality of Enschede: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the municipality of Enschede EUR 600,000. In 2017, the municipality decided to install special measurement boxes to measure crowds in the city center… THE NETHERLANDS ·AP ·Art. 5, 6 IP Address Education Public Authority Mar 11, 2021
€3,000 Comune di San Marco in Lamis: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,000 on the municipality of San Marco in Lamis. The municipality had uploaded documents containing personal data of the data… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Mar 11, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA ·ANSPDCP ·Art. 32, 58 Personal Data Security Controllers Mar 4, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Art. 12, 15, 31 +1 ·Insufficient fulfilment of information obligations Right of Access Procedures Right of Access Personal Data Mar 3, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA ·VDAI ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 2, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Healthcare Health Data Feb 26, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY ·Garante ·Art. 5, 25, 35 Fairness & Transparency Education DPIA Feb 25, 2021
€4,000 Ministero dell’Istruzione, Ufficio Scolastico Regionale per il Lazio: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the Lazio Region School Authority. A parent had filed a complaint against the school authority for forwarding data of… ITALY ·Garante ·Art. 5, 6, 9 Education Healthcare Public Authority Feb 25, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Data Breaches Integrity and Confidentiality Principle Security Feb 11, 2021
€350,000 Roma Capitale: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined the city of Rome EUR 350,000 for failing to take adequate technical and organizational measures regarding the data of citizens who had obtained… ITALY ·Garante ·Art. 5, 6, 28 +1 Security Education Privacy by Design & Default Feb 11, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Prior Consultation Public Authority Controllers Feb 11, 2021
€60,000 Roma Servizi per La Mobilita S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined Roma Servizi per La Mobilita S.r.l. EUR 60,000 for failing to take adequate technical and organizational measures regarding the data of citizens… ITALY ·Garante ·Art. 32 Security Controllers Processors Feb 11, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Education IP Address Personal Data Jan 27, 2021
€4,600 Anwara Sp. z.o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) fined the company Anwara Sp. z.o.o. EUR 4,600. The controller had not cooperated with the DPA and had not provided it with all the information necessary for… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Public Sector Jan 15, 2021
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY ·Garante ·Art. 5, 32 Security Controllers Education Jan 14, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Controllers Processors Processing Agreement Jan 14, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 5, 2021
€118,500 CZECH REPUBLIC DPA: Insufficient legal basis for data processing The Czech DPA (UOOU) fined 11 companies a total of EUR 118,500 for sending unrequested postal advertising messages to the mailboxes of various citizens. Based on a decision by the… UOOU ·Art. 6, 14 ·Insufficient legal basis for data processing Direct Marketing Processing Agreement Personal Data Jan 4, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Personal Data Public Authority Education Jan 1, 2021