Skip to content
Content type · 622 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 622 sort newestlargest fineoldest
€215,000 Humboldt Forum Service GmbH: Insufficient legal basis for data processing The DPA of Berlin has imposed fines totaling EUR 215,000 on Humboldt Forum Service GmbH. Humboldt Forum had improperly documented sensitive information about individual employees… GERMANY ·Insufficient legal basis for data processing Employees Controllers Fines Jan 1, 2023
€9,000 Magdeburg University Hospital: Insufficient fulfilment of data breach notification obligations The DPA of Sachsen-Anhalt has imposed a fine of EUR 9,000 on Magdeburg University Hospital. The clinic had failed to report to the DPA a data breach involving a former employee… GERMANY ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 1, 2023
€3,600 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records containing patient data in a public waste disposal site. GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Jan 1, 2023
€400 MAE WEST SYSTEMS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined MAE WEST SYSTEMS, S.L. EUR 400. The controller had installed video surveillance in a bar it operated without providing sufficient information… SPAIN ·AEPD ·Art. 13 Controllers Supervisory Authorities Video Surveillance Dec 28, 2022
€122,000 Company: Insufficient legal basis for data processing The Finnish DPA has imposed a fine of EUR 122,000 on a company with products that process health data, such as heart rate, etc. The DPA had received several complaints regarding… FINLAND ·Deputy Data Protection Ombudsman ·Art. 9 Healthcare Consent Types of Special Categories of Personal Data Dec 27, 2022
€100,000 VIEC Limited: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… IRELAND ·DPC ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 22, 2022
€8,000 Hotel: Insufficient legal basis for data processing The Hungarian DPA has imposed a fine of EUR 8,000 on a hotel. The controller had installed video surveillance cameras that covered the dining room and a whirlpool area permanently… HUNGARY ·NAIH ·Art. 5, 6, 12 +2 Controllers Supervisory Authorities Processing Dec 21, 2022
€55,000 Azienda Universitaria Friuli Centrale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Centrale. The health authority has created patient profiles using algorithms and personal patient… ITALY ·Garante ·Art. 2, 5, 9 +2 Healthcare DPIA Profiling Dec 15, 2022
€3,000 Scuola Statale Secondaria di I^ grado 'Bianco-Pascol': Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the school 'Scuola Statale Secondaria di I^ grado 'Bianco-Pascoli', di Fasano (BR)'. The educational institution had published a… ITALY ·Garante ·Art. 2, 5, 6 +2 Healthcare Types of Special Categories of Personal Data Supervisory Authorities Dec 15, 2022
€120,000 Eurosanità S.P.A.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 120,000 on Eurosanità S.P.A.. The controller operates various healthcare facilities. An individual had filed a complaint with the DPA for… ITALY ·Garante ·Art. 5, 9, 32 Security Healthcare Controllers Dec 15, 2022
€55,000 Azienda Universitaria Friuli Occidentale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Occidentale. The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Healthcare DPIA Marketing Dec 15, 2022
€16,000 HOSPITAL RECOLETAS PONFERRADA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on the healthcare facility HOSPITAL RECOLETAS PONFERRADA, S.L.. A patient had filed a complaint with the DPA. The patient had filled out a… SPAIN ·AEPD ·Art. 6, 15 Personal Data Consent Controllers Dec 15, 2022
€6,000 Comune di Bracciano: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on Comune di Bracciano. A former employee had filed a complaint with the DPA due to the fact, that the municipality had published a… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Dec 15, 2022
€55,000 Azienda Universitaria Giuliano Isontina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Healthcare DPIA Profiling Dec 15, 2022
€230,000 Viking Line Oy Abp: Non-compliance with general data processing principles The Finnish DPA has imposed a fine of EUR 230,000 on Viking Line Oy Abp. A former employee had filed a complaint with the DPA. During its investigation, the DPA found that the… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 12, 13 +2 Personal Data Controllers Supervisory Authorities Dec 9, 2022
€3,600 Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM: Insufficient legal basis for data processing The Spanish DPA has fined the Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM. The controller processed medical data from Covid-19… SPAIN ·AEPD ·Art. 9, 13 Healthcare Controllers Consent Dec 2, 2022
€6,000 A.R.N.A.S. Civico: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on A.R.N.A.S. Civico. Two employees of the controller had filed a complaint with the DPA. During its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Controllers Dec 1, 2022
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Consent Personal Data Types of Special Categories of Personal Data Nov 30, 2022
€1,991 Company in the hospitality industry: Insufficient fulfilment of information obligations The Croation DPA (azop) has imposed a fine of EUR 1,991 on a company in the hospitality industry. The controller had installed a video surveillance system in its premises, however… CROATIA ·AZOP ·Art. 27 Controllers Monitoring Video Surveillance Nov 25, 2022
€3,000 Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Board of Surgeons and Dentists of the Province of Cagliari. The controller had disclosed data of a doctor to third parties… ITALY ·Garante ·Art. 2, 5, 6 Controllers Processing Healthcare Nov 24, 2022
€4,000 Società Lombarda Sport s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Società Lombarda Sport s.r.l. EUR 4,000. An individual had filed a complaint with the DPA. The individual had undergone a sports fitness examination with… ITALY ·Garante ·Art. 5, 9 Healthcare Processing Supervisory Authorities Nov 24, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Personal Data Security Nov 24, 2022
€3,600 XASTRE DO PETO, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 3,600 on XASTRE DO PETO, S.L. (restaurant). An individual had filed a complaint with the DPA due to the fact that the controller required… SPAIN ·AEPD ·Art. 6, 13, 21 Personal Data Controllers Processing Nov 11, 2022
€15,000 Poliambulatorio Radiologico 'il Sorriso' S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Poliambulatorio Radiologico 'il Sorriso' S.r.l.. A patient had filed a complaint with the DPA for not receiving sufficient… ITALY ·Garante ·Art. 5, 13, 37 Personal Data Controllers Supervisory Authorities Nov 10, 2022
€40,000 Azienda Usl Valle d'Aosta: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Usl Valle d'Aosta EUR 40,000. An employee and patient of the health department had filed a complaint with the DPA because a colleague who had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Privacy by Design & Default Security Nov 10, 2022
€1,000 SC Das Sense Society SRL: Insufficient cooperation with supervisory authority The Romanian DPA (ANSPDCP) has fined SC Das Sense Society SRL EUR 1,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Personal Data Nov 9, 2022
€60,000 INFORMÁTICA MÉDICA, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 60,000 on INFORMÁTICA MÉDICA, S.L.. The company acted as a processor for other companies and had engaged a subcontractor without,… SPAIN ·AEPD ·Art. 28 Processors Controllers Supervisory Authorities Nov 7, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD (PT) ·Art. 5, 9, 12 +5 Privacy Shield Controllers DPIA Nov 2, 2022
€7,000 I.S.P.R.O.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the oncology health care facility I.S.P.R.O.. An individual had mistakenly received medical records from another… ITALY ·Garante ·Art. 5, 9 Healthcare Processing Health Data Oct 20, 2022
€9,000 Azienda Ospedaliero-Universitaria Careggi di Firenze: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 9,000 on Azienda Ospedaliero-Universitaria Careggi di Firenze. The controller had mistakenly sent a patient medical record to the wrong… ITALY ·Garante ·Art. 5, 9, 32 Security Controllers Personal Data Oct 20, 2022
€5,000 Fondazione Teatro Regio di Torino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Fondazione Teatro Regio di Torino. A foundation member had filed a complaint with the DPA due to the fact, that the foundation… ITALY ·Garante ·Art. 2, 5, 6 Types of Special Categories of Personal Data Processing Health Data Oct 20, 2022
€5,000 RESTEXPERIENCE, S.L.: Non-compliance with general data processing principles The Spanish DPA has fined RESTEXPERIENCE, S.L. EUR 5,000. The controller had accidentally sent an email containing tax information of 36 individuals to 11 unauthorized… SPAIN ·AEPD ·Art. 5, 32 Integrity and Confidentiality Principle Security Controllers Oct 19, 2022
€100,000 Veneto region: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 100,000 on the Veneto Region. The DPA had received a complaint from dozens of medical and nursing staff. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 Processing Public Authority Healthcare Oct 6, 2022
€1.5M Easylife Ltd.: Insufficient legal basis for data processing The UK DPA has imposed a fine of EUR 1,547,000 on Easylife Ltd. Easylife is a retailer that sells household items as well as services and products under its health, motor,… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +1 Personal Data Healthcare Types of Special Categories of Personal Data Oct 4, 2022
Danish DPA reprimands Region Syddanmark for inadequate processor audit procedures The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Denmark ·Datatilsynet (DK) Processors Controllers Supervisory Authorities
€1,200 Health insurance provider: Non-compliance with general data processing principles The Hungarian DPA has imposed a fine of EUR 1,200 on a health insurance provider. The insurer had published the result of a Covid-19 test of the data subject on its website. This… HUNGARY ·NAIH ·Art. 5, 12, 31 Personal Data Insurance Supervisory Authorities Sep 25, 2022
€100,000 Lazio Region: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Lazio Region. An individual had filed a complaint with the DPA because she had received an invitation from the regional health… ITALY ·Garante ·Art. 5, 6, 9 +4 Personal Data Supervisory Authorities Healthcare Sep 15, 2022
€180 EURO DONER KEBAB: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on EURO DONER KEBAB. The controller had installed video surveillance cameras which, among other things, also covered the public space.… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Personal Data Sep 9, 2022
€20,000 Medical laboratory: Insufficient technical and organisational measures to ensure information security The Belgian DPA imposed a fine of EUR 20,000 on a medical laboratory. During its investigation, the DPA found that the laboratory had failed to conduct a data protection impact… BELGIUM ·APD/GBA ·Art. 5, 12, 13 +3 Encryption DPIA Security Aug 19, 2022
€600,000 ACCOR SA: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has imposed a fine of EUR 600,000 on ACCOR SA. Both CNIL and other European DPAS had received complaints against ACCOR from several individuals. In the… FRANCE ·CNIL ·Art. 12, 13, 15 +2 Right to Object Direct Marketing Right of Access Aug 19, 2022
€6,700 Lolland municipiality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on Lolland municipiality. The municipality had reported a data breach to the DPA in accordance with Art. 33 GDPR. One of the… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Aug 11, 2022
€600 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on a restaurant owner. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Aug 8, 2022
€30,000 Private Polyclinic and Diagnostic Centre of Pyle Axiou: Non-compliance with general data processing principles The Hellenic DPA has fined Private Polyclinic and Diagnostic Centre of Pyle Axiou EUR 30,000. A patient had requested access to data from an imaging examination. Due to lack of… GREECE ·HDPA ·Art. 5 Processing Healthcare Supervisory Authorities Aug 3, 2022
€9,600 LAST LAP, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on LAST LAP, S.L.. Last Lap organizes the San Silvestre road running race. Race participants were required to show their vaccination certificate… SPAIN ·AEPD ·Art. 6, 9 Healthcare Types of Special Categories of Personal Data Processing Aug 1, 2022
€3,000 Azienda Socio Sanitaria Territoriale Rhodense: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Socio Sanitaria Territoriale Rhodense EUR 3,000. The healthcare facility had reported the loss of a patient's medical record. The file contained… ITALY ·Garante ·Art. 5, 32 Security Personal Data Privacy by Design & Default Jul 21, 2022
€5,000 Bar owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a bar owner EUR 5,000. The owner had unlawfully shared recordings from the CCTV in the bar via WhatsApp and other social media platforms. SPAIN ·AEPD ·Art. 5 Processing Video Surveillance Social Media Jul 19, 2022
Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022) During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Belgium ·APD/GBA Health Data Healthcare Types of Special Categories of Personal Data Jul 19, 2022
€202,000 Manx Care Ltd: Non-compliance with general data processing principles The DPA of Isle of Man has imposed a fine of EUR 202,000 on Manx Care Ltd. Manx Care had emailed an unsecured attachment containing a patient's confidential health information to… ISLE OF MAN ·Art. 5, 24, 25 +3 ·Non-compliance with general data processing principles Data Breaches Retention Period Privacy by Design & Default Jul 13, 2022
€132,000 DKV Seguros y Reaseguros, S.A.E.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DKV Seguros y Reaseguros, S.A.E.. An individual had filed a complaint with the DPA after receiving multiple e-mails from the controller… SPAIN ·AEPD ·Art. 5, 32, 33 Data Breaches Security Controllers Jul 13, 2022
€1,500 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 1,500 on a physician. A patient had asked the doctor to send her complete medical records, such as imaging records as well as consent… HUNGARY ·NAIH ·Art. 5, 12, 13 Personal Data Consent Supervisory Authorities Jul 8, 2022