Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3451–3500 of 3,651 sort newestlargest fineoldest
€10,000 Clearview AI Inc.: Insufficient cooperation with supervisory authority The DPA from Hamburg has fined Clearview AI Inc. EUR 10,000 for failing to provide information requested by the DPA during an investigation. GERMANY ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Processing Agreement Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Scientific Research Processing Supervisory Authorities Jan 1, 2020
€2,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security A third party has gained unauthorized access to another person's account. Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Data Breaches Security Jan 1, 2020
Corporation: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. GERMANY ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security IP Address Jan 1, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers IP Address Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Supervisory Authorities Jan 1, 2020
€10,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Jan 1, 2020
Ski rental company: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 5, 6, 7 +9 IP Address Controllers Personal Data Jan 1, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 5, 12, 28 Health Data Healthcare Healthcare Jan 1, 2020
Municipality: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 5, 6, 13 +1 Education Public Authority IP Address Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security Accidental loss of personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Processing Agreement Jan 1, 2020
€150,000 Aegean Marine Petroleum Network Inc.: Insufficient technical and organisational measures to ensure information security Companies outside the Aegean Marine Petroleum Group had access to its servers containing personal data and copied the contents of the servers, since Aegean Marine Petroleum failed… GREECE ·HDPA ·Art. 5, 6, 32 Security Privacy by Design & Default Personal Data Dec 19, 2019
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Telecommunications Security Dec 18, 2019
DSB (Austria) - D123.768/0004-DSB/2019 The complainant belongs to a political party and is a member of the city council of an Austrian municipality. In November, the municipality held a meeting on the "parking space… DSB-D123.768/0004-DSB/201 ·Art. 4, 85 Personal Data Social Media Legitimate Interest Dec 18, 2019
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM ·ICO ·Art. 32 Healthcare Healthcare Liability Dec 17, 2019
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM ·APD ·Art. 6, 12, 13 Personal Data Consent Telecommunications Dec 17, 2019
€2,000 Nursing Care Organisation: Insufficient fulfilment of data subjects rights The company failed to act on requests from the data subject to get access to his data and to have his data erased. BELGIUM ·APD ·Art. 12, 15, 17 Personal Data Supervisory Authorities Law Enforcement Dec 17, 2019
€6,000 SC Enel Energie S.A. (Electricity Distributor): Insufficient legal basis for data processing The sanctions were imposed following a complaint alleging that Enel Energie had unlawfully processed an individual's personal data and was unable to prove that it had obtained the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Right to Object Fines Personal Data Dec 16, 2019
€35,000 Nusvar AB: Insufficient legal basis for data processing Nusvar AB, operator of the website Mrkoll.se, which provides information on all Swedes over 16 years of age, had published information on people who are overdue. SWEDEN ·Art. 6 ·Insufficient legal basis for data processing Processing Supervisory Authorities Dec 16, 2019
€2,000 Globus Score SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Dec 16, 2019
€2,000 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused provided the data subject with access to their personal data only after being requested to do so by… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Supervisory Authorities Processing Agreement Dec 13, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company has excessively processed the personal data of his employees through the video cameras installed in the offices and in the places where there are cabinets where the… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 Employees IP Address Personal Data Dec 13, 2019
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company processed biometric data (fingerprints) of the employees for access to certain rooms tough less intrusive means for the privacy of the data subjects could be used… ROMANIA ·ANSPDCP ·Art. 5, 6, 7 +1 Employees Special Categories of Data Biometric Data Dec 13, 2019
€1,430 Unknown Company: Non-compliance with general data processing principles The employer restored the mailbox of a director who had left the company a year before and found an email containing a work-related document. The director received no warning that… HUNGARY ·NAIH ·Art. 5, 6, 13 +2 Representatives Archiving IP Address Dec 11, 2019
€8.5M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6, 17 +1 Fines Integrity and Confidentiality Principle Personal Data Dec 11, 2019
€3M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Garante ·Art. 5, 6 Fines Integrity and Confidentiality Principle Personal Data Dec 11, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Fines Security Dec 10, 2019
€1,600 Megastar SL: Non-compliance with general data processing principles The company operated a video surveillance system in which the observation angle of the cameras extended unnecessarily far into the public traffic area. Furthermore, no sign with… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Monitoring IP Address Dec 10, 2019
€5,000 Shop Macoyn, S.L.: Insufficient technical and organisational measures to ensure information security The company has sent advertising e-mails to several recipients where the e-mail addresses of all other recipients were visible to all recipients, because the recipient addresses… SPAIN ·aepd ·Art. 32 Recipient IP Address Direct Marketing Dec 10, 2019
€10,000 Rapidata GmbH: Insufficient involvement of data protection officer Despite repeated requests of the BfDI the company (an internet provider) did not comply with its legal obligation under Article 37 GDPR to appoint a data protection officer. GERMANY ·BfDI ·Art. 37 Telecommunications Supervisory Authorities Dec 9, 2019
€20,000 S CNTAR TAROM SA (Airline): Insufficient technical and organisational measures to ensure information security The Romanian data protection authority imposed a sanction on an airline because it has not taken appropriate measures to ensure that any natural person acting under its… ROMANIA ·ANSPDCP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Dec 4, 2019
€1,500 Cerrajeria Verin S.L.: Insufficient fulfilment of information obligations The company collected personal data without providing accurate information on their data processing activities in their privacy policy published on their website. SPAIN ·aepd ·Art. 13 Personal Data Processing Supervisory Authorities Dec 3, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2019
€5,000 Linea Directa Aseguradora: Insufficient legal basis for data processing The insurance company has sent advertising e-mails for the 'Reto Nuez' platform without the required consent. SPAIN ·aepd ·Art. 6 Insurance Direct Marketing Consent Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Healthcare Dec 2, 2019
€2,500 Royal President S.R.L.: Insufficient fulfilment of data subjects rights Royal President refused a request for access to personal data pursuant to Article 15 of the GDPR and disclosed personal data without the consent of the data subjects. In addition,… ROMANIA ·ANSPDCP ·Art. 6, 15, 32 Right of Access Personal Data Consent Nov 29, 2019
€500 Homeowners Association: Insufficient technical and organisational measures to ensure information security The association used video surveillance systems without proper information according to Art. 13 GDPR and without adequate security measures regarding the persons having access to… ROMANIA ·ANSPDCP ·Art. 32 Video Surveillance Security Monitoring Nov 29, 2019
€75,000 Curenergía Comercializador de último recurso: Insufficient legal basis for data processing An individual filed a complaint against the company alleging that the company had used its personal data as a former customer, such as first and last name, VAT identification… SPAIN ·aepd ·Art. 6 Personal Data Processing Identification Nov 28, 2019
€5,000 Mayor: Insufficient legal basis for data processing Fine for sending election mailings without a sufficient legal basis. The e-mail addresses used have not been collected for this purpose. BELGIUM ·APD ·Art. 6 Education Processing Public Authority Nov 28, 2019
€5,000 Municipal alderman: Insufficient legal basis for data processing Fine for sending election mailings without a sufficient legal basis. The e-mail addresses used have not been collected for this purpose. BELGIUM ·APD ·Art. 6 Education IP Address Public Authority Nov 28, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Processing Nov 28, 2019
€3,000 Modern Barber: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Nov 26, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA ·ANSPDCP ·Art. 32 Right of Access Security Personal Data Nov 25, 2019
€2,000 BNP Paribas Personal Finance S.A.: Insufficient fulfilment of data subjects rights BNP Paribas Personal Finance did not react to a request for erasure within the period set by the GDPR. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Insurance Processing Nov 22, 2019
€60,000 Viaqua Xestión Integral Augas de Galicia: Insufficient legal basis for data processing Processing (modification) of the personal data of a customer included in a contract by a third party without the consent of the customer. SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Nov 21, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE ·CNIL ·Art. 5, 6, 13 +4 Personal Data Healthcare Processing Nov 21, 2019
€6,000 Sports Bar: Non-compliance with general data processing principles The sports bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. SPAIN ·aepd ·Art. 5 Video Surveillance Monitoring IP Address Nov 19, 2019