Skip to content
Content type · 3,833 documents in this view · 3,838 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

3601–3650 of 3,833 sort newestlargest fineoldest
€75,000 EDP Comercializadora, S.A.U.: Insufficient legal basis for data processing The company processed personal data in connection with a gas contract without the consent of the applicant. The decision finds that the applicant received an invoice for a gas… SPAIN ·AEPD ·Art. 6 Personal Data Consent Processing Jan 7, 2020
€5,110 Utility Company: Insufficient legal basis for data processing The fine of EUR ca. 5,113 was imposed on a Bulgarian utility company for unlawful processing of the personal data of the data subject V.V. The personal data of V.V. was unlawfully… BULGARIA ·CPDP ·Art. 6 Personal Data Integrity and Confidentiality Principle Liability Jan 6, 2020
€300 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Fairness & Transparency Jan 1, 2020
Bank: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 21, 23, 48 Processing Insurance Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·HmbBfDI ·Art. 32 Security Healthcare Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·HmbBfDI ·Art. 5 Retention Period Processing Video Surveillance Jan 1, 2020
Public university: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 13 Personal Data Public Authority Education Jan 1, 2020
€4,100 LIECHTENSTEIN DPA: Non-compliance with general data processing principles Unlawful operation of a video surveillance system. Non-compliance with general data processing principles Supervisory Authorities Monitoring Video Surveillance Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2020
€2,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security A third party has gained unauthorized access to another person's account. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Integrity and Confidentiality Principle Jan 1, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2020
€300 Employee at a Covid 19 testing center: Non-compliance with general data processing principles An employee at a Covid 19 testing center used the data of a tested person to contact them via WhatsApp for private purposes. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Processing Supervisory Authorities Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Fairness & Transparency Jan 1, 2020
€3,850 Television broadcaster: Insufficient fulfilment of information obligations A TV broadcaster had provided information on its website about the processing of personal data, which was however hidden and inaccurate (links to outdated legal provisions). CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Telecommunications Processing Jan 1, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ÚOOÚ (CZ) ·Art. 5 ·Insufficient legal basis for data processing Processing Supervisory Authorities Employees Jan 1, 2020
Operator of a ballet school: Insufficient legal basis for data processing The operator of a ballet school had published photos of underage students on their website and Facebook page without the consent of the legal guardians. GERMANY ·Art. 5, 6, 7 ·Insufficient legal basis for data processing Consent Processing Education Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security Accidental loss of personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities Jan 1, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 12, 28 Personal Data Health Data Healthcare Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·HmbBfDI ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 1, 2020
€2,700 Mall.tv: Insufficient legal basis for data processing The Czech DPA (UOOU) fined Mall.tv EUR 2,700 for recording parts of the public space without a legal basis. The subject of the DPA's investigation was the operation of two cameras… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6 Identification Processing Telecommunications Jan 1, 2020
Ski rental company: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 7 +9 Personal Data Controllers Consent Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 24, 32 Security Health Data Privacy by Design & Default Jan 1, 2020
€1,900 CZECH REPUBLIC DPA: Insufficient fulfilment of data subjects rights A person had received an invoice for ordered goods, which, however, came from a different company than the one from which she had ordered the goods. Therefore, the data subject… ÚOOÚ (CZ) ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Controllers Jan 1, 2020
CZECH REPUBLIC DPA: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) ÚOOÚ (CZ) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Processing Supervisory Authorities Jan 1, 2020
Municipality: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 13 +1 Public Authority Processing Education Jan 1, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Jan 1, 2020
€19,200 CZECH REPUBLIC DPA: Non-compliance with general data processing principles A company copied personal data from public registers, which was considered illegal by the Czech DPA, as it was not deemed necessary. ÚOOÚ (CZ) ·Art. 5, 6, 12 +8 ·Non-compliance with general data processing principles Supervisory Authorities Personal Data Processing Jan 1, 2020
€8,000 LITHUANIA DPA: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) fined a company EUR 8,000 for conducting sound recordings on public transport buses in violation of Article 5 GDPR, Article 13 GDPR, Article 24 GDPR and… VDAI ·Art. 5, 13, 24 +1 ·Non-compliance with general data processing principles Supervisory Authorities DPIA Accountability Jan 1, 2020
€7,000 GERMANY DPA: Insufficient cooperation with supervisory authority The Bavarian DPA has imposed a fine on a company. The controller had refused access to the business premises and data processing equipment during an on-site inspection carried out… Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Jan 1, 2020
Police officer: Insufficient legal basis for data processing Several cases in which police officers have accessed data in a police database for private research purposes. GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Processing Scientific Research Supervisory Authorities Jan 1, 2020
€10,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·Art. 5 ·Non-compliance with general data processing principles Retention Period Processing Video Surveillance Jan 1, 2020
Medical assistant: Insufficient legal basis for data processing A medical assistant at a doctor's office stored a patient's telephone number in her mobile phone and then contacted him for private purposes. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Healthcare Processing Supervisory Authorities Jan 1, 2020
Corporation: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. GERMANY ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities Jan 1, 2020
€10,000 Clearview AI Inc.: Insufficient cooperation with supervisory authority The DPA from Hamburg has fined Clearview AI Inc. EUR 10,000 for failing to provide information requested by the DPA during an investigation. GERMANY ·HmbBfDI ·Art. 58 Supervision Supervisory Authorities Jan 1, 2020
€400 Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer has accessed data in a police database for private research purposes. GERMANY ·HmbBfDI ·Art. 5, 6 Processing Scientific Research Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·HmbBfDI ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 1, 2020
Police officer: Insufficient legal basis for data processing A police officer took photos of an official presentation that contained personal data and shared them in a Whats App group. GERMANY ·HmbBfDI ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 1, 2020
Company: Insufficient technical and organisational measures to ensure information security The DPA from Hamburg has issued a fine against a company that operates an online marketplace, especially for worn underwear. The company advertises that it guarantees one hundred… GERMANY ·HmbBfDI ·Art. 6, 32 Security Personal Data Privacy by Design & Default Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·HmbBfDI ·Art. 32 Security Healthcare Supervisory Authorities Jan 1, 2020
Restaurant: Insufficient technical and organisational measures to ensure information security In order to combat the Covid 19 pandemic, a restaurant had put out an open list in which visitors had to enter their contact data. The fact that the list was openly displayed… GERMANY ·HmbBfDI ·Art. 32 Security Healthcare Supervisory Authorities Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·HmbBfDI ·Art. 26 Personal Data Processing Agreement Supervisory Authorities Jan 1, 2020
€150,000 Aegean Marine Petroleum Network Inc.: Insufficient technical and organisational measures to ensure information security Companies outside the Aegean Marine Petroleum Group had access to its servers containing personal data and copied the contents of the servers, since Aegean Marine Petroleum failed… GREECE ·HDPA ·Art. 5, 6, 32 Personal Data Security Processing Dec 19, 2019
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Telecommunications Dec 18, 2019
The complainant belongs to a political party and is a member of the city council of an Austrian municipality In November, the municipality held a meeting on the "parking space concept", to which a certain group of addressees, including the complainant, was invited. The complainant did… DSB-D123.768/0004-DSB/201 ·Austria ·DSB Public Authority Pseudonymization Anonymization Dec 18, 2019
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM ·ICO ·Art. 32 Security Liability IP Address Dec 17, 2019