Skip to content
Content type · 950 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 950 sort newestlargest fineoldest
€358,000 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted… UODO ·Art. 5, 25, 28 +1 ·Insufficient technical and organisational measures to ensure information security Encryption Security Processing Agreement Nov 20, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period Monitoring Nov 20, 2024
€4,700 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4,700 on a subcontractor that was contracted to redesign the website of another company. This fine is linked to ETid-2491. Due to an error… UODO ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Privacy by Design & Default Nov 20, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Video Surveillance Security IP Address Nov 13, 2024
€678,897 Illumia Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints… ITALY ·Garante ·Art. 5, 6, 7 +4 Security Processing Agreement Privacy by Design & Default Nov 13, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Nov 12, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN ·aepd ·Art. 5, 32 Security IP Address Privacy by Design & Default Nov 11, 2024
€5,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA fined Vodafone Romania S.A. EUR 5,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Telecommunications Security IP Address Oct 28, 2024
€20,800 Grue municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA fined Grue municipality EUR 20,800 following the municipality's notification of a data breach. The municipality reported that personal data of students had been… NORWAY ·Datatilsynet ·Art. 24, 32 Data Breaches Security Education Oct 21, 2024
€9,000 Vilnius District Municipality Administration: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has imposed a fine of EUR 1,000 on the Vilnius District Municipality Administration. The Municipality Administration had been hacked. The attack resulted in… LITHUANIA ·VDAI ·Art. 5, 32, 34 Public Authority Security Public Sector Oct 18, 2024
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Your Consulting SRL. The controller had suffered a data breach involving the unauthorized disclosure of personal data. During… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Oct 16, 2024
€91M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 91 million on Meta Platforms Ireland Limited (MPIL). The DPC had initiated an investigation after MPIL reported that user passwords… Encryption Data Breaches Security Sep 27, 2024
€904,000 Police Service of Northern Ireland: Insufficient technical and organisational measures to ensure information security The ICO fined the Police Service of Northern Ireland £750,000 (EUR 904,000) after accidentally publishing personal data of 9,483 police officers and staff on the internet. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Personal Data Education Sep 26, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·aepd ·Art. 5 Telecommunications Security IP Address Sep 26, 2024
€3,000 Constanța South Container Terminal SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Constanța South Container Terminal SRL. The controller had suffered a data breach in which personal data of employees had been… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Sep 17, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·azop ·Art. 5, 6, 12 +4 Data Breaches Healthcare Healthcare Sep 13, 2024
€12,700 University of Agder: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the University of Agder (UiA) EUR 12,700. An employee of UiA had discovered that documents containing personal data of employees, students and external… NORWAY ·Datatilsynet ·Art. 24, 32 Personal Data Education Security Sep 4, 2024
€698,000 Apohem AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 698,000 on Apohem AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Social Media Security Healthcare Aug 29, 2024
€3.2M Apoteket AB.: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 3.2 million on Apoteket AB. The controller had used so-called meta pixels on its website which, due to incorrect settings, caused… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Social Media Security Healthcare Aug 29, 2024
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Aug 20, 2024
€26,800 Municipality of Vejen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 26,800 on the municipality of Vejen. The municipality had suffered a security incident involving the theft of three unencrypted computers… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Encryption Security Public Authority Aug 14, 2024
€270,000 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA. An individual who provided services to the controller filed a complaint with the DPA due to the fact… SPAIN ·aepd ·Art. 5, 32 Controllers Personal Data IP Address Aug 12, 2024
€5M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5 million on Hera Comm S.p.A. The investigation was launched following numerous complaints. The energy supplier had failed to take… ITALY ·Garante ·Art. 5, 12, 15 +3 IP Address Data Subject Rights Exercise Modalities and Procedures Processing Agreement Jul 17, 2024
€30,000 Pere Sihtkapital SA: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 30,000 on Pere Sihtkapital SA. The controller conducted a survey on childless families. In the process, the controller failed to take all… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Jul 15, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Criminal Data Security Health Data Jul 4, 2024
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA ·VDAI ·Art. 5, 12 Inspection Access Rights and Cooperation Obligations Fairness & Transparency Right of Access Procedures Jul 2, 2024
€50,000 METRO SA: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 50,000 on METRO SA. A former employee had sent text messages to the private mobile phone of a customer who had a user account in the… GREECE ·HDPA ·Art. 15, 17, 24 +2 Security Controllers Privacy by Design & Default Jun 27, 2024
€80,000 AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A. y SEUR GEOPOST, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A. y SEUR GEOPOST, S.L.. The controller had suffered a security incident which, according to… SPAIN ·aepd ·Art. 32 Security Processing Agreement Controllers Jun 26, 2024
€1,000 Rețele Electrice Dobrogea SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Rețele Electrice Dobrogea SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default Controllers Jun 25, 2024
€3,000 Rețele Electrice Muntenia SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Rețele Electrice Muntenia SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default Controllers Jun 25, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Insurance Jun 24, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND ·UODO ·Art. 24, 25, 32 +1 Security Healthcare Health Data Jun 13, 2024
€160,000 ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A person had filed a complaint with the DPA because their ex-partner had been given… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Insurance Jun 10, 2024
€100,000 Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data… AUSTRIA ·dsb ·Art. 5, 9, 28 +2 Data Breaches Controllers Processors Jun 6, 2024
€4,200 PILLOW HOTELS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PILLOW HOTELS, S.L.. A person had filed a complaint with the DPA. The individual had made a booking for an overnight stay with the controller… SPAIN ·aepd ·Art. 5, 32, 33 Data Breaches Controllers IP Address May 30, 2024
€400,000 Ministry of Interior (Greece): Insufficient technical and organisational measures to ensure information security The Hellenic DPA imposed a fine of EUR 400,000 on the Ministry of Interior for leaking email addresses from the voter registry of Greek expatriates. These personal data, which… HDPA ·Art. 5 ·Insufficient technical and organisational measures to ensure information security Personal Data Education Security May 27, 2024
€15,000 Association: Non-compliance with general data processing principles The French DPA has fined an association EUR 15,000 due to a lack of data security, non-compliance with the principle of data minimisation and a failure to comply with its… FRANCE ·CNIL ·Non-compliance with general data processing principles Retention Period IP Address Security May 25, 2024
€10,000 Association: Non-compliance with general data processing principles The French DPA has fined an association EUR 10,000 due to a lack of data security, non-compliance with the principle of data minimisation and a failure to comply with its… FRANCE ·CNIL ·Non-compliance with general data processing principles Retention Period Security IP Address May 25, 2024
€336,000 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 336,000 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During… POLAND ·UODO ·Art. 5, 32 Security Privacy by Design & Default Healthcare May 20, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA ·ANSPDCP ·Art. 32 Healthcare Healthcare Health Data May 9, 2024
€2,000 IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the… ROMANIA ·ANSPDCP ·Art. 32 IP Address Security Controllers May 9, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·aepd ·Art. 32, 33 Data Breaches Security Health Data May 8, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Healthcare May 8, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… aepd ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement May 7, 2024
€8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… UNITED KINGDOM ·ICO ·Art. 5, 32 IP Address Security Controllers Apr 30, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Data Breaches Encryption Security Apr 29, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Personal Data Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Apr 23, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·aepd ·Art. 6 Processing Agreement Insurance Consent Apr 12, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN ·aepd ·Art. 5, 32 IP Address Security Insurance Apr 12, 2024