Content type · 402 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€6,000 Azienda Ospedaliera Universitaria Careggi: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Azienda Ospedaliera Universitaria Careggi for a breach of Art. 5 GDPR and Art. 9 GDPR. Azienda Ospedaliera… ITALY · ·Art. 5, 9 Feb 25, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND · ·Art. 5, 25, 28 +1 Feb 11, 2021
€45,000 Istituti ospedalieri bergamaschi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 45,000 on Istituti ospedalieri bergamaschi. The DPA initiated an investigation against the controller after it reported a data… ITALY · ·Art. 5, 9, 32 Feb 11, 2021
€5,000 Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da Pietrelcina: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Foundation for Religion and Worship 'Casa sollievo della sofferenza' Opera di San Pio da Pietrelcina. On January… ITALY · ·Art. 5, 9 Feb 11, 2021
€75,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 27, 2021
€150,000 FRANCE DPA: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) fined a company and its subcontractor EUR 150,000 and EUR 75,000 for failing to take sufficient measures against credential stuffing attacks on the company's… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 27, 2021
€10,000 Azienda Ospedaliero Universitaria di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which… ITALY · ·Art. 5, 9 Jan 27, 2021
€30,000 Enea S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information… POLAND · ·Art. 33 Jan 11, 2021
€19,000 POLAND DPA: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of EUR 19,000 on a hospital operator. A former employee had unlawfully copied the personal data of 100 patients from the hospital's computer… ·Art. 34, 58 ·Insufficient fulfilment of data breach notification obligations Jan 5, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND · ·Art. 33, 34 Jan 5, 2021
€4M Bank: Insufficient technical and organisational measures to ensure information security Original fine summary: The Austrian DPA has imposed a fine of EUR 4,000,000 on a credit institution. The controller had stored an Excel file containing personal data, such as… AUSTRIA · ·Art. 5, 32 Jan 1, 2021
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND · ·Art. 33, 34 Dec 28, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA · ·Art. 5, 32 Dec 17, 2020
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND · ·Art. 5, 32, 33 Dec 17, 2020
€55,400 Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.): Insufficient technical and organisational measures to ensure information security The Hungarian DPA (NAIH) imposed a fine of HUF 20,500,000 (EUR 55,400) on Robinson Tours Idegenforgalmi és Szolgáltató Kft. (Robinson Tours Ltd.) The travel agent's reservation… HUNGARY · ·Art. 25, 32, 34 Dec 16, 2020
€450,000 Twitter International Company: Insufficient fulfilment of data breach notification obligations The Irish DPA (DPC) fined Twitter International Company EUR 450,000 for violating Art. 33 (1) GDPR and Art. 33 (5) GDPR for failing to notify the DPA in a timely manner of a data… IRELAND · ·Art. 33 Dec 15, 2020
€475,000 Booking.com B.V.: Insufficient fulfilment of data breach notification obligations The Dutch DPA (Autoriteit Persoonsgegevens) has fined Booking.com EUR 475,000 for not reporting a data breach to the DPA in a timely manner. In December 2018, criminals gained… THE NETHERLANDS · ·Art. 33 Dec 10, 2020
€18,850 TUiR Warta S.A.: Insufficient fulfilment of data breach notification obligations An insurance agent hired by the controller had sent an email to unauthorized third parties in regard to insurance policies that contained personal data of two of the company's… POLAND · ·Art. 33, 34 Dec 9, 2020
€394,000 City of Stockholm: Insufficient technical and organisational measures to ensure information security The Swedish DPA imposed a fine on the City of Stockholm for data breaches on a school education platform. The platform consists of different subsystems, including a system for… SWEDEN · ·Art. 5, 32 Nov 24, 2020
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Nov 19, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY · ·Art. 5, 9 Oct 26, 2020
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Oct 22, 2020
€15,000 Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found… ·Art. 5, 15, 32 +1 ·Insufficient technical and organisational measures to ensure information security Oct 19, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY · ·Art. 5, 32 Sep 3, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND · ·Art. 32 Aug 12, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY · ·Art. 32, 35 Jul 10, 2020
€3,600 Saunier-Tec Mantenimientos de Calor y Frio, SL.: Insufficient fulfilment of data breach notification obligations Although the company had taken steps to remedy a data breach, it had not informed the AEPD sufficiently. As a result, the AEPD imposed a fine of EUR 4,800, which was reduced to… SPAIN · ·Art. 33 Jul 2, 2020
€40,000 Tusla Child and Family Agency: Insufficient fulfilment of data breach notification obligations The organization sent a letter with abuse allegations to a third party who then uploaded it to social networks. IRELAND · ·Art. 33 Jun 30, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK · ·Art. 5, 6, 33 +1 Jun 30, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS · ·Art. 33 Jun 16, 2020
€1,168 Entrepreneur running a non-public nursery and pre-school: Insufficient cooperation with supervisory authority Fine for not answering requests for further information of the supervisory authority in due time following a data breach. POLAND · ·Art. 31, 58 Jun 3, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN · ·Art. 33, 34 Apr 29, 2020
€50,000 Proximus SA: Insufficient involvement of data protection officer According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not… BELGIUM · ·Art. 31, 37, 58 Apr 28, 2020
€42,000 Vodafone España, S.A.U.: Insufficient technical and organisational measures to ensure information security According to the AEPD, the company had not been able to demonstrate adequate measures to ensure information security, leading to unauthorized access to personal data of a client. SPAIN · ·Art. 5, 32 Mar 3, 2020
€65,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Lower Saxony has imposed a fine of EUR 65,000 on a company. The reason for the proceedings was a report by the company to the authority regarding a data breach pursuant… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€2,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security A third party has gained unauthorized access to another person's account. Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2020
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM · ·Art. 6, 12, 13 Dec 17, 2019
€20,000 S CNTAR TAROM SA (Airline): Insufficient technical and organisational measures to ensure information security The Romanian data protection authority imposed a sanction on an airline because it has not taken appropriate measures to ensure that any natural person acting under its… ROMANIA · ·Art. 32 Dec 4, 2019
€11,000 FAN Courier Express SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name,… ROMANIA · ·Art. 32 Nov 25, 2019
€7,400 Military Hospital: Insufficient fulfilment of data breach notification obligations A military hospital did not meet the reporting deadline for data breaches. Another part of the fine relates to a lack of technical and organisational measures. HUNGARY · ·Art. 32, 33 Oct 24, 2019
€660,000 Morele.net: Insufficient technical and organisational measures to ensure information security The Polish data protection authority imposed a fine of over PLN 2.8 million (approx. €644,780) on Morele.net for insufficient organisational and technical safeguards, which led to… POLAND · ·Art. 32 Sep 10, 2019
Deliberação 2019/494 In its Opinion 20/2018 concerning the draft of Law 58/2019 which ensures the implementation of the GDPR in the portuguese national legal framework, the DPA drew the attention of… Deliberação 2019/494 ·Portugal · Sep 3, 2019
€180,000 ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had… FRANCE · ·Art. 32 Jul 25, 2019
€3,000 LEGAL COMPANY & TAX HUB SRL: Insufficient technical and organisational measures to ensure information security The fine was imposed because adequate technical and organizational measures to ensure a level of security appropriate to the risk of processing were not implemented. This has led… ROMANIA · ·Art. 32 Jul 5, 2019
€15,150 HUNGARY DPA: Insufficient fulfilment of data breach notification obligations The data controller did not fulfil its data breach notification obligations when a flash memory with personal data was lost. ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Jun 25, 2019
€286 Directorate of Social and Child Welfare Institutions of the Ferencvaros District of Budapest: Insufficient fulfilment of data breach notification obligations The employee of the Directorate sent by mistake 9 letters to the wrong recipient, which contained personal data of 18 data subjects (including data of children, criminal data and… HUNGARY · ·Art. 33 May 21, 2019
€61,500 Payment service provider UAB MisterTango: Insufficient fulfilment of data breach notification obligations During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a… LITHUANIA · ·Art. 5, 32, 33 May 16, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY · ·Art. 32 Apr 17, 2019
€34,375 Hungarian political party: Insufficient fulfilment of data breach notification obligations NAIH imposed a fine of HUF 11,000,000 (EUR 34,375) on an undisclosed Hungarian political party for failing to notify the NAIH and relevant individuals about a data breach, and… HUNGARY · ·Art. 33, 34 Apr 5, 2019
€3,200 Mayor's Office of the city of Kecdkemét: Insufficient legal basis for data processing The fine was imposed on the Mayor’s Office of the city of Kecskemét for unlawful disclosure of the personal information of a whistleblower.NAIH imposed the fine after an employee… HUNGARY · ·Art. 5, 6 Feb 28, 2019