Skip to content
Content type · 408 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 408 sort newestlargest fineoldest
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 28, 2020
€36,000 Banco Bilbao Vizcaya Argentaria, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Dec 21, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Security Personal Data Dec 17, 2020
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… UODO ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Privacy by Design & Default Controllers Dec 17, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… NAIH ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Supervisory Authorities Retention Period Personal Data Dec 16, 2020
€5M Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Banco Bilbao Vizcaya Argentaria, S.A. EUR 5,000,000 for violating Art. 6 GDPR (EUR 3,000,000) and Art. 13 GDPR (EUR 2,000,000). The bank had not… SPAIN ·AEPD ·Art. 6, 13 Personal Data Consent Supervisory Authorities Dec 11, 2020
€18,850 TUiR Warta S.A.: Insufficient fulfilment of data breach notification obligations An insurance agent hired by the controller had sent an email to unauthorized third parties in regard to insurance policies that contained personal data of two of the company's… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 9, 2020
€10,000 Losada Advocats S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine on Losada Advocats S.L. for sending an e-mail to dozens of recipients without putting them on the Blind Carbon Copy (BCC) list, thus… SPAIN ·AEPD ·Art. 5, 32 Security Insurance Supervisory Authorities Dec 2, 2020
€800,000 Carrefour Banque: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine on Carrefour Banque for violation of its obligation to process data fairly (Article 5 (1) GDPR). If a person who subscribed to the Pass card… FRANCE ·CNIL ·Art. 5 Accountability Processing Insurance Nov 18, 2020
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Controllers Pseudonymization Healthcare Nov 5, 2020
€15,000 Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found… Cyprus DPA ·Art. 5, 15, 32 +1 ·Insufficient technical and organisational measures to ensure information security Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 19, 2020
€50,000 Centro de Investigación y Estudio para la Obesidad, SL: Insufficient legal basis for data processing Fines for the transfer of the data subject's personal data to Evo Finance EFC, SA in the course of processing a health insurance application, without a sufficient legal basis for… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Insurance Oct 9, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The complainant, through her attorney, requested access to her personal data. The accused failed to respond, even… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Insurance Aug 31, 2020
€50,000 Bankia S.A.: Non-compliance with general data processing principles The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this… SPAIN ·AEPD ·Art. 5 Personal Data Processing Insurance Aug 28, 2020
€100 Bank: Insufficient legal basis for data processing A bank employee made a copy of the identity card of a bank client who wanted to exchange EUR 100 in foreign currency and justified this with money laundering charges. However,… AUSTRIA ·DSB ·Art. 5, 6 Processing Insurance Supervisory Authorities Aug 5, 2020
€7,000 Acc Consulting Varsinais-Suomi: Insufficient legal basis for data processing Unsolicited marketing SMS without prior consent FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6 Consent Processing Direct Marketing Aug 5, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Insurance Supervision Jul 30, 2020
€24,000 Banco Bilbao Vizcaya Argentaria, SA: Insufficient legal basis for data processing BBVA had no legitimate basis for processing the data of the data subject and had therefore infringed Article 6(1) of the GDPR, since the company processed solvency and credit… SPAIN ·AEPD ·Art. 5, 6 Personal Data Processing Insurance Jul 20, 2020
€830,000 Bureau Krediet Registration ('BKR'): Insufficient fulfilment of data subjects rights BKR had required the payment of a fee when individuals requested access to their personal data and only provided access to their data once a year free of charge by post. THE NETHERLANDS ·AP ·Art. 12, 15 Personal Data Supervision Supervisory Authorities Jul 6, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Insurance Jun 30, 2020
€2,000 Attorney: Insufficient technical and organisational measures to ensure information security In the course of proceedings, an attorney submitted documents whose backs contained personal data of other parties. SPAIN ·AEPD ·Art. 32 Security Personal Data Insurance Jun 9, 2020
€5,000 Consulting de Seguridad e Investigacion Mira Dp Madrid S.L.: Insufficient legal basis for data processing A data subject has received marketing messages without having consented. SPAIN ·AEPD ·Art. 5, 6 Personal Data Consent Processing Jun 9, 2020
€75,000 Equifax Iberica, S.L.: Insufficient fulfilment of data subjects rights The Data Subject has requested by e-mail the deletion of his data from the file of the National Association of Financial Credit Institutions ('ASNEF'). Equifax Iberica had replied… SPAIN ·AEPD ·Art. 15 Personal Data Supervisory Authorities Insurance Jun 9, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ÚOOÚ (CZ) ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Personal Data Processing May 26, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance May 5, 2020
€2,890 Bank: Insufficient legal basis for data processing Due to an administrative error, the personal data of the data subject were registered and transferred to the Central Credit Information System (CCI) in connection with a loan… HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 26, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA ·AZOP ·Art. 15 Right of Access Personal Data Supervisory Authorities Mar 13, 2020
€870 Creditor: Insufficient legal basis for data processing Sending of SMS to a data subject as a reminder for a debt, even when the debt has already been paid. HUNGARY ·NAIH ·Art. 5, 6 Personal Data Processing Insurance Mar 9, 2020
€4,400 Vis Consulting Sp. z o.o.: Insufficient cooperation with supervisory authority The company prevented an inspection by the data protection authority. As a result, the company has violated Article 31 in conjunction with Article 58(1)(e) and (f) of the GDPR. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Personal Data Mar 9, 2020
€6,670 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The company repeatedly sent advertising messages to a data subject, although the data subject had objected to the processing of his data. SPAIN ·AEPD ·Art. 5, 6, 21 Direct Marketing Personal Data Processing Feb 3, 2020
€1,450 Accounting firm: Insufficient technical and organisational measures to ensure information security A printed customer list of an accounting firm, which also contained personal data, could be accessed by unauthorized persons. HUNGARY ·NAIH ·Art. 24, 32 Security Personal Data Insurance Jan 24, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Cyprus DPA ·Art. 32 Right of Access Security Personal Data Jan 13, 2020
Bank: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 21, 23, 48 Processing Insurance Jan 1, 2020
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Security Personal Data Dec 10, 2019
€5,000 Linea Directa Aseguradora: Insufficient legal basis for data processing The insurance company has sent advertising e-mails for the 'Reto Nuez' platform without the required consent. SPAIN ·AEPD ·Art. 6 Consent Insurance Direct Marketing Dec 3, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance Nov 28, 2019
€2,000 BNP Paribas Personal Finance S.A.: Insufficient fulfilment of data subjects rights BNP Paribas Personal Finance did not react to a request for erasure within the period set by the GDPR. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Supervision Supervisory Authorities Nov 22, 2019
€50,000 Menzis (Health Insurance Company): Non-compliance with general data processing principles Marketing staff had access to patient data. Among other things, this violated the purpose limitation principle. THE NETHERLANDS ·AP ·Art. 5 Insurance Processing Health Data Oct 31, 2019
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS ·AP ·Art. 32 Security Insurance Healthcare Oct 31, 2019
€15,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security Original fine summary: Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Insurance Oct 9, 2019
€20,000 Vreau Credit SRL: Insufficient technical and organisational measures to ensure information security Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the platform's staff via… ROMANIA ·ANSPDCP ·Art. 32, 33 Personal Data Security Supervision Oct 9, 2019
€511,000 DSK Bank: Insufficient technical and organisational measures to ensure information security Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit… BULGARIA ·CPDP ·Art. 32 Personal Data Security Insurance Aug 28, 2019
€180,000 ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had… FRANCE ·CNIL ·Art. 32 Security Insurance Integrity and Confidentiality Principle Jul 25, 2019
€130,000 UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations,… ROMANIA ·ANSPDCP ·Art. 5, 25 Security Personal Data Processing Jun 27, 2019
€2,850 Financial Enterprise: Insufficient legal basis for data processing A client of a financial enterprise complained that the financial enterprise transferred his data after he objected against the processing and did not provide information on the… HUNGARY ·NAIH ·Art. 5, 6, 21 Legitimate Interest Controllers Processing Jun 26, 2019
€2,850 Claim management company: Insufficient legal basis for data processing The complainants stated during the case that they concluded a credit agreement with the bank, which sold its claim against the complainants and transferred their respective data… HUNGARY ·NAIH ·Art. 5, 6 Legitimate Interest Controllers Consent Jun 3, 2019
€2,000 Local bank: Insufficient fulfilment of data subjects rights Customer of a local bank requested access to telephone conversation recordings as well as to CCTV recordings. The bank provided the copies of the recordings of telephone… HUNGARY ·NAIH ·Art. 12, 15, 18 Personal Data Controllers Insurance May 31, 2019
€61,500 Payment service provider UAB MisterTango: Insufficient fulfilment of data breach notification obligations During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a… LITHUANIA ·VDAI ·Art. 5, 32, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations May 16, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Anonymization Apr 12, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA ·CPDP ·Art. 5, 6, 9 Integrity and Confidentiality Principle Personal Data Healthcare Apr 8, 2019