Content type · 408 documents in this view · 3,831 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3594 Processing 2644 Personal Data 2403 Controllers 2026 Processing Agreement 1114 Security 1018 Supervision 854 Healthcare 622 Law Enforcement 568 Monitoring 553 Public Authority 542 Consent 508
€18,930 Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a… POLAND · ·Art. 33, 34 Dec 28, 2020
€36,000 Banco Bilbao Vizcaya Argentaria, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data… SPAIN · ·Art. 5 Dec 21, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA · ·Art. 5, 32 Dec 17, 2020
€235,300 ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) imposed a fine of EUR 235,300 on ID Finance Poland Sp. z o.o. Due to an error while restarting a server, the settings of the software responsible for the… ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Dec 17, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Dec 16, 2020
€5M Banco Bilbao Vizcaya Argentaria, S.A.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined Banco Bilbao Vizcaya Argentaria, S.A. EUR 5,000,000 for violating Art. 6 GDPR (EUR 3,000,000) and Art. 13 GDPR (EUR 2,000,000). The bank had not… SPAIN · ·Art. 6, 13 Dec 11, 2020
€18,850 TUiR Warta S.A.: Insufficient fulfilment of data breach notification obligations An insurance agent hired by the controller had sent an email to unauthorized third parties in regard to insurance policies that contained personal data of two of the company's… POLAND · ·Art. 33, 34 Dec 9, 2020
€10,000 Losada Advocats S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine on Losada Advocats S.L. for sending an e-mail to dozens of recipients without putting them on the Blind Carbon Copy (BCC) list, thus… SPAIN · ·Art. 5, 32 Dec 2, 2020
€800,000 Carrefour Banque: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine on Carrefour Banque for violation of its obligation to process data fairly (Article 5 (1) GDPR). If a person who subscribed to the Pass card… FRANCE · ·Art. 5 Nov 18, 2020
Austrian DSB: Controller's use of social security number for statutory financial aid was The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… 2020-0.714.215 ·Austria ·Art. 4, 9 Nov 5, 2020
€15,000 Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found… ·Art. 5, 15, 32 +1 ·Insufficient technical and organisational measures to ensure information security Oct 19, 2020
€50,000 Centro de Investigación y Estudio para la Obesidad, SL: Insufficient legal basis for data processing Fines for the transfer of the data subject's personal data to Evo Finance EFC, SA in the course of processing a health insurance application, without a sufficient legal basis for… SPAIN · ·Art. 5, 6 Oct 9, 2020
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The complainant, through her attorney, requested access to her personal data. The accused failed to respond, even… CZECH REPUBLIC · ·Art. 15 Aug 31, 2020
€50,000 Bankia S.A.: Non-compliance with general data processing principles The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this… SPAIN · ·Art. 5 Aug 28, 2020
€100 Bank: Insufficient legal basis for data processing A bank employee made a copy of the identity card of a bank client who wanted to exchange EUR 100 in foreign currency and justified this with money laundering charges. However,… AUSTRIA · ·Art. 5, 6 Aug 5, 2020
€7,000 Acc Consulting Varsinais-Suomi: Insufficient legal basis for data processing Unsolicited marketing SMS without prior consent FINLAND · ·Art. 5, 6 Aug 5, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA · ·Art. 17 Jul 30, 2020
€24,000 Banco Bilbao Vizcaya Argentaria, SA: Insufficient legal basis for data processing BBVA had no legitimate basis for processing the data of the data subject and had therefore infringed Article 6(1) of the GDPR, since the company processed solvency and credit… SPAIN · ·Art. 5, 6 Jul 20, 2020
€830,000 Bureau Krediet Registration ('BKR'): Insufficient fulfilment of data subjects rights BKR had required the payment of a fee when individuals requested access to their personal data and only provided access to their data once a year free of charge by post. THE NETHERLANDS · ·Art. 12, 15 Jul 6, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Jun 30, 2020
€2,000 Attorney: Insufficient technical and organisational measures to ensure information security In the course of proceedings, an attorney submitted documents whose backs contained personal data of other parties. SPAIN · ·Art. 32 Jun 9, 2020
€5,000 Consulting de Seguridad e Investigacion Mira Dp Madrid S.L.: Insufficient legal basis for data processing A data subject has received marketing messages without having consented. SPAIN · ·Art. 5, 6 Jun 9, 2020
€75,000 Equifax Iberica, S.L.: Insufficient fulfilment of data subjects rights The Data Subject has requested by e-mail the deletion of his data from the file of the National Association of Financial Credit Institutions ('ASNEF'). Equifax Iberica had replied… SPAIN · ·Art. 15 Jun 9, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) ·Art. 5, 6 ·Insufficient legal basis for data processing May 26, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA · ·Art. 32 May 5, 2020
€2,890 Bank: Insufficient legal basis for data processing Due to an administrative error, the personal data of the data subject were registered and transferred to the Central Credit Information System (CCI) in connection with a loan… HUNGARY · ·Art. 5, 6 Mar 26, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA · ·Art. 15 Mar 13, 2020
€870 Creditor: Insufficient legal basis for data processing Sending of SMS to a data subject as a reminder for a debt, even when the debt has already been paid. HUNGARY · ·Art. 5, 6 Mar 9, 2020
€4,400 Vis Consulting Sp. z o.o.: Insufficient cooperation with supervisory authority The company prevented an inspection by the data protection authority. As a result, the company has violated Article 31 in conjunction with Article 58(1)(e) and (f) of the GDPR. POLAND · ·Art. 31, 58 Mar 9, 2020
€6,670 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The company repeatedly sent advertising messages to a data subject, although the data subject had objected to the processing of his data. SPAIN · ·Art. 5, 6, 21 Feb 3, 2020
€1,450 Accounting firm: Insufficient technical and organisational measures to ensure information security A printed customer list of an accounting firm, which also contained personal data, could be accessed by unauthorized persons. HUNGARY · ·Art. 24, 32 Jan 24, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS · ·Art. 32 Jan 13, 2020
Bank: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC · ·Art. 21, 23, 48 Jan 1, 2020
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA · ·Art. 5, 25, 32 +1 Dec 10, 2019
€5,000 Linea Directa Aseguradora: Insufficient legal basis for data processing The insurance company has sent advertising e-mails for the 'Reto Nuez' platform without the required consent. SPAIN · ·Art. 6 Dec 3, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA · ·Art. 32 Nov 28, 2019
€2,000 BNP Paribas Personal Finance S.A.: Insufficient fulfilment of data subjects rights BNP Paribas Personal Finance did not react to a request for erasure within the period set by the GDPR. ROMANIA · ·Art. 12, 17 Nov 22, 2019
€50,000 Menzis (Health Insurance Company): Non-compliance with general data processing principles Marketing staff had access to patient data. Among other things, this violated the purpose limitation principle. THE NETHERLANDS · ·Art. 5 Oct 31, 2019
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS · ·Art. 32 Oct 31, 2019
€15,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security Original fine summary: Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the… ROMANIA · ·Art. 32 Oct 9, 2019
€20,000 Vreau Credit SRL: Insufficient technical and organisational measures to ensure information security Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the platform's staff via… ROMANIA · ·Art. 32, 33 Oct 9, 2019
€511,000 DSK Bank: Insufficient technical and organisational measures to ensure information security Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit… BULGARIA · ·Art. 32 Aug 28, 2019
€180,000 ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had… FRANCE · ·Art. 32 Jul 25, 2019
€130,000 UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations,… ROMANIA · ·Art. 5, 25 Jun 27, 2019
€2,850 Financial Enterprise: Insufficient legal basis for data processing A client of a financial enterprise complained that the financial enterprise transferred his data after he objected against the processing and did not provide information on the… HUNGARY · ·Art. 5, 6, 21 Jun 26, 2019
€2,850 Claim management company: Insufficient legal basis for data processing The complainants stated during the case that they concluded a credit agreement with the bank, which sold its claim against the complainants and transferred their respective data… HUNGARY · ·Art. 5, 6 Jun 3, 2019
€2,000 Local bank: Insufficient fulfilment of data subjects rights Customer of a local bank requested access to telephone conversation recordings as well as to CCTV recordings. The bank provided the copies of the recordings of telephone… HUNGARY · ·Art. 12, 15, 18 May 31, 2019
€61,500 Payment service provider UAB MisterTango: Insufficient fulfilment of data breach notification obligations During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a… LITHUANIA · ·Art. 5, 32, 33 May 16, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Apr 12, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA · ·Art. 5, 6, 9 Apr 8, 2019