Skip to content
Content type · 396 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–396 of 396 sort newestlargest fineoldest
€1,200 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,200 on a legal person. The complainant, through her attorney, requested access to her personal data. The accused failed to respond, even… CZECH REPUBLIC ·UOOU ·Art. 15 Personal Data Supervisory Authorities Insurance Aug 31, 2020
€50,000 Bankia S.A.: Non-compliance with general data processing principles The bank kept personal data of a data subject for several years, even after the data subject was no longer a customer. The data was also accessible to bank employees during this… SPAIN ·aepd ·Art. 5 Personal Data Insurance IP Address Aug 28, 2020
€100 Bank: Insufficient legal basis for data processing A bank employee made a copy of the identity card of a bank client who wanted to exchange EUR 100 in foreign currency and justified this with money laundering charges. However,… AUSTRIA ·dsb ·Art. 5, 6 Insurance Processing Supervisory Authorities Aug 5, 2020
€7,000 Acc Consulting Varsinais-Suomi: Insufficient legal basis for data processing Unsolicited marketing SMS without prior consent FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6 Direct Marketing Insurance Consent Aug 5, 2020
€2,000 SC Viva Credit IFN SA: Insufficient fulfilment of data subjects rights The company had not informed the data subject within one month (or up to three months if a reason for the delay is given) of the measures taken following the request for deletion… ROMANIA ·ANSPDCP ·Art. 17 Personal Data Insurance Human Resources Jul 30, 2020
€24,000 Banco Bilbao Vizcaya Argentaria, SA: Insufficient legal basis for data processing BBVA had no legitimate basis for processing the data of the data subject and had therefore infringed Article 6(1) of the GDPR, since the company processed solvency and credit… SPAIN ·aepd ·Art. 5, 6 Insurance Personal Data IP Address Jul 20, 2020
€830,000 Bureau Krediet Registration ('BKR'): Insufficient fulfilment of data subjects rights BKR had required the payment of a fee when individuals requested access to their personal data and only provided access to their data once a year free of charge by post. THE NETHERLANDS ·AP ·Art. 12, 15 Personal Data Insurance Supervisory Authorities Jul 6, 2020
€1.2M Allgemeine Ortskrankenkasse ('AOK') (health insurance company): Insufficient technical and organisational measures to ensure information security From 2015 to 2019, AOK Baden-Württemberg (insurance organization) organized competitions on various occasions and collected personal data of the participants, including their… GERMANY ·Art. 5, 6, 32 ·Insufficient technical and organisational measures to ensure information security Insurance Healthcare Security Jun 30, 2020
€2,000 Attorney: Insufficient technical and organisational measures to ensure information security In the course of proceedings, an attorney submitted documents whose backs contained personal data of other parties. SPAIN ·aepd ·Art. 32 Security Personal Data Insurance Jun 9, 2020
€75,000 Equifax Iberica, S.L.: Insufficient fulfilment of data subjects rights The Data Subject has requested by e-mail the deletion of his data from the file of the National Association of Financial Credit Institutions ('ASNEF'). Equifax Iberica had replied… SPAIN ·aepd ·Art. 15 Personal Data Insurance Supervisory Authorities Jun 9, 2020
€5,000 Consulting de Seguridad e Investigacion Mira Dp Madrid S.L.: Insufficient legal basis for data processing A data subject has received marketing messages without having consented. SPAIN ·aepd ·Art. 5, 6 Insurance Direct Marketing Personal Data Jun 9, 2020
CZECH REPUBLIC DPA: Insufficient legal basis for data processing Czech Data Protection Auhtority (UOOU) UOOU ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Insurance Personal Data May 26, 2020
€5,000 Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Personal Data May 5, 2020
€2,890 Bank: Insufficient legal basis for data processing Due to an administrative error, the personal data of the data subject were registered and transferred to the Central Credit Information System (CCI) in connection with a loan… HUNGARY ·NAIH ·Art. 5, 6 Personal Data Insurance Processing Mar 26, 2020
Bank (name not available at the moment): Insufficient fulfilment of data subjects rights In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan,… CROATIA ·azop ·Art. 15 Right of Access Procedures Right of Access Personal Data Mar 13, 2020
€4,400 Vis Consulting Sp. z o.o.: Insufficient cooperation with supervisory authority The company prevented an inspection by the data protection authority. As a result, the company has violated Article 31 in conjunction with Article 58(1)(e) and (f) of the GDPR. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Accountability Mar 9, 2020
€870 Creditor: Insufficient legal basis for data processing Sending of SMS to a data subject as a reminder for a debt, even when the debt has already been paid. HUNGARY ·NAIH ·Art. 5, 6 Personal Data Insurance Processing Mar 9, 2020
€6,670 Banco Bilbao Vizcaya Argentaria S.L.: Insufficient legal basis for data processing The company repeatedly sent advertising messages to a data subject, although the data subject had objected to the processing of his data. SPAIN ·aepd ·Art. 5, 6, 21 Direct Marketing Insurance Personal Data Feb 3, 2020
€1,450 Accounting firm: Insufficient technical and organisational measures to ensure information security A printed customer list of an accounting firm, which also contained personal data, could be accessed by unauthorized persons. HUNGARY ·NAIH ·Art. 24, 32 Security Insurance Personal Data Jan 24, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… CYPRUS ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Right of Access Security Insurance Jan 13, 2020
Bank: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 21, 23, 48 IP Address Insurance Processing Jan 1, 2020
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Fines Security Dec 10, 2019
€5,000 Linea Directa Aseguradora: Insufficient legal basis for data processing The insurance company has sent advertising e-mails for the 'Reto Nuez' platform without the required consent. SPAIN ·aepd ·Art. 6 Insurance Direct Marketing Consent Dec 3, 2019
ING Bank N.V.: Insufficient technical and organisational measures to ensure information security Original Fine Summary: ING Bank has not taken appropriate technical and organisational measures for an automated data processing system during the settlement process of card… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Processing Nov 28, 2019
€2,000 BNP Paribas Personal Finance S.A.: Insufficient fulfilment of data subjects rights BNP Paribas Personal Finance did not react to a request for erasure within the period set by the GDPR. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Insurance Processing Nov 22, 2019
€50,000 Menzis (Health Insurance Company): Non-compliance with general data processing principles Marketing staff had access to patient data. Among other things, this violated the purpose limitation principle. THE NETHERLANDS ·AP ·Art. 5 Insurance Health Data Healthcare Oct 31, 2019
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS ·AP ·Art. 32 Access Controls Security Health Data Oct 31, 2019
€15,000 Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security Original fine summary: Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Personal Data Oct 9, 2019
€20,000 Vreau Credit SRL: Insufficient technical and organisational measures to ensure information security Raiffeisen Bank Romania carried out scoring assessments on the basis of personal data of individuals registered on the Vreau Credit platform provided by the platform's staff via… ROMANIA ·ANSPDCP ·Art. 32, 33 Security Insurance Personal Data Oct 9, 2019
€511,000 DSK Bank: Insufficient technical and organisational measures to ensure information security Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit… BULGARIA ·KZLD ·Art. 32 Personal Data Security Insurance Aug 28, 2019
€180,000 ACTIVE ASSURANCES (car insurer): Insufficient technical and organisational measures to ensure information security Large amount of customer accounts, clients' documents (including copies of driver's licences, vehicle registration, bank statements and documents to determine whether a person had… FRANCE ·CNIL ·Art. 32 Insurance Integrity and Confidentiality Principle Data Breaches Jul 25, 2019
€130,000 UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security The fine was issued as a result of the failure to implement appropriate technical and organisational measures (related to (1) the determination of the processing means/operations,… ROMANIA ·ANSPDCP ·Art. 5, 25 Security Insurance Personal Data Jun 27, 2019
€2,850 Financial Enterprise: Insufficient legal basis for data processing A client of a financial enterprise complained that the financial enterprise transferred his data after he objected against the processing and did not provide information on the… HUNGARY ·NAIH ·Art. 5, 6, 21 Legitimate Interest Controllers Insurance Jun 26, 2019
€2,850 Claim management company: Insufficient legal basis for data processing The complainants stated during the case that they concluded a credit agreement with the bank, which sold its claim against the complainants and transferred their respective data… HUNGARY ·NAIH ·Art. 5, 6 Legitimate Interest Controllers Insurance Jun 3, 2019
€2,000 Local bank: Insufficient fulfilment of data subjects rights Customer of a local bank requested access to telephone conversation recordings as well as to CCTV recordings. The bank provided the copies of the recordings of telephone… HUNGARY ·NAIH ·Art. 12, 15, 18 Video Surveillance Insurance Personal Data May 31, 2019
€61,500 Payment service provider UAB MisterTango: Insufficient fulfilment of data breach notification obligations During an inspection, the Lithuanian Data Protection Supervisory Authority found that the controller processed more data than necessary to achieve the purposes for which he was a… LITHUANIA ·VDAI ·Art. 5, 32, 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction May 16, 2019
€80,000 Company in the financial sector: Insufficient technical and organisational measures to ensure information security In an administrative decision dated 12 April 2019, the authority imposed a fine of 80,000 euros on a medium-sized financial services company. This company had failed to take the… GERMANY ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Anonymization Apr 12, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA ·KZLD ·Art. 5, 6, 9 Integrity and Confidentiality Principle Healthcare Healthcare Apr 8, 2019
€3,200 Unnamed financial institution: Insufficient fulfilment of data subjects rights The fine was imposed in relation to a data subject's request for data correction and erasure. NAIH levied a fine against an unnamed financial institution for unlawfully rejecting… HUNGARY ·NAIH ·Art. 5, 6, 13 +1 Retention Period Legitimate Interest Personal Data Mar 4, 2019
€50,000 N26: Insufficient legal basis for data processing The fine was imposed against against a bank (according to a newspaper N26) that had processed 'personal data of all former customers' without permission.The Bank has acknowledged… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Insurance Personal Data Security Mar 1, 2019
€1,560 Debt collector: Non-compliance with general data processing principles A data subject requested information about and erasure of the data processed, which the debt collector refused stating that it could not identify the subject. For identification… HUNGARY ·NAIH ·Art. 5 Fairness & Transparency Personal Data Controllers Feb 20, 2019
€1,560 Bank: Non-compliance with general data processing principles A bank mistakenly sent SMS messages about a subject's credit card debt to the telephone number of another person. After receiving an incorrect telephone number from the client at… HUNGARY ·NAIH ·Art. 5 Personal Data Insurance IP Address Feb 8, 2019
€1,165 Credit brokerage: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… CZECH REPUBLIC ·UOOU ·Art. 32 Integrity and Confidentiality Principle Security Professional Secrecy Feb 4, 2019
€500 Bank: Insufficient legal basis for data processing A bank gained personal data concernign a student wihtout a legal basis. BULGARIA ·KZLD ·Art. 5, 6 Insurance Personal Data Processing Jan 17, 2019
Hamburger Volksbank eG: Insufficient fulfilment of data subjects rights The company had sent a customer a newsletter with advertising content by e-mail, although this customer had previously expressly objected to the sending of further advertising… GERMANY ·Art. 21 ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Insurance Jan 1, 2019
€500 Bank: Insufficient legal basis for data processing A fine of 1000 BGN (or roughly 500 EUR) was imposed on a bank for calling a client for the unresolved bills of his neighbor. This provoked the client to evoke his right to be… BULGARIA ·KZLD ·Art. 5, 6 Right to be Forgotten Personal Data Insurance Dec 4, 2018