Skip to content
Content type · 1,529 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 1,529 sort newestlargest fineoldest
€3,000 Rețele Electrice Muntenia SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Rețele Electrice Muntenia SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Privacy by Design & Default Controllers Jun 25, 2024
€1,000 Rețele Electrice Dobrogea SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Rețele Electrice Dobrogea SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Privacy by Design & Default Jun 25, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Insurance Jun 24, 2024
€42,000 CUI ZSQ FOOD, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CUI ZSQ FOOD, S.L.. An employee had filed a complaint with the DPA as video recordings of the company's surveillance system in which they… SPAIN ·aepd ·Art. 5 Monitoring Employees IP Address Jun 20, 2024
€4,000 Medical association: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,000 on the medical association 'Ordine dei Medici Chirurghi e degli Odontoiatri'. A patient had filed a complaint with the DPA. During… ITALY ·Garante ·Art. 12, 13, 15 Personal Data Storage Limitation Healthcare Jun 20, 2024
€10,000 TS Food Processing s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on TS Food Processing s.r.l.. A data subject (former emplyee) had filed a complaint with the DPA due to the controller's failure… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Employees Jun 20, 2024
€3,000 20 AÑOS DE MÚSICA A.I.E.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on 20 AÑOS DE MÚSICA A.I.E.. A person had filed a complaint with the DPA due to the fact that in order for minors to attend concerts organized… SPAIN ·aepd ·Art. 5, 13 IP Address Controllers Processing Agreement Jun 17, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND ·UODO ·Art. 24, 25, 32 +1 Security Healthcare Health Data Jun 13, 2024
€3,000 DQG NORTE A.I.E: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on DQG NORTE A.I.E.. A person had filed a complaint with the DPA due to the fact that in order for minors to attend concerts organized by the… SPAIN ·aepd ·Art. 5, 13 Controllers IP Address Personal Data Jun 13, 2024
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A.. A data subject had filed a complaint with the DPA because the controller had proposed to a credit… SPAIN ·aepd ·Art. 5 Personal Data Controllers IP Address Jun 12, 2024
€160,000 ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A person had filed a complaint with the DPA because their ex-partner had been given… SPAIN ·aepd ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Insurance Jun 10, 2024
€100,000 NATURGY IBERIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 100,000 on NATURGY IBERIA, S.A.. A customer had filed a complaint with the DPA because an amendment had been made to their electricity… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Jun 10, 2024
€2,000 EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.. The controller had installed video surveillance cameras which, among other… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers IP Address Jun 7, 2024
€1M CA Autobank S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1 million on CA Autobank S.p.A. A person had filed a complaint with the DPA because a rental car voucher had been refused due to his… ITALY ·Garante ·Art. 12, 15 Personal Data Processing Agreement Supervisory Authorities Jun 6, 2024
€100,000 Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data… AUSTRIA ·dsb ·Art. 5, 9, 28 +2 Data Breaches Controllers Healthcare Jun 6, 2024
€6.4M Eni Plenitude S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6.419.631 on Eni Plenitude S.p.A.. The DPA initiated an investigation against the controller due to 107 notifications and 8 complaints… ITALY ·Garante ·Art. 5, 6, 24 +3 IP Address Controllers Right to Object Jun 6, 2024
€180 Website operator: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the operator of a website for storing data of a data subject for an excessively long period of time and contrary to the principle of storage… SPAIN ·aepd ·Art. 5 Storage Limitation Retention Period IP Address Jun 5, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers IP Address Jun 5, 2024
€6,000 EUROBOX S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EUROBOX S.A.. A person had filed a complaint with the DPA because, after having their account with the controller blocked, they were asked to… SPAIN ·aepd ·Art. 5, 13 Retention Period IP Address Controllers Jun 5, 2024
€600,000 GSMA Limited: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 600,000 on GSMA Limited. In 2022, GSMA Limited required employees of its suppliers to register on an online platform and upload proof of… SPAIN ·aepd ·Art. 6, 9, 14 Archiving Processing Agreement Personal Data May 31, 2024
€4,200 PILLOW HOTELS, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on PILLOW HOTELS, S.L.. A person had filed a complaint with the DPA. The individual had made a booking for an overnight stay with the controller… SPAIN ·aepd ·Art. 5, 32, 33 Data Breaches Security IP Address May 30, 2024
€2,000 Corint Logistic SRL.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Corint Logistic SRL. A customer had filed a complaint with the DPA because they had received advertising text messages from the… ROMANIA ·ANSPDCP ·Art. 5, 17, 21 Right to be Forgotten Personal Data Data Subject Rights Exercise Modalities and Procedures May 30, 2024
€70,000 CAIXABANK S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 70,000 on CAIXABANK S.A.. A person had filed a complaint with the DPA because an employee of the controller had accidentally disclosed… SPAIN ·aepd ·Art. 5, 32 IP Address Personal Data Insurance May 28, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which also recorded parts of a neighbouring… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring May 28, 2024
€1,000 VOX ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on VOX ESPAÑA. The controller had installed video surveillance cameras which, among other things, also covered the public space.… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers May 24, 2024
€3,500 Professional association: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 3,500 on a professional association. An individual had filed a complaint with the DPA, for the unlawful publication of their personal… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Education IP Address May 23, 2024
€4,500 Azienda Socio-sanitaria Territoriale Rhodense: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,500 on Azienda Socio-sanitaria Territoriale Rhodense. An individual had filed a complaint with the DPA because the controller had not… ITALY ·Garante ·Art. 5, 12, 16 Healthcare Controllers Personal Data May 23, 2024
€96,000 WATIUM S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has fined WATIUM S.L. for failing to provide information requested by the DPA. The original fine of EUR 160,000 was reduced to EUR 96,000 due to voluntary payment… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement May 22, 2024
€336,000 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 336,000 on a company. The company had suffered a ransomware attack on their systems which resulted in the loss of personal data. During… POLAND ·UODO ·Art. 5, 32 Security Privacy by Design & Default Healthcare May 20, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… Autoriteit Persoonsgegevens Social Media Inspection Access Rights and Cooperation Obligations Fairness & Transparency May 16, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which also recorded the entrance area of the… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Monitoring May 14, 2024
€3,000 Medical association: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the… ITALY ·Garante ·Art. 2, 5, 6 Healthcare Healthcare Processing Agreement May 9, 2024
€10,000 Azzurro Club Hotels S.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on Azzurro Club Hotels S.r.l.. The controller had sent a data subject unsolicited advertising e-mail and failed to respond… ITALY ·Garante ·Art. 6, 12, 15 +1 Controllers Personal Data Direct Marketing May 9, 2024
€1,600 Homeowners' association: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a homeowners' association. A person had filed a complaint with the DPA due to the fact that the data controller had published a picture with… SPAIN ·aepd ·Art. 5, 32 Controllers IP Address Personal Data May 9, 2024
€3,000 Polisportiva Mimmo Ferrito s.r.l..: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 3,000 on Polisportiva Mimmo Ferrito s.r.l.. A data subject had filed a complaint with the DPA due to the controller's failure to respond… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Processing Agreement May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Healthcare May 8, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·aepd ·Art. 32, 33 Data Breaches Security Health Data May 8, 2024
€360,000 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… aepd ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Law Enforcement May 7, 2024
€1,200 ARRENDAMIENTOS DEUDORES, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on ARRENDAMIENTOS DEUDORES, S.L.. The controller had carried out a credit check on the data subject without any valid legal basis for this. The… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement May 7, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS ·AP ·Art. 5 Cookies Controllers Consent May 2, 2024
€1,200 DELPASO CAR HIRE, S.L.U.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on DELPASO CAR HIRE, S.L.U.. A data subject had filed a complaint against the controller with the DPA due to the controller's failure to… SPAIN ·aepd ·Art. 15 Personal Data Controllers Supervisory Authorities Apr 30, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Data Breaches Encryption Security Apr 29, 2024
€30,000 Rossi Carta S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 30,000 on Rossi Carta S.r.l.. An individual had filed a complaint with the DPA after repeatedly receiving unsolicited advertising emails… ITALY ·Garante ·Art. 6, 7, 12 +1 Data Subject Rights Exercise Modalities and Procedures Controllers Personal Data Apr 24, 2024
€5,000 Dly S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Dly S.r.l.. The company had installed video surveillance systems in its premises, however, their specific use was not authorized. ITALY ·Garante ·Art. 5, 88, 114 Video Surveillance Monitoring Employees Apr 24, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND ·UODO ·Art. 5, 25, 32 Security Privacy by Design & Default Personal Data Apr 24, 2024
€10,000 C.I.E.L. S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on C.I.E.L. S.p.A.. An employee working for the controller filed a complaint with the DPA due to the controller's failure to grant… ITALY ·Garante ·Art. 12, 15 Controllers Personal Data Employees Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Insurance Apr 23, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Fairness & Transparency Cookies IP Address Apr 22, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Cookies Fairness & Transparency Direct Marketing Apr 22, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·aepd ·Art. 6 Processing Agreement Insurance Consent Apr 12, 2024