Content type · 568 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA · ·Art. 32 Aug 20, 2024
€1.5M IKEA: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 1,500,000 on IKEA. The controller used excessive video surveillance, including in public spaces and the checkout area. Additionally, the… AUSTRIA · ·Art. 5, 6 Aug 16, 2024
€1.5M The Austrian DPA has imposed a fine of EUR 1,500,000 on a company, that is part of a group The controller installed video surveillance devices that did not comply with the GDPR, resulting in the company being fined. Company: €1,500,000 fine ·AUSTRIA · Aug 16, 2024
€270,000 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA. An individual who provided services to the controller filed a complaint with the DPA due to the fact… SPAIN · ·Art. 5, 32 Aug 12, 2024
€10,000 LOCAL VERTICALS, S.L.: Insufficient fulfilment of information obligations The Spanish DPA has fined LOCAL VERTICALS, S.L. EUR 10,000. An individual filed a complaint with the DPA because they could not access the privacy policy during the registration… SPAIN · ·Art. 13 Aug 6, 2024
€5M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5 million on Hera Comm S.p.A. The investigation was launched following numerous complaints. The energy supplier had failed to take… ITALY · ·Art. 5, 12, 15 +3 Jul 17, 2024
€30,000 Pere Sihtkapital SA: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 30,000 on Pere Sihtkapital SA. The controller conducted a survey on childless families. In the process, the controller failed to take all… ESTONIA · ·Insufficient technical and organisational measures to ensure information security Jul 15, 2024
€600 ASSOCIACIO CANNABICA DEL MARESME ACANNAM: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 600 on ASSOCIACIO CANNABICA DEL MARESME ACANNAM. The controller had installed video surveillance cameras which, among other… SPAIN · ·Art. 5, 13 Jul 11, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY · ·Art. 5, 25, 32 +1 Jul 4, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND · ·Art. 24, 25, 32 +1 Jun 13, 2024
€100,000 Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data… AUSTRIA · ·Art. 5, 9, 28 +2 Jun 6, 2024
€1M CA Autobank S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1 million on CA Autobank S.p.A. A person had filed a complaint with the DPA because a rental car voucher had been refused due to his… ITALY · ·Art. 12, 15 Jun 6, 2024
€600,000 GSMA Limited: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 600,000 on GSMA Limited. In 2022, GSMA Limited required employees of its suppliers to register on an online platform and upload proof of… SPAIN · ·Art. 6, 9, 14 May 31, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which also recorded the entrance area of the… SPAIN · ·Art. 5 May 14, 2024
€360,000 4FINANCE SPAIN
FINANCIAL SERVICES, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on 4FINANCE SPAIN FINANCIAL SERVICES, S.A.U.. The controller had suffered a data breach that led to the unlawful access to customer profiles.… ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security May 7, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND · ·Art. 24, 25, 32 Apr 29, 2024
€2,500 Committee: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 2,500 on a committee. The controller had collected signatures in favor of a legislative initiative and later stored the signature lists… POLAND · ·Art. 5, 25, 32 Apr 24, 2024
€525,000 HUBSIDE.STORE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 525,000 on HUBSIDE.STORE. The company had used data from data brokers for commercial acquisition campaigns without ensuring that the data… FRANCE · ·Art. 6, 14 Apr 4, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN · ·Art. 5 Mar 25, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN · ·Art. 5, 32 Mar 21, 2024
€3M IBERDROLA, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although… SPAIN · ·Art. 5, 32 Feb 7, 2024
€5M ENERGYA VM GESTIÓN DE ENERGÍA, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined ENERGYA VM GESTIÓN DE ENERGÍA, S.L. EUR 5 million following an investigation into unlawful personal data processing by Nivalco, a company… SPAIN · ·Art. 5 Feb 6, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND · ·Art. 5, 6, 9 +3 Jan 17, 2024
€15,200 Media Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine of EUR 15,200 on a media company. The company failed to react to requests by the DPA. AUSTRIA · ·Art. 58 Jan 2, 2024
€3,300 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,300 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Jan 1, 2024
€3,700 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,700 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Jan 1, 2024
Police employees: Insufficient legal basis for data processing The DPA of Hamburg has imposed two fines on members of the police for accessing police databases for private research purposes. GERMANY · ·Insufficient legal basis for data processing Jan 1, 2024
€12,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 12,000 on a company providing vehicle history check services. The controller refused a data subject's request to rectify personal data… LITHUANIA · ·Art. 5, 15, 16 Jan 1, 2024
Multiple Police Officers: Data Protection Authority of Berlin The DPA of Berlin imposed fined 23 police officers. The police officers misused their access to the police information system for private purposes. GERMANY ·Unknown Jan 1, 2024
€6.5M THE PHONE HOUSE SPAIN, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6.5 million on THE PHONE HOUSE SPAIN, S.L. The controller had suffered a ransomware attack affecting personal data of 13 million… ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Dec 27, 2023
€400,000 UK Ministry of Defense: Insufficient technical and organisational measures to ensure information security The UK DPA has fined the Ministry of Defense EUR 400,000 for disclosing personal data of individuals who were to be relocated to the UK after the Taliban took control of… UNITED KINGDOM · ·Insufficient technical and organisational measures to ensure information security Dec 13, 2023
APD/GBA · 159/2023 On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The… 159/2023 ·Belgium ·Art. 4, 6, 7 Nov 24, 2023
€1,040 Self Employed Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,040 on a self employed person. The accused's website did not comply with GDPR requirements for cookies, as it processed data before… CZECH REPUBLIC · ·Art. 5, 13 Sep 26, 2023
06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Ireland · Aug 22, 2023
€10,000 Cat s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Cat s.r.l. EUR 10,000. Cat s.rl. had installed CCTV systems near waste garbage cans on behalf of the municipality of Modica in order to combat illegal… ITALY · ·Art. 2, 5, 6 Jul 18, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA · ·Art. 32 Jul 18, 2023
54/2024 In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links -… 54/2024 ·Greece · Jun 29, 2023
€2,500 Farmacia Ardealul SRL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 2,500 on Farmacia Ardealul SRL. The controller had reported a data breach to the DPA. During its investigation, the DPA found that an… ROMANIA · ·Art. 32 Jun 27, 2023
€22,500 Irish Departement of Health: Non-compliance with general data processing principles The Irish DPA (DPC) has fined the Irish Department of Health EUR 22,500. The DPA launched an investigation into the department following public allegations that the department… IRELAND · ·Art. 5, 6, 9 Jun 16, 2023
€210,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 210,000 on Piraeus Bank. During its investigation, the DPA found that the bank had processed personal data of customers in violation of… GREECE · ·Art. 5, 6, 15 +1 Jun 12, 2023
€84,000 UNITED PARCEL SERVICE ESPAÑA LTD. Y CIA SRC: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on UNITED PARCEL SERVICE ESPAÑA LTD. Y CIA SRC a fine. A person had filed a complaint against the controller because a package addressed to them… SPAIN · ·Art. 5, 32 Jun 7, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA · ·Art. 32 May 12, 2023
€1,200M Meta Platforms Ireland Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had… ·Art. 46 May 12, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA · ·Art. 32 May 12, 2023
€3,810 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 3,810 on a legal person. The accused unlawfully processed the personal data of an unspecified number of creditors to purchase their claims… CZECH REPUBLIC · ·Art. 6, 14 May 4, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA · ·Art. 6, 13, 28 +1 May 4, 2023
€4,000 Università degli studi di Cassino e del Lazio Meridionale: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR on Università degli studi di Cassino e del Lazio Meridionale. A professor at the university had filed a complaint against the university… ITALY · ·Art. 2, 5, 6 +1 Apr 27, 2023
€3,000 Tensa Art Design SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on Tensa Art Design SRL. An individual had filed a complaint for receiving promotional messages despite having filed an objection… ROMANIA · ·Art. 21 Apr 4, 2023
€145,000 AFIANZA ASESORES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 145,000 on AFIANZA ASESORES S.L.. The controller had reported a data breach to the DPA, stating that a backpack containing a USB stick… SPAIN · ·Art. 5, 32 Mar 16, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA · ·Art. 32 Mar 14, 2023