Skip to content
Content type · 539 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 539 sort newestlargest fineoldest
€36,000 City of Reykjavík: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 36,000 on the City of Reykjavík. The city had used the digital education system 'Seesaw' at several schools. The student system… ICELAND ·Persónuvernd ·Art. 5, 6, 32 Retention Period Personal Data Security May 3, 2022
€1,500 Direzione Didattica Statale 1° Circolo-Eboli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on the school 'Direzione Didattica Statale 1° Circolo-Eboli'. The educational institution had sent a document containing the names… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Apr 28, 2022
€2,000 Comune di Partanna: Insufficient legal basis for data processing The community published information about a court case on its website, including personal data such as the name and professional information of a data subject. ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Public Authority Apr 28, 2022
€3,000 Comune di Monte Sant'Angelo: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on Comune di Monte Sant'Angelo. A person who had participated in a selection procedure had filed a complaint with the DPA due to… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Controllers Processing Apr 28, 2022
€2,500 'Isabella Gonzaga' high school: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the 'Isabella Gonzaga' high school. The school had published a document, which also contained personal health data of some… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Processing Apr 28, 2022
€50,000 Istituto Nazionale Assicurazione Infortuni sul Lavoro: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Istituto Nazionale Assicurazione Infortuni sul Lavoro (Public Accident Insurance for workers) EUR 50,000. As part of its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +2 Security Personal Data Data Breaches Apr 28, 2022
€150,000 Tarento municipality: Insufficient fulfilment of information obligations The Italian DPA has imposed a fine of EUR 150,000 on Tarento municipality. The company Amiu S.p.A had operated the local waste collection service on behalf of the municipality.… ITALY ·Garante ·Art. 5, 12, 13 +3 Monitoring DPIA Supervisory Authorities Apr 28, 2022
€10,000 Italian Ministry of Defense: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Italian Ministry of Defense. An employee of the ministry had filed a complaint with the DPA. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 +2 Personal Data Healthcare Processing Apr 28, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Retention Period Storage Limitation Security Apr 7, 2022
€5,000 Mayor: Insufficient legal basis for data processing The Hellenic DPA has fined a mayor EUR 5,000. The mayor had sent documents of an employee of the municipality to third parties without the employee's consent. The DPA considered… GREECE ·HDPA ·Art. 5 Processing Public Authority Employees Apr 4, 2022
€4,000 English School Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email… Cyprus DPA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data Mar 22, 2022
€5,000 English School staff union (ESSA): Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a… CYPRUS ·Cyprus DPA ·Art. 32 Data Breaches Security Personal Data Mar 21, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Identification Mar 4, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS ·AP ·Art. 13, 32 Security Personal Data Supervisory Authorities Feb 24, 2022
€2,000 Comune di Guidizzolo: Insufficient legal basis for data processing The community published information about a court case on its website, including personal data such as the name and professional information of a data subject. ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Feb 10, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Garante ·Art. 28, 32 Personal Data Supervisory Authorities Security Feb 10, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Garante ·Art. 2, 5, 6 Data Breaches Personal Data Supervisory Authorities Feb 10, 2022
€30,000 Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 30,000 on Lillestrøm Municipality. The municipality had accidentally published a document in which 10 out of 21 attachments contained… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 32 Security Personal Data Public Authority Feb 2, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€2,000 Oroklini Municipal Council: Insufficient cooperation with supervisory authority The Cypriot DPA has fined the Oroklini Municipal Council EUR 2,000 for not properly cooperating with the DPA during an investigation. CYPRUS ·Cyprus DPA ·Art. 31 Supervisory Authorities Supervision Public Authority Jan 1, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… CYPRUS ·Cyprus DPA ·Art. 24, 32 Security Controllers Processors Jan 1, 2022
Physician: Insufficient legal basis for data processing The DPA of Nordrhein-Westfalen has fined a physician. The physician had responded to a negative online reviews regarding their practice, disclosing personal data of a patient. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Personal Data Processing Public Authority Jan 1, 2022
€75,000 Greek Ministry of Tourism: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 75,000 on the Greek Ministry of Tourism. A data breach had occurred at the authority. According to the DPA, an attempt by a citizen to… GREECE ·HDPA ·Art. 13, 32, 33 +1 Data Breaches Notification Obligation Public Authority Dec 29, 2021
€1.3M Lisbon City Council: Insufficient legal basis for data processing The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since… PORTUGAL ·CNPD (PT) ·Art. 5, 6, 9 +2 DPIA Personal Data International Transfer Dec 21, 2021
€1,000 Università Telematica Internazionale Uninettuno: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,000 on Università Telematica Internazionale Uninettuno. A professor had filed a complaint with the DPA against the educational… ITALY ·Garante ·Art. 5 Retention Period Personal Data Processing Dec 16, 2021
€13,450 Municipality of Frederiksberg: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Security Personal Data Dec 16, 2021
€10,000 Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has fined Warsaw University of Technology EUR 10,000. The university had reported a data breach to the authority pursuant to Art. 33 GDPR. One of the… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Privacy by Design & Default Dec 9, 2021
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·DPC ·Art. 12, 13, 15 Right of Access Personal Data Controllers Dec 9, 2021
€60,000 Irish Teacher Council: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 60,000 on the Irish Teaching Council. The Council notified the DPA of a data breach under Art. 33 of the GDPR. Accordingly, two employees… IRELAND ·DPC ·Art. 5, 32, 33 Data Breaches Personal Data Security Dec 2, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY ·Garante ·Art. 5, 32 Security Personal Data Privacy by Design & Default Dec 2, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Processing Nov 30, 2021
€5,000 ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has fined ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINE in the amount of EUR 5,000. A data subject had indicated that he had objected to further newsletter… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Processing Nov 30, 2021
€2.8M Dutch Minister of Finance: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the Minister of Finance EUR 2,75 million. In the context of childcare benefit applications, tax offices had processed data on the dual nationality of… THE NETHERLANDS ·AP ·Art. 5, 6, 8 Personal Data Processing Education Nov 25, 2021
€585,000 Cabinet Office: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Cabinet Office EUR 585,000. On December 27, 2019, the Cabinet Office published a file on GOV.UK containing the names and uncensored addresses of… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Personal Data Data Breaches Nov 25, 2021
€98,000 Norwegian State Pension Fund (SPK): Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 98,000 on the Norwegian State Pension Fund (SPK). The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… NORWAY ·Datatilsynet (NO) ·Art. 5, 6, 9 Data Breaches Controllers Healthcare Nov 24, 2021
€51,000 Icelandic Ministry of Industry and Innovation: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Persónuvernd ·Art. 5, 6, 7 +4 Retention Period Privacy by Design & Default Personal Data Nov 23, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Encryption Personal Data Security Oct 18, 2021
€11,000 Territorial Administration of the Government of Genoa: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 11,000 on the Territorial Administration of the Government of Genoa. The department had published a file on its website that contained a… ITALY ·Garante ·Art. 2, 5, 6 Processing Public Authority Supervisory Authorities Sep 29, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet (NO) ·Art. 5, 28, 32 +1 Processors Controllers International Transfer Sep 27, 2021
€2,000 Istituto Comprensivo - IC Cosenza III “V. Negroni”: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo - IC Cosenza III “V. Negroni”. The educational institution had published a document, which also contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Processing Sep 21, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY ·Datatilsynet (NO) ·Art. 32 Data Breaches Security Personal Data Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 17, 2021
€5,000 Comune di Montalbano Jonico: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the municipality of Montalbano Jonico. An individual had filed a complaint against the municipality with the DPA. He… ITALY ·Garante ·Art. 2, 5, 6 +1 Retention Period Personal Data Processing Sep 16, 2021
€10,000 Favrskov municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 10,000 on Favrskov municipality. On August 19, 2020, the DPA received a notification from Favrskov Municipality of a personal data breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Data Breaches Notification Obligation Security Sep 16, 2021
€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Garante ·Art. 2, 5, 6 +6 Privacy Shield Retention Period Monitoring Sep 16, 2021
€53,800 Midtjylland Region: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach… DENMARK ·Datatilsynet (DK) ·Art. 32 Security Personal Data Supervisory Authorities Sep 8, 2021
€20,100 Danish Immigration Agency: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 20,100 on the Danish Immigration Agency. Media reports brought the DPA's attention to possible logging errors in one of the agency's IT… DENMARK ·Datatilsynet (DK) ·Art. 5, 32 Security Privacy by Design & Default Public Authority Aug 17, 2021
€2,200 President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 2,200 on the president of the Zgierz District Court. The president had reported a data breach involving the loss of an unencrypted… POLAND ·UODO ·Art. 5, 25, 32 Encryption Security Personal Data Aug 13, 2021
€600 Private individual: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 600 on a private individual. A private individual had sent a document obtained in a court case between the data subject and himself to… AUSTRIA ·DSB ·Art. 9 Personal Data Processors Legitimate Interest Aug 5, 2021
€200 Private Individual: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on a private individual due to the unlawful disclosure of personal data. The controller had disclosed personal data of… ROMANIA ·ANSPDCP ·Art. 5, 6, 14 Personal Data Controllers Processing Jul 30, 2021