Content type · 468 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY · ·Art. 24, 32, 35 Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY · ·Art. 5, 6, 24 +1 Mar 15, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN · ·Art. 5 Mar 15, 2021
€3,000 Comune di San Marco in Lamis: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,000 on the municipality of San Marco in Lamis. The municipality had uploaded documents containing personal data of the data… ITALY · ·Art. 5, 6 Mar 11, 2021
€600,000 Municipality of Enschede: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the municipality of Enschede EUR 600,000. In 2017, the municipality decided to install special measurement boxes to measure crowds in the city center… THE NETHERLANDS · ·Art. 5, 6 Mar 11, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA · ·Art. 32, 58 Mar 4, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Art. 12, 15, 31 +1 ·Insufficient fulfilment of information obligations Mar 3, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA · ·Art. 32 Mar 2, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA · ·Art. 5, 13, 24 +3 Feb 26, 2021
€6,000 Comune di Commezzadura: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 6,000 on the municipality of Commezzadura. A former employee of the municipality filed a complaint with the DPA because a document… ITALY · ·Art. 5, 6, 9 Feb 25, 2021
€4,000 Ministero dell’Istruzione, Ufficio Scolastico Regionale per il Lazio: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the Lazio Region School Authority. A parent had filed a complaint against the school authority for forwarding data of… ITALY · ·Art. 5, 6, 9 Feb 25, 2021
€2,000 Comune di Conflenti: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 2,000 on the municipality of Conflenti. A former employee of the municipality filed a complaint with the DPA because a document… ITALY · ·Art. 5, 6 Feb 25, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY · ·Art. 5, 25, 35 Feb 25, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND · ·Art. 5, 25, 28 +1 Feb 11, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY · ·Art. 5, 6, 37 Feb 11, 2021
€60,000 Roma Servizi per La Mobilita S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined Roma Servizi per La Mobilita S.r.l. EUR 60,000 for failing to take adequate technical and organizational measures regarding the data of citizens… ITALY · ·Art. 32 Feb 11, 2021
€350,000 Roma Capitale: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined the city of Rome EUR 350,000 for failing to take adequate technical and organizational measures regarding the data of citizens who had obtained… ITALY · ·Art. 5, 6, 28 +1 Feb 11, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY · ·Art. 2, 5, 6 Jan 27, 2021
€4,600 Anwara Sp. z.o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) fined the company Anwara Sp. z.o.o. EUR 4,600. The controller had not cooperated with the DPA and had not provided it with all the information necessary for… POLAND · ·Art. 31, 58 Jan 15, 2021
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY · ·Art. 5, 32 Jan 14, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY · ·Art. 5, 28 Jan 14, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND · ·Art. 33, 34 Jan 5, 2021
€118,500 CZECH REPUBLIC DPA: Insufficient legal basis for data processing The Czech DPA (UOOU) fined 11 companies a total of EUR 118,500 for sending unrequested postal advertising messages to the mailboxes of various citizens. Based on a decision by the… ·Art. 6, 14 ·Insufficient legal basis for data processing Jan 4, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully accessed data in a police database. For this reason, the DPA of Brandenburg imposed a fine for a violation of § 32 (1) BbgDSG. The Brandenburg Data… GERMANY ·Insufficient legal basis for data processing Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Jan 1, 2021
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a cemetery had put out an open list in which visitors had to enter their contact data. A cemetery employee obtained first names, last… Unknown Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried the investigation process of a friend against the background of a… GERMANY ·Insufficient legal basis for data processing Jan 1, 2021
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY · ·Art. 12 Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY · ·Art. 5, 13, 14 +2 Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY · ·Art. 5, 6, 37 Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY · ·Art. 5, 6, 9 +1 Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY · ·Art. 5, 6 Dec 17, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Dec 11, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY · ·Art. 5, 6, 9 +2 Dec 10, 2020
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY · ·Art. 6, 32 Dec 3, 2020
€19,500 Gnosjö Municipality: Insufficient legal basis for data processing The Swedish DPA imposed a fine on the municipality of Gnosjö for illegal video surveillance in a care home for persons with certain functional disabilities. SWEDEN ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Nov 25, 2020
€394,000 City of Stockholm: Insufficient technical and organisational measures to ensure information security The Swedish DPA imposed a fine on the City of Stockholm for data breaches on a school education platform. The platform consists of different subsystems, including a system for… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Nov 24, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Nov 19, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY · ·Art. 12, 13, 14 Nov 17, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY · ·Art. 9 Nov 17, 2020
DSB (Austria) - DSB-D124.1749 The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… DSB-D124.1749 ·Art. 4, 9 Nov 5, 2020
€1,000 American College of Greece: Insufficient fulfilment of information obligations The Hellenic DPA (HDPA) imposed a fine of EUR 1,000 against the American College of Greece for violations of the right of access and the right to erasure of personal data. ·Art. 12 ·Insufficient fulfilment of information obligations Oct 29, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY · ·Art. 5, 9 Oct 26, 2020
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… Art. 32 ·Insufficient technical and organisational measures to ensure information security Oct 22, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA · ·Art. 5 Oct 21, 2020
€1,500 Political Party: Insufficient legal basis for data processing Sending of an e-mail to a former party member who had since resigned, with the request to act as an election representative without sufficient legal basis to process the personal… SPAIN · ·Art. 5, 6 Sep 11, 2020
€11,200 Warsaw University of Life Sciences: Insufficient technical and organisational measures to ensure information security Theft of a private notebook belonging to a university employee who also used this device for business purposes and on which personal data of candidates for study at SGGW was… POLAND · ·Art. 32 Sep 8, 2020
€5,000 Former mayor of a community: Insufficient legal basis for data processing Originial fine summary: Sending election advertising to citizens without sufficient legal basis. Update: On January 27th, 2021, the Brussels Court of Appeal overturned the fine of… BELGIUM · ·Art. 5, 6 Sep 7, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Sep 7, 2020