Skip to content
Content type · 468 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 468 sort newestlargest fineoldest
€4,900 Ålesund Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine of EUR 4,900 on the municipality of Ålesund. At two schools in Ålesund, teachers asked students to download the training app Strava… NORWAY ·Datatilsynet ·Art. 24, 32, 35 DPIA Data Breaches Security Mar 15, 2021
€100,000 Asker Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) has fined the municipality of Asker EUR 100,000. On May 20, 2020, the DPA received a notice that the municipality had unlawfully published… NORWAY ·Datatilsynet ·Art. 5, 6, 24 +1 Data Breaches Education Security Mar 15, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data Accuracy IP Address Mar 15, 2021
€3,000 Comune di San Marco in Lamis: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,000 on the municipality of San Marco in Lamis. The municipality had uploaded documents containing personal data of the data… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Mar 11, 2021
€600,000 Municipality of Enschede: Insufficient legal basis for data processing The Dutch DPA (AP) has fined the municipality of Enschede EUR 600,000. In 2017, the municipality decided to install special measurement boxes to measure crowds in the city center… THE NETHERLANDS ·AP ·Art. 5, 6 IP Address Education Public Authority Mar 11, 2021
€500 Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) imposed a fine in the amount of EUR 500 against a natural person holding the position of General Secretary for a political party in Bucharest. The… ROMANIA ·ANSPDCP ·Art. 32, 58 Personal Data Security Controllers Mar 4, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… CYPRUS ·Art. 12, 15, 31 +1 ·Insufficient fulfilment of information obligations Right of Access Procedures Right of Access Inspection Access Rights and Cooperation Obligations Mar 3, 2021
€15,000 Registrų Centras: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA (VDAI) imposed a fine of EUR 15,000 on Registrų Centras. The controller is a company which manages several Lithuanian registers. The company suffered a data… LITHUANIA ·VDAI ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security Mar 2, 2021
€12,000 Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles The Lithuanian DPA (VDAI) imposed a fine of EUR 12,000 on the Lithuanian National Health Service (NVSC). The DPA had opened an investigation regarding a quarantine app introduced… LITHUANIA ·VDAI ·Art. 5, 13, 24 +3 DPIA Healthcare Health Data Feb 26, 2021
€6,000 Comune di Commezzadura: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 6,000 on the municipality of Commezzadura. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Healthcare IP Address Feb 25, 2021
€4,000 Ministero dell’Istruzione, Ufficio Scolastico Regionale per il Lazio: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 4,000 on the Lazio Region School Authority. A parent had filed a complaint against the school authority for forwarding data of… ITALY ·Garante ·Art. 5, 6, 9 Education Healthcare Public Authority Feb 25, 2021
€2,000 Comune di Conflenti: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 2,000 on the municipality of Conflenti. A former employee of the municipality filed a complaint with the DPA because a document… ITALY ·Garante ·Art. 5, 6 Personal Data IP Address Public Authority Feb 25, 2021
€300,000 Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social… ITALY ·Garante ·Art. 5, 25, 35 Fairness & Transparency DPIA Education Feb 25, 2021
€22,200 Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller… POLAND ·UODO ·Art. 5, 25, 28 +1 Data Breaches Integrity and Confidentiality Principle Security Feb 11, 2021
€75,000 Ministero dello Sviluppo Economico: Non-compliance with general data processing principles The Italian DPA (Garante) has fined the Ministry of Economic Development (Ministero dello Sviluppo Economico) EUR 75,000 for failing to appoint a data protection officer by May… ITALY ·Garante ·Art. 5, 6, 37 Prior Consultation Public Authority IP Address Feb 11, 2021
€60,000 Roma Servizi per La Mobilita S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined Roma Servizi per La Mobilita S.r.l. EUR 60,000 for failing to take adequate technical and organizational measures regarding the data of citizens… ITALY ·Garante ·Art. 32 Security Controllers Processors Feb 11, 2021
€350,000 Roma Capitale: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) fined the city of Rome EUR 350,000 for failing to take adequate technical and organizational measures regarding the data of citizens who had obtained… ITALY ·Garante ·Art. 5, 6, 28 +1 Security Education Privacy by Design & Default Feb 11, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Education IP Address Jan 27, 2021
€4,600 Anwara Sp. z.o.o.: Insufficient cooperation with supervisory authority The Polish DPA (UODO) fined the company Anwara Sp. z.o.o. EUR 4,600. The controller had not cooperated with the DPA and had not provided it with all the information necessary for… POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Public Sector Jan 15, 2021
€8,000 Agenzia regionale protezione ambientale Campania (ARPAC): Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) imposed a fine of EUR 8,000 on the Regional Environmental Protection Agency of Campania (ARPAC). An external hard drive containing personal data had been… ITALY ·Garante ·Art. 5, 32 Security Controllers Personal Data Jan 14, 2021
€75,000 Regione Lazio: Insufficient data processing agreement The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for… ITALY ·Garante ·Art. 5, 28 Controllers Processors Processing Agreement Jan 14, 2021
€5,500 Śląski Uniwersytet Medyczny (Medical University of Silesia): Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) imposed a fine of PLN 25,000 (EUR 5,500) on the Medical University of Silesia. In the course of exams held in the form of videoconferences at the end of May… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jan 5, 2021
€118,500 CZECH REPUBLIC DPA: Insufficient legal basis for data processing The Czech DPA (UOOU) fined 11 companies a total of EUR 118,500 for sending unrequested postal advertising messages to the mailboxes of various citizens. Based on a decision by the… UOOU ·Art. 6, 14 ·Insufficient legal basis for data processing Direct Marketing Processing Agreement Personal Data Jan 4, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully accessed data in a police database. For this reason, the DPA of Brandenburg imposed a fine for a violation of § 32 (1) BbgDSG. The Brandenburg Data… GERMANY ·Insufficient legal basis for data processing Public Authority Processing Agreement Public Sector Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully disclosed personal data of a drunk driving incident to the offender's mother during a chance encounter. He thought that the mother, as his… GERMANY ·Insufficient legal basis for data processing Personal Data Public Authority Education Jan 1, 2021
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a cemetery had put out an open list in which visitors had to enter their contact data. A cemetery employee obtained first names, last… Unknown Personal Data IP Address Education Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried the investigation process of a friend against the background of a… GERMANY ·Insufficient legal basis for data processing Public Authority Education Public Sector Jan 1, 2021
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Garante ·Art. 12 Personal Data Education Controllers Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Public Authority IP Address Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data IP Address Dec 17, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Retention Period Storage Limitation Healthcare Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data Education IP Address Dec 17, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Healthcare Dec 11, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY ·NAIH ·Art. 5, 6, 9 +2 Education Personal Data IP Address Dec 10, 2020
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet ·Art. 6, 32 Education Public Authority Personal Data Dec 3, 2020
€19,500 Gnosjö Municipality: Insufficient legal basis for data processing The Swedish DPA imposed a fine on the municipality of Gnosjö for illegal video surveillance in a care home for persons with certain functional disabilities. SWEDEN ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Video Surveillance Monitoring Healthcare Nov 25, 2020
€394,000 City of Stockholm: Insufficient technical and organisational measures to ensure information security The Swedish DPA imposed a fine on the City of Stockholm for data breaches on a school education platform. The platform consists of different subsystems, including a system for… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Audit Logs Education Nov 24, 2020
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Healthcare Fairness & Transparency Nov 19, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY ·Garante ·Art. 12, 13, 14 Video Surveillance Personal Data Public Authority Nov 17, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY ·Garante ·Art. 9 Personal Data Healthcare Education Nov 17, 2020
DSB (Austria) - DSB-D124.1749 The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… DSB-D124.1749 ·Art. 4, 9 Health Data Insurance Healthcare Nov 5, 2020
€1,000 American College of Greece: Insufficient fulfilment of information obligations The Hellenic DPA (HDPA) imposed a fine of EUR 1,000 against the American College of Greece for violations of the right of access and the right to erasure of personal data. HDPA ·Art. 12 ·Insufficient fulfilment of information obligations Right to be Forgotten Right of Access Procedures Personal Data Oct 29, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY ·Garante ·Art. 5, 9 Notification Obligation Data Breaches Healthcare Oct 26, 2020
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Data Breaches Security Oct 22, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Personal Data Accuracy Oct 21, 2020
€1,500 Political Party: Insufficient legal basis for data processing Sending of an e-mail to a former party member who had since resigned, with the request to act as an election representative without sufficient legal basis to process the personal… SPAIN ·aepd ·Art. 5, 6 Personal Data Education Processing Sep 11, 2020
€11,200 Warsaw University of Life Sciences: Insufficient technical and organisational measures to ensure information security Theft of a private notebook belonging to a university employee who also used this device for business purposes and on which personal data of candidates for study at SGGW was… POLAND ·UODO ·Art. 32 Education Security Personal Data Sep 8, 2020
€5,000 Former mayor of a community: Insufficient legal basis for data processing Originial fine summary: Sending election advertising to citizens without sufficient legal basis. Update: On January 27th, 2021, the Brussels Court of Appeal overturned the fine of… BELGIUM ·APD ·Art. 5, 6 Direct Marketing Education Processing Sep 7, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Telecommunications Cookies Supervision Sep 7, 2020