Skip to content
Content type · 441 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 441 sort newestlargest fineoldest
GERMANY DPA: Data Protection Authority of Berlin In order to combat the Covid 19 pandemic, a cemetery had put out an open list in which visitors had to enter their contact data. A cemetery employee obtained first names, last… Unknown Personal Data IP Address Education Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had unlawfully accessed data in a police database. For this reason, the DPA of Brandenburg imposed a fine for a violation of § 32 (1) BbgDSG. The Brandenburg Data… GERMANY ·Insufficient legal basis for data processing Public Authority Education Processing Agreement Jan 1, 2021
Police department: Insufficient legal basis for data processing A police officer had accessed data in a police database for private research purposes. The police officer queried the investigation process of a friend against the background of a… GERMANY ·Insufficient legal basis for data processing Public Authority Education Public Sector Jan 1, 2021
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Garante ·Art. 12 Education Personal Data Controllers Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Education Personal Data Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data Public Authority IP Address Dec 17, 2020
€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Healthcare Dec 11, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY ·NAIH ·Art. 5, 6, 9 +2 Education Personal Data Controllers Dec 10, 2020
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet ·Art. 6, 32 Education Public Authority Personal Data Dec 3, 2020
€394,000 City of Stockholm: Insufficient technical and organisational measures to ensure information security The Swedish DPA imposed a fine on the City of Stockholm for data breaches on a school education platform. The platform consists of different subsystems, including a system for… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Audit Logs Security Nov 24, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY ·Garante ·Art. 9 Personal Data Education Healthcare Nov 17, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY ·Garante ·Art. 12, 13, 14 Video Surveillance Personal Data Public Authority Nov 17, 2020
DSB (Austria) - DSB-D124.1749 The controller shared the data subject's social security number with a financial service provider in order to provide financial aid, to which the data subject did not consent. On… DSB-D124.1749 ·Art. 4, 9 Health Data Insurance Healthcare Nov 5, 2020
€1,000 American College of Greece: Insufficient fulfilment of information obligations The Hellenic DPA (HDPA) imposed a fine of EUR 1,000 against the American College of Greece for violations of the right of access and the right to erasure of personal data. HDPA ·Art. 12 ·Insufficient fulfilment of information obligations Right to be Forgotten Right of Access Procedures Right of Access Oct 29, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY ·Garante ·Art. 5, 9 Notification Obligation Data Breaches Health Data Oct 26, 2020
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Data Breaches Security Oct 22, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Accuracy Personal Data Oct 21, 2020
€1,500 Political Party: Insufficient legal basis for data processing Sending of an e-mail to a former party member who had since resigned, with the request to act as an election representative without sufficient legal basis to process the personal… SPAIN ·aepd ·Art. 5, 6 Personal Data Education Processing Sep 11, 2020
€11,200 Warsaw University of Life Sciences: Insufficient technical and organisational measures to ensure information security Theft of a private notebook belonging to a university employee who also used this device for business purposes and on which personal data of candidates for study at SGGW was… POLAND ·UODO ·Art. 32 Security Education Personal Data Sep 8, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Telecommunications Cookies Supervision Sep 7, 2020
€5,000 Former mayor of a community: Insufficient legal basis for data processing Originial fine summary: Sending election advertising to citizens without sufficient legal basis. Update: On January 27th, 2021, the Brussels Court of Appeal overturned the fine of… BELGIUM ·APD ·Art. 5, 6 Direct Marketing Education Processing Sep 7, 2020
€2,000 Istituto Comprensivo Statale Crucoli Torretta: Insufficient technical and organisational measures to ensure information security Publication of personal data of students on the website of the Institute with, inter alia, notes about health and progress in school due to technical failure. ITALY ·Garante ·Art. 5, 32 Education Healthcare Personal Data Sep 7, 2020
€276,000 Bergen Municipality: Insufficient technical and organisational measures to ensure information security In October 2019, the Data Protection Authority was informed by the Municipality of Bergen about a data breach in connection with the municipality's tool for communication between… NORWAY ·Datatilsynet ·Art. 5, 32 Data Breaches Education Security Sep 3, 2020
€2,000 Comune di Casaloldo: Insufficient legal basis for data processing Publication of personal data on the website of the community. ITALY ·Garante ·Art. 5, 6 Personal Data Education Processing Sep 3, 2020
€22,700 Surveyor General of Poland ('GKK'): Insufficient legal basis for data processing Processing of personal data on the GEOPORTAL2 platform in the form of land and mortgage registers (including names, surnames and other personal data) without sufficient legal… UODO ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Education Processing Aug 31, 2020
€5,000 Party of the Socialists of Catalonia: Non-compliance with general data processing principles The Socialist Party of Catalonia has used the personal data provided by a professional doctor to send a letter to the complainant's relative asking for political support. This… SPAIN ·aepd ·Art. 5 Personal Data IP Address Education Aug 17, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Data Breaches Security Aug 12, 2020
€10,000 Community of Baronissi: Insufficient legal basis for data processing The community published on its website personal data of data subjects including names, birth dates, place of birth, place of residence, etc. ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Aug 10, 2020
€2,000 School: Insufficient legal basis for data processing Placing personal data of pupils on a public notice board. ITALY ·Garante ·Art. 5, 6 Education Personal Data Processing Aug 5, 2020
€5,000 National Institute for Social Security - Department of the Province of Brescia: Insufficient fulfilment of data subjects rights Failure to graint access to personal health data of a data subject according to Art. 15 GDPR. ITALY ·Garante ·Art. 15 Healthcare Health Data Personal Data Aug 4, 2020
€3,000 Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights The data subject received telephone calls regarding a candidacy for parliamentary elections. When the data subject made use of its right to access according to Art. 15 GDPR, it… GREECE ·HDPA ·Art. 15 Personal Data Education Data Subject Rights Exercise Modalities and Procedures Aug 3, 2020
HDPA (Greece) - 23/2020 The data subject filed an application to the Human Resources Directorate of the Hellenic Electricity Distribution Network Operator S.A. [HEDNO S.A.] for the purposes of obtaining… 23/2020 ·Art. 4, 5, 12 +6 Controllers Personal Data Processors Jul 30, 2020
€4,000 Region of Campania: Insufficient legal basis for data processing Publication of an enforcement order in civil proceedings on the Region's website. The document listed the names and place of residence and the amount of the claim. ITALY ·Garante ·Art. 5, 6 Education Public Authority Processing Jul 29, 2020
€3,000 Community of San Giorgio Jonico: Insufficient legal basis for data processing Publication of personal data on the municipal website with regard to legal proceedings. ITALY ·Garante ·Art. 5, 6 Personal Data Education Public Authority Jul 29, 2020
€3,000 Communal political association: Insufficient legal basis for data processing A local political association has sent out election advertisements to the residents of the municipality for the local elections in 2018. For this purpose, the association used the… BELGIUM ·APD ·Art. 5, 6, 14 IP Address Education Public Authority Jul 28, 2020
€22,300 Office for geodesy and cartography: Insufficient cooperation with supervisory authority Refusal of access to the premises by the supervisory authority in the course of an audit. POLAND ·UODO ·Art. 31, 58 Supervisory Authorities Supervision Public Authority Jul 15, 2020
€46,660 Municipality of Rælingen: Insufficient technical and organisational measures to ensure information security Fine for the processing of children's health data in connection with disability through the digital learning platform 'Showbie'. The Municipality had failed to carry out a Data… NORWAY ·Datatilsynet ·Art. 32, 35 DPIA Privacy Impact Assessment Health Data Jul 10, 2020
€6,700 Lejre Municipality: Non-compliance with general data processing principles The data protection authority had found that the Lejre Municipal Child and Youth Centre had regularly uploaded minutes of meetings with particularly sensitive and sensitive… DENMARK ·Datatilsynet ·Art. 5, 6, 33 +1 Data Breaches Personal Data Public Authority Jun 30, 2020
€40,000 Tusla Child and Family Agency: Insufficient fulfilment of data breach notification obligations The organization sent a letter with abuse allegations to a third party who then uploaded it to social networks. IRELAND ·Art. 33 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 30, 2020
€5,000 New York College S.A.: Non-compliance with general data processing principles The College had contacted the complainant directly by telephone with regard to an educational programme and had processed personal data in a non-transparent manner. GREECE ·HDPA ·Art. 5 Personal Data Education IP Address Jun 29, 2020
€13,500 Department of Home Affairs: Insufficient fulfilment of data subjects rights Fines for failure to comply with the right of access to personal data under Articles 12 and 15 GDPR. The Isle of Man has declared the GDPR - although it is not an EU state - to be… ISLE OF MAN ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Right of Access Procedures Right of Access Personal Data Jun 25, 2020
€6,000 National Police Brigade: Insufficient legal basis for data processing Making copies of a company's business records in the context of investigations which contained data from third parties and for which there was no legal basis for processing. SPAIN ·aepd ·Art. 5, 6 Public Authority Education Processing Jun 19, 2020
€7,500 PVV Overijssel: Insufficient fulfilment of data breach notification obligations The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email… THE NETHERLANDS ·AP ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jun 16, 2020
€5,000 Municipal employee: Insufficient legal basis for data processing In the context of a municipal election in 2018, the data controller had sent election advertisements to a group of employees of the same municipal administration, unlawfully using… BELGIUM ·APD ·Art. 5, 6 Controllers Education IP Address Jun 8, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Education Public Authority May 17, 2020
€11,200 Health and Medical Board of the Region of Örebro County: Insufficient legal basis for data processing Publication of personal data of a patient without sufficient legal basis. SWEDEN ·Art. 5, 6 ·Insufficient legal basis for data processing Healthcare Personal Data Healthcare May 12, 2020
€18,700 National Government Service Centre (NGSC): Insufficient fulfilment of data breach notification obligations The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification… SWEDEN ·Art. 33, 34 ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 29, 2020
€2,000 Political Party: Insufficient legal basis for data processing Forging signatures on a voters' list. BULGARIA ·KZLD ·Art. 6 Education Processing Public Authority Apr 14, 2020