Skip to content
Content type · 622 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 622 sort newestlargest fineoldest
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Data Breaches Personal Data Fairness & Transparency Jul 7, 2022
€2,120 University Hospital of the Medical University of Warsaw: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 2,120 on the University Hospital of the Medical University of Warsaw. The university hospital had suffered a data breach in which a… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jul 6, 2022
€3,000 Pediatric psychologist: Insufficient cooperation with supervisory authority The Hellenic DPA has fined a pediatric psychologist EUR 3,000. The psychologist had not properly cooperated with the DPA during an investigation. GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Healthcare Jun 29, 2022
€1,000 SCOTCH CORNER BAR: Non-compliance with general data processing principles The Spanish DPA has fined the bar operator SCOTCH CORNER BAR EUR 1,000. The controller had installed a CCTV which also covered parts of the public space. Furthermore the… SPAIN ·AEPD ·Art. 5, 58 Controllers Supervisory Authorities Processing Jun 16, 2022
€91,000 Tavistock & Portman NHS Foundation Trust: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Tavistock and Portman NHS Foundation Trust EUR 91,000. The Tavistock and Portman NHS Foundation Trust is a mental health specialist trust located in… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Privacy by Design & Default Public Authority Jun 9, 2022
€3,000 LODEJU, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on the restaurant operator LODEJU, S.L.. The controller had installed video surveillance cameras in its premises which,… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jun 3, 2022
€1,600 CORON ISLAND SLU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,600 on CORON ISLAND SLU. A customer had filed a complaint with the DPA against the restaurant. The customer had asked for a bill in her… SPAIN ·AEPD ·Art. 5 Retention Period Processing Supervisory Authorities May 31, 2022
€2,100 Stołeczny Ośrodek dla Osób Nietrzeźwych: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 2,100 on 'Stołeczny Ośrodek dla Osób Nietrzeźwych', a center for people suffering from alcoholism. During its investigation, the DPA found… POLAND ·UODO ·Art. 5, 6 Personal Data Processing Video Surveillance May 31, 2022
€50,000 Azienda sanitaria universitaria Friuli Occidentale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Personal Data Types of Special Categories of Personal Data May 26, 2022
€70,000 Azienda sanitaria universitaria Friuli Centrale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 70,000 on the healthcare facility Azienda sanitaria universitaria Friuli Centrale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Personal Data Types of Special Categories of Personal Data May 26, 2022
€46,000 Azienda Sanitaria Locale Roma: Insufficient legal basis for data processing The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most… ITALY ·Garante ·Art. 2, 5, 6 +1 Retention Period Healthcare Personal Data May 26, 2022
€5,000 MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on MED LIFE S.A.. The company had disposed of documents containing sensitive patient data in a publicly accessible garbage can. An… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Privacy by Design & Default May 24, 2022
€7,000 Azienda Socio Sanitaria Territoriale Dei Sette Laghi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the healthcare facility Azienda Socio Sanitaria Territoriale Dei Sette Laghi. A patient had mistakenly received… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Security Health Data May 22, 2022
€5,000 Kredyt Inkaso Investments RO S.A: Insufficient legal basis for data processing The Romanian DPA has fined Kredyt Inkaso Investments RO S.A. EUR 5,000. A data subject had filed a complaint with the DPA against the controller for having disclosed their… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +1 Data Breaches Personal Data Controllers May 18, 2022
€600 Bar owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined a bar owner EUR 600. The bar operated a video surveillance system in which the observation angle of the cameras extended into the public space. The… SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance May 11, 2022
€1,200 CONTIMAG INVEST, S.L.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined CONTIMAG INVEST, S.L. EUR 1,200 for failing to provide sufficient information on video surveillance in one of the restaurants it operates SPAIN ·AEPD ·Art. 13 Supervisory Authorities Video Surveillance Monitoring May 9, 2022
€10,600 HEI – Medical Travel: Insufficient fulfilment of data subjects rights The Icelandic DPA has imposed a fine of EUR 10,600 on HEI - Medical Travel. A data subject had filed a complaint with the DPA against the controller. The controller had gained… ICELAND ·Persónuvernd ·Art. 9, 15, 17 Personal Data Healthcare Controllers May 3, 2022
€16,000 LABORATORIOS GONZÁLEZ, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined LABORATORIOS GONZÁLEZ, S.L.. The laboratory had sent the results of a Covid-19 test that the data subject had taken not only to them but also to… SPAIN ·AEPD ·Art. 5 Personal Data Processing Healthcare Apr 29, 2022
€4,200 CLÍNICA DENTAL SAN FRANCISCO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA (AEPD) has imposed a fine on CLÍNICA DENTAL SAN FRANCISCO, S.L.. A data subject had filed a complaint with the AEPD against the controller due to the fact that the… SPAIN ·AEPD ·Art. 17, 21 Personal Data Controllers Supervisory Authorities Apr 29, 2022
€2,000 Ekss s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined the restaurant operator Ekss s.r.l. EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the… ITALY ·Garante ·Art. 5, 13 Personal Data Controllers Supervisory Authorities Apr 28, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Data Breaches Security Apr 28, 2022
€1,500 Direzione Didattica Statale 1° Circolo-Eboli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on the school 'Direzione Didattica Statale 1° Circolo-Eboli'. The educational institution had sent a document containing the names… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Apr 28, 2022
€2,500 'Isabella Gonzaga' high school: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the 'Isabella Gonzaga' high school. The school had published a document, which also contained personal health data of some… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Processing Apr 28, 2022
€10,000 Italian Ministry of Defense: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Italian Ministry of Defense. An employee of the ministry had filed a complaint with the DPA. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 +2 Personal Data Healthcare Processing Apr 28, 2022
€1,000 ASST di Lodi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 1,000 on ASST di Lodi. The healthcare facility had reported a data breach to the DPA pursuant to Art. 33 GDPR. A patient had… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Personal Data Security Apr 26, 2022
€5,600 Physician: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined a physician. The physician had used recordings of a patient's treatment for advertising purposes. However, the patient had not consented to this.… SPAIN ·AEPD ·Art. 6 Consent Direct Marketing Healthcare Apr 22, 2022
€1.5M DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press… FRANCE ·CNIL ·Art. 28, 29, 32 Encryption Security Personal Data Apr 15, 2022
€3.7M Dutch Tax and Customs Administration: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 3,7 million on the Dutch Tax and Customs Administration. This is the highest fine ever imposed by the Dutch DPA As part of its… THE NETHERLANDS ·AP ·Art. 5, 6, 32 +1 Storage Limitation Retention Period Security Apr 7, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY ·Garante ·Art. 5, 13, 14 +4 DPIA Personal Data Processing Apr 7, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY ·Garante ·Art. 28 Processors Supervisory Authorities Processing Apr 7, 2022
€15,000 Rebirth s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Rebirth s.r.l. EUR 15,000. The controller had installed 14 surveillance cameras in a café it operated without, however, informing about the video… ITALY ·Garante ·Art. 5, 13, 114 +1 Controllers Supervisory Authorities Video Surveillance Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Integrity and Confidentiality Principle Personal Data Controllers Apr 7, 2022
€200,000 Brussels Airport Zaventem: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +3 Healthcare DPIA Types of Special Categories of Personal Data Apr 4, 2022
€100,000 Brussels Airport Charleroi: Insufficient legal basis for data processing The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of… BELGIUM ·APD/GBA ·Art. 5, 6, 9 +3 Healthcare DPIA Types of Special Categories of Personal Data Apr 4, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM ·APD/GBA ·Art. 5, 6, 9 Healthcare Types of Special Categories of Personal Data Processing Apr 4, 2022
€6,700 Danish National Genome Center: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 6,700 on the Danish National Genome Center. The center had conducted a data protection impact assessment that revealed circumstances that… DENMARK ·Datatilsynet (DK) ·Art. 36 DPIA Supervisory Authorities Processing Agreement Mar 25, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Garante ·Art. 2, 5, 6 +3 Personal Data Controllers Supervisory Authorities Mar 10, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Security Healthcare Mar 10, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Security Personal Data Processing Mar 10, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Identification Mar 4, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Types of Special Categories of Personal Data Controllers Mar 3, 2022
€3,000 Hotel operator: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a hotel operator. The controller had installed video surveillance cameras which, among other things, also covered the… SPAIN ·AEPD ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Feb 22, 2022
€1,500 RESTATURANTE FUENTEBRO, S.C.: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined RESTATURANTE FUENTEBRO, S.C. EUR 1,500 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN ·AEPD ·Art. 13 Supervisory Authorities Video Surveillance Monitoring Feb 21, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Processing Feb 10, 2022
€1,000 Cafe operator: Non-compliance with general data processing principles The cafe used CCTV cameras which also captured the public space outside resulting in a violation of the so called principle of data minimisation. SPAIN ·AEPD ·Art. 5 Retention Period Processing Video Surveillance Feb 7, 2022
€1,000 Café owner: Non-compliance with general data processing principles The DPA from Luxembourg has imposed a fine of EUR 1,000 on a café owner. The owner had installed two video surveillance cameras in the café for the purpose of protecting company… LUXEMBOURG ·CNPD (LU) ·Art. 5, 13 Retention Period Processing Supervisory Authorities Feb 2, 2022
€1,000 SC Grupex 2000 SRL: Insufficient legal basis for data processing The Romanian DPA (ANSPDCP) has fined SC Grupex 2000 SRL EUR 1,000. The controller unlawfully uploaded videos of patients on its website. ROMANIA ·ANSPDCP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 1, 2022
€152,000 Uppsala hospital board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 152,000 on the Uppsala hospital board. The fine is the result of an investigation by the Uppsala Region (the regional board and the… SWEDEN ·IMY ·Art. 5, 32 Integrity and Confidentiality Principle Encryption Security Jan 26, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jan 26, 2022
€2,400 PHARMA TALENTS, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine against PHARMA TALENTS, S.L.U. A data subject had filed a complaint against the company after he found a database on one of the company's… SPAIN ·AEPD ·Art. 5, 32 Security Personal Data Privacy by Design & Default Jan 14, 2022