Skip to content
Content type · 950 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

401–450 of 950 sort newestlargest fineoldest
€20,000 Istituto Nazionale di Previdenza Sociale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on the Italian National Institute of Social Security (INPS). The controller had published personal data of participants in a… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Education IP Address Apr 11, 2024
€25,000 Innova Camara: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 25,000 on Innova Camara. The controller had suffered a cyber attack in which databases were accessed and malicious files (backdoors) were… ITALY ·Garante ·Art. 5 Security Privacy by Design & Default Controllers Apr 11, 2024
€175,000 Greek Ministry of Immigration and Asylum: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 175,000 on the Greek Ministry of Immigration and Asylum. The DPA found that the controller had failed to properly carry out a required… GREECE ·HDPA ·Art. 25, 31, 35 DPIA Privacy Impact Assessment Security Apr 2, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·aepd ·Art. 5, 32 Video Surveillance Social Media Monitoring Mar 21, 2024
EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA. The EDPS investigated whether these modifications were sufficient to… 2021-0518 ·European Union ·Art. 5, 6, 28 +1 Privacy Shield Controllers Processors Mar 8, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Mar 5, 2024
€3M Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ): Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 2,995,140 on the Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ). The controller had suffered a data breach which resulted in… GREECE ·HDPA ·Art. 5, 32 Data Breaches Security Controllers Feb 28, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 26, 2024
€365,000 CTC EXTERNALIZACIÓN, S.L: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested… SPAIN ·aepd ·Art. 13, 32, 35 DPIA Controllers Privacy Impact Assessment Feb 12, 2024
€79M Enel Energia SpA: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by… Garante Security Human Resources Processing Agreement Feb 8, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Healthcare Feb 8, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY ·Garante ·Art. 5, 32 Security Controllers Insurance Feb 8, 2024
€3M IBERDROLA, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although… SPAIN ·aepd ·Art. 5, 32 Security IP Address Processing Agreement Feb 7, 2024
€3.5M I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3.5 million on I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U. The controller had suffered a cyber attack on its GEA web application resulting… SPAIN ·aepd ·Art. 5, 32 Security IP Address Processing Agreement Feb 5, 2024
€5,000 Dentist: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5,000 on a dentist due to a lack of data security and a failure to respect the right of access of a data subject. FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right of Access Procedures Right of Access Healthcare Jan 31, 2024
€10,000 FRANCE DPA: €10,000 fine The French DPA has imposed a fine of EUR 10,000 on a data controller due to data security vulnerabilities. CNIL ·Unknown Controllers Security Processing Agreement Jan 31, 2024
€20,000 Website editor: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a website editor for data security vulnerabilities. FRANCE ·CNIL ·Unknown Security Supervisory Authorities Processing Agreement Jan 31, 2024
€20,000 Pharmaceutical wholesaler: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a pharmaceutical wholesaler due to violations of several regulations, including a lack of data security and insufficient… FRANCE ·CNIL ·Unknown Accountability Processing Agreement Controllers Jan 24, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Healthcare Encryption Healthcare Jan 17, 2024
€3,000 TECHNINK LEB SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on TECHNINK LEB SRL. The controller had suffered a data breach in which personal customer data had been unlawfully disclosed.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Jan 15, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS ·AP ·Art. 35 DPIA Privacy Impact Assessment Security Jan 15, 2024
€11,500 Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg imposed a fine of EUR 11,500 on a company operating in the advertising industry for failing to comply with its deletion obligations. In addition, it was found… GERMANY ·Insufficient technical and organisational measures to ensure information security Security Direct Marketing Processing Agreement Jan 1, 2024
€32,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 32,000 on a logistics company for incorrectly disposing of delivery lists. GERMANY ·Insufficient technical and organisational measures to ensure information security Security Processing Agreement Supervisory Authorities Jan 1, 2024
€2,500 Doctor´s Office: Insufficient technical and organisational measures to ensure information security The DPA of Hessen has imposed a fine of EUR 2,500 on a doctor´s office. The controller hired an office manager who worked partly from home. The manager worked with patient files,… GERMANY ·Art. 5, 6, 9 +1 ·Insufficient technical and organisational measures to ensure information security Healthcare IP Address Security Jan 1, 2024
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine on a company due to technical security vulnerabilities in its support ticket systems. GERMANY ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Processing Agreement Jan 1, 2024
Company: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine on a company due to technical security vulnerabilities in its support ticket systems. GERMANY ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Processing Agreement Jan 1, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Healthcare Jan 1, 2024
€6.5M THE PHONE HOUSE SPAIN, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6.5 million on THE PHONE HOUSE SPAIN, S.L. The controller had suffered a ransomware attack affecting personal data of 13 million… aepd ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Telecommunications Controllers Dec 27, 2023
Municipality: Non-compliance with general data processing principles Fine against municipality for lack of security measures (insufficient passwords) FRANCE ·CNIL ·Non-compliance with general data processing principles Security Education Public Authority Dec 22, 2023
€23,000 Polish Minister of Health: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 23,000 on the Polish Minister of Health. The controller had accessed information via a database relating to a physician who had prescribed… POLAND ·UODO ·Art. 25, 32, 34 Healthcare Security Controllers Dec 20, 2023
€400,000 UK Ministry of Defense: Insufficient technical and organisational measures to ensure information security The UK DPA has fined the Ministry of Defense EUR 400,000 for disclosing personal data of individuals who were to be relocated to the UK after the Taliban took control of… UNITED KINGDOM ·ICO ·Insufficient technical and organisational measures to ensure information security Personal Data IP Address Security Dec 13, 2023
€3,000 Veranda Obor S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Veranda Obor S.A.. The controller had disclosed personal data (e.g. name, e-mail adress etc.) of lottery participants on its… ROMANIA ·ANSPDCP ·Art. 32 Personal Data Controllers IP Address Dec 11, 2023
€24,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 24,000 on Hora Credit IFN SA. The controller had accidentally sent documents containing the personal data of another person to a customer by… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Security Personal Data Controllers Dec 7, 2023
€1,000 Techno Security s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Techno Security s.r.l.. A data subject had filed a complaint with the DPA due to the controller's failure to respond to a… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 30, 2023
€26,500 Östersund Municipality's Department for Children and Education: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 26,500 on the Östersund Municipality's Department for Children and Education. The authority had failed to carry out a data protection… SWEDEN ·Art. 35 ·Insufficient technical and organisational measures to ensure information security DPIA Privacy Impact Assessment Public Authority Nov 28, 2023
€1.7M Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 1.7 million on Arbeids- og velferdsetaten, the Norwegian Labor and Welfare Administration (NAV). During its investigation, the DPA… NORWAY ·Datatilsynet ·Art. 5, 24, 25 +1 Security Right of Access Privacy by Design & Default Nov 27, 2023
€45,000 Open University of Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 45,000 on Open University of Cyprus. The university had suffered a data breach involving hackers publishing personal data of students,… Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 22, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Right of Access Nov 13, 2023
€43,000 Indcap AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 43,000 on Indecap AB. The controller had accidentally sent an email to a large number of its customers containing an Excel document… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Privacy by Design & Default Nov 7, 2023
€2,000 SINDICATO LIBRE DE TRANSPORTES: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on SINDICATO LIBRE DE TRANSPORTES. A member of the union had shared the data subject's payslip in a WhatsApp group without the data subject's… SPAIN ·aepd ·Art. 5, 32 Personal Data IP Address Processing Agreement Nov 3, 2023
€3,000 OTP BANK ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA. The controller had accidentally transmitted personal data of an individual to an unauthorized third party.… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Privacy by Design & Default Nov 3, 2023
€48,000 INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P.: Non-compliance with general data processing principles The Spanish DPA has imposed a finea INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P. The controller had suffered a data breach in which personal patient and employee data had… SPAIN ·aepd ·Art. 5, 32, 34 Data Breaches Healthcare Employees Nov 2, 2023
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·aepd ·Art. 5, 25, 32 Privacy by Default Privacy by Design Privacy by Design & Default Oct 26, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·aepd ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Social Media Oct 25, 2023
€3,000 Mensajero SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Mensajero SRL. The controller had suffered a data breach where a link on the controller's website was publicly accessible… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 24, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN ·aepd ·Art. 25, 32 Security Privacy by Design & Default Controllers Oct 20, 2023
€70,000 Scionti Selezioni Superiori S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on Scionti Selezioni Superiori S.r.l.. The controller had made unsolicited marketing calls, in some cases to individuals who were… ITALY ·Garante ·Art. 5, 6, 7 +7 Personal Data IP Address Data Subject Rights Exercise Modalities and Procedures Oct 12, 2023
€5.5M Debt collection company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 5,470,000 to a debt collection company. The investigation was triggered by an anonymous complaint stating that controller… CROATIA ·azop ·Art. 5, 6, 12 +2 Personal Data Controllers Legitimate Interest Oct 5, 2023
€1,000 Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Cez Vânzare S.A.. The controller had accidentally sent emails containing personal customer data to the wrong recipients. The… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers IP Address Oct 2, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Healthcare Healthcare Sep 28, 2023