Skip to content
Content type · 427 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

401–427 of 427 sort newestlargest fineoldest
€50,000 Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Types of Special Categories of Personal Data Jan 27, 2021
€10,000 City of Rome (Roma capitale): Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education Jan 27, 2021
€40,000 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 40,000 on a controller. The controller had violated the principle of accountability (lack of proof that a data protection impact… Slovak Data Protection Office ·Art. 5, 28 ·Non-compliance with general data processing principles Supervisory Authorities Controllers Processors Jan 1, 2021
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives Personal Data Supervision Dec 20, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Dec 17, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… NAIH ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Supervisory Authorities Retention Period Personal Data Dec 16, 2020
€2.9M Capio St. Göran AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Capio St. Göran AB SEK 30,000,000 (EUR 2,900,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet (NO) ·Art. 6, 32 Personal Data Security Public Authority Dec 3, 2020
€243,800 Västerbotten Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Västerbotten Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Healthcare Dec 3, 2020
€390,100 Karolinska University Hospital of Solna: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Karolinska University Hospital of Solna SEK 4,000,000 (EUR 390,100) for failing to implement adequate technical and… SWEDEN ·IMY ·Art. 5, 32 Security Privacy by Design & Default Education Dec 3, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… NAIH ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers Processing Nov 18, 2020
€1,500 BELGIUM DPA: Non-compliance with general data processing principles The Belgian DPA (APD/GBA) imposed a fine of EUR 1,500 on a social housing company for non-compliance with several principles of the GDPR such as data processing as well as the… APD/GBA ·Art. 5, 6, 12 +3 ·Non-compliance with general data processing principles Supervisory Authorities Fairness & Transparency Transparency Nov 13, 2020
€200 Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Encryption Controllers Processing Oct 24, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Oct 21, 2020
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. In connection with the delivery of magazine subscriptions, the company did not provide the data subject with… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Supervisory Authorities Processing Sep 25, 2020
€400 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide evidence that the data subject had consented to the scanning or copying of their ID card… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 6, 7 +3 Personal Data Identification Consent Jul 14, 2020
€1,900 Housing Association: Non-compliance with general data processing principles Unlawful usage of surveillance cameras. In the decision, the data protection authority stressed that sound recordings have additional privacy implications, especially in a… SWEDEN ·IMY ·Art. 5, 6 Processing Video Surveillance Monitoring Jun 16, 2020
€13,000 Company: Insufficient data processing agreement The DPA from Hamburg as imposed a fine of EUR 13,000 on a company. An individual had booked and attended a course with a company, but had not paid the course fees incurred. Some… GERMANY ·HmbBfDI ·Art. 26 Personal Data Processing Agreement Processors Jan 1, 2020
€3,000 Restaurant: Non-compliance with general data processing principles Excessive use of video surveillance in violation of the principle of data minimization. GERMANY ·HmbBfDI ·Art. 5 Retention Period Processing Video Surveillance Jan 1, 2020
€4,100 LIECHTENSTEIN DPA: Non-compliance with general data processing principles Unlawful operation of a video surveillance system. Non-compliance with general data processing principles Supervisory Authorities Monitoring Video Surveillance Jan 1, 2020
€15,000 Website providing legal information: Insufficient fulfilment of information obligations An operator of a website for legal news had the privacy statement only available in English, although it was also addressed to a Dutch and French speaking audience. In addition,… BELGIUM ·APD/GBA ·Art. 6, 12, 13 Personal Data IP Address Fairness & Transparency Dec 17, 2019
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM ·ICO ·Art. 32 Security Liability IP Address Dec 17, 2019
€92,146 Organizer of SZIGET festival and VOLT festival: Insufficient legal basis for data processing The NAIH found that there were inappropriate legal bases is use and that the controller did not comply with the principle of purpose limitation. Also, information on the data… HUNGARY ·NAIH ·Art. 5, 6, 13 Controllers Personal Data Processing May 23, 2019
€120,000 Oslo Municipal Education Department: Insufficient technical and organisational measures to ensure information security Fine for security vulnerabilities in a mobile messaging app developed for use in an Oslo school. The app allows parents and students to send messages to school staff. Due to… NORWAY ·Datatilsynet (NO) ·Art. 32 Security Right of Access Personal Data Apr 29, 2019
€10,000 CZECH REPUBLIC DPA: Non-compliance with general data processing principles Data was not only processed if adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation') and not only kept… ÚOOÚ (CZ) ·Art. 5 ·Non-compliance with general data processing principles Retention Period Storage Limitation Personal Data Mar 21, 2019
€294,000 GERMANY DPA: Non-compliance with general data processing principles A company was fined EUR 294 000 for 'unnecessarily long' storage and retention of personnel files and for 'excessive' data collection in the personnel selection process, during… Art. 5 ·Non-compliance with general data processing principles Processing Supervisory Authorities Health Data Jan 1, 2019
€160,000 Taxa 4x35: Non-compliance with general data processing principles The Danish DPA reported the taxi company to the police and recommended a fine (of 1.2M DKK) for non-adherence to the data-minimization principle. While the company deleted the… DENMARK ·Datatilsynet (DK) ·Art. 5 Processing Administrative Fines on Union Institutions, Bodies, Offices and Agencies Fines Jan 1, 2019