Skip to content
Content type · 1,535 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

401–450 of 1,535 sort newestlargest fineoldest
€5,000 Dly S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Dly S.r.l.. The company had installed video surveillance systems in its premises, however, their specific use was not authorized. ITALY ·Garante ·Art. 5, 88, 114 Video Surveillance Monitoring Employees Apr 24, 2024
€10,000 C.I.E.L. S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on C.I.E.L. S.p.A.. An employee working for the controller filed a complaint with the DPA due to the controller's failure to grant… ITALY ·Garante ·Art. 12, 15 Controllers Personal Data Employees Apr 24, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… ANSPDCP ·Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Insurance Apr 23, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Fairness & Transparency Cookies Direct Marketing Apr 22, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·azop ·Art. 6, 7, 13 Cookies Fairness & Transparency Direct Marketing Apr 22, 2024
€300 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 300 on a private individual. The individual had installed a video surveillance camera which, among other things, also recorded public… SPAIN ·aepd ·Art. 5 Video Surveillance IP Address Processing Agreement Apr 12, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·aepd ·Art. 6 Processing Agreement Personal Data Consent Apr 12, 2024
€1,800 PRESTAMER, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on PRESTAMER, S.L.. The controller had sent an e-mail without using the blind copy option, revealing the email addresses of all recipients to… SPAIN ·aepd ·Art. 5, 32 IP Address Security Controllers Apr 12, 2024
€1,000 DELSA ALQUILERES S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on DELSA ALQUILERES S.L.. The controller had installed video surveillance cameras in a residential complex which, among other… SPAIN ·aepd ·Art. 6, 13 Video Surveillance Controllers Monitoring Apr 12, 2024
€1,000 Store owner: Insufficient fulfilment of information obligations The Italian DPA has fined a store owner EUR 1,000. The controller had installed video surveillance cameras in its premises without properly informing data subjects about the… ITALY ·Garante ·Art. 5, 13 Video Surveillance Personal Data Monitoring Apr 11, 2024
€100,000 Facile.Energy S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Facile.Energy S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of… ITALY ·Garante ·Art. 5, 6, 24 +3 IP Address Controllers Processing Agreement Apr 11, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Processing Agreement IP Address Apr 11, 2024
€25,000 Innova Camara: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 25,000 on Innova Camara. The controller had suffered a cyber attack in which databases were accessed and malicious files (backdoors) were… ITALY ·Garante ·Art. 5 Security Privacy by Design & Default Education Apr 11, 2024
€525,000 HUBSIDE.STORE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 525,000 on HUBSIDE.STORE. The company had used data from data brokers for commercial acquisition campaigns without ensuring that the data… FRANCE ·CNIL ·Art. 6, 14 Processing Agreement Personal Data Consent Apr 4, 2024
€175,000 Greek Ministry of Immigration and Asylum: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 175,000 on the Greek Ministry of Immigration and Asylum. The DPA found that the controller had failed to properly carry out a required… GREECE ·HDPA ·Art. 25, 31, 35 DPIA Privacy Impact Assessment Security Apr 2, 2024
€2,400 Restaurant owner: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The data controller had installed a video surveillance camera in their restaurant, which also captured the guest area.… SPAIN ·aepd ·Art. 5 Video Surveillance Controllers IP Address Mar 25, 2024
€27,000 20 MINUTOS EDITORA, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine 20 MINUTOS EDITORA, S.L. for failing to prove compliance with an order issued by the DPA. The original fine of EUR 45,000 was reduced to EUR… SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Law Enforcement Mar 25, 2024
€10,000 Stjörnuna ehf: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 10,000 on Stjörnuna ehf. (the operator of a Subway branch). An employee had filed a complaint with the DPA regarding video surveillance… ICELAND ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Video Surveillance Monitoring IP Address Mar 24, 2024
€5,000 HIPERBAZAR YONGFA 2018 SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 5,000 on HIPERBAZAR YONGFA 2018 SL. A person had filed a complaint with the DPA against the controller. The controller had provided… SPAIN ·aepd ·Art. 5, 32 Video Surveillance Social Media Monitoring Mar 21, 2024
€500 JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 500 on JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SAT. The controller had installed a video surveillance system without… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Controllers Mar 21, 2024
€800 Private individual: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on a private individual. The controller had installed video surveillance cameras which, among other things, also covered the public space. The… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Mar 15, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on Vodafone España, S.A.U. A data subject had filed a complaint against the data controller as unauthorized fraudsters… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Mar 15, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance IP Address Controllers Mar 7, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Mar 5, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Agreement Mar 1, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·aepd ·Art. 6 Personal Data Processing Agreement Telecommunications Feb 29, 2024
€3M Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ): Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 2,995,140 on the Hellenic Post (ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ). The controller had suffered a data breach which resulted in… GREECE ·HDPA ·Art. 5, 32 Data Breaches Security Privacy by Design & Default Feb 28, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Access Controls Feb 26, 2024
€2,000 Camera di Commercio Industria Artigianato e Agricoltura: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Camera di Commercio Industria Artigianato e Agricoltura. An individual had filed a complaint against the controller with the DPA… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Controllers Education Feb 22, 2024
€40,000 IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA. A data subject had filed a complaint against the controller with the DPA due to the… SPAIN ·aepd ·Art. 15 Personal Data Controllers Processing Agreement Feb 13, 2024
€4,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.. A data subject had filed a complaint against the controller with the… SPAIN ·aepd ·Art. 15 Personal Data Controllers Insurance Feb 13, 2024
€100,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 100,000 on VODAFONE ESPAÑA, S.A.U. for insufficient legal basis for data processing. The data subject had filed a complaint against the… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Personal Data Feb 13, 2024
€365,000 CTC EXTERNALIZACIÓN, S.L: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested… SPAIN ·aepd ·Art. 13, 32, 35 DPIA Privacy Impact Assessment Controllers Feb 12, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY ·Garante ·Art. 5, 32 Security Controllers Insurance Feb 8, 2024
€300,000 Medtronic Italia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Medtronic Italia. The controller had sent emails in an open distribution list to hundreds of individuals using the… ITALY ·Garante ·Art. 5, 9, 12 +2 Healthcare IP Address Personal Data Feb 8, 2024
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Agreement Feb 8, 2024
€79M Enel Energia SpA: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by… Garante Security Human Resources Processing Agreement Feb 8, 2024
€30,000 CENTRO MÉDICO SALUS BALEARES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 30,000 on CENTRO MÉDICO SALUS BALEARES, S.L.. An individual had filed a complaint with the DPA due to the clinic's use of an electronic… SPAIN ·aepd ·Art. 5, 32 Healthcare IP Address Processing Agreement Feb 8, 2024
€5,000 Wi-Planet sas di Torri Carlo Alberto e c.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Wi-Planet sas di Torri Carlo Alberto e c.. A data subject had filed a complaint with the DPA due to the controller's failure to… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Telecommunications Feb 7, 2024
€3M IBERDROLA, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IBERDROLA, S.A. EUR 3 million following a cyberattack on I-DE Redes, which led to the compromise of customer data from millions of individuals. Although… SPAIN ·aepd ·Art. 5, 32 Security IP Address Processing Agreement Feb 7, 2024
€160,000 SANITAS, S.A. DE SEGUROS: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on SANITAS, S.A. DE SEGUROS. A customer had filed a complaint with the DPA due to the fact that the controller had concluded a contract without… SPAIN ·aepd ·Art. 6, 9 Insurance Controllers Consent Feb 6, 2024
€5M ENERGYA VM GESTIÓN DE ENERGÍA, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined ENERGYA VM GESTIÓN DE ENERGÍA, S.L. EUR 5 million following an investigation into unlawful personal data processing by Nivalco, a company… SPAIN ·aepd ·Art. 5 Controllers IP Address Processing Feb 6, 2024
€36,000 HISPAPOST, S.A.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine on HISPAPOST, S.A.. The police had found over a thousand abandoned letters containing the Hispapost logo. Hispapost had been contracted by… SPAIN ·aepd ·Art. 28 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 1, 2024
€6,000 Municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on a municipality. The municipality had unlawfully published information on citizens' Covid cases on its Facebook page. The… ITALY ·Garante ·Art. 2, 5, 6 +3 Public Authority Social Media IP Address Jan 24, 2024
€1,200 VUKMAL TRADE, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on a VUKMAL TRADE, S.L.. A former employee had filed a complaint against the controller due to unlawful disclosure of their private mobile… SPAIN ·aepd ·Art. 6 Controllers Employees Processing Agreement Jan 24, 2024
€200,000 ORANGE ESPAGNE S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Orange Espagne S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM card… SPAIN ·aepd ·Art. 6 Personal Data Consent Processing Agreement Jan 23, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Healthcare Encryption Healthcare Jan 17, 2024
€174,640 Black Tiger Belgium: Insufficient fulfilment of information obligations The Belgian DPA has imposed a fine of EUR 174,640 on Black Tiger Belgium. An individual had filed a complaint with the DPA due to the controller's failure to properly comply with… APD ·Art. 5, 6, 12 +5 ·Insufficient fulfilment of information obligations Storage Limitation Right of Access Right of Access Procedures Jan 16, 2024
€3,000 TECHNINK LEB SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on TECHNINK LEB SRL. The controller had suffered a data breach in which personal customer data had been unlawfully disclosed.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Privacy by Design & Default Jan 15, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS ·AP ·Art. 35 DPIA Privacy Impact Assessment Security Jan 15, 2024