Content type · 622 documents in this view · 3,831 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3594 Processing 2644 Personal Data 2403 Controllers 2026 Processing Agreement 1114 Security 1018 Supervision 854 Healthcare 622 Law Enforcement 568 Monitoring 553 Public Authority 542 Consent 508
€1,000 A.S.L. Napoli 1 Centro: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 1,000 on A.S.L. Napoli 1 Centro. An employee at the health authority had filed a complaint with the DPA against the… ITALY · ·Art. 2, 5, 6 Jan 13, 2022
€14,000 Azienda sanitaria unica regionale Marche: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 14,000 on Azienda sanitaria unica regionale Marche. The DPA launched an investigation against the health department following media… ITALY · ·Art. 5, 32, 35 Jan 13, 2022
€4,000 Medicina & Lavoro s.r.l.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY · ·Art. 12, 15 Jan 13, 2022
€7,500 Azienda Sanitaria Locale Frosinone: Insufficient fulfilment of information obligations The Italian DPA has fined Azienda Sanitaria Locale Frosinone EUR 7,500. In the course of its investigation against the medical facility, the Garante found that their privacy… ITALY · ·Art. 5, 12, 13 Jan 13, 2022
€1,000 Villa Masi Residenza per anziani: Insufficient fulfilment of information obligations Inexistence of signalization regarding the use of CCTV systems in a nursing care facility. ITALY · ·Art. 13 Jan 13, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Jan 5, 2022
Aid organization: Insufficient technical and organisational measures to ensure information security The DPA of Brandenburg has imposed a five-figure fine on an aid organization. The aid organization provides transportation for people with illnesses. The organization had reported… GERMANY ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 1, 2022
€1,000 Covid-19 test center: Insufficient fulfilment of data subjects rights The DPA of Hamburg has fined a Covid-19 test center EUR 1,000 for failing to comply with the right of data subjects to have their personal data deleted. GERMANY · ·Art. 17 Jan 1, 2022
€1,400 Covid-19 test center: Insufficient legal basis for data processing The DPA from Hamburg has imposed a fine of EUR 1,400 on a Covid-19 test center. The controller intended to fulfill its statutory documentation obligations and scanned the front… GERMANY · ·Art. 6 Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Berlin has imposed a fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with their personal data… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2022
Physician: Insufficient legal basis for data processing The DPA of Bremen imposed a fine on a physician for transmitting patient's data to a billing office without their consent. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2022
€500 The DPA from Baden-Württemberg imposed a fine of EUR 500 on a restaurant The owner had disposed of a large quantity of Covid contact forms in the forest. Restaurant: €500 fine ·GERMANY ·Unknown Jan 1, 2022
€1,500 Physician: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. The DPA had conducted an investigation against the physician for the unlawful operation of a video surveillance… CYPRUS · ·Art. 31 Jan 1, 2022
Physician: Insufficient legal basis for data processing The DPA of Bremen imposed a fine on a physician for using a patient's contact details to contact them privately without their consent. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2022
€2,700 Covid-19 test center: Insufficient technical and organisational measures to ensure information security The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them… GERMANY · ·Art. 32 Jan 1, 2022
Restaurant operator: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a five-figure fine on a restaurant operator. During the Corona pandemic, the operator had required restaurant visitors to fill out forms with… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Jan 1, 2022
€6,500 Pharmacy: Non-compliance with general data processing principles The DPA of Baden-Württemberg imposed a fine of EUR 6,500 on a pharmacy. The pharmacy had disposed of a large number of personal documents, including diagnoses and medical… GERMANY ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2022
€1,400 Dentist: Non-compliance with general data processing principles The Hungarian DPA has fined a dentist EUR 1,300. The controller had installed several surveillance cameras in their practice, which permanently recorded employees and patients.… HUNGARY · ·Non-compliance with general data processing principles Jan 1, 2022
€1,000 Physician: Insufficient technical and organisational measures to ensure information security A physician's office had disposed of records of positive and negative Covid-19 Antigen Rapid test results from patients in a public waste disposal site. GERMANY · ·Art. 32 Jan 1, 2022
€1,800 Covid-19 test center: Non-compliance with general data processing principles The DPA of Hessen imposed a fine of EUR 1,800 on a Covid-19 test center. An employee had taken an adhesive label from the trash, written the test center's e-mail address on it and… GERMANY ·Art. 5, 6 ·Non-compliance with general data processing principles Jan 1, 2022
€16,400 Covid-19 test center: Insufficient legal basis for data processing The DPA of Hessen has fined a Covid-19 test center EUR 16,400. The controller had sent an e-mail containing personal data to several recipients in an open distribution list. The… GERMANY ·Art. 6, 33 ·Insufficient legal basis for data processing Jan 1, 2022
€1,600 Physician: Insufficient fulfilment of data subjects rights The Hungarian DPA imposed a fine of EUR 1,600 on a physician. A patient had filed a complaint against the controller with the DPA. The patient had asked the doctor to send all… HUNGARY · ·Art. 5, 12, 13 Jan 1, 2022
Medical care center: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a medical care center for having scanned a customer's ID card against their will and stored the copy. Once the customer complained, they… GERMANY ·Insufficient legal basis for data processing Jan 1, 2022
Physician: Insufficient fulfilment of data subjects rights The DPA of Bremen imposed a fine on a physician for failing to respond to a data subject's request for access to their data in a timely manner. GERMANY ·Art. 12 ·Insufficient fulfilment of data subjects rights Jan 1, 2022
€5,000 Medical clinic: Insufficient fulfilment of information obligations The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic… FINLAND · ·Art. 5, 12, 13 +2 Dec 26, 2021
€1,500 LA OFICINA BAR: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined LA OFICINA BAR. The bar operated a video surveillance system in which the observation angle of the cameras extended into the public traffic area. The… SPAIN · ·Art. 5 Dec 23, 2021
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY · ·Art. 5, 6, 9 Dec 17, 2021
€52,000 Motor insurance center: Non-compliance with general data processing principles The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of… FINLAND · ·Art. 5, 25 Dec 16, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY · ·Art. 5, 25, 32 +1 Dec 16, 2021
€50,000 IZA OBRAS Y PROMOCIONES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined IZA OBRAS Y PROMOCIONES, S.A. EUR 50,000. An employee had filed a complaint with the DPA against the company, alleging that the controller had… SPAIN · ·Art. 5 Dec 14, 2021
€608,000 Psykoterapiakeskus Vastaamo: Non-compliance with general data processing principles The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An… FINLAND · ·Art. 5, 33, 34 Dec 7, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY · ·Art. 5, 32 Dec 2, 2021
€5,000 Azienda USL di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda USL di Parma EUR 5,000. A patient filed a complaint with the DPA because she had mistakenly received two reports of diagnostic tests on two… ITALY · ·Art. 5, 9 Dec 2, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY · ·Art. 5, 32 Dec 2, 2021
€1,000 Restaurant owner: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) has fined a restaurant owner EUR 1,000 for failing to provide information signs about CCTV surveillance in the establishment. SPAIN · ·Art. 13 Nov 29, 2021
€6,000 Società H San Raffaele Resnati s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. The DPA initiated an investigation against the health care provider after it… ITALY · ·Art. 5, 9 Nov 25, 2021
€98,000 Norwegian State Pension Fund (SPK): Insufficient legal basis for data processing The Norwegian DPA has imposed a fine of EUR 98,000 on the Norwegian State Pension Fund (SPK). The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… NORWAY · ·Art. 5, 6, 9 Nov 24, 2021
€400,000 Transavia: Insufficient technical and organisational measures to ensure information security The Dutch DPA has fined airline Transavia EUR 400,000. In 2019, the airline suffered a data breach, in which a hacker gained access to Transavia's systems through two accounts… THE NETHERLANDS · ·Art. 32 Nov 12, 2021
€412,000 Østre Toten municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined Østre Toten municipality EUR 412,000. The municipality suffered a cyberattack in January 2021, as a result of which the municipality's data was… NORWAY · ·Art. 5, 32 Oct 18, 2021
€8,000 Health Protection Agency of Sardinia (ATS): Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 8,000 on the Health Protection Agency of Sardinia (ATS). A patient had mistakenly received medical records and clinical… ITALY · ·Art. 5, 9 Oct 14, 2021
€2,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has fined a physician EUR 2,000. A patient had complained to the DPA that the doctor had disclosed his personal data to third parties without… ITALY · ·Art. 5, 9 Sep 29, 2021
€107,000 Danish Cancer Society: Insufficient technical and organisational measures to ensure information security The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer… DENMARK · ·Art. 32 Sep 29, 2021
€3,000 Bar owner: Non-compliance with general data processing principles The Spanish DPA (AEPD) has fined a bar owner EUR 3,000. A data subject had filed a complaint with the DPA. He had suffered an accident in the bar which was recorded by the… SPAIN · ·Art. 5 Sep 28, 2021
€2,000 Istituto Comprensivo - IC Cosenza III “V. Negroni”: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo - IC Cosenza III “V. Negroni”. The educational institution had published a document, which also contained… ITALY · ·Art. 2, 5, 6 +1 Sep 21, 2021
€18,000 CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.. The data subject filed a complaint with the AEPD. He had requested an MRI scan of… SPAIN · ·Art. 5 Sep 20, 2021
€75,600 ST. OLAVS HOSPITAL HF: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined St. Olav's Hospital in the amount of EUR 75,600. The hospital suffered three data leaks in accordance with Art. 33 the GDPR. The first incident had… NORWAY · ·Art. 32 Sep 20, 2021
€40,200 Høylandet Municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 40,200 on the municipality of Høylandet. The latter had reported a data breach to the DPA in accordance with Art. 33 GDPR. An employee… NORWAY · ·Art. 32 Sep 20, 2021
€67,200 Syddanmark Region: Insufficient technical and organisational measures to ensure information security The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach… DENMARK · ·Art. 32 Sep 17, 2021
€10,000 Mediterranean Hospital of Cyprus: Insufficient cooperation with supervisory authority The Cypriot DPA has fined Mediterranean Hospital of Cyprus EUR 10,000 for failing to provide information requested by the DPA during an investigation. ·Art. 31, 58 ·Insufficient cooperation with supervisory authority Sep 17, 2021
€1,000 Farpa s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,000 on Farpa s.r.l.. The company had installed video surveillance systems in social facilities it operates, however, their specific use… ITALY · ·Art. 5, 13, 88 +1 Sep 16, 2021