Skip to content

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Filtering by source: Data Protection Commision of Bulgaria (KZLD) (9 items)
Clear filter
9 Posts
12 Topics
Apr 14 Latest

Political Party: Insufficient legal basis for data processing

โ‚ฌ2,000 fine - Data Protection Commision of Bulgaria (KZLD)

Forging signatures on a voters' list.

T.K. EOOD: Insufficient technical and organisational measures to ensure information security

โ‚ฌ2,560 fine - Data Protection Commision of Bulgaria (KZLD)

The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to ensure the information security. T.K. EOOD processed the personal data of I.S. unlawfully nine times in duration of five months. The breaches caused damages to the data subject.

L.E. EOOD: Insufficient technical and organisational measures to ensure information security

โ‚ฌ2,560 fine - Data Protection Commision of Bulgaria (KZLD)

The fine of ca EUR 2,557 was imposed on L.E. EOOD for unlawful processing of personal data of data subject I.S. without the knowing and the consent of the data subject and also without a valid contractual relationship between L.E. EOOD and I.S. The enterprise processed the personal data of I.S. unlawfully seven times in duration of 3 months by failure to adopt technical and organizational measures to ensure the information security. In addition to the fine, the Commission for Personal Data Prote

Utility Company: Insufficient legal basis for data processing

โ‚ฌ5,110 fine - Data Protection Commision of Bulgaria (KZLD)

The fine of EUR ca. 5,113 was imposed on a Bulgarian utility company for unlawful processing of the personal data of the data subject V.V. The personal data of V.V. was unlawfully processed and subsequently used for initiating an enforcement case against him for outstanding payment obligations. During the enforcement case, the bailiff seized the data subjectโ€™s salary, and the latter suffered damages as a result of the unlawful processing.

National Revenue Agency: Insufficient legal basis for data processing

โ‚ฌ28,100 fine - Data Protection Commision of Bulgaria (KZLD)

The pecuniary sanction of EUR 28, 121 was imposed on the National Revenue Agency for unlawful processing of the personal data of data subject G.B.I. The personal data of G.B.I. was unlawfully collected and subsequently used to form an enforcement case against her for recovery of the sum of EUR ca. 86, 569. In relation to the enforcement case formed, additional data concerning the bank accounts of G.B.I was collected by the National Revenue Agency from the register of the Bulgarian National Bank.

National Revenue Agency: Insufficient technical and organisational measures to ensure information security

โ‚ฌ2,600,000 fine - Data Protection Commision of Bulgaria (KZLD)

Leakage of personal data in a hacking attack due to inadequate technical and organisational measures to ensure the protection of information security. It was found that personal data concerning about 6 million persons was illegally accessible.

DSK Bank: Insufficient technical and organisational measures to ensure information security

โ‚ฌ511,000 fine - Data Protection Commision of Bulgaria (KZLD)

Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit records relating to over 33000 bank customers including personal data such as names, citizenships, identification numbers, adresses, copies of identity cards and biometric data.

Medical centers: Insufficient legal basis for data processing

โ‚ฌ510 fine - Data Protection Commision of Bulgaria (KZLD)

The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his GP. The medical centre used a software to generate a registration form for change of GP which was submitted to the Regional Health Insurance Fund and then to another medical centre, which subsequently also unlawfully processed the personal data of G.B.

A.P. EOOD: Insufficient legal basis for data processing

โ‚ฌ5,100 fine - Data Protection Commision of Bulgaria (KZLD)

The sanction was imposed on personal data administrator A.P. EOOD for unlawful processing of personal data. The personal data of data subject D.D. was used by A.P. EOOD for preparing an Employment Contract, while he was in prison.