Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

152 fines found

Total: $1.6M

DateCompanyFineRegulationAuthorityCountryTypeSummary
2023-03-06Integral Collection SRL€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b), c) GDPR, Art. 32 (2) GDPR

2022-06-15S.C. Wine Point S.R.L.€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b) GDPR

2020-04-23Telekom Romania Communications SA€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-07-05Legal Company & Tax Hub SRL€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
The company had not imposed sufficient security measures, which led to the unaut...

The company had not imposed sufficient security measures, which led to the unauthorized access of personal information related to the people who had made transactions with the website avocatoo.ro. This information includes names, emails, phone numbers, jobs, surnames, mailing addresses, and transaction details). Documents dated 10th of November 2018 – 1st of February 2019 had become publicly accessible to anyone. The company was sanctioned following a notification by the National Supervisory Authority when transaction details were publicly accessible via two links.

Articles: Art. 32 GDPR

2023-04-19Partidul Uniunea Salvați România€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b) GDPR, Art. 6 GDPR

2019-07-05Legal Company & Tax Hub SRL€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2022-02-22IAMSAT Muntenia SA€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-compliance with lawful basis for data processing
--

Articles: Art. 12 GDPR, Art. 13 GDPR, Art. 21 GDPR

2021-11-14Vodafone România SA€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b) GDPR, Art. 32 (2) GDPR, Art. 3 (1) Law No. 506/2004, Art. 3 (3) a), b) Law No. 506/2004

2019-10-17UTTIS INDUSTRIES€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaInformation obligation non-compliance
A controller was sanctioned because he had unlawfully processed the personal dat...

A controller was sanctioned because he had unlawfully processed the personal data (CNP), and images of employees obtained through the surveillance system. The disclosure of the CNP in a report for the ISCIR training in 2018 wasn’t legal, as per Art.6 GDPR.

Articles: Art. 12 GDPR, Art. 13 GDPR, Art. 5 (1) c) GDPR, Art. 6 GDPR

2019-10-17UTTIS INDUSTRIES€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaInformation obligation non-compliance
--

Articles: Art. 12 GDPR, Art. 13 GDPR, Art. 5 (1) c) GDPR, Art. 6 GDPR

2019-11-29Royal President S.R.L.€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaInformation obligation non-compliance
The pension Royal President near Bucharest was fined €2,500 after it refused to ...

The pension Royal President near Bucharest was fined €2,500 after it refused to process a request for the exercise of the right of access. The Romanian Data Processing Authority also determined that customers’ personal data was not processed in accordance with GDPR principles.

Articles: Art. 12 GDPR, Art. 15 GDPR

2019-11-29Royal President S.R.L.€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaInformation obligation non-compliance
--

Articles: Art. 12 GDPR, Art. 15 GDPR

2023-03-06Finopro IFN SA€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b), c) GDPR, Art. 32 (2) GDPR

2022-06-30Continental Automotive Romania SRL€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 24 GDPR, Art. 32 (1) d) GDPR

2022-06-03Kaufland Romania SCS €2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 29 GDPR, Art. 32 (1) b) GDPR, Art. 32 (2), (4) GDPR

2022-08-04Sephora Cosmetics România SA€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)Romania Non-compliance with subjects' rights protection safeguards
--

Articles: Art. 21 GDPR

2019-11-22BNP Paribas SA€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaInformation obligation non-compliance
BNP Paribas Personal Finance was requested to erase personal data of a client an...

BNP Paribas Personal Finance was requested to erase personal data of a client and it did not do so during the timeframe required by GDPR legislation.

Articles: Art. 12 GDPR, Art. 17 GDPR

2019-12-02Nicola Medical Team 17 SRL€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-cooperation with Data Protection Authority
The company did not comply with measures imposed by the Data Protection Authorit...

The company did not comply with measures imposed by the Data Protection Authority.

Articles: Art. 58 GDPR

2019-12-16Globus Score SRL€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-cooperation with Data Protection Authority
The company did not comply with measures imposed by the Data Protection Authorit...

The company did not comply with measures imposed by the Data Protection Authority.

Articles: Art. 58 GDPR

2019-12-18Telekom Romania€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
The company did not ensure the accuracy of the processing of personal data. This...

The company did not ensure the accuracy of the processing of personal data. This resulted in the disclosure of a client’s personal data to a different client.

Articles: Art. 32 GDPR

2020-03-25SOS Infertility Association€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-cooperation with Data Protection Authority
The SOS Infertility Association failed to provide the necessary data to the data...

The SOS Infertility Association failed to provide the necessary data to the data protection authority after it had unlawfully processed personal data of its clients.

Articles: Art. 58 GDPR

2022-09-22Bitfactor SRL€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information
--

Articles: Art. 25 (1) GDPR, Art. 32 (1), (2) GDPR

2022-09-19Banca Comercială Română SA€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information
--

Articles: Art. 25 (1) GDPR, Art. 32 (1) b), d), e) GDPR

2022-11-07Romanian Post€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b), (2) GDPR

2022-09-09SC Raiffeisen Bank SA€2KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to comply with data processing principles
--

Articles: Art. 5 (1) d) GDPR

PreviousPage 4 of 7Next