點選標題閱覽案例摘要
Year|2021
GDPR Case 105. Polish DPA fines Anwara Sp. zo.o. for failing to cooperate
GDPR Case 106. Polish DPA Fines ENEA S.A.: A Data breach must be notified to the supervisory authority
GDPR Case 107. Polish DPA & Virgin Mobile Polska: Incidental safeguards review is not regular testing of technical measures
GDPR Case 108. Polish DPA & WARTA: Failure to notify a personal Data breach without undue delay as a reason for imposing a fine
GDPR Case 109. Polish DPA & ID Finance Poland: Checking potential system vulnerabilities cannot be delayed
GDPR Case 110. Polish DPA: University Fined for the lack of Data breach Notifications
GDPR Case 111. Italian DPA imposes limitation on processing on TikTok after the death of a Girl from Palermo
GDPR Case 112. Dutch DPA issues Formal Warning to a Supermarket for its use of Facial Recognition Technology
GDPR Case 113. Belgian DPA imposes €50,000 Fine on Family Service
GDPR Case 114. Polish DPA fines Smart Cities: Another fine for lack of cooperation with the Personal Data Protection Office
GDPR Case 115. Norwegian DPA issues fine to Lindstrand Trading AS
GDPR Case 116. Norwegian DPA issues fine to Gveik AS
GDPR Case 117. Dutch DPA fines OLVG hospital for inadequate protection of medical records
GDPR Case 118. Norwegian DPA issues fine for forwarding e-mail
GDPR Case 119. Polish DPA fines the National School of Judiciary and Public Prosecution (KSSIP) for breaching the GDPR rules
GDPR Case 120. Norwegian DPA issues fine to Cyberbook AS
GDPR Case 121. Norwegian DPA issues reprimand to Telenor for inadequate protection of personal data
GDPR Case 122. Swedish DPA: Police unlawfully used facial recognition app
GDPR Case 123. Norwegian DPA issues fine to Municipality of Indre Østfold
GDPR Case 124. Polish DPA: The first fine for non-compliance with an administrative decision order
GDPR Case 125. Spanish Data Protection Authority (AEPD) imposes fine of €6,000,000 on CAIXABANK, S.A.
GDPR Case 126. Norwegian DPA issues fine to Aquateknikk AS
GDPR Case 127. Polish DPA: Breach of the GDPR provisions by Funeda results in a fine
GDPR Case 128. Lithuania DPA issues €12,000 fine for infringements of the General Data Protection Regulation in application “Karantinas” (Quarantine)
GDPR Case 129. Lithuania DPA issues €15,000 fine for infringements of the General Data Protection Regulation in the Centre of Registers
GDPR Case 130. Bavarian DPA (BayLDA) calls for German company to cease the use of 'Mailchimp' tool
GDPR Case 131. Spanish DPA Fines Vodafone Spain more than €8 Million
GDPR Case 132. Polish DPA: Identifying breaches too late puts customers at risk
GDPR Case 133. Polish DPA: Failure to respond to the supervisory authority’s requests is also a failure to cooperate
GDPR Case 134. Dutch DPA fines municipality for Wi-Fi tracking
GDPR Case 135. Norwegian DPA: Intent to issue €2,5 million fine to Disqus Inc.
GDPR Case 136. Finnish DPA: Administrative fine imposed on ParkkiPate for data protection violations connected to parking control fees
GDPR Case 137. Dutch DPA: PVV Overijssel fined for failing to report Data breach
GDPR Case 138. Dutch DPA imposes fine of €525,000 on Locatefamily.com
GDPR Case 139. Italian SA: unfettered employee surveillance to be banned
GDPR Case 140. Norwegian DPA: Miljø- og Kvalitetsledelse AS fined
GDPR Case 141. Norwegian DPA: Dragefossen AS fined
GDPR Case 142. Norwegian DPA: Municipality of Asker fined
GDPR Case 143. Norwegian DPA: Company fined for illegal forwarding of e-mail
GDPR Case 144. Norwegian DPA: Ålesund municipality fined for use of Strava
GDPR Case 145. Norwegian DPA: Basaren Drift AS fined
GDPR Case 146. Spanish DPA imposes fine of €1,500,000 on EPD Comercializadora, S.A.U. for two infractions of the GDPR.
GDPR Case 147. Spanish DPA imposes fine of €1,500,000 on EPD Energía, S.A.U. for two infractions of the GDPR
GDPR Case 148. Italian DPA: The Italian SA issues a warning to the Campania Region
GDPR Case 149. Italian DPA: Processing limitation on a COVID19-related app (‘Mitiga’)
GDPR Case 150. Polish DPA fines P4 company PLN 100,000
GDPR Case 151. Dutch DPA: CP&A receives fine for violating privacy of sick employees
GDPR Case 152. Austrian DPA Fine for ignoring several requests to provide information concerning an alleged infringement of the GDPR
GDPR Case 153. Swedish DPA: Incorrect use of 24/7 surveillance of firefighters
GDPR Case 154. Dutch DPA: Orthodontic practice fined for unsecured patient website
GDPR Case 155. Swedish DPA: Investigation of 1177-incident finalized
GDPR Case 156. Norwegian DPA: Municipality of Oslo fined
GDPR Case 157. Norwegian DPA: Norwegian Confederation of Sport fined for inadequate testing
GDPR Case 158. Unlawful use of body cams in Stockholm’s public transport
GDPR Case 159. Polish DPA: The controller should carry out a fair risk analysis
GDPR Case 160. Norwegian DPA: BRAbank ASA fined
GDPR Case 161. The Icelandic DPA has fined a company running ice cream parlours for processing employee‘s personal data via video surveillance camera installed in an employee area.
GDPR Case 162. Polish DPA: The incident must be notified to the supervisory authority and the data subjects
GDPR Case 163. German SAs: Cross-state audit: Consent on media companies’ websites is mostly ineffective - Improvements are needed
GDPR Case 164. Norwegian DPA: Order to improve solutions for consent
GDPR Case 165. Norwegian DPA: Oslo University Hospital ordered to amend agreements
GDPR Case 166. Norwegian DPA: Innovation Norway fined
GDPR Case 167. Norwegian DPA: Fine for accessing former employee’s e-mail inbox and failing to close e-mail inbox
GDPR Case 168. RIDERS: ITALIAN SA SAYS NO TO ALGORITHMS CAUSING DISCRIMINATION A platform in the Glovo group fined €2.6 million
GDPR Case 169. Finnish SA: Fine for a company for carrying out direct marketing with robocalls without consent
GDPR Case 170. Norwegian DPA: Moss Municipal Council fined
GDPR Case 171. Lithuania DPA: Fine Imposed on a Sports Club for Infringements of the GDPR in Processing of Fingerprints of the Customers and Employees
GDPR Case 172. Polish SA: Personal data carrier must be secured
GDPR Case 173. Dutch DPA: TikTok fined for violating children’s privacy
GDPR Case 174. French DPA: €1.75 million penalty against AG2R LA MONDIALE
GDPR Case 175. Slovenian SA orders the controller to delete a collection of 88 photos according to §17 of the GDPR
GDPR Case 176. Italian SA finds monitoring system for online university exams to be in breach of privacy, fines university
GDPR Case 177. Dutch SA fines Transavia for poor personal data security
GDPR Case 178. Norwegian DPA: Reprimanded after accessing e-mail account
GDPR Case 179. Finnish SA: Police reprimanded for illegal processing of personal data with facial recognition software
GDPR Case 180. Italian SA reprimands a real estate agency and fines it because it failed to reply to the SA’s requests for information
GDPR Case 181. The Norwegian Data Protection Authority: Ferde AS fined
GDPR Case 182. Hamburg DPA: Penalty against Vattenfall Europe Sales GmbH
GDPR Case 183. Slovenian Administrative Court upholds the decision of the Slovenian SA: the right of erasure does not enable an individual to have his personal data erased from GDPR Case Baptismal Register
GDPR Case 184. Norwegian DPA: St. Olavs Hospital fined
GDPR Case 185. Italian SA bans remote surveillance of customer care employees
GDPR Case 186. Norwegian DPA: Waxing Palace AS fined
GDPR Case 187. Norwegian DPA: Høylandet Municipal Council Fined
GDPR Case 188. Norwegian DPA: Ultra-Technology AS fined
GDPR Case 189. AEPD impose a fine to a telephone company for a loss of confidentiality and a lack of adequate technical and organisational measures
GDPR Case 190. Polish DPA: Bank Millennium fined for failure to notify the breach and the data subjects about the incident
GDPR Case 191. The Norwegian SA issues fine to the Norwegian Public Service Pension Fund
GDPR Case 192. Icelandic DPA issues fine to the Ministry of Industries and Innovation and YAY ehf. for data processing through a digital gift card app
GDPR Case 193. The Norwegian SA imposes fine against Elektro & Automasjon Systemer AS
GDPR Case 194. The Norwegian SA issues fine and order company to establish procedures after unlawful credit rating
GDPR Case 195. Norwegian DPA imposes fine against Grindr LLC