| Ország | Dátum | Bírság(€) | Szervezet | Cikk | Típus | Összefoglaló | Linkek |
|---|---|---|---|---|---|---|---|
| BELGIUM | 2020.05.29 | 1.000 € | Non-profit organisation | GDPR 6. cikk GDPR 21. cikk | Insufficient fulfilment of data subjects rights | The Belgian data protection authority has imposed a fine of EUR 1000 on a non-profit organisation for sending out direct marketing messages, despite the fact that data subjects had exercised their right to erasure and objection. The organisation claimed that it was relying on legitimate interests as a legal basis and not on the explicit consent of the data subjects. The data protection authority, however, denied the existence of any outweighing of legitimate interests. | Link |
| FINLANDIA | 2020.05.22 | 100.000€ | Posti Group Oyj | GDPR 12. cikk GDPR 13. cikk GDPR 14. cikk GDPR 15. cikk | Insufficient fulfilment of data subjects rights | The decision relates to complaints alleging that data subjects received direct marketing from the company although they had requested that their postal data be deleted. Investigations also revealed that the data protection information provided by the company was not transparent enough. | Link |
| FINLANDIA | 2020.05.22 | 16 000 € | Kymen Vesi Oy | GDPR 35. cikk | Non-compliance with general data processing principles | Fine for failure to carry out a data protection impact assessment ("DPIA") for the processing of location data of employees with a vehicle information system | Link |
| FINLANDIA | 2020.05.22 | 12 500 € | Unknown Company | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | Processing of employee data without sufficient legal basis. | Link |
| FINLANDIA | 2020.05.17 | 75 000 € | Tusla | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a child were disclosed to an alleged offender, and in two other cases, data about children in foster care were improperly disclosed to blood relatives, including in one case to a father in prison. | Link |
| DÁNIA | 2020.05.15 | 6 700 € | JobTeam A/S DKK | GDPR 15. cikk | Insufficient fulfilment of data subjects rights | The company has deleted personal data affected by a request for access without legal reason. Datatilsynet received a complaint stating that JobTeam A/S had deleted personal data covered by a registrar's request for access during the period after the request was made and before the company responded. Datatilsynet hold that JobTeam unlawfully foreclosed the citizen's ability to verify whether he or she had the right to gain access to the information with Datatilsynet and a court. (https://gdprhub.eu/index.php?title=Datatilsynet_-_JobTeam_indstillet_til_b%C3%B8de) | Link |
| SVÉDORSZÁG | 2020.05.12 | 11 200 € | Health and Medical Board of the Region of Örebro County | GDPR 5. cikk GDPR 6. cikk GDPR 9. cikk | Insufficient legal basis for data processing | Publication of personal data of a patient without sufficient legal basis. Datainspektionen has received a complaint against the Health and Medical Committee in the Örebro County Region, which claimed that sensitive personal information about a patient admitted to a forensic psychiatric clinic was published on the region's website. The examination by Datainspektionen shows that there are no written procedures concerning the publication of documents and personal data on the website. Procedures for publishing are communicated orally. In this case, the oral procedures have not been followed and the document was inadvertently published, which indicates that the Comittee has not taken adequate organizational measures to ensure that personal data is protected from being incorrectly published on the region's website. Therefore, Datainspektionen decided that the Board has to produce written instructions and introduce procedures that ensure that the person who publishes personal data on the Web does so in accordance with those instructions. Further, Datainspektionen ruled that the Comittee had neither a legitimate purpose, a legal basis nor a reason for exempting from the prohibition in the Data Protection Regulation against the handling of sensitive personal data. The Data Inspectorate also issued an administrative penalty fee of SEK 120,000 against the Committee. (https://gdprhub.eu/index.php?title=Datainspektionen_-_DI-2020-1539) | Link |
| ROMÁNIA | 2020.05.05 | 5 000 € | Banca Comercialã Românã SA | GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | The data protection authority finds that the company has not taken adequate technical and organisational measures to ensure an adequate level of information security. This applies in particular to the collection and transmission of copies of customers' identification documents via WhatsApp. | Link |
| HOLLANDIA | 2020.04.30 | 725 000 € | Unknown Organisation | GDPR 5. cikk A GDPR 9. cikk (2) bekezdésének a) és b) pontja | Insufficient legal basis for data processing | The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation could not rely on exceptions to the processing of this special category of personal data and the company could also not provide any evidence that the employees had given their consent to this data processing. "Employees of a company have had their fingerprints scanned for attendance and time registration." "After investigation, the Personal Data Authority (AP) concluded that the company should not have processed fingerprints of employees. Indeed, the company cannot invoke an exceptional ground for processing special personal data. The company will be fined EUR 725,000 for this. [...] For the use of fingerprints, two exceptions to the prohibition could be possible in this case: if explicit consent of the data subjects is requested or if the use of biometric data is necessary for authentication or security purposes. The AP concluded that this company cannot invoke one of these two exceptions for the collection, storage and use of employees' fingerprints. [...] This company has not demonstrated that the employees have given explicit consent. Employees have also experienced the recording of their fingerprint as an obligation." (https://gdprhub.eu/index.php?title=AP_-_Fine_for_processing_employees%27_fingerprints) | Link |
| SVÉDORSZÁG | 2020.04.29 | 18 700 € | National Government Service Centre (NGSC) | GDPR 33. cikk, GDPR 34. cikk | Insufficient fulfilment of data breach notification obligations | The DPA's decision shows that it took almost five months for the company to notify the data subjects of a data breach and almost three months for the DPA to receive a notification of a data breach concerning an security lack of IT systems of the company. | Link |
| BELGIUM | 2020.04.28 | 50 000 € | Proximus SA | GDPR 31. cikk, GDPR 37. cikk, GDPR 58. cikk | Lack of appointment of data protection officer | According to the data protection authority, the company's data protection officer was not sufficiently involved in the processing of personal data breaches and the company did not have a system in place to prevent a conflict of interest of the DPO, who also held numerous other positions within the company (head of compliance and audit department), which led the DPA to the conclusion that the company's DPO was not able to work independently. | Link |
| ROMÁNIA | 2020.03.25 | 2 000 € | SOS Infertility Association | GDPR 58. cikk (1) bekezdésének a) pontja és e) pontja GDPR 83. cikk (5) bekezdésének e) pontja | Insufficient cooperation with supervisory authority | The Association did not provide the data protection authority with the information requested by the latter after the Association had processed personal data without a sufficient legal basis. The ANSPDCP was notified that the the Association SOS Infertility processed personal data without consent and it initiated investigation. It ordered the Association to to provide information and allow access to personal data according to Article 58(1)(a) and (e) GDPR. The controller did not comply. Since the data controller did not respond to the ANSPDCP's orders, the latter decided to impose a fine of 9529.2 lei (approx. EUR. 2,000) and to order the controller to provide all requested information within 5 days. (https://gdprhub.eu/index.php?title=ANSPDCP_-_Association_SOS_Infertility) | Link |
| ROMÁNIA | 2020.03.25 | 3 000 € | Enel Energie | GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | The company has sent an email to a client which contained personal data of another client since the company failed to implement adequate technical and organisational measures to ensure an adequate level of information security. The energy company Enel Energie Muntenia SA was investigated after a notification sent by a customer to the DPA. The ANSPDCP found that Enel Energie Muntenia SA transmitted a client's personal data to the e-mail address of another client. The DPA decided that the controller did not have adequate technical and organizational measures in place to ensure a level of security that corresponds to the risk of the processing. Thus, the controller violated the security of processing as required by Article 32 GDPR and the DPA imposed the fine of 14,423.7 lei (approx. EUR. 3,000) and ordered the controller to take the necessary measures within 30 days. (https://gdprhub.eu/index.php?title=ANSPDCP_-_fine_to_Enel_Energie_Muntenia_SA) | Link |
| ROMÁNIA | 2020.03.25 | 4 150 € | Vodafone Romania | GDPR 32. cikk GDPR 5. cikk (1) bekezdés d) és f) pont GDPR 5. cikk (2) bekezdés GDPR 58. cikk (2) bekezdés d) pont | Insufficient technical and organisational measures to ensure information security | The company has sent an email to a customer which contained personal data of another customer due to inadequate technical and organisational measures to ensure information security. The ANSPDCP carried out investigation against the Romanian telecommunication operator Vodafone România SA. The company transmitted personal data to inaccurate e-mail address while handling a data subject's complaint. The ANSPDCP found that the company processed personal data without having implemented sufficient security measures. Thus it violated the principles of accuracy, integrity and confidentiality as laid down in Article 5(1)(d) and (f) GDPR read in conjunction with the principle of accountability according to Article 5(2) GDPR. The ANSPDCP imposed a fine of 14308.8 lei (equivalent to EUR. 3.000) and pursuant to Article 58(2)(d) GDPR it ordered the complany to put in place efficient technical and organisational measures within 30 days. (https://gdprhub.eu/index.php?title=ANSPDCP_-_Vodafone_Rom%C3%A2nia_SA) | Link |
| ROMÁNIA | 2020.03.25 | 3 000 € | Dante International | GDPR 6. cikk GDPR 21. cikk (3) bekezdés GDPR 58. cikk (2) bekezdés c) pont GDPR 58. cikk (2) bekezdés d) pont | Insufficient legal basis for data processing | The company has sent a commercial e-mail to a client though the client had previously unsubscribed from commercial communications. The complainant received a commercial message from Dante Interna?ional SA (the data controller), although they had exercised their right to object to processing as foreseen in Article 21(3) GDPR. The ANSPDCP confirmed that the complainant had exercised the right to object and nevertheless the controller contacted them for commercial purposes. The ANSPDCP imposed two corrective measures on the controller according to Article 58(2)(c) and (d) GDPR and the fine of 14,420.4 lei, the equivalent of the amount of EUR 3,000. (https://gdprhub.eu/index.php?title=ANSPDCP_-_fine_to_Dante_Interna%C8%9Bional_SA) | Link |
| SPANYOLORSZÁG | 2020.03.25 | 5 000 € | Xfera Moviles S.A. | 58. cikk, (1) bekezdés, GDPR 83. cikk, (5) bekezdés, GDPR | Insufficient cooperation with supervisory authority | The company did not provide the data protection authority with the requested information in a timely manner. The AEPD's request was preceded by a request from a data subject for access to its personal data. Following a complaint against the mobile network operator Xfera Móviles, S.A.U., the AEPD ordered the controller to provide all information that was necessary for the AEPD to investigate the complaint. The controller did not comply. The AEPD considered all aggravating and mitigating circumstances in this particular case and imposed the fine of EUR. 5,000. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00436/2019) | Link |
| GÖRÖGORSZÁG | 2020.03.20 | 8 000 € | Speech and Special Education Centre - Mihou Dimitra | GDPR 58. cikk GDPR 5. cikk (2) bekezdés GDPR 15. cikk (1) bekezdés GDPR 15. cikk (3) bekezdés | Insufficient fulfilment of data subjects rights | The complainant had requested access to his child's data and to tax information. This request was rejected by the data controller. In addition, the data controller had violated an order of the data protection authority regarding access to the data. For this, a fine of EUR 8000 was imposed: EUR 3000 for not granting access to the data and EUR 5000 for violating orders of the data protection authority. The complainant requested twice via e-mail all data that the Centre as data controller held on his minor child. The controller refused to provide the data because of the complainant's ex-wife's (and mother's of his child) refusal. The controller argued that the mother had custody. The HDPA first asked the controller to immediately fulfill the complainant's request according to Article 15(1) and (3) GDPR and inform the authority accordingly. It invoked is own case law, according to which any parent who has parental responsibility of the child may have the right of access according to Article 15, even if they don't have custody, unless there is a specific court decisions ordering otherwise e.g. prohibition of communication with the child. The controller did not comply and it did not notify the HDPA of any decision it took with this regard. The HDPA, as had initially decided, found that the controller should have fulfilled the complainant's right of access or should have justified its refusal to do so -especially after the HDPA's initial order. Thus, it found that the controller had violated Article 15 (1) and (3) as well as the principle of accountability as provided for in Article 5(2) GDPR. (https://gdprhub.eu/index.php?title=HDPA_-_4/2020) | Link |
| SPANYOLORSZÁG | 2020.03.19 | 6 000 € | Oliveros Ustrell, SL | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | The company forwarded an unsigned porting contract to the operator Vodafone. However, the data controller was unable to provide evidence of the order. For this reason, the personal data of the data subject has been processed without sufficient legal basis. The AEPD found different data processing activities related to the claimant. The claimant argued that he had received a message from Vodafone about a purchase made in a physical shop. The complainant denies that this purchase actually happened. Further, a seller from Oliveros Ustrell forwarded an unsigned number portability contract to Vodafone concerning the claimant. Oliveros Ustrell was unable to provide proof of the order. In addition, the AEPD could not find a legal basis for the collection and processing of personal data on the information systems of the Oliveros Ustrell. Dispute: Whether the collection and process of personal data from Oliveros Ustrell was based on consent. Since the AEPD did not receive evidence of the existence of consents for the different data processing activities and no other justifications apply, the AEPD considered these activities as unlawful. The original amount of the fine was set up to EUR 10,000. The AEPD considered the voluntarily payment from Oliveros Ustrell of the fine and therefore deducted the amount to EUR 6,000. (https://gdprhub.eu/index.php?title=AEPD_-_PS-00008-2020) | Link |
| SPANYOLORSZÁG | 2020.03.18 | 30 000 € | Telefónica | GDPR 58. cikk (2) bekezdésk c) pont | Insufficient cooperation with supervisory authority | Telefonica had failed to comply with decision TD / 00127/2019 of the Director of the AEPD, which states that it had to reply to data subjects' request for right of access and erasure of data. The decision is the consequence of a second complaint submitted in June 2019 by a Spanish citizen stating that, after a first complaint (July 2018) in which he informed the AEPD that he had exercised his rights of access and erasure before the data controller without results (and, according to which, the AEPD had issued a decision requesting the data controller to grant such rights), the data controller only granted the erasure right to the citizen, but not the access right. The data controller answered to the AEPD investigation requests that it had sent the citizen the corresponding information on the reason why it could not grant such access right: it had not been able to do so because it had already managed and granted the erasure right also requested. Did the data controller infringe its obligation to fulfill the data subject's rights of access and erasure? The AEPD found that the data controller did not comply with its previous decision (as it did not grant the access right to the citizen) and, after considering some aggravating (the data controller has the consideration of a big company) and extenuating (the data controller has not obtained any benefits from its actions) circumstances, it decided to impose a fine of 30,000 to the data controller. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00351/2019) | Link |
| SPANYOLORSZÁG | 2020.03.16 | 5 000 € | Centro De Estudio Dirigidos Delta, S.L. | GDPR 5. cikk (1) bekezdés f) pont GDPR 5. cikk (2) bekezdés | Non-compliance with general data processing principles | Centro De Estudio Dirigidos Delta sent a message containing personal data such as first and last name and ID numbers to a third party via WhatsApp without the consent of the data subjects. This constitutes a violation of the principles of integrity and confidentiality under Article 5(1)(f) GDPR. The decision is the consequence of a complaint submitted by a Civil Guard local office (the claimant) stating that the data controller had sent a Whatsapp message to a third party including personal data (name, surname, ID number) of three people (a mother and her children, probably underage) without their knowledge nor their consent. The complaint includes a copy of such message and a certification by the Civil Guard (although the mobile number of the sender is not identified). The data controller did not answer to any AEPD investigation requests, so the AEPD started the corresponding sanction procedure. The AEPD found that the data controller has infringed not only the integrity and confidentiality principle, but also the accountability principle of Article 5(2) GDPR and, after considering some aggravating circumstances [(i) the data controller has performed a not intentional, but significantly negligent action; (ii) basic personal identification data have been affected (name, surname, domicile)], it decided to impose a fine of 30,000 to the data controller. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00425/2019) | Link |
| SPANYOLORSZÁG | 2020.03.16 | 4 000 € | Private Person | GDPR 5. cikk GDPR 6. cikk (1) bekezdés a) pont | Insufficient legal basis for data processing | On a beach, a private person secretly photographed female bathers. The incident was reported to the AEPD by the local police. The data processor took pictures of women at the beach. The pictures allowed an identification of the concerned women. The police filed a respective claim with the AEPD on July 9, 2019. Dispute: Whether the taking of pictures in public without the consent of the data subjects infringes Article 6 (1) (a) GDPR. The AEPD fined the data processor in an amount of 4,000 Euro for the violation of Article 6 (1) (a) GDPR. Since the women on the pictures can be identified, a consent was required for capturing the pictures. The fact that the women were in public does not harm their right of privacy. The opposite, the facts that the women were mainly not aware of the pictures and the pictures are quite sensitive make the strengthen of the privacy rights necessary. The intention of using the pictures on the phone and the denunciation of sexual touching in a public area were further taking into account for the fine. | Link |
| SPANYOLORSZÁG | 2020.03.16 | 6 000 € | Amalfi Servicios de Restauracion S.L. | GDPR 13. cikk, GDPR 14. cikk GDPR 5. cikk (1) bekezdés c) pont A GDPR 12. cikk A GDPR 30. cikk (1) bekezdés A GDPR 83. cikk (2) bekezdés A LOPDGDD 22. cikke | Non-compliance with general data processing principles | Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has been provided about video surveillance. ?he complaint regarded the installation of a video-surveillance system on the perimeter of a hotel which also captured public spaces. The defendant claimed that the images were not processed by any third party and that it made available information about the cameras both at the hotel reception and in its privacy policy. It also argued that the video-surveillance system is only accessed by the manager of the hotel, the leading engineer and the head of customer service while third persons may only have access if it is necessary and upon prior explicit approval by the DPO. The images are stored for a maximum period of one month. The AEPD first confirmed that the image of natural persons is personal data and the processing carried out through the video surveillance system should be in line with the GDPR. It recalled the principle of data minimisation according to Article 5(1)(c) GDPR, which has to be followed both during the data collection and the subsequent processing. It stressed that such systems may capture public spaces when it cannot be avoided or when this is necessary for the intended security purposes. There is always the duty to inform the affected parties as provided for in Article 12 GDPR and Article 13 GDPR. According to Article 30(1) GDPR a record must be kept by the responsible person. According to the national law in the video-surveiled areas, at least an information sign must be placed in a sufficiently visible place, both in open and closed spaces, which shall identify at least the existence of processing, the identity of the person responsible and the possibility of exercising the rights provided. The cameras should not obtain images of private and/or public space without a justified cause duly accredited, nor can they affect the privacy of passers-by. It is not permitted to place cameras on the private property of neighbors in order to intimidate them or affect their private sphere without justified cause. In this case the AEPD found that the capture of images from the public space was excessive and the data controller acted with serious lack of diligence. The data controller had also not adopted any measures to mitigate the effects of the infringement. However, it noted that the damage to those affected by the processing of their data was not significant, the processing was carried out only by the data controller at a local level and no benefit was obtained from this processing. Finally, after having considered all the mentioned factors, the AEPD imposed a reduced fine of EUR 6,000. | Link |
| HORVÁTORSZÁG | 2020.03.13 | Unknown | Bank (name not available at the moment) | GDPR 15 cikk (1) és (3) bekezés | Insufficient fulfilment of data subjects rights | In the period from May 2018 to April 2019, the bank (name not available at the moment) refused to provide its customers with copies of credit documentation (e.g. repayment plan, loan agreement annex, interest rates changes review etc.). The bank insisted with the argument that the documentation is related to repaid loans and represents loan documentation that cannot be subject to the customers right of access. During the procedure initiated based on data subjects complaints, the DPA ordered the bank to enable the right of access and provide copies of the requested loan documentation. When imposing the fine, the DPA took into consideration especially that the bank failed to comply with the ordered measures, that it continued with such practice for almost a year and denied the right of access to more than 2500 of its customers. The amount of the fine is now known at the moment, but as the DPA qualified the breach as severe, a high fine is expected. The AZOP received complaints from citizens against private Bank. The complainants exercised their right of access under Article 15 GDPR and requested copies of credit documentation (e.g. book keeping card, repayment plan, an annex to the loan agreement, review of changes in interest rates). The Bank refused to grant the access of the requested documentation. The latter stated that according to the Consumer Credit Law and other special regulations, the documentation requested did not contain personal data, only documents related to credits and loans. Following to the complaint, the AZOP established that the requested documents contained personal data and investigated the matter, by virtue of Article 58 GDPR. Despite several orders which have been previously issued (34 decisions), the Bank infringed the data subjects' rights. While deciding about the amount of the fine, the AZOP was applied Article 83 (1) GDPR: the described conduct of the Bank resulted in a serious violation of the data subjects' rights - regulated by art. 83 (5) (b) . It has been established that: the Bank knowingly and intentionally acted; it has not been an isolated case; the longer duration of the violation; it has not made any efforts to mitigate any possible consequences and risks for rights and freedoms of data subjects; the access to personal data has not been made possible even after individual decisions. It was pointed out that by not responding to the requests, the Bank directly avoided certain financial expenses that could be considered to be material gain to the detriment of the data subjects. It was also taken into account that no violations of the Regulation have been established so far, as well as the degree of cooperation with the AZOP. (https://gdprhub.eu/index.php?title=AZOP_-_credit_institution_decision) | Link |
| SPANYOLORSZÁG | 2020.03.12 | 2 000 € | Homeowners Association | GDPR 5. cikk, GDPR 13. cikk, GDPR 14. cikk | Non-compliance with general data processing principles | Video surveillance of public space and thus violation of the principle of data minimization. Furthermore: Violation of information obligations, as insufficient information has been provided about video surveillance. | Link |
| SVÉDORSZÁG | 2020.03.11 | 7 000 € | Google LLC | GDPR 5. cikk, GDPR 6. cikk, GDPR 17. cikk | Insufficient fulfilment of data subjects rights | The Swedish data protection authority has fined Google LLC 7 million for failing to adequately comply with its obligations regarding the right of data subjects to have search results removed from the results list. Datainspektionen had already completed a review in 2017 of the way in which Google deals with the right of individuals to have search results removed from Google's search engine and that Datainspektionen had instructed Google to remove a number of search results. In addition, data inspections stated that it had initiated a further review of Google's practices in 2018 after it received indications that several of the results that should have been removed still appeared in search results. Datainspektionen also objected to Google's current practice of informing web site owners about which results Google is removing from search results, specifically which link has been removed and who is behind the request for removal from the list, as this is without legal basis. | Link |
| DÁNIA | 2020.03.10 | 7 000 € | H?rsholm Municipality | GDPR 5. cikk (1) bekezdés f) pont, GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | A city government employee had his work computer stolen, which contained the personal data of about 1,600 city government employees, including sensitive information and information about social security numbers. | Link |
| DÁNIA | 2020.03.10 | 14 000 € | Gladsaxe Municipality | GDPR 5. cikk (1) bekezdés f) pont, GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | A computer, containing personal data that was not protected by encryption, has been stolen, including sensitive information and personal identification numbers of 20,620 city residents. One laptop belonging to the municipality Gladsaxe has been stolen from the city hall. The laptop was not encrypted. Personal data from more than 20,620 citizen were stored on the device, including information of sensitive nature and personal identification numbers. The working laptop from one employee of the municipality H?rsholm has been other stolen from the car. It was also not encrypted. The data stored on the laptop referred to 1,600 employees of the municipality and contained social security numbers and other information of a sensitive nature. The Danish DPA emphasized the great responsibility of municipalities, since processing of personal data happens in a large scale and also refers to sensitive data. According to the DPA the lack of encryption of devices means an unnecessary high risk to all citizen and, therefore, an actual breach of data security. The DPA imposed a fine of DKK 100,00 against the municipality Gladsaxe and a fine of DKK 50,000 against the municipality H?rsholm. (https://gdprhub.eu/index.php?title=Datatilsynet_-_To_kommuner_indstillet_til_b%C3%B8de) | Link |
| IZLAND | 2020.03.10 | 20 600 € | National Center of Addiction Medicine ('SAA') | GDPR 5. cikk (1) bekezdés f) pont, GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | Persónuvernd noted that a former employee of the SAA received boxes of allegedly personal belongings that he had left there, but which also contained patient data, including the health records of 252 former patients and documents with the names of about 3,000 people who had participated in rehabilitation for alcohol and drug abuse. The case and investigation was opened as a result of a data breach notification sent to Persónuvernd from S.Á.Á. A retired employee, who was the head of the treatment home Vik before retiring, received «a significant amount» of personal data concerning patients, including the detailed medical records of 252 individuals and records of check-ins containing 3,000 names. The personal data was stored in boxes that was sent to the retired employee alongside his belongings. S.Á.Á. did not dispute that a breach of personal data had occurred. However, S.Á.Á. emphasized that the former head packed the boxes himself, and as a former chief he should have been clear about the contents of the boxes. In addition, S.Á.Á. stressed that the incident was related to human error, and that the organization had reviewed their organisational measures to avoid data breaches. In the view of Persónuvernd, the delivery of the medical records was a result of lacking technical and organisational measures. The fact that the former employee had packed the boxes himself did not justify the lack of technical and organisational measures that should have prevented such a disclosure from S.Á.Á. as a controller of the personal data. | Link |
| IZLAND | 2020.03.10 | 9 000 € | Brei?holt Gimnázium | GDPR 5. cikk (1) bekezdés f) pont, GDPR 32. cikk GDPR 83. cikk (2) bekezdés c) pont | Insufficient technical and organisational measures to ensure information security | In violation of Art. 32 GDPR, a teacher had sent an e-mail to his students and their parents with an attachment containing data on their well-being, academic performance and social conditions. Persónuvernd received a notification of a personal data breach from Brei?holt Multicultural School. According to the notification, an attachment containing sensitive information about earlier students was mistakenly sent by a teacher to new students. The teacher mistakenly sent an email with an attachment that included information about interviews that had been conducted the previous semester. The document contained special categories of data concerning the former students. The comments included information about the students well-being, learning outcomes and social conditions. The information was to a large extent about qualities that the students lacked. In one case it related to the fact that the child protection authorities were connected. In another case there was information about mental health, and in another case, physical health. Persónuvernd highlighted that personal data must be processed in accordance to the principles found in Article 5 GDPR, in this case Article 5(1)(f) GDPR. In addition, Persónuvernd highlighted Article 32 GDPR as operationalising the requirement to implement adequate technical and organisational measures to ensure the secure processing of personal data. In light of the requirements for controllers to provide adequate security of personal data, Persónuvernd found that the dissemination of special categories of data was not in line with the requirements as found in GDPR. In reference to Article 83(2)(c), the Supervisory Authority referenced mitigating factors carried out by the school when assessing the fine. (https://gdprhub.eu/index.php?title=Pers%C3%B3nuvernd_-_2020010382) | Link |
| SPANYOLORSZÁG | 2020.03.09 | 15 000 € | Gesthotel Activos Balagares | GDPR 5. cikk (1) bekezdés f) pont | Non-compliance with general data processing principles | The data subject argued that he had sent a private letter to the hotel management and union delegates containing information about an episode of harassment he had suffered, describing a specific medical condition. In violation of the principle of integrity and confidentiality, the hotel management and union delegates subsequently read the contents of this letter in a meeting with other employees. | Link |
| LENGYELORSZÁG | 2020.03.09 | 4 400 € | Vis Consulting Sp. z o.o. | GDPR 31. cikk, GDPR 58. cikk | Insufficient cooperation with supervisory authority | The company prevented an inspection by the data protection authority. As a result, the company has violated Article 31 in conjunction with Article 58(1)(e) and (f) of the GDPR. The President of the UODO decided to conduct inspection activities at a company Vis Consulting Sp. z o.o. which provides telemarketing services to other companies - one of which was a subject of a decision issued earlier by the UODO. The supervisory authority found it necessary to conduct inspection activities at the entity which actually operated the telephone calls and processed the data. On two consecutive days of the planned inspection activities, the company made it impossible to carry out the inspection twice. Furthermore, on the date on which the inspectors attempted to conduct inspection at Vis Consulting Sp. z o.o., its authorities decided to liquidate that entity. The President of the UODO had to make a decision about the company's compliance with Article 31 GDPR. The President of the UODO decided that Vis Consulting Sp. z o.o. in no way wished to cooperate with the supervisory authority. The UODO concluded that the company deliberately thwarted the inspection and thus prevented the President of the UODO from performing statutory tasks under Article 58(1)(e) and (f) GDPR. The situation gives rise to the suspicion that the Company's thwarting of the inspection was aimed at preventing the UODO from collecting evidence of unlawful processing of personal data by the company. Thus the company infringed the provisions of the GDPR referring to cooperation with the supervisory authority and enabling it access to all personal data and any information. Hence, the President of the UODO concluded that the conditions for imposing a fine on the company were satisfied. In connection with suspicion of commission of an offence under Article 108 (1) of the Act on the Protection of Personal Data by the President of the Company, the supervisory authority notified the District Public Prosecutors Office in Katowice thereof. According to that provision, the prevention or hindering of conducting inspection of compliance with the personal data protection provisions shall be subject to a fine, restriction of personal liberty or imprisonment for up to two years. The Public Prosecutors Office has lodged an indictment against the President of the Company to the court. (https://gdprhub.eu/index.php?title=UODO_-_ZSPR.421.19.2019) When arrived at the company's registered address, the UODOs inspectors did not find any representatives of the Vis Consulting Sp. z o.o. After the back-and-forth communication between the UODO representatives and the company's proxy, the latter informed the UODO on the phone that the inspection cannot take place. | Link |
| OLASZORSZÁG | 2020.03.06 | 4 000 € | Liceo Artistico Statale di Napoli | GDPR 5. cikk (1) bekezdés a) pont GDPR 6. cikk (1) bekezdés c) pont GDPR 6. cikk (1) bekezdés e) pont GDPR 9. cikk (1) bekezdés GDPR 9. cikk (2) bekezdés GDPR 9. cikk (4) bekezdés | Insufficient legal basis for data processing | The AEPD's decision reveals that the high school unlawfully published health data and other information in the teacher rankings published on the Institute's website. This publication was made in violation of the principles of lawfulness, fairness, transparency and data minimization. The Garante examined a complaint against the publication on the school website of the details of the teaching staff (around 1.500 subjects concerned), including address, phone number, number of children and data concerning health. Dispute: The Garante had to assess whether such disclosure was justified and lawful. The Garante considered that the most likely applicable lawful basis for the process of personal data in the public sector is the compliance with a legal obligation or the performance of a task carried out in the public interest or in the exercise of official authority under Article 6 (1) (c) (e) GDPR. In this regard, in the Garantes view part of the data was disclosed unlawfully with no Article 6 basis for processing. Moreover, the Garante found that the disclosure of the teaching staff personal data contravened the data protection principle of lawfulness, fairness and transparency and data minimization under Article 5 (1) (a) (c) GDPR. The Garante further found that the school also published data concerning health, failing to respect the prohibition under Article 9 (1) GDPR and without relying on any specific exemptions under Article 9 (2) (4) GDPR. (https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_-_9283029) | Link |
| OLASZORSZÁG | 2020.03.06 | 4 000 € | Liceo Scientifico Nobel di Torre del Greco | GDPR 5. cikk, GDPR 6. cikk, GDPR 9. cikk | Insufficient legal basis for data processing | The AEPD's decision reveals that the high school unlawfully published health data and other information of more than 2000 teachers in the teacher rankings published on the Institute's website. This publication was made in violation of the principles of lawfulness, fairness, transparency and data minimization. The Garante examined a complaint against the publication on the school website of the details of the teaching staff (around 1.500 subjects concerned), including address, phone number, number of children and data concerning health. Dispute: The Garante had to assess whether such disclosure was justified and lawful. The Garante considered that the most likely applicable lawful basis for the process of personal data in the public sector is the compliance with a legal obligation or the performance of a task carried out in the public interest or in the exercise of official authority under Article 6 (1) (c) (e) GDPR. In this regard, in the Garantes view part of the data was disclosed unlawfully with no Article 6 basis for processing. Moreover, the Garante found that the disclosure of the teaching staff personal data contravened the data protection principle of lawfulness, fairness and transparency and data minimization under Article 5 (1) (a) (c) GDPR. The Garante further found that the school also published data concerning health, failing to respect the prohibition under Article 9 (1) GDPR and without relying on any specific exemptions under Article 9 (2) (4) GDPR. (https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_-_9283029) | Link |
| SPANYOLORSZÁG | 2020.03.06 | 4 000 € | Private person | GDPR 5. cikk (1) bekezdés c) pont | Non-compliance with general data processing principles | Unlawful usage of video surveillance cameras which also monitored parts of the public space (violation of principle of data minimization). The decision is the consequence of a complaint submitted by the Spanish local police stating that the defendant has installed a video surveillance system on the façade of her domicile that, not only records freely the public road, but neither it includes any kind of information poster; such complaint included pictures proving that the video surveillance system was installed in the main façade of the domicile. Besides, the Spanish local police states that the domicile in which the video surveillance system is installed is used by the defendant for the illicit traffic of narcotic drugs and substances. The defendant did not answer to any AEPD investigation requests, so the AEPD started the corresponding sanction procedure. The AEPD highlighted that private individuals can install video surveillance systems as long as they comply with the corresponding obligations, but they can only record the main access of their domicile, and never freely record the whole public record (such activity is reserved for the Spanish law enforcement agents). Thus, the AEPD understood that not only the video surveillance system is illegal, but also it has infringed the data minimisation principle and, after considering some circumstances [(i) the surveillance system is recording the public road without just cause, (ii) there is intentionality, as the defendant is using the surveillance system to prevent police raids, (iii) the defendant is a natural person, (iv) there is no evidence of the income level of the defendant and (v) the defendant has been already warned by the police of the unlawfulness of such video surveillance system], it decided to impose a fine of 4,000 to the defendant. The AEPD also requires the defendant to uninstall the video surveillance system or to prove that, from now on, it only records the allowed portion of public road necessary in order to protect only the access to the domicile. Additionally, the AEPD also reminds that, in case the defendant does not comply with these requirements, this could lead to new investigation and sanction procedures. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00293/2019) | Link |
| SPANYOLORSZÁG | 2020.03.06 | 3 200 € | Retailer | GDPR 13. cikk, GDPR 14. cikk | Insufficient fulfilment of information obligations | Insufficient declaration of video surveillance. | Link |
| LENGYELORSZÁG | 2020.03.04 | 4 600 € | School in Gdansk (Danzig) (fine imposed against town of Gdansk) | GDPR 5. cikk (1) bekezdés c) pont GDPR 9. cikk (1) bekezdés GDPR 58. cikk (2) bekezdés f) pont GDPR 58. cikk (2) bekezdés g) pont GDPR 58. cikk (2) bekezdés i) pont GDPR 83. cikk (2) bekezdés GDPR 83. cikk (3) bekezdés GDPR 83. cikk (5) bekezdés a) pont GDPR 83. cikk (7) bekezdés | Insufficient legal basis for data processing | A school in Gdansk used biometric fingerprint scanners to authenticate students for the payment process in the school canteen. Although the parents had given their written consent to such data processing, the data protection authority considered the processing of the student data to be unlawful, as the consent to data processing was not given voluntarily. Primary school in school Gdañsk processed special categories of personal data (biometric data) of 680 children when they used the school canteen after receiving their parents' consent. The solution has been in place since 1 April 2015. The parents get informed via the canteen's website. Children whose parents have consented get their meals with priority. Two people, the system administrator and the authorising officer, have access to the database. The server is protected against unauthorized access with a password. Following an ex officio administrative proceedings, the President of the UODO has established that the school is using a biometric reader at the entrance to the school canteen that identifies the children in order to verify the payment of the meal fee. The UODO highlighted that it is special categories of personal data and that extra protection has been set out for children. In this case the UODO found that the consent given by the parents was not valid in particular because of the imbalance of the parties, hence the processing of biometric data did not have a valid legal basis. It also stressed that there it promotes unequal treatment among the students. The identification of the students could have been achieved through less intrusive means. For the mentioned reasons, the UODO ordered the primary school to delete the biometric data concerned, to cease the collection of this data in the first place and it imposed the fine of PLN 20,000. (https://gdprhub.eu/index.php?title=UODO_-_ZSZZS.440.768.2018) | Link |
| SPANYOLORSZÁG | 2020.03.04 | 60 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk, GDPR 6. cikk 1) bekezdés | Insufficient legal basis for data processing | According to the AEPD, the data subject has received several SMS from a separate operator indicating the activation of a new contract. The reason for this was that an employee of Vodafone Espa?a activated a contract with a third operator on behalf of the data subject. Vodafone could not demonstrate consent or sufficient legitimate interests for this processing of personal data. The decision is the consequence of a complaint submitted by a Spanish citizen stating he has contracted the data controller telecommunications services as a new customer, but an employee of the data controller used his information and falsified his signature in order to register into another telecommunications company (Llamaya) as if the claimant had requested his portability right; such complaint included screenshots of the text messages received by the second telecom company, as well as delivery notes by Llamaya. The data controller did not answer to any AEPD investigation requests, so the AEPD started the corresponding sanction procedure. In such procedure, the data controller alleged that the infringement was due to a illegal use of data by the employee (as the data controller effectively applied the security protocols with the consent of the claimant during the contracting of the services and, as soon as the data controller got news of the problem, it marked the as a fraud and deregister its contracting), so there would be no guilt nor intentionality by the data controller. Thus, the AEPD understood that not only there is a fraud in the contracting of the services and in using the name of the claimant without his consent, but also the data controller has infringed the lawfulness of processing principle (as it has not proved that it has even obtained the consent by the claimant for the contracting nor it carried out any due diligence in order to prove the identity of the claimant) and, after considering some aggravating circumstances [(i) the nature, severity and duration of the infringement, (ii) there is intentionality and or negligence by the data controller, (iii) personal identification data such as the name or the domicile have been affected, and (iv) the data controller has already committed other infringements], it decided to impose a fine of 60,000 to the data controller. | Link |
| MAGYARORSZÁG | 2020.03.04 | 13 136 € | Representative of a local government | GDPR 5. cikk 1) bekezdés, GDPR 6. cikk, GDPR 12. cikk, GDPR 15. cikk, GDPR 17. cikk | Insufficient legal basis for data processing | A local representative took a photo of the director of a company fully owned by the local government depicting the director allegedly tearing off an election poster of the opposition in the company of his child. The local representative uploaded the photo to his Facebook page. The childs image was blurred, yet it was hinted in the post that she was the daughter of the director. The director told the local representative at the scene that he does not consent to the taking of the photo. NAIH determined that the act of the director was not public information and the photo does not prove that the director torn off an election poster. NAIH also underpinned that only the name of the director of the company fully owned by the local government was public information. When the picture was taken the complainant warned the defendant not to publish the photo anywhere and especially on social media. The complainant's minor daughter was also present in the photo and although her face was obscured but she was easily recognizable because it was mentioned in the post that the daughter was also present. The defendant as being the data controller was asked by the complainant both via e-mail and postal letter to inform her about the legal basis and the purpose of the data processing, and in case of lack of legal basis or of violation of the purpose limitation principle the data controller was called to remove the post immediately. However, the data controller neither replied to the letters nor removed the post. The post at stake was reported on Facebook on the 3rd September 2019 but the company did not respond to the request. Dispute: Is it lawful to take a picture and make it public on a Facebook site without the depicted data subject's consent if it is about a chief officer of a local government-owned business who allegedly removes a campaign poster during local election campaign? The data controller violated the right of access under Article 15 GDPR, the right to erasure (right to be forgotten) of the data subject under Article 17 GDPR, and the duties on transparent information, communication and modalities for the exercise of the rights of the data subject according to Article 12 GDPR, as well as the principles of lawfulness, fairness and transparency under Article 5(1) GDPR. The data controller did not indicate any of the legal basis of Article 6(1) GDPR and the data subject did not give his consent to the data processing. The NAIH found that the name of the data subject was considered to be information of public interest as she held a public office and this was allowed to be made public under the Hungarian Act CXII of 2011 on Informational Self-determination and Freedom of Information. The photo at stake, however, could not be considered to be information of public interest as it did not provide any further information of public interest. The publication of the data subject's name would have sufficed to inform the public so that the publication of the photo was not necessary. (https://gdprhub.eu/index.php?title=NAIH_-_NAIH/2020/32/4) | Link |
| HOLLANDIA | 2020.03.03 | 525 000 € | Royal Dutch Tennis Association ("KNLTB") | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | The Dutch Data Protection Authority has fined the Royal Dutch Tennis Association ("KNLTB") with EUR 525,000 for selling the personal data of more than 350,000 of its members to sponsors who had contacted some of the members by mail and telephone for direct marketing purposes. It was found that the KNLTB sold personal data such as name, gender and address to third parties without obtaining the consent of the data subjects. The data protection authority also rejected the existence of a legitimate interest for the sale of the data and therefore decided that there was no legal basis for the transfer of the personal data to the sponsors. | Link |
| SPANYOLORSZÁG | 2020.03.03 | 1 800 € | Solo Embrague | GDPR 13. cikk | Insufficient fulfilment of information obligations | The corporate website did not present a privacy policy or a cookie banner on its main page. | Link |
| SPANYOLORSZÁG | 2020.03.03 | 42 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk, (1) bekezdés, f) pont, GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | According to the AEPD, the company had not been able to demonstrate adequate measures to ensure information security, leading to unauthorized access to personal data of a client. A clients personal data was accessed without authorization. The AEPD explained that this happened due to lack of technical and organizational measures taken by the company to ensure information security. (https://www.privacyaffairs.com/gdpr-fines/) | Link |
| SPANYOLORSZÁG | 2020.03.03 | 40 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | According to the AEPD, the company sent an SMS to an clients mobile number confirming that a telephone contract with that number had been signed even though the client was not a Vodafone client, resulting in the processing of personal data without the data subjects consent or other legitimate interests of the company. The company sent a text message to a persons phone number informing them that their contract was modified. The affected person, however, was not actually a Vodafone client. The AEPD determined that Vodafone had processed the affected persons personal details without consent. | Link |
| SPANYOLORSZÁG | 2020.03.03 | 24 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | According to the AEPD, the company sent two SMS to an clients mobile number informing about a rate change in its contract and confirming the purchase of a new mobile phone, resulting in the processing of personal data without the data subjects consent or other legitimate interests of the company. The company sent two SMS messages to a person informing them about the rate change of a contract as well as the purchase of a mobile phone. The customer did not consent to the processing of their personal data and Vodafone sent the text messages without prior written consent from the customer. | Link |
| SPANYOLORSZÁG | 2020.02.28 | 3 600 € | AEMA Hispánica | GDPR 5. cikk (1) bekezdés f) pont | Non-compliance with general data processing principles | The company had sent the payroll of an employee to another employee and therefore disclosed personal data to an unauthorised party. The company in question has sent an employees payroll to another employee, thus disclosing personal data to an unauthorized party. | Link |
| NORVÉGIA | 2020.02.28 | 36 800 € | Coop Finnmark SA | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | The company had distributed video surveillance footage of children under 16 who had allegedly stolen from a store. There was no sufficient legal basis for this data processing. Coop Finmark SA had unlawfully distributed video surveillance showing children under 16 allegedly stealing from a store. The data processing event had no legal basis. | Link |
| SPANYOLORSZÁG | 2020.02.27 | 120 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk, GDPR 6. cikk (1) bekezdés a) pontja | Insufficient legal basis for data processing | Vodafone Espa?a was unable to prove to the data protection authority that the data subject had given his consent to the processing of his personal data for the provision of a telephone contract. Furthermore, the decision of the data protection authority emphasises that Vodafone Espa?a also unlawfully disclosed the personal data of the data subject to various credit agencies. In January 2018, Mr A.A.A. contacted Vodafone to open an account. By mistake, his 14-year old son was subscribed for the services offered by Vodafone. Mr A.A.A. tried to rectify the data soon after the subscription. In September 2018, Mr A.A.A.'s son received a letter from Vodafone informing that his son had entered into a debt of 93,77 EUR and that, in the event of non-payment, his son would be included in the debtors' records. In the absence of payment, the reference was finally made in the debtors' records in October 2018. In February 2019, Mr A.A.A. attempted to withdraw his son from the services since the processing of his son's personal data was unlawful and lasted for 13 months. According to the AEPD, the processing was unlawful. Neither the complainant nor his son have given consent to the processing of the personal data by Vodafone. The processing has therefore violated Articles 6(1)(a) and 5(1)(a) GDPR. Moreover, the AEPD stated that apart from the unlawful processing of the complainants personal data Vodafone has included unduly the complainant's son's personal data in the ASNEF and DEXCUUG debtors' records. The complainant received the prior payment order giving him 10 days to remedy the alleged non-payment, but Vodafone included the complainant's personal data in the ASNEF file already one day later, and in the FIDEXCUG file 4 days later without waiting for the 10-day period granted. After conducting the investigation, the AEPD decided that Vodafone has seriously violated Articles 6(1)(a) and 5(1)(a) GDPR and the relevant provisions of the national law. The AEPD decided to impose a fine of 120,000 Eur on the Controller, VODAFONE ESPA?A SAU. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00235/2019938-0419) | Link |
| NORVÉGIA | 2020.02.26 | 73 600 € | R?lingen Municipality | GDPR 5. cikk, (1) bekezdés, f) pont, GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | Health information on 15 children with physical and mental disabilities was processed in the Showbie digital learning platform, for the transfer of health-related personal information between schools and their homes. Datatilsynet found that no necessary risk assessments, privacy impact assessments or tests had been carried out before using the application and that a lack of security when logging into the application allowed access to the information of other students in the group. The municipality sent a notification of a personal data breach to Datatilsynet concerning the use of the app Showbie, which started an investigation by Datatilsynet. The app was used in school by a group which consisted of pupils with special needs. The main use of the app was to ease communication between the school and the home, in particular with regards to communication messages about absence. The app did not include separate accounts or logins for parents and the pupils. Information concerning health and medications could be added to tabs in the app. The tabs did not include health information, but personal data regarding medication was found in the calendar and in chats with parents. There were no guidelines or routines on how to use the app securely. Teachers and employees used the schools wireless internet, while the parents used it on unsecured home networks or mobile internet. There was no two-factor authentication implemented, as required under security level 4 when dealing with health information Datatilsynet highlighted statements from the municipality concerning how Showbie was not adapted for the processing of special categories of personal data, and that there had been no assessment of the risks connected to such processing. The person responsible for IT-security in the municipality stated that the app did not fulfil the requirements for the appropriate security level to process health data pursuant to Article 5(1)(f) GDPR, a conclusion Datatilsynet seemed to support in their decision. Furthermore, Datatilsynet found it necessary to highlight that the established security level did not conform to the requirements under Article 32(1)(b), and ordered the municipality to implement measure to ensure a sufficient level of security. Datatilsynet found that the municipality did not clearly communicate that the app should not be used to process special categories of data. The inclusion of the folders health and medication was carried out in cooperation between the special needs group at the school and the company RIKT AS. Datatilsynet emphasized that an impact assessment pursuant to Article 35 GDPR would have clearly established this. The municipality did not find that any unauthorized persons had used or taken advantage of the lack of security. However, Datatilsynet stated that unauthorized persons could have had the opportunity to access personal data in the app due to the lacking security. (https://gdprhub.eu/index.php?title=Datatilsynet_-_19/01478-6) | Link |
| SPANYOLORSZÁG | 2020.02.25 | 48 000 € | HM Hospitales | GDPR 5. cikk, GDPR 6. cikk GDPR 4. cikk (11) bekezdés GDPR 5. cikk (1) bekezdés a) pont GDPR 6. cikk (1) bekezdés a) pont GDPR 83. cikk (5) bekezdés a) pont | Insufficient legal basis for data processing | The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the transfer of his data to third parties. This form, provided by HM, was not compatible with the GDPR, since consent was to be obtained through the inactivity of the data subject. The AEPD examined a complaint submitted against HM HOSPITALES 1989, S.A. for failing to properly obtain the complainants consent. The complainant argued that at the moment of her admission in the Hospital, she was requested to fill in a form which, among others, included the following clauses in relation to the treatment of her personal data: If you do not wish your personal data to be provided to third parties, check this box Likewise, and unless expressly stated, I authorize HM HOSPITALES 1989, S.A., as the person responsible for the file, to use the patient's personal data to send information about their products and services, being able to revoke this consent at any time. If you do not want to authorize the sending of advertising, check this box Therefore, the complainant argued that the method used by the Hospital to obtain her consent was not only confusing but contrary to GDPR, specifically, articles Articles 5(1)(a) and 6(1)(a) GDPR. Though the Hospital acknowledged that the form was not adapted to the new GDPR rules, it also stated that the information given to the patients is in accordance with articles 13 and 14 GDPR. Moreover, it argued that in this specific case, the complainant had an insurance company, this made it absolutely necessary to transfer her personal data in order to proceed with the payment of the expenses derived from the medical services requested. Dispute: Does the GDPR allow the data controller to obtain the consent through "opt-out" clauses, only oferring the possibility for the data subject to expressly object to the sharing of her personal data with third party? The AEPD hold that HM HOSPITALES 1989, S.A. obtained consent through the inaction of the complainant, and therefore acted contrary to the GDPR. It clarified that a pure inaction (the "opt-out") cannot ensure that the interested party unequivocally grants consent. Moreover, by using the double denial in its clauses, it creates confusion and also requires extra attention from the data subject. The AEPD concluded that this method should be regarded as tacit consent (the consent is deducted from inaction) and therefore contrary to the GDPR within the meaning of Article 4(11) GDPR. For all the above, the AEPD hold that HM HOSPITALES 1989, S.A. breached Articles 5(1)(a) and 6(1)(a) GDPR and therefore, imposed a fine of 48,000 pursuant to Article 83(5) GDPR. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00187/2019) | Link |
| SPANYOLORSZÁG | 2020.02.25 | 6 000 € | Casa Gracio Operation | GDPR 5. cikk (1) bekezdés c) pont GDPR 12. cikk GDPR 13. cikke GDPR 30. cikk (1) bekezdés GDPR 83. cikkének (2) bekezdése LOPDGDD 22. cikk | Non-compliance with general data processing principles | The company used CCTV cameras in the premises of a hotel which also captured the public roads outside the hotel resulting in a violation of the so called principle of data minimisation. ?he complaint regarded the installation of a video-surveillance system on the perimeter of a hotel which also captured public spaces. The defendant claimed that the images were not processed by any third party and that it made available information about the cameras both at the hotel reception and in its privacy policy. It also argued that the video-surveillance system is only accessed by the manager of the hotel, the leading engineer and the head of customer service while third persons may only have access if it is necessary and upon prior explicit approval by the DPO. The images are stored for a maximum period of one month. The AEPD first confirmed that the image of natural persons is personal data and the processing carried out through the video surveillance system should be in line with the GDPR. It recalled the principle of data minimisation according to Article 5(1)(c) GDPR, which has to be followed both during the data collection and the subsequent processing. It stressed that such systems may capture public spaces when it cannot be avoided or when this is necessary for the intended security purposes. There is always the duty to inform the affected parties as provided for in Article 12 GDPR and Article 13 GDPR. According to Article 30(1) GDPR a record must be kept by the responsible person. According to the national law in the video-surveiled areas, at least an information sign must be placed in a sufficiently visible place, both in open and closed spaces, which shall identify at least the existence of processing, the identity of the person responsible and the possibility of exercising the rights provided. The cameras should not obtain images of private and/or public space without a justified cause duly accredited, nor can they affect the privacy of passers-by. It is not permitted to place cameras on the private property of neighbors in order to intimidate them or affect their private sphere without justified cause. In this case the AEPD found that the capture of images from the public space was excessive and the data controller acted with serious lack of diligence. The data controller had also not adopted any measures to mitigate the effects of the infringement. However, it noted that the damage to those affected by the processing of their data was not significant, the processing was carried out only by the data controller at a local level and no benefit was obtained from this processing. Finally, after having considered all the mentioned factors, the AEPD imposed a reduced fine of EUR 6,000. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00369/2019) | Link |
| GÖRÖGORSZÁG | 2020.02.21 | 5 000 € | Public Power Corporation S.A. | GDPR 15. cikk GDPR 12. cikk L. 2472/1997 (korábbi nemzeti adatvédelmi törvény) | Insufficient fulfilment of data subjects rights | The Decision clarified that data subjects have a right of access to the processing of their personal data and that they must also be provided with a copy of the personal data processed. No reasons need to be given for the request. The complainant exercised their right of access asking the DPO of the Hellenic Public Power Corporation SA to provide them copy of any correspondence from 2015 until the present, but they did not receive any response. The HDPA asked the company to clarify its position. The HDPA stressed that the fulfillment of the right to information and access does not require the data subject to prove any legitimate interest; this interest is inherent in the right to access, so that transparency and legitimacy of processing can be assured. Similarly, there is no requirement for the data subject to invoke any particular reasons why they want to exercise their right to access. The HDPA emphasised that, following the case law of the Greek Council of State, even in the case that the data controller does not keep any record of the data subject's personal data, it will still have the obligation to reply pursuant to Article 12(4) GDPR. The HPDA found that after one month from the receipt of the data subject's complaint, the company as data controller did not notify the data subject of its inability to promptly respond to their request. Thus, the HDPA imposed a fine of EUR 5,000. (https://gdprhub.eu/index.php?title=HDPA_-_2/2020) | Link |
| BULGÁRIA | 2020.02.20 | 2 560 € | T.K. EOOD | GDPR 25. cikk, (1) bekezdés GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to ensure the information security. T.K. EOOD processed the personal data of I.S. unlawfully nine times in duration of five months. The breaches caused damages to the data subject. | Link |
| BULGÁRIA | 2020.02.20 | 2 560 € | L.E. EOOD | GDPR 25. cikk, (1) bekezdés GDPR 32. cikk GDPR 6. cikk | Insufficient technical and organisational measures to ensure information security | The fine of ca EUR 2,557 was imposed on L.E. EOOD for unlawful processing of personal data of data subject I.S. without the knowing and the consent of the data subject and also without a valid contractual relationship between L.E. EOOD and I.S. The enterprise processed the personal data of I.S. unlawfully seven times in duration of 3 months by failure to adopt technical and organizational measures to ensure the information security. In addition to the fine, the Commission for Personal Data Protection (KZLD) instructed L.E. EOOD to do regular inspections of its data processing activities, to do risk analysis regarding customers and employees and to conduct periodic trainings of the employees. The KZLD also ordered L.E. EOOD to archive and keep the documents containing the personal data only for limited purposes and the timeframe as required by law. | Link |
| SPANYOLORSZÁG | 2020.02.18 | 1 500 € | Mymoviles Europa 2000, S.L. | GDPR 13. cikk | Insufficient fulfilment of information obligations | The AEPD found that the company did not publish a privacy statement on its website and that its legal notice did not sufficiently identify itself. On 17 October 2019, the complainant filed a complaint with the Spanish Supervisory Authority (AEPD) against MYMOVILES EUROPA 2000, S.L. company. The company used an online form that allowed for a collection of certain categories of personal data on their website, but did not provide for any information under Article 13 GDPR, according to the complainant. The creation of user accounts on the website was allowed, where, among other things, the name, surname, e-mail address and password were provided. The form also included the option to mark "Receive offers from our partners" and "Subscribe to our newsletter". Following the complaint, the AEPD agreed to initiate investigations against the data controller for the alleged infringement of Article 13 GDPR - the information to be provided where personal data are collected from the data subject. Dispute: Can the lack of a privacy policy in the present case constitute a violation of Article 13 GDPR? The AEPD ruled that the the collection of personal data from users who fill in the form on the website without providing them, prior to collection, all the information under Article 13 GDPR is illegal. Consequently, the APED decided to issue a fine of 1.500 for the violation of Article 13 GDPR. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00423/2019) | Link |
| SPANYOLORSZÁG | 2020.02.14 | 2 500 € | Grupo Valsor Y Losan, SL | GDPR 5. cikk (1) bekezdés f) pont | Insufficient technical and organisational measures to ensure information security | The controller had disclosed personal data to a third party in a property purchase agreement (breach of principles of integrity and confidentiality of personal data) | Link |
| SPANYOLORSZÁG | 2020.02.14 | 3 000 € | Colegio Arenales Carabanchel (School) | GDPR 6. cikk | Insufficient legal basis for data processing | The decision of the data protection authority states that the school transferred pictures (and therefore personal data) to third parties, who published them without legal basis. The Spanish Data Protection Authority explained that the school had transferred pictures of students to third parties who then posted those pictures online. | Link |
| SPANYOLORSZÁG | 2020.02.14 | 80 000 € | Iberdrola Clientes | GDPR 6. cikk | Insufficient legal basis for data processing | Iberdola Clientes, an electricity company, terminated the data subject's contract without its consent, concluded three new contracts with the data subject, processed his personal data unlawfully and transferred the plaintiff's personal data to a third party without legal basis. In addition to this fine the AEPD also imposed another fine in the amount of EUR 50.000 under the old Spanish Data Protection Law. The electricity company Iberdrola Clientes closed a clients contract without their consent and opened three new contracts on their name also without their consent. The company also transferred the clients personal data to third-party entities without a legal basis. | Link |
| SPANYOLORSZÁG | 2020.02.14 | 42 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk, (1) bekezdés, f) pont GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | The complainant had access to third party data in his personal Vodafone profile. A clients personal data was accessed without authorization. The AEPD explained that this happened due to lack of technical and organizational measures taken by the company to ensure information security. | Link |
| SPANYOLORSZÁG | 2020.02.14 | 30 000 € | Xfera Moviles S.A. | GDPR 5. cikk, (1) bekezdés, f) pont, GDPR 32. cikk | Insufficient technical and organisational measures to ensure information security | The AEPD found that a third party had access to the name, telephone number and address of another customer. The Spanish Data Protection Authority determined that a customer of the company had access to the personal data of other customers. | Link |
| OLASZORSZÁG | 2020.02.13 | 4 000 € | Comune di Urago | GDPR 6. cikk GDPR 5. cikk, (1) bekezdés, a) pont | Insufficient legal basis for data processing | The local council has published on its website information containing a person's personal data, including health information. The Garante examined a complaint submitted by an employee of the Municipality of Urago d'Oglio. The official website of the Municipality published the full text of a judgment containing her personal data, including data related to her health status. Thus, the data controller disseminated this data and users could find it online. It has to be specified that the Municipality deleted the document before the beginning of the proceeding before the Garante. Dispute: The Garante had to assess whether such disclosure was justified and lawful, although the controller deleted the document containing the personal data. The Garante declared that the Municipality of Urago d'Oglio, while having the right to publish the judgement - which is a public document - for transparency purposes, was required not to carry out unnecessary and disproportionate processing of personal data of Mrs. XXX, in breach of art. 5(1) (a)(c) GDPR. It also found that the data controller did not rely on appropriate legal grounds while processing employee's personal data. Indeed, such processing was not based on the cases set forth by art. 6(1) (c)(e) GDPR. Moreover, given that the Municipality was not complying with a legal obligation, nor performing a task carried out in the public interest, the dissemination of personal data, included information related to health status, was unlawful according to art. 2-ter and 2-septies of the Italian Privacy Code. Eventually, the Garante imposed a fine of EUR 4.000, considering the amount and sensitiveness of disseminated data, and, on the other hand, the small budget of the Municipality and the deletion of the document before the proceeding started. (https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_-_9285411) | Link |
| ROMÁNIA | 2020.02.11 | 3 000 € | Vodafone Romania | GDPR 5. cikk, (1) bekezdés, f) pont GDPR 32 GDPR | Insufficient technical and organisational measures to ensure information security | Vodafone Romania had incorrectly processed personal data of an individual in order to process a complaint, which was subsequently sent to a wrong e-mail address. The reason for this was that there were insufficient security measures in place to prevent such erroneous data processing. | Link |
| OLASZORSZÁG | 2020.02.06 | 20 000 € | RTI - Reti Televisive Italiane s.p.a. | GDPR 5. cikk (1) bekezdés a) pont GDPR 6. cikk | Insufficient legal basis for data processing | The television station broadcasted a documentary about prostitution in Switzerland, in which the persons interviewed were not made sufficiently anonymous. The Garante examined a complaint submitted against R.T.I. regarding the broadcasting of a TV report identifying and providing information relating to the complainant (e.g. hometown, occupation) as well as broadcasting the complainants voice, without her consent. Namely, the complainant requested for the removal of the video report, which was also available online. Based on the complaint, the Garante examined whether the collect of information from the complainant and the further public disclosure violate journalism ethics and standards, whose compliance is necessary for the respect of the principles of lawfulness and fairness of the processing. The Garante concluded that by fraudulently collecting and disclosing the complainants personal data without consent, R.T.I. infringed the relevant journalism ethics and standards, thus breaching the general principles of lawfulness and fairness of the processing under Article 5 (1) (a) GDPR. (https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_-_9283121) | Link |
| SPANYOLORSZÁG | 2020.02.04 | 1 500 € | Cafetería Nagasaki | GDPR 6. cikk GDPR 5. cikk (1) bekezdés c) pont GDPR 83. cikk (5) bekezdés a) pont | Insufficient legal basis for data processing | The AEPD found that the Nagasaki Cafetería did not comply with its obligations under the GDPR, as it placed its surveillance cameras in such a way as to monitor the public space outside its premises, which disproportionately affected pedestrians. A citizen filed a complaint with the AEPD against the cafeteria Nagasaki for collecting, recording and storing personal data by the mean of surveillance cameras placed in a public space. Following the complaint, the APED agreed to investigate the matter against the establishment the data controller for the alleged violation of Article 5(1)(c) GDPR, the data minimisation principle, pursuant to Article 83(5)(a) GDPR. Thereafter, the AEPD proposed a fine of 1.500 euros against the data controller for a violation of the data minimisation principle. The defendant argued that the surveillance cameras was placed outside its establishment for security reasons. In addition, it claimed that the surveillance system was set up to comply with a mandatory regularity provision. However, the AEPD ruled it was not clear from the facts that the surveillance system implemented complies with the regulation in force given the distance of the cameras. Lastly, the defendant requested to dismiss the action on the basis of the violation of its right to defense and its presumption of innocence. Dispute: The issue was whether the use of surveillance cameras recording personal data of pedestrian was justified and proportionate. First, the APED decided there were no violation of the right to presumption or innocence, neither of the right to a fair trial and that the procedure should continue. Indeed, it pointed out that the defendant had the opportunity to provide for evidence regarding the surveillance video system and it did not provide for any. Also, the AEPD ruled that the surveillance cameras affected the rights of any passengers taking the side walk which was recorded by the cameras. The authority pointed out that the processing of personal data in public spaces should be carried out only by the public forces. Otherwise, the recording of public spaces by private entities has to be essential for the purpose of surveillance that is intended, or it is impossible to avoid it because of the location of those. In any case, any processing of data which is unnecessary for the intended purpose must be avoided. It has been concluded that the defendant did not succeed to justified the use of surveillance cameras. Consequently, the APED decided to issue a fine of 1.500 for the violation of the principle of data minimisation. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00427/2018) | Link |
| SPANYOLORSZÁG | 2020.02.03 | 60 000 € | Xfera Moviles S.A. | GDPR 5. cikk GDPR 6. cikk (1) bekezdés a) pont | Insufficient legal basis for data processing | According to the data protection authority, XFERA MOVILES has violated Article 6(1) of the GDPR, as the company has unlawfully processed data, including bank details, customer address and name of the data subjects. Ms Y subscribed a contract with Xfera Moviles for the provision of an internet connection. After a few months, the company interrupts the service. Following a phone request, Ms Y learned that she was no longer a party to the contract. In fact, although she was still paying for it, the service was being provided to another person, who had requested such change few weeks earlier. Notwithstanding the clear incongruence of the information provided by the third party, Xfera operators accepted the request, changed the contract without Ms Y's consent and sent invoices to the new billing address. Moreover, such invoices still contained details of Ms Y, such as email address and bank account, which she had never agreed to disclose. According to the AEPD, the controller violated Art. 6(1)(a) GDPR. The data subject had never authorized, amongst the others, the contractual changes, the linking of her data with a new name and the disclosure of such information. On that subject, the Agency refers to a long-established, consistent national case-law which requires the controller to prove the existence of a consent in case it intends to use it for justifying a processing operation. In the present case, such proof was missing and the company was found responsible of a violation of Art. 6 GDPR. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00227/2019) | Link |
| SPANYOLORSZÁG | 2020.02.03 | 75 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk | Insufficient legal basis for data processing | The fine preceded the complaint by the data subject, who argued that Vodafone Espa?a had signed a contract for the transfer of a telephone subscription with a third party without the data subject's knowledge or consent and that, as a result, he, the data subject, had received an e-mail from the third party for a purchase made by him. | Link |
| SPANYOLORSZÁG | 2020.02.03 | 60 000 € | Vodafone Espa?a, SAU | GDPR 5. cikk GDPR 6. cikk (1) bekezdés | Insufficient legal basis for data processing | The fine was preceded by a complaint from the data subject, who argued that he had received an e-mail from Vodafone Espa?a, which contained the billing of a telephone line that the data subject had never requested, which led to his personal data being processed without his consent. As a result, the data subject's personal data were incorporated into the information systems of Vodafone Espa?a without Vodafone being able to show that the data subject had consented to the collection and subsequent processing of his personal data. The fine of 100,000 EUR was reduced to 60,000 EUR due to a voluntary payment. The complainant filed a complaint against Vodafone Espa?a, S.A.U. (respondent) with the Spanish Data Protection Agency (AEPD) on 16 May 2019. On 20 February 2019 the complainant received an email with an invoice for an alleged contracted telephone line from Vodafone Espa?a, S.A.U. Despite the efforts to clarify the situation, the claimant had not received a response from the respondent. Dispute: In view of the facts denounced in the complaint and the documents provided by the complainant, the AEPD initiated an investigation pursuant to Article 57(1) GDPR to clarify the facts. Th AEPD has transferred the complaint to the respondent, but the latter had not responded to the requests. As a result of the investigation, the AEPD found that that the person responsible for the processing is the one who is being claimed. According to the documentation in the file, the AEPD decided that Vodafone Espa?a, S.A.U. processed the personal data of the claimant without their consent. The claimant's personal data were recorded in the files and were treated for the issuance of invoices for services associated with the person claimed. When making a decision in this case, the AEPD considered the following aggravating factors: - the present case is dealing with an unintentional negligent action, but was identified as significant (Article 83(2)(b) GDPR). - basic personal identifiers were affected (name, identification number, the line identifier) (Article 83(2)(g) GDPR). The fine was therefore set to the amount of 100.000 euros for the infringement of Article 6(1) GDPR. (https://gdprhub.eu/index.php?title=AEPD_-_PS/00405/2019) | Link |
| SPANYOLORSZÁG | 2020.02.03 | 50 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk | Non-compliance with general data processing principles | The fine was preceded by a complaint from a data subject who argued that Vodafone Espa?a had sent invoices containing his personal data, such as name, identity card and address, to its neighbour. The fine followed a complaint submitted by a Spanish citizen who claimed that the data controller had sent some services invoices to her neighbour, and that, although the letters were clearly addressed to that neighbour on the envelope (name and address), the content included personal data of the complainant (name, national ID number, address, etc). The data controller did not answer to AEPD's first requirement, but it finally did so during the allegations phase and admitted a technical mistake on the wrong delivery. It also specified that the technical mistake had been fixed, and that, although the data controller may be responsible for its commission, it was no guilty nor was there any intention. Dispute: The AEPD had to assess whether the data controller's culpability is determining for finding a violation and for imposing a fine. Based on Article 83(5) GDPR and Article of 72 the Spanish Data Protection Law (LOPDGDD), the AEPD found that the confidentiality principle has been breached and decided to impose the fine of EUR 50,000. The fine was calculated after the consideration of the following facts: (1) the breach only affected two individuals and (2) the breach was no significantly harmful, but (3) the data controller is a big company, (4) it showed a significant lack of diligence, and (5) its business is clearly related to personal data. | Link |
| SPANYOLORSZÁG | 2020.02.03 | 20 000 € | Iberia Lineas Aereas de Espana, S.A. Operadora Unipersonal | GDPR 5. cikk, GDPR 6. cikk, GDPR 21. cikk GDPR 83. cikk | Insufficient legal basis for data processing | Iberia continued to send e-mails to the data subject, despite the data subject had requested the withdrawal of his consent and the erasure of his personal data and that the execution of these measures had already been confirmed to him. In 2019, Mr D, a customer of Iberia Airlines, requested the company to delete all his personal data, including those concerning an ongoing Loyalty Program. Although the controller confirmed the deletion, Mr D continued to receive unsolicited marketing emails from the company. These facts led to a first complaint which ended in the sanctioning procedure PS/00370/2018. Notwithstanding the first formal notice, the sending of promotional did not stop. Therefore, Mr D lodged a second complaint alleging the ongoing violation of Article 6 GDPR. The AEPD finds the violation of Article 6 quite apparent and focuses on the criteria to assess the amount of the fine under Article 83 GDPR. In particular, the Agency finds a certain "recidivism" due to the commission of infringements of the same nature, already sanctioned in the context of a previous procedure. This integrate the aggravating criteria under Art. 83(2)(b) (intentional or negligent character of the infringement) and (e) (previous infringements) of the GDPR. For these reasons, the controller was given a penalty of 20.000 euros. | Link |
| SPANYOLORSZÁG | 2020.02.03 | 75 000 € | Vodafone Espa?a, S.A.U. | GDPR 5. cikk GDPR 4. cikk (11) bekezdés GDPR 6. cikk (1) bekezdés a) pont GDPR 83. cikk (1) bekezdés GDPR 83. cikk (2) bekezdés GDPR 83. cikk (5) bekezdés | Insufficient legal basis for data processing | The data subject, a former customer of the company, continued to receive invoice notifications, although at that time there was neither a contractual relationship nor any payment overdue from the expired contractual relationship. As a reason for the incorrect mailings Vodafone indicated a technical error. The AEPD examined a complaint submitted by a customer concerning the processing of his data by Vodafone Espa?a. The company kept sending him emails after he had expressly withdrawn his consent to the processing of his personal data, and then alleged that it was caused by a computer failure. Dispute: The AEPD had to assess whether the culpability constitutes a requirement for imposing an administrative sanction under the GDPR. The AEPD ruled that by sending the customer/complainant company emails after he had asked them to erase his data file, VODAFONE had illegally processed the his data because of the lack of valid consent under Article 6(1)(a) GDPR. Thus, it imposed VODAFONE a fine of EUR 75,000 under Article 83(5) GDPR, being indecisive whether there was culpability or not in the companys actions. | Link |
| SPANYOLORSZÁG | 2020.02.03 | 6 670 € | Banco Bilbao Vizcaya Argentaria S.L. | GDPR 5. cikk, GDPR 6. cikk, GDPR 21. cikk | Insufficient legal basis for data processing | The company repeatedly sent advertising messages to a data subject, although the data subject had objected to the processing of his data. The company has sent several advertising messages to a person, even after the affected person made it clear that they do not consent to their personal data to be processed. | Link |
| SPANYOLORSZÁG | 2020.02.03 | 5 000 € | Queseria Artesenal Ameco S.L. | GDPR 5. cikk, GDPR 6. cikk | Insufficient legal basis for data processing | The company processed personal data of customers without required consent. The company was fined because it processed personal data without the consent of the affected parties. | Link |
| SPANYOLORSZÁG | 2020.02.03 | 800 € | Automoción | GDPR 5. cikk (1) bekezdés a) pont GDPR 6. cikk (1) bekezdés b) pont GDPR 83. cikk (2) bekezdés b) pont GDPR 83. cikk (2) bekezdés g) pont GDPR 83. cikk (5) bekezdés a) pont | Insufficient legal basis for data processing | An employee created a fake profile about a female colleague on an erotic portal, which contained, among other things, her contact details, a photo of her and information about her sexual nature. Based on the profile, the data subject received several phone calls from people who wanted to contact her regarding the information provided on the website. As the private person was found to have a personality disorder, the fine was reduced from initial EUR 1000 to EUR 800. A website containing aimed at offering services for adults published the picture, name, telephone number and a sexual related description of a citizen the complainant - as a contact person for the performance of these services without her consent. Following the publication of her personal data on the website, the complainant received unsolicited phone calls from people who wished to have sex with her. The complainant pointed out that the pictures published had been obtained from her work intranet with an external IP address. Thus, she filed a complaint with the AEPD against the IP address' owner which added her personal data to the website. Therefore, she complained that the advertiser who created the false ad unlawfully processed her personal data and did not sue the service provider which removed the publication immediately. Dispute: The AEPD had to pronounce itself on the legal basis of the processing of personal data the consent or the performance of a contract and had to decide which circumstances should be takne into account for the administrative fine. The AEPD stated that it was clear from the procedure that the advertiser added a false ad on the web portal, containing the personal data of the complainant without her consent. Thus, the AEPD ruled that the personal data published on the website were not necessary for the performance of the contract between the advertiser and the website. Therefore, it has been concluded that the advertiser violated Articles 5(1)(a) and 6(1)(b) GDPR. In addition, the AEPD decided to impose a fine of 1.000 in accordance with Article 83(5)(a) GDPR by taking into consideration that the action was intentional (Article 83(2)(b) GDPR), and that the personal data are sensitive (Article 83(2)(g) GDPR). (https://gdprhub.eu/index.php?title=AEPD_-_PS/00292/2019) | Link |
