Search results

From GDPRhub
  • CNIL (France) - SAN-2019-005 (category Article 32(2) GDPR)
    violates Article 32 GDPR. Retaining personal data of an applicant for a lease after another applicant has been selected also violates Article 5(1)(e) GDPR
    41 KB (6,558 words) - 17:09, 6 December 2023
  • AEPD (Spain) - EXP202205932 (category Article 6(1) GDPR)
    third parties (article 83.2.k, of the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 10/11 RGPD in relation to article 76.2.b, of the LOPDGDD)
    32 KB (4,952 words) - 13:11, 13 December 2023
  • BVwG - W211 2210458-1/10 (category Article 2(1) GDPR)
    2019, BVwerG 6 C 2.18 "It follows that the opening clauses of Article 6.2 and 6.3 GDPR for processing operations under Article 6.1(1)(e) GDPR do not cover
    92 KB (15,435 words) - 16:00, 22 March 2022
  • APD/GBA (Belgium) - 149/2023 (category Article 13(2) GDPR)
    of article 4.19 of the GDPR – (article 13.1. c) of the GDPR) and does not mention the data retention periods personal data processed (article 13.2. a)
    113 KB (17,325 words) - 08:50, 19 March 2024
  • HDPA (Greece) - 22/2023 (category Article 58(2)(b) GDPR)
    reprimand in accordance with Article 58(2)(b) GDPR for these established violations. The DPA issued an order, as per Article 15(4)(b) of the Greek Law 4624/2019
    5 KB (616 words) - 09:37, 24 October 2023
  • AZOP (Croatia) - Decision 22-02-2021 (category Article 32(1)(b) GDPR)
    Decision 22-02-2021 Authority: AZOP (Croatia) Jurisdiction: Croatia Relevant Law: Article 32(1)(b) GDPR Article 32(1)(d) GDPR Article 32(2) GDPR Article 32(4)
    2 KB (197 words) - 15:52, 30 October 2023
  • Court of Appeal of Brussels - 2019/AR/1600 (category Article 13(2)(a) GDPR)
    violation of Article 6(1) GDPR; 2. Did not provide the complainant with enough information prior to the processing, in violation of Article 13 GDPR; 3. Processed
    60 KB (9,144 words) - 16:17, 22 March 2022
  • OLG Nürnberg - 8 U 2907/21 (category Article 12(5)(b) GDPR)
    right to access under Article 15 GDPR because the controller was entitled to reject the request pursuant to Article 12(5)(b) GDPR. The court reasoned that
    24 KB (3,847 words) - 15:19, 11 September 2022
  • CNIL (France) - SAN-2019-010 (category Article 21(2) GDPR)
    investigations the CNIL found five breaches of the GDPR: -         Violation of the right to object, Article 21(2) GDPR: no procedure was implemented to ensure effectively
    62 KB (10,001 words) - 17:09, 6 December 2023
  • AEPD (Spain) - PS/00070/2019 (category Article 5(1)(b) GDPR)
    referred to Article 5(1)(a) (principle of lawfulness, fairness and transparency), Article 12(1), Article 7, Article 13 and Article 14 GDPR, the corresponding
    422 KB (70,184 words) - 13:56, 13 December 2023
  • Finnish DPA found a healthcare provider to have breached Article 32(1) GDPR and Article 32(2) GDPR for not implementing appropriate technical and organisational
    14 KB (1,978 words) - 16:09, 21 February 2024
  • reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA also ordered the controller to erase the
    15 KB (2,137 words) - 20:18, 27 March 2024
  • AEPD (Spain) - E/10529/2021 (category Article 45 GDPR)
    section 2, letter b), of this article. The The implementing act shall be adopted in accordance with the examination procedure referred to in re article 93,
    44 KB (6,642 words) - 10:34, 13 December 2023
  • protection regulation's article 5, subsection 2, cf. Article 5, subsection 1, letter a, Article 24, cf. Article 28, subsection 1, Article 35, subsection 1, as
    117 KB (18,075 words) - 10:19, 12 September 2022
  • AEPD (Spain) - EXP202205353 (category Article 5(1)(f) GDPR)
    the alleged violation of article 5.1.f) of the GDPR and article 32 of the GDPR, typified in article 83.5 and 83.4 of the GDPR. The initiation agreement
    22 KB (3,386 words) - 16:05, 13 December 2023
  • CNIL (France) - SAN-2020-014 (category Article 9 GDPR)
    breach of Article 32 of the GDPR has occurred. B. On the failure to notify the data breach to the CNIL 32. Pursuant to Article 33 (1) of the GDPR, in the
    26 KB (4,050 words) - 17:10, 6 December 2023
  • Personvernnemnda (Norway) - 2021-03 (category Article 5(2) GDPR)
    Ordinance Article 6 No. 1 letter f, for failure to assess protests, cf. Article 21, and for lack of information, cf. Article 13. 2. Pursuant to Article 58 (2)
    25 KB (4,046 words) - 18:37, 5 March 2022
  • CNIL (France) - SAN-2022-019 (category Article 3(2) GDPR)
    did not react either. GDPR applicable? (Article 3(2) GDPR) The DPA held that the GDPR was applicable pursuant of Article 3(2) GDPR. Because the controller
    11 KB (1,452 words) - 17:03, 6 December 2023
  • AEPD (Spain) - PS/00220/2020 (category Article 83(2)(b) GDPR)
    significant negligent action (Article 83(2)(b) GDPR) and that basic personal identifiers were affected (Article 83(2)(g) GDPR). The economic volume of the
    28 KB (4,295 words) - 14:11, 13 December 2023
  • APD/GBA (Belgium) - 02/2021 (category Article 6 GDPR)
    Compétence de la Chambre de Résolution des Litiges (Article 2 AVG ; Article 4 WOG) 55. Conformément à l'article 2, paragraphe 1, de l'AVG, le règlement s'applique
    96 KB (15,396 words) - 16:50, 12 December 2023
View ( | ) (20 | 50 | 100 | 250 | 500)