Search results

From GDPRhub
  • OGH - 6Ob35/21x (category Article 4(1) GDPR)
    constitute personal data under Article 4(1) GDPR? If so, do they qualify as special categories of personal data under Article 9 GDPR? Is the defendant obliged
    27 KB (4,090 words) - 09:54, 10 September 2021
  • APD/GBA (Belgium) - 06/2019 (category Article 5(1)(c) GDPR)
    conformity with Article 5.1. c), Article 6.1., Article 13.1. c), Article 13.1. c), Article 13.1. e) and Article 13.2. a) of the DGPS pursuant to Article 101 of
    20 KB (3,137 words) - 16:51, 12 December 2023
  • AEPD (Spain) - TD/00183/2021 (category Article 15 GDPR)
    free circulation of these data (hereinafter, GDPR); and in article 47 of the Law Organic 3/2018, of December 5, Protection of Personal Data and guarantee
    20 KB (3,087 words) - 13:30, 13 December 2023
  • this from happening, in violation with Article 24(1), Article 24(2), and Article 25(1) GDPR. According to Article 24(4) of the Finish Data Protection Act,
    42 KB (6,579 words) - 08:46, 27 January 2022
  • communication service. Therefore, TikTok had to obtain valid consent (Article 4(11) GDPR) from users before using the identifiers. The DPA stated that it should
    73 KB (11,864 words) - 17:03, 6 December 2023
  • HDPA (Greece) - 26/2023 (category Article 15 GDPR)
    under Article 15 GDPR." The DPA rejected the request for review. Genealogical research on a family surname did not fall within the scope of Article 15 GDPR
    14 KB (2,181 words) - 11:27, 13 September 2023
  • right to privacy. Health data are sensitive data covered by Article 9 GDPR. According to Article 137 of the Italian Data Protection Code, health data can
    16 KB (2,354 words) - 15:45, 6 December 2023
  • HDPA (Greece) - 2/2020 (category Article 12(4) GDPR)
    subject of its inability to respond to the access request according to Article 12(4) GDPR. The complainant exercised their right of access asking the DPO of
    12 KB (1,773 words) - 15:33, 6 December 2023
  • LG Magdeburg - 9 O 1571/20 (category Article 6(1) GDPR)
    that under Article 82 (1) and (2) GDPR, any person who has suffered material or non-material damage as a result of a violation of the GDPR is entitled
    27 KB (4,216 words) - 13:26, 8 January 2024
  • Datatilsynet (Norway) - 20/01868 (category Article 5(1)(d) GDPR)
    of personal data, cf. Article 5, also to the processing of personal data pursuant to Article 16. This interpretation of Article 16 is based on, among others
    26 KB (4,150 words) - 16:14, 6 December 2023
  • LG Köln - 28 O 138/22 (category Article 82 GDPR)
    provisions of Article 5(1)(a) and Articles 13 and 14 GDPR. Furthermore, the defendant violated the principle of integrity and confidentiality from Art. 5 Para.
    39 KB (6,362 words) - 14:01, 22 June 2023
  • was outdated and was no longer of importance to society. Pursuant to Article 17(1) GDPR, the data subject had requested Google LLC (the controller) to remove
    26 KB (4,072 words) - 12:18, 27 March 2024
  • implementation of Article 5(3) ePD. § 25(1) TTDSG mandates that information (notably also information that is not considered personal data under the GDPR) may only
    18 KB (1,831 words) - 13:49, 3 November 2022
  • found Vodafone S.p.A in violation of the following GDPR provisions: Article 5(1) and Article 5(2) and Article 25(1): for failing to implement control systems
    7 KB (810 words) - 15:52, 6 December 2023
  • OVG Sachsen-Anhalt - 1 M 49/23 (category Article 53(1) GDPR)
    this regulation in accordance with Article 57 (1) (a) GDPR and which has the powers in accordance with Article 58 GDPR. For this reason alone, there was
    14 KB (1,999 words) - 14:20, 18 July 2023
  • decision under Article 66 GDPR when the lead SA fails to respond to provide mutual assistance within a month as per Article 61(8) GDPR. The CJEU adopted
    10 KB (1,311 words) - 15:26, 13 June 2023
  • BVerfG - 1 BvR 16/13 (category Article 17 GDPR)
    completely determined by it. This already follows from Article 1.3, Article 20.3 and Article 93.1 No. 4a of the Basic Law. According to these, the commitment
    133 KB (21,944 words) - 15:59, 22 March 2022
  • CNIL (France) - SAN-2020-014 (category Article 9 GDPR)
    obligation of Article 32 GDPR? - Does the fact that this health data is not encrypted constitute a breach of the security obligation under Article 32 GDPR? - Does
    26 KB (4,050 words) - 17:10, 6 December 2023
  • HDPA (Greece) - 3/2020 (category Article 15 GDPR)
    coverage of the image of the third party shall not be required.” 4. As follows from Article 12 (4) of Law 2472/1997, the controller was required to respond to
    19 KB (3,034 words) - 15:33, 6 December 2023
  • HDPA (Greece) - 11/2024 (category Article 17 GDPR)
    information [...]". 5. Because according to the above article 17 of the GDPR, as it has been interpreted according to the content of the Guidelines 5/2019 of the
    36 KB (5,761 words) - 17:19, 22 April 2024
  • UODO (Poland) - DKN.5131.6.2020 (category Article 34(4) GDPR)
    as Article 57 (1) (a), Article 58 (2) (e) and (i), Article 83 (1) - (3) and Article 83 (4) (a) in connection with Article 33 (1) and Article 34 (1), (2)
    66 KB (10,785 words) - 10:00, 17 November 2023
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,671 words) - 08:49, 27 January 2022
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,677 words) - 08:47, 27 January 2022
  • HDPA (Greece) - 4/2022 (category Article 5(1)(a) GDPR)
    under Article 35(7) GDPR, for not complying with the principle of transparency under Article 5(1) GDPR and for not anonymising the data under Article 25(1)
    11 KB (1,274 words) - 10:37, 23 February 2022
  • 99 GDPR |GDPR_Article_4= |GDPR_Article_Link_4= |GDPR_Article_5= |GDPR_Article_Link_5= |GDPR_Article_6= |GDPR_Article_Link_6= |GDPR_Article_7= |GDPR_Article_Link_7=
    32 KB (6,006 words) - 16:33, 7 July 2021
  • 99 GDPR |GDPR_Article_4= |GDPR_Article_Link_4= |GDPR_Article_5= |GDPR_Article_Link_5= |GDPR_Article_6= |GDPR_Article_Link_6= |GDPR_Article_7= |GDPR_Article_Link_7=
    34 KB (5,924 words) - 18:14, 20 April 2021
  • and voice) according to Article 5(1)(a) GDPR and Article 6(1) GDPR? The ANSPDCP found that the staff of the General Directorate of 4th District Local Police
    7 KB (931 words) - 15:22, 13 December 2023
  • EDPB - Binding Decision 1/2020 - 'Twitter' (category Article 4(24) GDPR)
    infringements of Article 5(1)(f), Article 24, and Article 32 GDPR, and to the objection of the IT SA on the possible infringement of Article 5(2) GDPR, the EDPB
    183 KB (30,819 words) - 09:50, 20 January 2023
  • BVwG - W258 2227269-1/14E (category Article 4(7) GDPR)
    violating Article 5(1) GDPR Article 6 (1) GDPR Article 6(4) GDPR Article 9 GDPR Article 14 GDPR Article 30 GDPR Article 35 GDPR and Article 36 GDPR. The fine
    47 KB (7,345 words) - 09:41, 10 September 2021
  • minimisation according to Article 5(1)(c) GDPR. The court ruled that the second clause violated the transparency obligation of Article 5(1)(a) GDPR, in particular
    24 KB (3,579 words) - 12:05, 7 July 2021
  • unlawfully, as it breached Articles 5 and 6(1) GDPR. For this violation, the DPA used its powers under Article 82(5)(a) and fined the association with €500
    6 KB (779 words) - 15:16, 13 December 2023
  • accordance with Article 60(3) GDPR. Ten DPAs (AT, DE, FI, FR, IT, NL, NO, PL, PT, SE) raised objections, in accordance with Article 60(4) GDPR, to the Draft
    21 KB (3,005 words) - 14:16, 1 February 2023
  • VGH München – 5 CS 19.2087 (category Article 4(1) GDPR)
    § 68 (1) sentence 5 LFGB § 40 paragraph 1a Basic Law Article 5(1), first sentence VIG § 1, § 2, § 3, § 4 para. 4, § 5 para. 1, para. 4 p. 1, § 6 para. 1
    40 KB (6,397 words) - 08:03, 21 March 2022
  • respect the prohibition under Article 9 (1) GDPR and without relying on any specific exemptions under Article 9 (2) (4) GDPR. Feel free to add your comment
    6 KB (316 words) - 15:47, 6 December 2023
  • AEPD (Spain) - EXP202104006 (category Article 4(12) GDPR)
    ends and means of such activity, by virtue of article 4.7 of the GDPR. Article 4 section 12 of the GDPR broadly defines “violations of security of personal
    31 KB (4,578 words) - 12:11, 6 March 2024
  • HDPA (Greece) - 5/2023 (category Article 5(1)(a) GDPR)
    fairness and transparency established in Article 5(1)(a) GDPR. Moreover, the DPA found a violation of Article 13 GDPR, since the controller did not correctly
    5 KB (578 words) - 05:32, 26 April 2023
  • Court of Appeal of Brussels - 2022/AR/723 (category Article 5(1)(c) GDPR)
    21(2) and 21(4) GDPR. Moreover, the DPA held that the controller violated Article 5(1)(a), 5(1)(c), 5(2), 6(1), 12(2), 21(2) and 21(4) GDPR. The controller
    8 KB (919 words) - 09:54, 14 December 2023
  • Rb. Den Haag - C/09/581706 / HA RK 19-593 (category Article 12(5) GDPR)
    data subject under Articles 17 (1) GDPR and 21 (1) GDPR can submit , also given the provisions of Article 12 (5) GDPR ? 5. Does it make any difference to
    34 KB (5,811 words) - 09:44, 8 December 2020
  • DSB (Austria) - D550.038/0003-DSB/2018 (category Article 5(1)(a) GDPR)
    62(1)(4) and 69(5) DSG 2000 (missing deletion) € 800 under §§ 52(2)(4), 62(1)(4) and 69(5) DSG 2000 (missing signage) +10% administrative fee € 5.280 TOTAL
    31 KB (5,161 words) - 14:02, 12 May 2023
  • DSB (Austria) - 2020-0.111.488 (category Article 4(15) GDPR)
    (Datenschutzbehörde - DSB) held that the doctor had violated Article 5(1)(a) GDPR and Article 9(1) and (2) GDPR as the patients had not given their ecplicit consent
    8 KB (1,048 words) - 13:50, 12 May 2023
  • HDPA (Greece) - 7/2023 (category Article 15 GDPR)
    (definition) Article 4.1: Data subject (definition) Article 4.2: Processing (definition) Article 4.3: Restriction of processing (definition) Article 4.4 : Profiling
    9 KB (1,251 words) - 12:15, 8 May 2023
  • a violation of Article 5(1)(b) GDPR. As a result, the DPA issued a reprimand to the controller in accordance with Article 58(2)(b) GDPR. Generally, a controller
    20 KB (2,859 words) - 13:11, 13 March 2024
  • AEPD (Spain) - PS/00187/2019 (category Article 4(11) GDPR)
    contrary to the GDPR within the meaning of Article 4(11) GDPR. For all the above, the AEPD hold that HM HOSPITALES 1989, S.A. breached Articles 5(1)(a) and 6(1)(a)
    5 KB (497 words) - 14:08, 13 December 2023
  • HDPA (Greece) - 48/2023 (category Article 5(1)(a) GDPR)
    personal data in violation of Article 5(1)(a) GDPR, Article 6(1) GDPR, Article 12(3) GDPR, Article 12(4) GDPR and Article 15 GDPR. As such, the DPA issued a
    6 KB (685 words) - 14:58, 21 March 2024
  • AEPD (Spain) - PS/00192/2022 (category Article 4(1) GDPR)
    violating Article 5(1)(c) GDPR, the DPA fined the controller €50,000. In its assessment of the fine, the DPA noted three aggravating factors per Article 83(2)
    15 KB (2,257 words) - 13:02, 13 December 2023
  • HDPA (Greece) - 39/2020 (category Article 4(7) GDPR)
    under the GDPR and needs to establish a valid legal basis to process personal data. Unsolicited political communication is regulated with Article 11 L. 3471/2006
    56 KB (7,755 words) - 15:39, 6 December 2023
  • accordance with Article 60(3) GDPR. Ten DPAs (AT, DE, ES, FI, FR, HU, IT, NL, NO, SE) raised objections, in accordance with Article 60(4) GDPR, to the Draft
    468 KB (51,340 words) - 14:10, 30 January 2023
  • HDPA (Greece) - 51/2021 (category Article 22 GDPR)
    (definition) Article 4.1: Data subject (definition) Article 4.2: Processing (definition) Article 4.3: Restriction of processing (definition) Article 4.4: Profileing
    9 KB (1,168 words) - 15:30, 6 December 2023
  • DSB (Austria) - 2020-0.550.322 (category Article 4(2) GDPR)
    other legal basis for processing under Article 6 GDPR, the controller had violated Article 5(1)(a) and Article 6(1) GDPR. Taking into account the low income
    26 KB (4,098 words) - 13:51, 12 May 2023
  • Rb. Gelderland - C/05/391171 / HA RK 21-135 (category Article 5(1)(c) GDPR)
    personal data in accordance with the basic principles of Article 5 of the GDPR. Article 5(1)(a) of the GDPR states that personal data must be processed in a manner
    56 KB (9,287 words) - 16:00, 26 January 2022
  • HDPA (Greece) - 2/2023 (category Article 4(7) GDPR)
    protected by article 5 par. 1 item a) GDPR, in conjunction with Article 13 GDPR. 12. Because, since a lack of compliance with the provisions of article 5 par.
    31 KB (5,021 words) - 16:15, 18 July 2023
  • Datatilsynet (Denmark) - 2023-432-0016 (category Article 4(11) GDPR)
    fairness and transparency under Article 5(1)(a) GDPR, as well as the principle of data minimisation pursuant to Article 5(1)(c) GDPR, since they did not process
    46 KB (7,192 words) - 12:37, 19 December 2023
  • Commissioner (Cyprus) - 17.05.23 (category Article 5(1)(c) GDPR)
    five (5) complainants in three (3) of the four (4) publications exceeded the principle of data minimisation in violation of Article 5(1)(c) GDPR, and the
    31 KB (4,973 words) - 16:50, 6 December 2023
  • obligations under Article 5(1)(f) and Article 32 of GDPR. Article 5 (1) : Ticketmaster has failed to comply with the requirements of GDPR including to process
    130 KB (21,195 words) - 13:52, 25 April 2021
  • of an infringement of the Article 5(1)(a) GDPR principle of fairness, and infringements of the Article 5(1)(b) and (c) GDPR principles of purpose limitation
    289 KB (33,568 words) - 15:00, 1 February 2023
  • Articles 5(1)(a), (d) and (f), 9 and 32(1)(b) GDPR.” Pursuant to Article 58(2)(i), the DPA hence imposed an administrative fine as per Article 83(4) and (5)
    10 KB (1,206 words) - 15:54, 6 December 2023
  • DVI (Latvia) - SIA “Lursoft IT” (category Article 5(1)(a) GDPR)
    paragraph of Article 166, Article 168, Article 262, Article 269, 1. to find SIA “Lursoft IT” guilty in Article 83 (5) “a” of the Data Regulation and committed
    90 KB (14,351 words) - 16:10, 6 December 2023
  • Datatilsynet (Norway) - 21/02873 (category Article 4(16) GDPR)
    in Article 12(5) GDPR, Article 15(4) GDPR or Article 16 of the Norwegian Personal Data Act were applicable. The DPA ordered the controller (Article 58(2)(d)
    13 KB (1,583 words) - 16:20, 6 December 2023
  • ICO - FS50819531 (category Article 4(1) GDPR)
    Section 3(2) of the Data Protection Act (DPA) and Article 4(1) GDPR. Pursuant to the FOIA and the GDPR, the ICO balanced the right to information and the
    3 KB (212 words) - 16:21, 7 March 2022
  • AEPD (Spain) - PS/00322/2020 (category Article 5(1)(f) GDPR)
    data integrity, security and confidentiality under Article 5(1)(f) GDPR. For the violation of Article 32, the AEPD issued the law firm with a reprimand
    26 KB (3,840 words) - 14:28, 13 December 2023
  • AEPD (Spain) - PS/00099/2022 (category Article 5(1)(f) GDPR)
    infringement of Article 5.1.f) of the RGPD, typified in Article 83.5 of the RGPD, and Article 32 of the RGPD, typified in article 83.4 of the RGPD Once
    38 KB (5,920 words) - 12:43, 13 December 2023
  • protection of personal data, approved by resolution no. 98 of 4/4/2019, published in OJ no. 106 of 8/5/2019 and www.gpdp.it, web doc. no. 9107633 (hereinafter
    24 KB (3,697 words) - 15:52, 6 December 2023
  • HDPA (Greece) - 38/2019 (category Article 4(1) GDPR)
    purposes? 4) Is the data subjects’ consent valid? The HDPA found that: 1) The telephone number constitutes personal data according to Article 4(1) GDPR as the
    4 KB (347 words) - 15:37, 6 December 2023
  • AKI (Estonia) - 2.1.-1/19/126 (category Article 13(4) GDPR)
    provide data that the data subject already possesses under Articles 13(4) and 14(5)(a) GDPR. Thus, the DPA found that the company has adequately fulfilled the
    3 KB (195 words) - 10:30, 13 December 2023
  • APD/GBA (Belgium) - 20/2023 (category Article 2(4) GDPR)
    objection for data processing under Article 21 GDPR and the principle of liability under Article 2(4) GDPR and Article 24 GDPR. The complainant, the data subject
    14 KB (1,883 words) - 16:59, 20 March 2023
  • Commissioner (Cyprus) - 11.17.001.008.001 (category Article 5(1)(f) GDPR)
    orrequest-related processing activities. ». 2.5. Article 32 - Processing security:2.5.1. In accordance with the provisions of Article 32 of the Rules of Procedure, which
    61 KB (9,412 words) - 16:52, 6 December 2023
  • APD/GBA (Belgium) - 10/2019 (category Article 5(1)(b) GDPR)
    been taken up in Article 5(1)(b) of the GDPR under the Principles relating to the processing of personal data (Chapter II). Article 5(1)(b) of the RGPD
    32 KB (5,190 words) - 16:51, 12 December 2023
  • incoming communications" (note cit., p. 6). 1.4. On 10 September 2019, pursuant to Article 166, paragraph 5, of the Code, the Office notified the company
    34 KB (5,414 words) - 15:50, 6 December 2023
  • APD/GBA (Belgium) - 11/2019 (category Article 5(1)(b) GDPR)
    the processing carried out by the controller violated Articles 5(1)(b), 5(1)(e) and 6(4) GDPR and imposed a fine accordingly. Share your comments here! Share
    24 KB (3,844 words) - 16:51, 12 December 2023
  • APD/GBA (Belgium) - 34/2020 (category Article 5(1)(b) GDPR)
    GDPR and Article 66.2 WOG); and • compliance with the transparency obligations (Article 12 GDPR) and the te provide information (Article 13 GDPR). Page
    82 KB (13,250 words) - 16:57, 12 December 2023
  • Court of Appeal of Brussels - 2020/AR/1333 (category Article 5(1)(a) GDPR)
    people affected and the level of damage the elves suffered (article 83.2.4 of the GDPR) 4.1.4. The Data Protection Authority should have taken into account
    51 KB (7,792 words) - 11:43, 24 January 2022
  • Datatilsynet (Norway) - 20/02291 (category Article 5(1)(f) GDPR)
    patient data cf. Article 32 GDPR and Article 5(1)(f) GDPR and inadequate internal controls cf. Article 24 GDPR and Article 5(2) GDPR. Østfold Hospital
    45 KB (6,645 words) - 14:40, 28 March 2022
  • AEPD (Spain) - EXP202104873 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    24 KB (3,512 words) - 10:43, 13 December 2023
  • APD/GBA (Belgium) - 11/2024 (category Article 5(2) GDPR)
    established in Article 12(3) and (4) GDPR. Therefore, the Belgian DPA found the controller to have breached Article 15 GDPR in conjunction with Article 12(3) and
    26 KB (3,856 words) - 08:51, 19 March 2024
  • APD/GBA (Belgium) - 137/2022 (category Article 12(4) GDPR)
    result, the controller has acted in violation of Article 12.3 and 12.4 GDPR, as well as Article 17.1 GDPR. 5. The Disputes Chamber is of the opinion that on
    14 KB (1,946 words) - 08:50, 29 June 2023
  • GHAL - 200.256.426 (category Article 4(2) GDPR)
    on legitimate interests according to Article 6(1)(f) GDPR and that Ziggo had to comply with Article 6(4)(d) GDPR. The Court found that DFW had a legitimate
    40 KB (6,777 words) - 16:28, 15 March 2022
  • Supreme Court - C.20.0323.N (category Article 4(11) GDPR)
    minimisation under Article 5(1)(c) GDPR, and contrary to the obligation to obtain the freely given consent of the data subject under Article 6(1)(a) GDPR, when refusal
    43 KB (6,749 words) - 07:07, 28 October 2021
  • DSB (Austria) - D130.206/0006-DSB/2019 (category Article 4(7) GDPR)
    - the rectification of the violation of Article 13 GDPR would also rectify the violation of Article 5(1)(a) GDPR (principle of transparency) and therefore
    40 KB (6,007 words) - 13:59, 12 May 2023
  • must be respected. More particularly, the personal data must, under Article 5(1)(b) or 5(1)(c) of Regulation 2016/679, be collected for specified, explicit
    7 KB (1,005 words) - 13:10, 1 June 2023
  • Datatilsynet (Norway) - 18/02579 (category Article 5(1)(f) GDPR)
    subsequent violations of Article 32(1)(b) GDPR and Article 32(1)(d) GDPR and of the principle of accountability as foreseen in Article 5(2) GDPR read in conjunction
    41 KB (6,337 words) - 18:52, 5 March 2022
  • AEPD (Spain) - EXP202204631 (category Article 5(1)(f) GDPR)
    comes regulated in article 32 of the GDPR. II Article 5.1.f) of the GDPR Article 5.1.f) of the GDPR establishes the following: "Article 5 Principles relating
    36 KB (5,485 words) - 13:19, 13 December 2023
  • AP (The Netherlands) - 24.03.2020 (category Article 4(15) GDPR)
    unlawfully. 2.4 Administrative fine Pursuant to Article 58, paragraph 2, preamble, in conjunction with Article 83, paragraph 4, of the GDPR and article 14, third
    48 KB (7,461 words) - 17:04, 12 December 2023
  • DSB (Austria) - 2020-0.743.659 (category Article 4(15) GDPR)
    requirements of Article 9 GDPR. In the DSB held that the processing violated Articles 5, 6 and 9 GDPR: Consent under Articles 6(1)(a), 7 and 9(2)(a) GDPR cannot
    50 KB (8,015 words) - 13:52, 12 May 2023
  • Court of Appeal of Brussels - 2020/AR/813 (category Article 5(1)(c) GDPR)
    Therefore the controller violated Article 5(1)(a) and (2), Article 6(1), Article 12(1), Article 13(1)(b) and (c) GDPR. The DPA imposed a fine of €50.000
    85 KB (12,340 words) - 15:30, 19 August 2022
  • Rb. Noord-Nederland - C/ 18/189406/HA ZA 19-6 (category Article 5(1)(f) GDPR)
    loss of control of personal data and a breach of Article 5(1)(f) GDPR, Article 6 GDPR and Article 32(2) GDPR. The first complainant is a company that is engaged
    105 KB (18,002 words) - 16:24, 10 March 2022
  • RvS - 202100789/1/A3 (category Article 5(1)(b) GDPR)
    in accordance with Article 5, paragraph 1, preamble and under b, of the GDPR. 4.4. Article 6, paragraph 1, opening words, of the GDPR stipulates that processing
    20 KB (2,965 words) - 12:52, 28 June 2023
  • HDPA (Greece) - 38/2022 (category Article 4 GDPR)
    processing personal data, in line with the definition of Article 4(1) GDPR. In accordance with Article 5(3) GDPR, the controller had an obligation to demonstrate
    9 KB (974 words) - 15:54, 20 December 2022
  • accordance with Article 60(3) GDPR. Ten DPAs (AT, DE, ES, FI, FR, HU, IT, NL, NO, SE) raised objections, in accordance with Article 60(4) GDPR, to the Draft
    21 KB (3,069 words) - 14:17, 1 February 2023
  • AKI (Estonia) - 2.1.-1/23/2891-5 (category Article 6(1)(a) GDPR)
    it was not possible to rely on Article 6(1)(a) GDPR. Secondly, the DPA recalled that, according to Article 6(1)(f) GDPR, processing of personal data on
    23 KB (3,657 words) - 11:23, 17 April 2024
  • CNIL (France) - SAN-2023-082 (category Article 5(2) GDPR)
    etc.). 2.4.1.9. These documents must include all of the information provided for in Article 14 of the GDPR. 2.4.2. Exercise of people’s rights 2.4.2.1. The
    46 KB (7,106 words) - 17:06, 6 December 2023
  • GHAL - 200.278.124/01 (category Article 5(1)(c) GDPR)
    in Article 17 GDPR (cf. Article 17 (3) b GDPR). In that case, the data subject does not have the right to object as referred to in Article 21 GDPR, because
    35 KB (5,805 words) - 10:04, 14 December 2023
  • AEPD (Spain) - PS/00320/2020 (category Article 4(11) GDPR)
    described violates article 6.1. of the RGPD and is subsumable in the sanctioning type of the article 83.5.a, of the RGPD. IV Article 72.1.b) of the LOPDGDD
    18 KB (2,736 words) - 14:28, 13 December 2023
  • AEPD (Spain) - EXP202201247 (category Article 4(11) GDPR)
    hereinafter, LPACAP), for the alleged violation of article 6.1 of the RGPD, typified in Article 83.5 of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid
    17 KB (2,350 words) - 13:17, 13 December 2023
  • EDPB - Binding Decision 2/2022 - 'Instagram' (category Article 5(1)(c) GDPR)
    the performance of a contract (Article 6(1)(b) GDPR) and for legitimate interest (Article 6(1)(f) GDPR). Article 6(1)(b) GDPR In its original draft decision
    276 KB (38,206 words) - 09:46, 20 January 2023
  • AKI (Estonia) - 18.02.2022 (category Article 5(1) GDPR)
    issues a reprimand under Article 58(2)(b) GDPR. After this, the DPA draws attention to the fact that pursuant of Article 5(1)(a) GDPR, data must be processed
    42 KB (5,838 words) - 10:27, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.010.201 (category Article 5(1)(a) GDPR)
    personal data (Article 5 GDPR). 9 4. Conclusion 4.1 Having regard to all the above facts, as stated and, based on the powers granted to me by Article 58 of the
    23 KB (3,737 words) - 10:30, 7 June 2023
  • RvS - 201905347/1/A3 (category Article 5 GDPR)
    decision of the Minister is no longer based on Article 17(3) GDPR. Instead the decision is based on Article 6(4) GDPR. However the Minister did not explain well
    25 KB (3,824 words) - 22:46, 10 October 2020
  • Datatilsynet (Norway) - 20/01865 (category Article 4(1) GDPR)
    under Article 4(1) GDPR. These statistics even included health data which qualify as a special category of personal data under Article 9(1) GDPR. The Datatilsynet
    19 KB (2,942 words) - 09:03, 14 September 2023
  • DSB (Austria) - 2020-0.349.984 (category Article 4(2) GDPR)
    Paragraph 4 DSG) rely on an authorization norm within the meaning of Article 6 Paragraph 1 lit. c GDPR. This also results from Art. 5 Para. 1 lit. a GDPR, according
    28 KB (4,228 words) - 14:00, 12 May 2023
  • AEPD (Spain) - PS/00117/2022 (category Article 4(11) GDPR)
    (hereinafter, LPACAP), for the alleged violation of article 6 of the RGPD, typified in article 83.5 of the GDPR. SIXTH: On June 30, 2022, the claimed party presented
    30 KB (4,623 words) - 12:58, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.042 (category Article 4(11) GDPR)
    An employer should explore the specific exceptions in Article 9(2)(b) GDPR to Article 9(2)(j) GDPR to lawfully process health-related data of employees
    4 KB (472 words) - 16:52, 6 December 2023
  • without references to names. Moreover, (2) it included health data (Article 4(15) GDPR) as the newsletters were send to patients of the respected medical
    63 KB (9,916 words) - 11:28, 16 August 2022
  • AEPD (Spain) - PS/00151/2020 (category Article 5(1)(c) GDPR)
    of the duty of information as per article 13 GDPR. The DPA imposed thus a fine of €1000 for violating Article 13 GDPR. Share your comments here! Share blogs
    28 KB (4,525 words) - 14:06, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.010.045 (category Article 5(1)(c) GDPR)
    that the article’s publication was in violation of Article 5(1)(c) GDPR, Article 6(1)(f) GDPR, when read in line with Article 85 GDPR. Article 5(1)(c) outlines
    74 KB (12,375 words) - 10:07, 4 October 2023
  • APD/GBA (Belgium) - 03/2021 (category Article 5(1)(b) GDPR)
    Chamber thus concludes that the infringement of Article 5.1.b) in conjunction with Article 6.4. GDPR, and Article 6.1. AVG has been proven. 28. Despite the fact
    32 KB (4,880 words) - 16:50, 12 December 2023
  • VGH München – 11 ZB 19.991 (category Article 5(1)(b) GDPR)
    (1) lit. d GDPR. The procedure was also compatible with the principle of purpose limitation within the meaning of Article 5 para. 1 lit. b GDPR. In September
    31 KB (5,184 words) - 17:19, 15 April 2023
  • GHAL - 200.266.445 (category Article 5 GDPR)
    the registration. assessment framework 4.4 The assessment framework that the court used in paragraphs 4.1 to 4.4 of the decision of 24 June 2019 was not
    15 KB (2,380 words) - 13:35, 5 July 2022
  • NAIH (Hungary) - NAIH/2020/974/4 (category Article 5(1)(a) GDPR)
    breach of the General Data Protection Regulation5. Article 5 (1) (a), Article 5 (2) and Article 13 Article 1 (1) to (2). III.3. JogkövetkezményekIII.3.1
    67 KB (10,815 words) - 10:11, 17 November 2023
  • AEPD (Spain) - EXP202208091 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    40 KB (6,014 words) - 13:24, 13 December 2023
  • processing of personal data within the meaning of Article 4 GDPR and is it justified on the basis of Article 6 GDPR? Can the controller raise the argument that
    73 KB (11,238 words) - 16:59, 12 December 2023
  • AEPD (Spain) - PS/00187/2020 (category Article 5(1)(f) GDPR)
    the alleged violation of Article 32 of the RGPD, Article 5.1.f) of the RGPD, Article 25 of the RGPD, typified in Article 83.5 of the RGPD. FOURTH: On October
    51 KB (7,770 words) - 14:08, 13 December 2023
  • APD/GBA (Belgium) - 154/2023 (category Article 5(1)(b) GDPR)
    principle (Article 5.1 b) GDPR) and the principle of minimum data processing (Article 5.1 c) GDPR). This follows from both provisions of the GDPR camera surveillance
    21 KB (3,034 words) - 15:30, 26 January 2024
  • AEPD (Spain) - PS/00278/2019 (category Article 4(11) GDPR)
    lack of valid consent under Article 6(1)(a) GDPR. Thus, it imposed VODAFONE a fine of EUR 75,000 under Article 83(5) GDPR, being indecisive whether there
    23 KB (3,672 words) - 14:25, 13 December 2023
  • Datatilsynet (Norway) - 20/02274 (category Article 5(1)(a) GDPR)
    fundamental principles of the GDPR, notably Article 5(1)(a) and (e) GDPR. The DPA found violations of various provisions of the GDPR. It held that the controller
    47 KB (7,661 words) - 18:54, 5 March 2022
  • APD/GBA (Belgium) - 51/2023 (category Article 5(1)(b) GDPR)
    Articles 5.1.b) and 5.1.c) of the GDPR pursuant to Article 95, §1, 3° of the LCA; - pursuant to Article 58.2.c) of the GDPR and Article 95, § 1, 5° of the
    18 KB (2,611 words) - 12:45, 16 June 2023
  • administrative fines provided for by Article 83, paragraphs 4 and 5, of the Regulation and Article 166, paragraph 1 of the Code. 4.4. On the publication of the data
    129 KB (21,020 words) - 15:49, 6 December 2023
  • APD/GBA (Belgium) - 48/2021 (category Article 5(1)(a) GDPR)
    defendant on the basis of Article 100.1, 5 ° LCA given the breach noted in Article 6 of the GDPR combined with Article 5.1.a) of GDPR; - To dismiss the remainder
    43 KB (6,670 words) - 16:58, 12 December 2023
  • NAIH (Hungary) - NAIH/2020/2555 (category Article 4(1) GDPR)
    Debtor pursuant to Article 58 (2) (b) of the General Data Protection Regulation because its data processing activities violated Article 5 (1) (d) of the General
    33 KB (5,033 words) - 10:12, 17 November 2023
  • AEPD (Spain) - PS/00029/2020 (category Article 5(1)(f) GDPR)
    Q4500146H, for the alleged infringement of Article 5.1.f) of the RGPD, in accordance with the provisions of Article 83.5 of the RGPD and 72.1.i) of the LOPDGDD
    44 KB (6,943 words) - 13:49, 13 December 2023
  • AEPD (Spain) - PS/00268/2022 (category Article 5(1)(f) GDPR)
    infringement of Article 5.1.f) of the RGPD, Article 33 of the RGPD, Article 25 of the RGPD and Article 32 of the RGPD, typified in Article 83.5 of the RGPD
    63 KB (9,551 words) - 12:33, 13 December 2023
  • DSB (Austria) - D122.970/0004-DSB/2019 (category Article 12(5) GDPR)
    executed. Legal basis: Article 4 lines 1, 2 and 5, Article 11 paragraphs 1 and 2, Article 12 paragraph 2, Article 17 paragraph 1 and Article 58 paragraph 2 lit
    23 KB (3,622 words) - 13:57, 12 May 2023
  • Rb. Amsterdam - C/13/692003/HA RK 20-302 (category Article 15(1) GDPR)
    be regarded as the controller within the meaning of Article 4 under 7 GDPR. The legal framework 4.4. [Applicants] argue that Uber has infringed their right
    30 KB (4,797 words) - 10:03, 19 May 2021
  • AEPD (Spain) - PS/00348/2020 (category Article 5(1)(a) GDPR)
    claimant’s signature constitute a breach under the GDPR? The AEPD held that Vodafone violated Article 6(1) GDPR, as they had processed the claimant’s data without
    38 KB (5,648 words) - 14:31, 13 December 2023
  • AEPD (Spain) - PS/00326/2020 (category Article 37(1)(a) GDPR)
    28001 - Madrid sedeagpd.gob.es 3/5 The infringement is considered as such in article 83.4.a of the RGPD which states: ”4. The Infractions of the following
    14 KB (1,992 words) - 14:29, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/32/4 (category Article 5(1) GDPR)
    pursuant to Article 4(2) of the GDPR, and the applicant operating and managing the Facebook page is a controller pursuant to Article 4(7) of the GDPR, given
    75 KB (12,586 words) - 10:10, 17 November 2023
  • AEPD (Spain) - PS/00329/2020 (category Article 37 GDPR)
    period ”. In this sense, article 77.1 c) and 2, 4 and 5 of the LOPGDD, indicates: 1. "The regime established in this article shall apply to the treatment
    13 KB (2,002 words) - 14:29, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/2000/5 (category Article 5(1)(a) GDPR)
    of a Commission decision on adequacy , or in Article 46, Article 47 or the second subparagraph of Article 49 (1) (a) the period for which the personal
    24 KB (3,815 words) - 10:11, 17 November 2023
  • APD/GBA (Belgium) - 37/2021 (category Article 5(1)(b) GDPR)
    person concerned. ” 4.3.1- As regards respect for the principles of minimization and finality (article 5.1.c. and article 5.1.b of the GDPR) 24. In its capacity
    45 KB (6,780 words) - 16:57, 12 December 2023
  • AKI (Estonia) - 2.1.-3/20/4479 (category Article 5(1)(c) GDPR)
    are a special type of personal data (see also IKÜM art. 4 p. 15 definition of health data). 4.5. Challenger: AKI's position, as if any person in an e-pharmacy
    28 KB (4,474 words) - 10:31, 13 December 2023
  • Datatilsynet (Denmark) - 2019-431-0052 (category Article 4(11) GDPR)
    place in accordance with Article 5 (1) of the Data Protection Regulation. 1, letter e, and Article 6, para. 1, cf. Article 4, point 11. The Danish Data
    27 KB (4,300 words) - 16:36, 6 December 2023
  • AZOP (Croatia) - Decision 28-08-2019 (category Article 4(1) GDPR)
    violation of Article 5, Article 6, and Article 25 GDPR. It ordered the controller to comply with the data subject's erasure request pursuant to Article 17(1)(d)
    16 KB (2,373 words) - 15:31, 30 October 2023
  • (possible) fraud. This resulted in a breach of Article 5(1)(a) GDPR and Article 6(1) GDPR in conjunction with Article 8 of the Dutch Personal Data Protection
    49 KB (7,201 words) - 17:06, 12 December 2023
  • HDPA (Greece) - 35/2023 (category Article 4(12) GDPR)
    personal data by bank to the data subject's wife under Article 5 (1) (a) GDPR and Article 5 (1) (f) GDPR. An additional €50,000 was added for the violation
    52 KB (8,460 words) - 10:54, 10 January 2024
  • APD/GBA (Belgium) - 22/2020 (category Article 5(1)(f) GDPR)
    observations, which, in accordance with Article 54(1)(b), (3) and (4), (4) and (4), (5) and (5), (5) and (5), (5) and (5), (5) and (6). 2 of the Rules of Procedure
    35 KB (5,526 words) - 16:56, 12 December 2023
  • HDPA (Greece) - 24/2020 (category Article 4(2) GDPR)
    possibility of exercising their right to access (Article 15 GDPR), not mentioning any of the elements of Article 14 GDPR regarding the processing of data, but only
    8 KB (879 words) - 15:37, 6 December 2023
  • OLG Köln - 15 U 126/19 (category Article 17(1)(d) GDPR)
    pursuant to Article 17(1)(d) GDPR since the data was unlawfully processed. The defendant claimed that its activities fall under exception in (Article 85 GDPR)
    121 KB (20,412 words) - 15:58, 10 March 2022
  • APD/GBA (Belgium) - 08/2019 (category Article 12(4) GDPR)
    violated Articles 12(3), (4), 13(2)(b), 30(1)(d) and (g) of the GDPR and issued a warning by virtue of Article 58(2)(b) of the GDPR. Due to the anonimisation
    24 KB (3,843 words) - 16:51, 12 December 2023
  • provided for by Article 83, paragraphs 4 and 5, of the Regulation. 4. ORDER INJUNCTION FOR THE APPLICATION OF THE PECUNIARY ADMINISTRATIVE SANCTION 4.1. Information
    58 KB (9,448 words) - 15:50, 6 December 2023
  • AEPD (Spain) - PS/00446/2021 (category Article 5(1)(c) GDPR)
    for the alleged violation of article 5.1.c) of the GDPR and article 13 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Once the aforementioned
    24 KB (3,717 words) - 13:04, 13 December 2023
  • information pursuant to Article 13 (1) of the GDPR of what is written in paragraph Recital (39) of the GDPR and Article 5 (1) point a) of the GDPR stipulate that
    69 KB (11,255 words) - 10:08, 17 November 2023
  • AEPD (Spain) - PS/00003/2020 (category Article 5(1)(c) GDPR)
    of Article 5.1.c) of the RGPD, typified in Article 83.5 of the RGPD, a fine of FIVE THOUSAND EUROS (€ 5,000). That, under the provisions of article 58
    50 KB (7,524 words) - 13:44, 13 December 2023
  • AEPD (Spain) - EXP202105669 (category Article 5(1)(f) GDPR)
    violation of article 5.1.f) of the GDPR, typified in article 83.5 of the GDPR, a warning sanction and for a violation of article 32 of the GDPR, typified
    45 KB (6,998 words) - 12:58, 13 December 2023
  • Court of Appeal of Brussels - 2019/AR/1006 (category Article 16 GDPR)
    inadmissible rational personae. 5.4. The merits of the appeal to the extent directed against the GBA - the violation of Article 16 GDPR. 5.4.1. The general framework
    59 KB (9,290 words) - 09:10, 5 May 2024
  • et seq. 13Investigation report, page 29, point 4.4.5.1. 14Investigation report, page 30, point 4.4.5.2.5.1. 15 Statement of Objections, point 18. 16 Statement
    82 KB (11,472 words) - 16:58, 6 December 2023
  • DSB (Austria) - 2021-0.101.211 (category Article 4(15) GDPR)
    to be qualified as a health data pursuant to Article(4)(15) GDPR and that the scope of protection of Article 9(2) must be taken into account as a standard
    37 KB (5,745 words) - 13:53, 12 May 2023
  • APD/GBA (Belgium) - 136/2023 (category Article 5(1)(f) GDPR)
    violating Article 5(1)(f) GDPR, Article 5(1)(a) GDPR, Article 5(2) GDPR, Article 12 GDPR, Article 13 GDPR, Article 14 GDPR, Article 24(1) GDPR, and Article
    58 KB (9,184 words) - 16:49, 12 December 2023
  • AEPD (Spain) - PS/00279/2020 (category Article 83(5) GDPR)
    fine of € 5 000 for the violation of Article 6 GDPR and € 4 000 for the violation of article 13, under the power conferred by Article 83(5) GDPR. Share your
    21 KB (3,123 words) - 14:25, 13 December 2023
  • AP (The Netherlands) - 16.06.2020 (category Article 4(12) GDPR)
    the sense of Article 4, headings under 12, of the GDPR. What should be clear is that a breach is some type of security incident Article 4, headings under
    54 KB (8,224 words) - 17:07, 12 December 2023
  • AEPD (Spain) - EXP202200471 (category Article 5(1)(f) GDPR)
    the violation of Article 5(1)(f) GDPR and €30,000 for the violation of Article 32 GDPR. According to the national legislation (Article 76(2)(b) LOPDGDDon
    40 KB (6,014 words) - 13:21, 13 December 2023
  • OLG Hamm - 7 U 19/23 (category Article 82 GDPR)
    contract (Article 6(1)(b) GDPR), nor could be based on legitimate interest of the controller (Article 6(1)(f) GDPR). Consent (Article 6(1)(a) GDPR) could
    130 KB (21,874 words) - 09:43, 15 February 2024
  • personal data, approved by resolution no. 98 of 4/4/2019, published in the Official Gazette n. 106 of 8/5/2019 and in www.gpdp.it, doc. web n. 9107633 (hereinafter
    57 KB (9,144 words) - 15:55, 6 December 2023
  • CNPD (Luxembourg) - Délibération n° 18/FR/2022 (category Article 5(1)(b) GDPR)
    criteria laid down by article 83.2 of the GDPR for breach of Articles 5.1.a), 6.1, 12.3 and 4 as well as Article 15.1.b) and c) of the GDPR. As regards the amount
    76 KB (11,147 words) - 16:58, 6 December 2023
  • APD/GBA (Belgium) - 07/2021 (category Article 5(1) GDPR)
    infringement of Article 5.1 b) in conjunction with Article 6.4. AVG, on article 5.1 a) in conjunction with article 6.1. AVG and on article 5.1 c) GDPR has been
    72 KB (11,208 words) - 16:51, 12 December 2023
  • NAIH (Hungary) - NAIH/2020/193/8 (category Article 5(1)(d) GDPR)
    been deleted by the employer upon request pursuant to Article 16, Article 17 and Article 5(1)(d) GDPR (inaccuracy of personal data). Therefore, the employer
    58 KB (9,413 words) - 10:11, 17 November 2023
  • AEPD (Spain) - PS/00287/2020 (category Article 5(1)(f) GDPR)
    established by Article 5(1)(f) GDPR? Was there a personal data breach? The AEPD considered that there was an infringement of Article 5(1)(f), as there
    32 KB (4,837 words) - 14:26, 13 December 2023
  • AEPD (Spain) - PS/00071/2020 (category Article 5(1)(a) GDPR)
    P3120800B, for the alleged violation of article 5.1.b) in relation to article 6.4 of the RGPD, in accordance with article 83.5.a) of the RGPD. SECOND: INITIATE
    45 KB (7,267 words) - 13:56, 13 December 2023
  • LG München - 31 O 16606/20 (category Article 5(1)(f) GDPR)
    subject pursuant to Article 82(1) GDPR, for a theft of their personal identity and financial data, because it violated Article 32(1) GDPR which led to a data
    25 KB (4,028 words) - 07:10, 8 February 2022
  • Personvernnemnda (Norway) - 2021-03 (category Article 5(1)(a) GDPR)
    Ordinance Article 6 No. 1 letter f, for failure to assess protests, cf. Article 21, and for lack of information, cf. Article 13. 2. Pursuant to Article 58 (2)
    25 KB (4,046 words) - 18:37, 5 March 2022
  • GDPRhub is a wiki with GDPR-related decisions and knowledge, enabling anyone to find and share GDPR insights across Europe! GDPRhub collects and summarises
    6 KB (277 words) - 12:46, 10 April 2024
  • consultation with the DPA as per Article 36 GDPR. The DPA temporarily suspended its processing ban against Helsingor municipality until 5 November 2022, and also
    25 KB (3,660 words) - 08:42, 14 September 2022
  • Giessegi violated Articles 5(1)(a) and 13 GDPR, as it did not provide the data subject with a proper privacy policy. Article 28 GDPR was also infringed, as
    87 KB (14,104 words) - 15:45, 6 December 2023
  • AP (The Netherlands) - 14.01.2022 (category Article 5(1)(c) GDPR)
    increase or decrease. 4.4 Conclusion The AP sets the total fine at €525,000. 4For the justification, see paragraphs 4.3.1 and 4.3.2. 18/19,Date Unidentified
    50 KB (7,656 words) - 17:05, 12 December 2023
  • AP (The Netherlands) - 25.11.2021 (category Article 5(1)(a) GDPR)
    fairness principle, violating Article 5(1)(a) in conjunction with Article 6(1)(e) GDPR, and Article 6 in conjunction with Article 8 Personal Data Protection
    87 KB (11,601 words) - 17:08, 12 December 2023
  • Datatilsynet (Norway) - 20/01627 (category Article 4(1) GDPR)
    cf. Article 5 (2). A basic principle for the processing of personal data is that the processing must take place in a lawful manner, cf. Article 5, paragraph
    45 KB (6,973 words) - 05:12, 15 September 2022
  • APD/GBA (Belgium) - 136/2022 (category Article 4(1) GDPR)
    right of access (Article 12(4) GDPR). The DPA held that data concerning the vehicle of the complainant is personal data (Article 4(1) GDPR), since the data
    19 KB (2,700 words) - 08:49, 29 June 2023
  • AEPD (Spain) - EXP202309109 (category Article 5(1)(c) GDPR)
    purposes and means of such activity, by virtue of article 4.7 of the GDPR. For its part, article 5.1.c) of the GDPR regulates the “principles relating to processing”
    18 KB (2,733 words) - 13:18, 13 December 2023
  • stakeholders did not follow the security principles as per Article 5(1)(f) GDPR (ed.: the decision actually reads 5(2)(f)), highlighting ‘the absence of an assessment
    55 KB (8,833 words) - 15:54, 6 December 2023
  • (2016/679) Article 5 (1) (a), Article 12 (1), (2) and (6) , Article 13, Article 15 (1) (h), (3) and (4), Article 58 (2) (c) and (d) subparagraphs Article 34 (1)
    41 KB (6,220 words) - 09:48, 17 November 2023
  • AEPD (Spain) - PS/00128/2020 (category Article 4(13) GDPR)
    with article 4.1 of the RGPD. As for the fingerprint, it is also data that must be qualified. two as biometric data and in accordance with article 4.14 of
    39 KB (5,912 words) - 14:02, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.007.220 (category Article 7(4) GDPR)
    time tracking system, due to a lack of compatibility with Article 7(4) and Article 35(9) of GDPR. KEO PLC decided to upgrade its ERP system, whose upgrade
    56 KB (8,913 words) - 16:52, 6 December 2023
  • OLG Köln - 20 U 295/21 (category Article 4(1) GDPR)
    invoked the excessiveness of the request under Article 12(5) GDPR alleging that the data subject uses Article 15 GDPR only to verify the validity of the premium
    42 KB (6,689 words) - 08:30, 21 November 2022
  • CNPD (Portugal) - Deliberação 984/2018 (category Article 5(1)(f) GDPR)
    ofcombined provisions of Articles 5, paragraph 1 to 1. c) and article 5, paragraph 1 al. f) with article83, paragraph 5, al. a), the General Data Protection
    40 KB (5,935 words) - 16:55, 6 December 2023
  • AP (The Netherlands) - 23.09.2021 (category Article 32(1) GDPR)
    11, report of 5 December 2019, page 23. 16See File 11, report of 5 December 2019, page 25. 17See File 11, report of 5 December 2019, page 4. 18See File 11
    66 KB (8,861 words) - 17:08, 12 December 2023
  • Datatilsynet (Norway) - 20/01896 (category Article 5(2) GDPR)
    of the fee. 5.5. The amount of the infringement fee In determining the fee, the points in section 5.4 above shall be given weight, cf. Article 83 (2). The
    28 KB (4,387 words) - 18:58, 5 March 2022
  • AEPD (Spain) - E/01090/2021 (category Article 4(9) GDPR)
    before the Social Court 4 of this city, in dismissal orders *** CARS.1. " The aforementioned order that you attached is dated February 5, 2020 with the claimant
    17 KB (2,544 words) - 13:39, 13 December 2023
  • AEPD (Spain) - PS/00134/2019 (category Article 5(1)(a) GDPR)
    a violation of article 5.1 a) of the RGPD, ofin accordance with article 83.5 of the RGPD, a fine of APPEARANCE, in accordancewith article 58.2.b) of the
    26 KB (4,034 words) - 14:04, 13 December 2023
  • AEPD (Spain) - PS/00200/2019 (category Article 5(1)(f) GDPR)
    Jorge Juan, 6www.aepd.es28001 - Madridsedeagpd.gob.es Page 4 4/5The LOPDGDD states in its article 5:" 1. Those responsible and in charge of data processing
    14 KB (2,163 words) - 14:10, 13 December 2023
  • AEPD (Spain) - PS/00483/2020 (category Article 5(1)(f) GDPR)
    established by Article 5(1)(f) GDPR? Was there a personal data breach? The AEPD considered that there was an infringement of Article 5(1)(f), as there
    32 KB (4,834 words) - 14:43, 13 December 2023
  • APD/GBA (Belgium) - 12/2019 (category Article 4(11) GDPR)
    the ePrivacy Directive and Articles 6(1)(a) and 7 GDPR, in the lights of Article 4(11) and Recital 32 GDPR. Following this report, the GBA issued a decision
    107 KB (17,697 words) - 16:52, 12 December 2023
  • AEPD (Spain) - PS/00335/2020 (category Article 5(1)(f) GDPR)
    protocols. This therefore breached Article 5(1)(f) GDPR and Article 32 GDPR. The initial sanction for infringing Article 5(1)(f) was a fine of €5000 and the
    34 KB (5,427 words) - 14:30, 13 December 2023
  • AEPD (Spain) - EXP202104917 (category Article 4(11) GDPR)
    valid consent under Article 4(11) GDPR and Article 6(1) LOPDGDD (National data protection law aimed at the implementation of the GDPR). In both articles
    27 KB (4,356 words) - 12:41, 13 December 2023
  • Datatilsynet (Norway) - 20/02172 (category Article 6(1)(f) GDPR)
    under Article 6(1)(f) GDPR. The DPA also requires that the company implement internal controls of their credit rating process as per Article 24 GDPR. The
    28 KB (4,155 words) - 18:57, 5 March 2022
  • AEPD (Spain) - EXP202100639 (category Article 5(1)(c) GDPR)
    alleged infringement of article 5.1.c) of the RGPD and article 13 of the RGPD, typified in Article 83.5 a) and b) of the GDPR. FIFTH: On 12/17/2021 the
    32 KB (4,945 words) - 13:25, 13 December 2023
  • AG Pankow - 4 C 199/21 (category Article 15 GDPR)
    according to Article 82 GDPR. The District Court rejected the claim of the data subject. It held that the controller did not violate Article 15(1) GDPR. It found
    17 KB (2,569 words) - 07:15, 17 May 2022
  • DPC (Ireland) - IN-21-3-1 (category Article 4 GDPR)
    controller had infringed Article 6(1) GDPR, in addition to violating the principle of data minimisation in Article 5(1)(c) GDPR. Concerning the second issue
    20 KB (3,069 words) - 18:48, 24 January 2023
  • accuracy of the data processed (Article 5, paragraph 1, letter d) of the Regulation), nor in terms of safety and integrity (Article 5, paragraph 1, letter f) of
    50 KB (8,001 words) - 15:52, 6 December 2023
  • AEPD (Spain) - PS/00272/2019 (category Article 5(1)(c) GDPR)
    with the GDPR. Especially, if the installation of surveillance camera is contrary to the data minimisation principle, under Article 5(1)(c) GDPR. First,
    22 KB (3,438 words) - 14:24, 13 December 2023
  • AEPD (Spain) - PS/00239/2022 (category Article 15 GDPR)
    violation of Article 15 of the GDPR, typified in Article 83.5 of the GDPR, as well as for the alleged infringement of Article 17 of the GDPR, typified in
    60 KB (9,630 words) - 12:34, 13 December 2023
  • Datatilsynet (Norway) - 21/00480 (category Article 5(1)(f) GDPR)
    fined a municipality €409,768 (NOK 4,000,000) for breaches of Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack
    31 KB (4,380 words) - 06:12, 14 March 2023
  • Commissioner (Cyprus) - 11.17.001.010.007 (category Article 5(1)(c) GDPR)
    intention to infringe either article 5(1)( c) or article 34(1) of the GDPR. Legal framework 8.1. Pursuant to Article 5(1)(c) of the GDPR “Personal Data shall be:
    20 KB (3,082 words) - 13:42, 31 January 2024
  • AEPD (Spain) - PS/00430/2020 (category Article 4(11) GDPR)
    his/her consent. The DPA first outlined Article 6(1)(a) and (b) GDPR, Articles 4(11) GDPR on consent, as well as Article 6 of the Spanish Data Protection Law
    31 KB (4,738 words) - 14:39, 13 December 2023
  • GHAL - 200.186.790/01 (category Article 6(1)(b) GDPR)
    terminated, must be assessed in the light of Article 6 GDPR and not Article 10 GDPR. Article 6(1)(f) GDPR provides a sufficient basis for processing. The
    50 KB (8,219 words) - 12:42, 4 March 2022
  • HDPA (Greece) - 44/2019 (category Article 5(1) GDPR)
    internal compliance and accountability according to Article 5(1) GDPR, Article 5(2) GDPR and Article 6(1) GDPR. Since the company had totally ignored the its
    127 KB (21,184 words) - 15:39, 6 December 2023
  • APD/GBA (Belgium) - 24/2021 (category Article 6 GDPR)
    and transparency (Article 5.1 a) GDPR), purpose limitation (Article 5.1 b) GDPR) and minimum data processing (Article 5.1 c) GDPR); 4) the legal basis for
    110 KB (18,238 words) - 16:56, 12 December 2023
  • AEPD (Spain) - PS/00104/2020 (category Article 5(1)(f) GDPR)
    defendant is defined in Articles 83.4.a) and 83.4.b) respectively. 83.5.a) of the RGPD, precepts that they establish: Article 83.4: "Violations of the following
    36 KB (6,022 words) - 13:59, 13 December 2023
  • AEPD (Spain) - TD/00129/2020 (category Article 4(1) GDPR)
    recording is "processing" of "personal data" within the meaning of Article 4(1) and 4(2) GDPR. Therefore, the data subject has the right to request access to
    22 KB (3,422 words) - 14:50, 13 December 2023
  • Rb. Noord-Holland - C/15/311101 / HA RK 20-227 (category Article 17(1) GDPR)
    reluctant to minimize data. 4.4. The municipality takes the position that Article 17 paragraph 3 under b AVG in conjunction with Article 7.3.8 paragraph 3 Youth
    22 KB (3,333 words) - 13:22, 2 June 2021
  • AEPD (Spain) - PS/00439/2019 (category Article 5(1)(c) GDPR)
    Spanish City Council with a warning of an infringement of Article 5(1)(c) pursuant to Article 83(5) over installed surveillance cameras in the City Hall.
    21 KB (2,946 words) - 14:40, 13 December 2023
  • definition of the concept of consent in the data protection regulation article 4, No. 11. Article 4 of the Data Protection Regulation, no. 11 states that consent
    52 KB (8,025 words) - 05:01, 23 November 2023
  • APD/GBA (Belgium) - 25/2020 (category Article 5 GDPR)
    the basis of article 92, 3° of the WOG. 14. The inspection report shall identify potential breaches of Article 5(1). 2 of the AVG, Article 6 of the AVG
    84 KB (14,035 words) - 16:56, 12 December 2023
  • CNIL (France) - SAN-2020-056 (category Article 5(1)(d) GDPR)
    down in Article 28 of the GDPR. The Commission wonders about such a qualification in the light of the definition of a subcontractor given in Article 4.8 of
    43 KB (6,847 words) - 17:11, 6 December 2023
  • AEPD (Spain) - PS/00201/2019 (category Article 4(1) GDPR)
    data had taken place, meaning GDPR obligations did not apply. Are these magnetic cards personal data within Article 4(1) GDPR? If so, did the MCP infringe
    54 KB (9,019 words) - 14:10, 13 December 2023
  • Rb. Rotterdam - 9436020 \ CV EXPL 21-30289 (category Article 4(2) GDPR)
    data is a form of processing as referred to in the GDPR (article 4 sub 2 GDPR). Article 6 of the GDPR provides that the processing of personal data is only
    19 KB (2,828 words) - 10:09, 18 March 2022
  • Court of Appeal of Brussels - 2021/AR/163 (category Article 83 GDPR)
    information obligation provided for a / 'article 14, §5, (c) of the GDPR. (...) Pursuant to article 14, §5, (c) of the GDPR, the responsibility for processing
    72 KB (11,389 words) - 08:59, 20 August 2021
  • Datatilsynet (Norway) - 20/02225 (category Article 5(2) GDPR)
    dissuasive" as per Article 83(1). In addition to a breach of Article 6(1)(f), the lack of organisational measures pursuant to Article 5(2) was weighted when
    45 KB (7,286 words) - 18:55, 5 March 2022
  • AEPD (Spain) - EXP202104875 (category Article 5(1)(f) GDPR)
    of the article 5.1.f) of the RGPD, infringement typified in its article 83.5.a) of the aforementioned regulation. IV. Article 83.5 a) of the GDPR, considers
    54 KB (8,451 words) - 13:35, 13 December 2023
  • AP (The Netherlands) - 24.02.2022 (category Article 13(1)(e) GDPR)
    Contents 1.Introduction 4 1.1Background 4 1.2Target research 5 1.3Visa ProcessforSchengen Short Stay Visa 5 1.4 Legal framework 8 1.5Process flow 8 2.Findings
    179 KB (22,957 words) - 17:07, 12 December 2023
  • year 2005-2006, 29 708, no. 19 (p. 523) Article 4:32 The obligation from this article is taken over from Article 52 of the Wfd. Under Section 14(2) of the
    91 KB (15,371 words) - 15:11, 5 October 2021
  • AEPD (Spain) - PS/00280/2022 (category Article 5(1)(f) GDPR)
    LPACAP), for the alleged infringement of article 5.1.f) of the RGPD and article 32 of the RGPD, typified in article 83.5 of the RGPD. EIGHTH: Notification of
    30 KB (4,551 words) - 11:51, 9 February 2023
  • HDPA (Greece) - 12/2022 (category Article 5(1)(a) GDPR)
    lawfulness, fairness and transparency under Article 5(1)(a) GDPR, and the principle of accountability under Article 5(2) GDPR. Additionally, the HDPA held that the
    46 KB (7,390 words) - 08:07, 1 April 2022
  • violated Article 5(1)(c) GDPR, Article 25(2) GDPR and Section 29(4) of the Finnish Data Protection Act. As a result, and in accordance with Article 58(2)(d)
    25 KB (3,651 words) - 09:37, 3 April 2024
  • AEPD (Spain) - PS/00075/2020 (category Article 83(5)(a) GDPR)
    respondent: a) for the alleged infringement of Article 6.1.a) of the GDPR, sanctioned in accordance with the Article 83.5.a) of the aforementioned RGPD and, b)
    31 KB (4,909 words) - 13:56, 13 December 2023
  • power conferred by Article 58(2)(d) and (f) and Article 83(3) and (5) GDPR, imposed to Fastweb multiple corrective measures and a fine of € 4.501.868. Share
    131 KB (21,014 words) - 15:55, 6 December 2023
  • NAIH (Hungary) - NAIH-2020-2546-5 (category Article 5(1)(c) GDPR)
    agreements Article 12 (1) of the GDPR 17 IV.5. Legal consequences (72) The Authority finds that the Client has infringed Article 5 (1) (c) GDPR, Article 6 Article
    72 KB (11,159 words) - 10:09, 17 November 2023
  • processing carried out is in violation of Article 5(1)(f) GDPR, Article 25(1) GDPR, Article 32 GDPR and Article 35 GDPR. Especially, the controller cannot exclude
    119 KB (19,123 words) - 11:29, 16 August 2022
  • AEPD (Spain) - PS/00183/2022 (category Article 5(1)(d) GDPR)
    of rectification of Article 16 GDPR and Article 14 of LOPDGDD, the national data protection law, the DPA stated that Article 12(4) LOPDGDD obliges the
    63 KB (10,203 words) - 13:01, 13 December 2023
  • AEPD (Spain) - PS/00422/2018 (category Article 5(1)(f) GDPR)
    RETAIL S.L. for alleged infringement of Article 5.1 f) of the GDPR, in accordance with Article 83.5.a) of the GDPR- Initiate sanctioning procedure against
    25 KB (3,933 words) - 14:37, 13 December 2023
  • UODO (Poland) - DKN.5131.5.2020 (category Article 83(4)(a) GDPR)
    subjects, according to Article 33(1) GDPR and Article 34(1) GDPR? The PUODO held that the insurance company infringed the GDPR provisions, failing to notify
    47 KB (7,608 words) - 10:00, 17 November 2023
  • AEPD (Spain) - PS/00436/2019 (category Article 83(5) GDPR)
    LPACAP), for the alleged infringement of Article 58. 1 of the RGPD, typified in Article 83.5 of the RGPD. 2/5 SIXTH: The aforementioned agreement to commence
    14 KB (2,123 words) - 14:40, 13 December 2023
  • APDCAT (Catalonia) - PS 49/2019 (category Article 5(1)(a) GDPR)
    provided for in Article 83.5.b) in relation to Article 13; and third, an infringement provided for in Article 83.4.a) in relation to Article 28 all of them
    38 KB (5,760 words) - 08:26, 8 September 2021
  • APD/GBA (Belgium) - XX/2021 (category Article 60 GDPR)
    personal data under Article 17 GDPR. On 21 September 2021, the controller confirmed the deletion, as required by Article 12(3) and (4) GDPR. However, the complainant
    17 KB (2,189 words) - 12:34, 3 August 2022
  • APD/GBA (Belgium) - 73/2020 (category Article 5 GDPR)
    Pursuant to Article 37(5) GDPR, the DPO should be designated, inter alia, on the basis of their in data protection law and practice. Article 37(7) GDPR provides
    93 KB (14,040 words) - 17:00, 12 December 2023
  • (infringement of Article 24 and 5.2 GDPR)Second vemreermiddel: the request of the complainant 's request for erasure in themeaning of Article 17 GDPR; third party
    67 KB (10,544 words) - 09:24, 10 September 2021
  • AEPD (Spain) - PS/00449/2019 (category Article 5(1)(b) GDPR)
    with NIF G08564379, an infringement of article 5.1.b) GDPR, typified in Article 83.5 GDPR, in relation to Article 72.1 a) of the LOPDGDD, a fine of 5000
    19 KB (2,862 words) - 14:43, 13 December 2023
  • AEPD (Spain) - PS/00129/2022 (category Article 83(5) GDPR)
    violation of article 5.1.f) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter RGPD), typified in the article 83.5 of the RGPD
    22 KB (3,420 words) - 12:59, 13 December 2023
  • accountability (Article 5 (2) and 24 (1), (2) GDPR), privacy by design (Article 25 (1) GDPR) and as controller towards its data processors (Article 28 GDPR). Consequently
    144 KB (23,155 words) - 15:46, 6 December 2023
  • TGI Paris - N° 14/07224 (category Article 5(1)(d) GDPR)
    - of article L.121-20-3 of the Consumer Code in its wording prior to the law of March 17, 2014 for all contracts, - of article R.132-1 / 4 ° & 5 ° of the
    392 KB (67,730 words) - 15:27, 17 March 2022
  • AEPD (Spain) - PS/00058/2020 (category Article 5(1)(f) GDPR)
    for the alleged violation of article 5.1f) of the RGPD in relation to the Article 5 of the LOPDGDD, typified in article 83.5 a) of the RGPD. C / Jorge Juan
    28 KB (4,619 words) - 13:53, 13 December 2023
  • AEPD (Spain) - EXP202103746 (category Article 5(1)(c) GDPR)
    violation of data minimisation, Article 5(1)(c) GDPR. No fines can be imposed against the controller and Article 83(5) GDPR can therefore not be imposed.
    16 KB (2,041 words) - 13:34, 13 December 2023
  • to the criteria laid down by Article 83 paragraph 2 of the GDPR. With regard to the breach of Article L. 34-5 of the GDPR, the restricted committee considers
    69 KB (11,007 words) - 17:10, 6 December 2023
  • Protection Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned
    26 KB (3,862 words) - 17:41, 25 June 2022
  • APD/GBA (Belgium) - 15/2021 (category Article 5(2) GDPR)
    Internal Rules and Article 93 of the LCA, concerning morespecifically the articulation between article 15.4 of the GDPR and recital 63 of the GDPR, as well asbalancing
    85 KB (13,724 words) - 16:52, 12 December 2023
  • AEPD (Spain) - PS/00139/2020 (category Article 5(1)(a) GDPR)
    violation of Article 5(1)(d) of the GPRS, in relation to Article 4(1) of the LOPDGDD, which governs the principle of accuracy of personal data. IV Article 72.1
    20 KB (3,086 words) - 14:04, 13 December 2023
  • Datatilsynet (Norway) - 20/01626 (category Article 5(1)(a) GDPR)
    processing as per Article 5(1)(b), nor legal grounds as per Article 6. In sum, the DPA found that NIF had breached Article 5(1)(a), (c) and (f), Article 6, and Article
    50 KB (8,081 words) - 18:52, 5 March 2022
  • APD/GBA (Belgium) - 75/2023 (category Article 6(1)(f) GDPR)
    Authority. II.5.2. Established infringement of Article 5(1)(a) j° Article 6(1)(f) and Article 12(2) GDPR in conjunction with Article 17 (1) GDPR. II.5.2.1. Administrative
    77 KB (11,604 words) - 08:55, 29 June 2023
  • AEPD (Spain) - PS/00197/2020 (category Article 5(1)(b) GDPR)
    Articles 6(1)(b), 5(1)(b) and 5(1)(c) GDPR? The Spanish DPA (AEPD) deemed itself competent under Article 58(2) GDPR in conjunction with Article 47 of the Spanish
    129 KB (21,793 words) - 14:09, 13 December 2023
  • AEPD (Spain) - EXP202209175 (category Article 13 GDPR)
    party, for the alleged violation of Article 5.1.c) of the RGPD and Article 13 of the RGPD, typified in Article 83.5 of the RGPD. C/ Jorge Juan, 6 www.aepd
    17 KB (2,368 words) - 13:28, 13 December 2023
  • AEPD (Spain) - PS/00048/2021 (category Article 5 GDPR)
    Articles 5 and 6 GDPR? The AEPD held that publishing personal data on Twitter without the consent of the claimant is a violation of Article 6 GDPR, due to
    17 KB (2,458 words) - 13:51, 13 December 2023
  • APD/GBA (Belgium) - 38/2021 (category Article 5 GDPR)
    DPA under Article 100 § 1, 6, 10 and 12 of the LCA. The complainant y also denounces a breach of Article 5.1. c) and Article 5.1. e) of the GDPR. 18. The
    73 KB (11,604 words) - 16:57, 12 December 2023
  • AP (The Netherlands) - 4.02.2021 (category Article 8 GDPR)
    which the factors mentioned in article 7 give rise to this. Article7.Relevant factors Without prejudice to articles 3:4 and 5:46 of the General Law, administrative
    57 KB (8,053 words) - 17:07, 12 December 2023
  • CNPD (Portugal) - Deliberação 2022/140 (category Article 5(1)(e) GDPR)
    violation of Article 5(1)(f) GDPR and a fine of €100,000 for the violation of Article 37 GDPR. The DPA issued a reprimand for the violations of Article 5(1)(e)
    75 KB (12,306 words) - 10:02, 21 December 2022
  • Gerechtshof Amsterdam - 200.251.466/01 (category Article 21 GDPR)
    request under Article 21 GDPR can be made at any time and several times. It also found that a provisional measure can be granted under Article 21 GDPR if an urgent
    19 KB (3,021 words) - 15:48, 15 March 2022
  • CE - N° 433311 (category Article 5(1)(e) GDPR)
    company for faulty website security (article 32 GDPR) and violation of the storage limitation principle (article 5(1)(e) GDPR). After a complaint in 2018, the
    18 KB (2,677 words) - 09:50, 10 September 2021
  • Persónuvernd (Island) - 2022020363 (category Article 5 GDPR)
    and thus failed to fulfil its obligations under Article 5(1) GDPR, Article 24(1) GDPR and Article 28(1) GDPR. Second, the DPA found that, since the data processing
    142 KB (22,881 words) - 12:42, 16 January 2024
  • APD/GBA (Belgium) - 46/2024 (category Article 5(1)(b) GDPR)
    complied with the obligation of transparency (Article 5.1 a) GDPR in conjunction with Article 12.1 GDPR) because not only the privacy statement was updated
    46 KB (7,313 words) - 10:11, 16 May 2024
  • APD/GBA (Belgium) - 145/2023 (category Article 4(1) GDPR)
    with Article 4 WOG. 17. First, it is clear that the content of the disputed e-mail messages constitute personal data within the meaning of Article 4.1. AVG
    39 KB (6,247 words) - 09:14, 15 November 2023
  • with art. 5 and 6 of the GDPR? The DPA held that Regione Campania violated art 5(1)(a)(c), art. 6(1)(c)(e), art. 6(2) and art. 6(3)(b) GDPR, and concluded
    27 KB (4,339 words) - 15:50, 6 December 2023
  • AEPD (Spain) - PS/00262/2020 (category Article 5(2) GDPR)
    (hereinafter, LPACAP), for the alleged violation of Article 6.1 of the RGPD, typified in Article 83.5 a) of the RGPD. FOURTH: Once the aforementioned commencement
    22 KB (3,293 words) - 14:23, 13 December 2023
  • AEPD (Spain) - PS/00028/2022 (category Article 5(1)(f) GDPR)
    hereinafter, LPACAP), for the alleged infringement of Article 6.1 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned start-up
    58 KB (9,301 words) - 12:39, 13 December 2023
  • UODO (Poland) - ZSPR.421.3.2018 (category Article 4(1) GDPR)
    pursuant to this Article in respect of the infringement of this Regulation referred to in paragraphs 4, 5 and 6 of the above Article shall in each individual
    52 KB (8,444 words) - 10:01, 17 November 2023
View ( | ) (20 | 50 | 100 | 250 | 500)