Search results

From GDPRhub
  • Article 32 GDPR (category GDPR Articles) (section (1) Measures appropriate to the risk)
    non-material damage. Article 32(1) GDPR reflects the principle of integrity and confidentiality enshrined in Article 5(1)(f) GDPR. The controller and the
    41 KB (5,197 words) - 12:17, 17 April 2024
  • requirements of data minimization (Article 5(1)(c) GDPR) and storage limitation (Article 5(1)(e) GDPR). Under Article 30(1)(f) GDPR, where possible, the controller
    31 KB (3,327 words) - 15:31, 5 June 2023
  • (e.g. Article 25 (1) and (2), Article 28(1), Article 32(1) GDPR, Article 89(1) GDPR). These measures can also be regarded as measures under Article 24(1)
    30 KB (3,458 words) - 10:31, 25 April 2024
  • limited to, security of processing (Article 32(1) GDPR) and the general principles of processing set out in Article 5 GDPR. In confirming the above interpretation
    20 KB (1,854 words) - 16:32, 8 March 2024
  • Article 82 GDPR (category GDPR Articles) (section (1) Right to receive compensation)
    specific rules. Article 82 GDPR introduces a right to compensation for damage caused as a result of an infringement of the GDPR. Article 82(1) contains the
    33 KB (4,215 words) - 09:57, 19 March 2024
  • Ordinance Article 5, paragraph Article 5 (2) 1, letter c and letter f., Article 5, paragraph Article 6 (1) (a) Article 32 (1), (1), (33) 1 and 35, para. 1. Below
    48 KB (7,442 words) - 10:24, 12 September 2022
  • CNIL (France) - SAN-2019-005 (category Article 32(1) GDPR)
    violates Article 32 GDPR. Retaining personal data of an applicant for a lease after another applicant has been selected also violates Article 5(1)(e) GDPR
    41 KB (6,558 words) - 17:09, 6 December 2023
  • to the data. The infringement of Article 32 of the GDPR led to a €10,000 fine (RON 48,748). The infringement of Article 3 of Law 506/2004 led to a fine
    7 KB (900 words) - 15:18, 13 December 2023
  • least one of the conditions set out in Article 6(1) GDPR? On the topic of non-material damages 4) Does Article 82(1) GDPR have a specific or general preventive
    14 KB (1,916 words) - 16:03, 2 February 2024
  • Article 4 GDPR (category GDPR Articles) (section (1) Personal data)
    required under the GDPR (e.g. from a security perspective under Article 32 GDPR or as a means of data minimisation under Article 5(1)(c) GDPR) can get confused
    125 KB (16,328 words) - 16:01, 8 March 2024
  • AP (The Netherlands) - 26.11.2020 (category Article 32(1) GDPR)
    pursuant to article 32(1) of the GDPR. The AP disagrees. The conclusion of the AP that OLVG does not comply with article 32(1) of the GDPR by not meeting
    67 KB (11,415 words) - 17:15, 12 December 2023
  • UODO (Poland) - ZSPR.421.2.2019 (category Article 32(1)(b) GDPR)
    (f), Article 5(2), Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), Article 32(1)(c) and Article 32(1)(b), Article 32(1)(c) and
    71 KB (11,304 words) - 10:01, 17 November 2023
  • AEPD (Spain) - EXP202201721 (category Article 32(1) GDPR)
    violated Article 6 and Article 32 GDPR. The DPA seems to consider the authentication procedure itself as "processing" and therefore Article 32 GDPR applies
    79 KB (12,408 words) - 13:24, 13 December 2023
  • Datatilsynet (Denmark) - 2021-442-12980 (category Article 32(1) GDPR)
    In an Article 60 GDPR procedure, the Danish DPA reprimanded Danske bank for a violation of Article 32(1) GDPR. A technical error resulted in the unauthorised
    10 KB (1,214 words) - 11:39, 22 March 2024
  • ANSDPCP (Romania) - Fan Courrier Express SRL (category Article 32(1) GDPR)
    fined € 11.000 Fan Courrier Express SRL for violations of f Article 32 paragraphs (1) and (2) GDPR. The controller Fan Courrier Express SRL was sanctioned
    3 KB (197 words) - 15:10, 13 December 2023
  • AEPD (Spain) - PS/00064/2021 (category Article 32(1) GDPR)
    constituted a data breach and were therefore a violation of Article 32(1), and additionally Article 5(1)(f) for violating the confidentiality principle. The AEPD
    2 KB (174 words) - 13:55, 13 December 2023
  • Finnish DPA found a healthcare provider to have breached Article 32(1) GDPR and Article 32(2) GDPR for not implementing appropriate technical and organisational
    14 KB (1,978 words) - 16:09, 21 February 2024
  • AZOP (Croatia) - Decision 22-02-2021 (category Article 32(1)(b) GDPR)
    Jurisdiction: Croatia Relevant Law: Article 32(1)(b) GDPR Article 32(1)(d) GDPR Article 32(2) GDPR Article 32(4) GDPR Type: Complaint Outcome: Upheld Started:
    2 KB (197 words) - 15:52, 30 October 2023
  • level of security appropriate to the risk of processing according to Article 32(1) GDPR? The ANSPDCP found that the controller did not implement adequate
    5 KB (547 words) - 15:18, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.029 (category Article 32(1) GDPR)
    Commissioner held that CYTA violated articles 5 (1), 24 (1) and (2), 25 (1) and (2) and 32 of the GDPR and instructed CYTA to establish such security measures
    3 KB (193 words) - 16:52, 6 December 2023
  • regarding the security of processing, respectively art. 32 para. (4) in conjunction with art. 32 para. (1) and para. (2) of the General Data Protection Regulation
    4 KB (422 words) - 15:16, 13 December 2023
  • Datatilsynet (Norway) - 20/02137 (category Article 32(1) GDPR)
    Norge violated Article 33 GDPR by failing to notify the Datatilsynet of the data breach? Had Telenor Norge violated Article 32(1) GDPR by failing to implement
    5 KB (684 words) - 08:06, 7 May 2022
  • that the controller had breached its obligations under Articles 5(1)(f), as well as 32(1) and (2). As a consequence, the ANSPDCP issued an administrative
    4 KB (422 words) - 15:20, 13 December 2023
  • Datatilsynet (Denmark) - 2021-431-0138 (category Article 32(1) GDPR)
    there was a personal data breach pursuant to Article 4(12) GDPR. Moreover, it stated that Article 32(1) GDPR obliges controllers to take appropriate technical
    16 KB (2,496 words) - 15:23, 24 March 2022
  • Commissioner (Cyprus) - 11.17.001.007.251 (category Article 32(1)(b) GDPR)
    reason, claimed that she shall receive the medical report under the veil of GDPR. The Cypriot Office of the Commissioner for Personal Data Protection disagreed
    4 KB (448 words) - 16:52, 6 December 2023
  • concluded that the controller violated Article 32(1)(b), Article 32(1)(d), Article 32(2), and Article 32(4) GDPR. Therefore, the DPA decided to impose a
    6 KB (730 words) - 15:49, 30 October 2023
  • DPC - Health Service Executive (IN-19-9-2) (category Article 32(1) GDPR)
    garden. The decision found that the HSE infringed Articles 5(1)(f) and 32(1) of the GDPR by failing to implement appropriate technical and organisational
    3 KB (240 words) - 09:18, 3 March 2021
  • Datatilsynet (Denmark) - 2021-442-12425 (category Article 32(1) GDPR)
    in accordance with the rules in the Data Protection Regulation [1], Article 32 (1). 1. Below is a more detailed review of the case and a justification
    15 KB (2,304 words) - 15:24, 24 March 2022
  • AZOP (Croatia) - Decision 05-07-2021 (category Article 32(1)(b) GDPR)
    activities further violated Article 32(1)(b) and (d) GDPR. Accordingly, the DPA, in accordance with its powers under Article 58 (2) GDPR, imposed an administrative
    5 KB (599 words) - 15:38, 30 October 2023
  • provisions of Article 32 paragraph (4) in conjunction with Article 32 paragraph (1) and paragraph (2) of the GDPR, as well as of Article 33 paragraph (1) of the
    5 KB (568 words) - 15:10, 13 December 2023
  • Commissioner (Cyprus) - Α/Π 68/2017 (category Article 32(1)(d) GDPR)
    that Cyprus Police was responsible for a violation of Article 32 par.1(b) & (d) and par.(4) GDPR, as a result of the acts and/or omissions of the Police
    6 KB (649 words) - 16:51, 6 December 2023
  • Romanian DPA (ANSPDCP) fined leasing company €15,000 for violation of Article 32(1) and (2) GDPR after investigating a data breach reported by the company, where
    6 KB (732 words) - 15:17, 13 December 2023
  • AEPD (Spain) - E/03003/2020 (category Article 32(1) GDPR)
    this data breach a violation of Article 32(1) GDPR? The AEPD concluded that there was no violation of Article 32(1) GDPR, because the company had implemented
    21 KB (3,039 words) - 13:39, 13 December 2023
  • €283,000). It held that the controller violated Articles 25(1), 32(1)(b), 32(1)(d) and 32(2) GDPR by not taking appropriate technical and organizational security
    7 KB (855 words) - 15:30, 30 October 2023
  • violated Article 5(1)(f) GDPR and proved the ineffectivness of the controller's employee compliance training, in violation of Article 32 GDPR. The DPA
    7 KB (845 words) - 15:17, 13 December 2023
  • VDAI - VDAI vs VĮ Registrų centras (category Article 32(1)(b) GDPR)
    SE Register Center 15 thousand. A fine of EUR 1 million was imposed for infringements of Article 32 (1) (b) and (c) of the BDAR, ie failure to ensure
    8 KB (999 words) - 09:16, 17 November 2023
  • IMY (Sweden) - DI-2021-4355 (category Article 32(1) GDPR)
    6 November 2020, has processed personal data in violation of Article 32(1) 1 of the GDPR by sending sensitive personal data to the complainant in an e-mail
    28 KB (3,101 words) - 09:49, 7 June 2023
  • AEPD (Spain) - PS/00054/2021 (category Article 32(1) GDPR)
    infringement of article 32.1 of the RGPD, typified in article 83.4.a) of the RGPD, a fine of € 3,000 (three thousand euros), in accordance with article 73.g) of
    27 KB (3,993 words) - 13:52, 13 December 2023
  • AP (The Netherlands) - 19.01.2023 (category Article 32(1) GDPR)
    assessed if it ensured an appropriate level of security under Articles 32(1) and 32(2) GDPR. The DPA held that the controller did not make a proper risk assessment
    10 KB (1,351 words) - 17:05, 12 December 2023
  • VDAI (Lithuania) - VDAI vs UAB Prime Leasing (category Article 32(1)(a) GDPR)
    data. Hence, it considered Article 32(1)(a), Article 32(1)(b), Article 32(1)(d) GDPR to be breached. Pursuant to Article 82(2) GDPR, the DPA took several aggravating
    37 KB (4,319 words) - 09:20, 17 November 2023
  • AZOP (Croatia) - Decision 04-05-2023 (category Article 32(1) GDPR)
    organizational measures when processing personal data, as requested by Article 32(1)(b) and (d) GDPR. This implied a risk for the security of the personal data of
    12 KB (1,626 words) - 15:22, 30 October 2023
  • implement sufficient security measures, in breach of Articles 32 (1) b), d) and 32 (2) GDPR. NN Pensii Societate de Administrare a unui Fond de Pensii Administrat
    8 KB (1,064 words) - 08:35, 31 May 2023
  • AZOP (Croatia) - Decision 26-09-2023 (category Article 32(1) GDPR)
    accomodation via its web form and via e-mail, acting contrary to Article 13(1) GDPR and Article 13(2) GDPR. Further, the AZOP held that the controller failed to adopt
    12 KB (1,634 words) - 17:02, 6 November 2023
  • IMY (Sweden) - DI-2019-9457 (category Article 32(1) GDPR)
    administrative bodies, researchers and physicians in violation of Article 32(1) GDPR. Uppsala regional authorities notified the Swedish DPA (Integritetsskyddsmyndigheten
    43 KB (4,600 words) - 17:08, 23 March 2022
  • AEPD (Spain) - PS/00464/2020 (category Article 32(1) GDPR)
    data is regulated in articles 32, 33 and 34 of the GDPR. Article 32 of the RGPD "Security of treatment", establishes that: "1. Taking into account the state
    29 KB (4,300 words) - 14:41, 13 December 2023
  • LG München - 31 O 16606/20 (category Article 32(1) GDPR)
    subject pursuant to Article 82(1) GDPR, for a theft of their personal identity and financial data, because it violated Article 32(1) GDPR which led to a data
    25 KB (4,028 words) - 07:10, 8 February 2022
  • judicial remedy against the controller under Article 79(1) GDPR. Having said that, Article 32(1) and (2) GDPR make it clear that national courts must assess
    13 KB (1,963 words) - 11:04, 5 January 2024
  • Datatilsynet (Denmark) - 2019-431-0044 (category Article 32(1) GDPR)
    personal data did not comply with the rules of Article 5 (1) of the Data Protection Regulation. 1 (f) and Article 32 (1) of the Data Protection Regulation. First
    16 KB (2,399 words) - 16:34, 6 December 2023
  • AEPD (Spain) - E/07796/2020 (category Article 32(1) GDPR)
    certain level of security. Therefore, they did not find a violation of Article 32(1) and decided not to fine the controller. Share your comments here! Share
    18 KB (2,698 words) - 13:41, 13 December 2023
  • AEPD (Spain) - PS/00104/2020 (category Article 32(1) GDPR)
    violation of articles 5.1.f, of the RGPD -as set out in Article 83(5)(a) of the said regulation and 5(1)(f) in relation to Article 32(1)(b) and (c) - specified
    36 KB (6,022 words) - 13:59, 13 December 2023
  • Datatilsynet (Norway) - 19/02985 (category Article 32(1)(b) GDPR)
    implemented sufficient technical and organisational measures pursuant to Article 32 GDPR in relation to the leakage of pupils personal data to third-parties
    3 KB (253 words) - 18:52, 5 March 2022
  • could not be considered appropriate in accordance with Article 32(1) GDPR and Article 32(2) GDPR regarding the online appointment booking system. As a result
    25 KB (3,734 words) - 19:37, 27 March 2024
  • LG Bonn - 29 OWi 1/20 (category Article 32(1) GDPR)
    83(4)(a) GDPR in conjunction with [Article 32(1) GDPR. Article 32 (1) GDPRby failing, at least with gross negligence, to ensure processes for sufficient authentication
    58 KB (9,577 words) - 08:06, 16 September 2021
  • Datatilsynet (Denmark) - 2020-442-8866 (category Article 32(1) GDPR)
    of for shredding. 4.1. Article 32 of the Data Protection Regulation Pursuant to Article 32 (1) of the Data Protection Regulation 1, the data controller
    20 KB (3,045 words) - 16:40, 6 December 2023
  • ANSPDCP (Romania) - SC Medicover SRL (category Article 32(1)(b) GDPR)
    address. The Romanian DPA found a violation of Article 32(1)(b), Article 32(2) and Article 32(4) of the GDPR and fined SC Medicover SRL €2,000. Share your
    5 KB (575 words) - 15:21, 13 December 2023
  • ANSPDCP (Romania) - 04.01.2023 (category Article 32(1)(b) GDPR)
    violation of Article 32 GDPR, the "Security of processing". More specifically, the controller violated Article 32(1)(b), 32(2), and 32(4) GDPR. For its breaches
    4 KB (471 words) - 15:15, 13 December 2023
  • violating Article 32 GDPR. The DPA took also the corrective measure to order the operator to bring its processing operations into compliance with the GDPR according
    4 KB (456 words) - 15:18, 13 December 2023
  • Datatilsynet (Norway) - 20/01984 (category Article 32(1)(b) GDPR)
    breach of Article 32? The DPA concluded that the municipality had breached the required information security requirements as per Article 32(1)(b), cf. Article
    6 KB (653 words) - 18:55, 5 March 2022
  • Datatilsynet (Norway) - 18/02579 (category Article 32(1)(b) GDPR)
    subsequent violations of Article 32(1)(b) GDPR and Article 32(1)(d) GDPR and of the principle of accountability as foreseen in Article 5(2) GDPR read in conjunction
    41 KB (6,337 words) - 18:52, 5 March 2022
  • Datatilsynet (Denmark) - 2020-31-4131 (category Article 32(1) GDPR)
    the rules on e.g. data protection. It follows from Article 32 (1) of the Data Protection Regulation 1, that data controllers and data processors, taking
    24 KB (3,651 words) - 16:38, 6 December 2023
  • ANSPDCP (Romania) - 12.01.2023 (category Article 32(1)(b) GDPR)
    data. Hence, the controller violated Articles 32(1)(b) and 32(2) GDPR. Pursuant to its Article 58(2) GDPR statutory powers, the DPA ordered the controller
    5 KB (613 words) - 15:13, 13 December 2023
  • IMY (Sweden) - DI-2021-5595 (category Article 32(1) GDPR)
    of approximately €150,000 (1,600,000 SEK) on the University Hospital Board for the violation of Articles 5(1)(f) and 32(1) GDPR. The data breach notification
    47 KB (5,207 words) - 18:51, 21 March 2022
  • ANSPDCP (Romania) - 27.12.2022 (category Article 32(1)(b) GDPR)
    would have been required by Article 29 GDPR. Moreover, in violation of Article 32(1)(b), Article 32(2), and Article 34(4) GDPR, the controller had not implemented
    6 KB (790 words) - 15:13, 13 December 2023
  • CNIL (France) - SAN-2020-015 (category Article 32(1) GDPR)
    obligation of Article 32 GDPR? Does the fact that this health data is not encrypted constitute a breach of the security obligation under Article 32 GDPR? Does
    29 KB (4,374 words) - 16:03, 19 January 2024
  • AEPD (Spain) - PS/00287/2020 (category Article 32(1) GDPR)
    Online Levante, S.L.: for the infringement of Article 5(1)(f), €2,000. for the infringement of Article 32(1), €1,000. Share your comments here! Share blogs
    32 KB (4,837 words) - 14:26, 13 December 2023
  • AEPD (Spain) - PS/00483/2020 (category Article 32(1) GDPR)
    Asesoria Alpi Clua: for the infringement of Article 5(1)(f), €2,000. for the infringement of Article 32(1), €1,000. Share your comments here! Share blogs
    32 KB (4,834 words) - 14:43, 13 December 2023
  • UODO (Poland) - DKN.5130.2815.2020 (category Article 32(1) GDPR)
    and Article 58(2)(b) in connection with Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1) and (2) of 2 of Regulation EU 2016/679 of the European
    37 KB (5,819 words) - 09:58, 17 November 2023
  • Articles 5(1)(a), (d) and (f), 9 and 32(1)(b) GDPR.” Pursuant to Article 58(2)(i), the DPA hence imposed an administrative fine as per Article 83(4) and
    10 KB (1,206 words) - 15:54, 6 December 2023
  • CNPD (Portugal) - Deliberação 984/2018 (category Article 32(1)(b) GDPR)
    the combined provisions of article 32, paragraph 1, subparagraphs b) and d) and article 83, paragraph 4, al.a), of the GDPR, with a fine of € 0.00 to €
    40 KB (5,935 words) - 16:55, 6 December 2023
  • Datatilsynet (Norway) - 20/01879 (category Article 32(1)(b) GDPR)
    highly sensitive personal data exposed, thus breaching Article 32(1)(b) GDPR and Article 32(2), cf. Article 24. An employee in a municipal health care center
    30 KB (4,302 words) - 18:53, 5 March 2022
  • LfDI (Baden-Württemberg) - O 1018/115 (category Article 32(1)(a) GDPR)
    for infringement of Article 32 (1) lit. a DSGVO [German Penal Code]. (Storage of unhashed passwords) here: Fine notice Enclosure: 1 transfer form, cash
    13 KB (1,926 words) - 10:22, 17 November 2023
  • Datatilsynet (Denmark) - 2020-432-0037 (category Article 32(1) GDPR)
    life and health. 5.1. Article 32 of the Data Protection Regulation It follows from Article 32 (1) of the Data Protection Regulation 1, that the data controller
    46 KB (7,343 words) - 16:39, 6 December 2023
  • (possible) fraud. This resulted in a breach of Article 5(1)(a) GDPR and Article 6(1) GDPR in conjunction with Article 8 of the Dutch Personal Data Protection
    49 KB (7,201 words) - 17:06, 12 December 2023
  • considered appropriate in accordance with Article 31(1)(b) GDPR and Article 32(2) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to identify
    17 KB (2,339 words) - 13:39, 12 January 2024
  • controller had violated Article 5(1)(f) GDPR, Article 17(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR. As a result, the DPA issued
    56 KB (8,980 words) - 08:47, 4 March 2024
  • AEPD (Spain) - EXP202104875 (category Article 32(1) GDPR)
    A., with NIF A28157360, for a violation of article 32.1 of the GDPR, typified in article 83.4, a) of the GDPR, with a fine of €40,000 (forty thousand euros)
    54 KB (8,451 words) - 13:35, 13 December 2023
  • Court of Appeal of Brussels - 2020/AR/1333 (category Article 32(1) GDPR)
    5- □ 1-i; -J L ..J Brussels-2020 Court of Appeal / AR / 1333 p. 3 breach of articles 5.1.a} and 5.1.b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the GDPR read
    51 KB (7,792 words) - 11:43, 24 January 2022
  • Datatilsynet (Norway) - 20/01516 (category Article 32(1)(b) GDPR)
    title of documents containing sensitive information was a breach of Article 32(1)(b) GDPR, highlighting that the breach was reported to the municipality by
    26 KB (3,885 words) - 08:43, 7 May 2022
  • AP (The Netherlands) - 23.09.2021 (category Article 32(1) GDPR)
    which led to a (sensitive) data breach, in violation of Article 32(1) and Article 32(2) GDPR In Oktober 2019, a malicious third party gained unauthorized
    66 KB (8,861 words) - 17:08, 12 December 2023
  • Datatilsynet (Norway) - 20/02191 (category Article 32(1)(b) GDPR)
    processing special categories of data, cf. Article 32(1)(b) GDPR, Article 32(1)(d), Article 24 and Article 35, cf. Article 5. In May 2019, a municipality reported
    38 KB (5,967 words) - 11:48, 7 May 2022
  • Datatilsynet (Norway) - 20/02147 (category Article 32(1)(b) GDPR)
    the lack of security routines, thus breaching Article 32(1)(b) cf. Article 5 GDPR, Article 35 and Article 24(1), respectively. Teachers at two junior high
    24 KB (3,591 words) - 18:57, 5 March 2022
  • CNIL (France) - SAN-2020-003 (category Article 32(1) GDPR)
    principle, namely the breaches of articles 5-1-c), 5 -1 e), 13, 32 and 35-1 of the GDPR; no breach of Article 6 of the GDPR and of Directive 2002/58 / EC of the
    61 KB (10,028 words) - 17:09, 6 December 2023
  • UODO (Poland) - DKN.5130.1354.2020 (category Article 32(1)(b) GDPR)
    expressed in Article 5 (1 ) (a)) f, and reflected in the obligations set out in Article 24 (1), Article 25 (1), Article 32 (1 ) (b ) and (d) and Article 32 (2)
    74 KB (11,513 words) - 09:58, 17 November 2023
  • UODO (Poland) - DKN.5130.2024.2020 (category Article 32(1) GDPR)
    provisions of Regulation art. 5 sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and 3 and article. 32 sec. 1 and 2. In addition, by letters of
    75 KB (12,104 words) - 09:58, 17 November 2023
  • AEPD (Spain) - PS/00179/2020 (category Article 32(1) GDPR)
    as established in article 5 of the GDPR. The security of personal data is regulated in articles 32, 33 and 34 of the GDPR. III The GDPR defines personal
    100 KB (16,401 words) - 14:07, 13 December 2023
  • UODO (Poland) - DKN.5101.25.2020 (category Article 32(1)(d) GDPR)
    with Art. 5 sec. 1 lit. f, art. 24 sec. 1, art. 25 sec. 1, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 33 paragraph. 1 and art. 34 sec. 1 of the Regulation
    63 KB (10,088 words) - 09:52, 17 November 2023
  • NAIH (Hungary) - NAIH/2020/66/21 (category Article 32(1)(b) GDPR)
    regard to Client 1 that data management - infringed Article 25 (1) to (2) of the General Data Protection Regulation, - infringed Article 32 (1) (b) of the General
    67 KB (10,492 words) - 10:11, 17 November 2023
  • UODO (Poland) - ZSOŚS.421.25.2019 (category Article 32(1)(b) GDPR)
    5 sec. 1 lit. f, art. 5 sec. 2, art. 25 sec. 1, art. 32 sec. 1 lit. b, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 38 sec. 1, art. 39 sec. 1 lit. b and
    156 KB (25,012 words) - 10:01, 17 November 2023
  • Datatilsynet (Denmark) - 2018-423-0018 (category Article 5(1) GDPR)
    responsibility under Article 26 GDPR. Categories of data subjects and categories of personal data Pursuant to Article 30 (I) (1) (c) GDPR, a list must contain
    21 KB (3,119 words) - 16:22, 6 December 2023
  • ICO - Monetary Penalty on Ticketmaster UK Limited (category Article 32(1)(d) GDPR)
    failed to comply with the requirements of Article 32(1) and (2) GDPR. In particular: 6.12.1 Article 32(1)(b) GDPR required Ticketmaster to ensure the ongoing
    130 KB (21,195 words) - 13:52, 25 April 2021
  • AEPD (Spain) - EXP202105923 (category Article 5(1)(d) GDPR)
    controller violated Article 5(1)(d) GDPR ("accuracy"), but a more natural conclusion would be to find a violation of Article 32(1)(d) GDPR ("adoption of adequate
    26 KB (3,846 words) - 12:42, 13 December 2023
  • DPC (Ireland) - IN-20-7-1 (category Article 32(1) GDPR)
    measures when recording group sessions in violation of Article 5(1)(f) GDPR and Article 32(1) GDPR. The controller is Men Overcoming Violence Ireland ("MOVE")
    4 KB (352 words) - 10:00, 8 March 2022
  • Datatilsynet (Denmark) - 2021-423-0241 (category Article 32(1) GDPR)
    DPA found no violation of Article 32(1) GDPR. The elements that the DPA took into account to exclude the existence of a GDPR infringement were the following
    14 KB (1,916 words) - 12:07, 11 October 2023
  • Datatilsynet (Denmark) - 2021-423-0236 (category Article 32(1) GDPR)
    The Danish DPA found that the Høje-Taastrup Municipality violated Article 32(1) GDPR because it did not have guidelines or objective criteria in place
    13 KB (1,970 words) - 16:12, 22 March 2022
  • AP (The Netherlands) - 24.02.2022 (category Article 13(1)(e) GDPR)
    requirements of article 24 and 32, paragraph 1, AVG and further elaborated in article32, paragraph2, preamble, FISHOrdinancesBIO standards5.1.1,5.1.1.1and5.1.2.1.
    179 KB (22,957 words) - 17:07, 12 December 2023
  • Datatilsynet (Denmark) - 2021-31-5743 (category Article 32(1) GDPR)
    wall. The DPA held that the controller violated Article 32(1) GDPR. The obligation under Article 32(1) GDPR to implement appropriate technical and organisational
    16 KB (2,304 words) - 09:50, 7 September 2022
  • ANSPDCP (Romania) - Banca Comercială Română SA (category Article 32(1)(b) GDPR)
    This amounted to a violation of Article 25(1) GDPR, Article 32(1)(b) GDPR, Article 32(1)(d) GDPR, Article 32(2) GDPR. Consequently, the DPA fined the
    5 KB (558 words) - 08:06, 26 September 2022
  • ANSPDCP (Romania) - 24.10.2023 (category Article 32(1)(b) GDPR)
    Romanian DPA found that the controller had violated Articles 32(1)(b), 32(1)(d) and 32(2) GDPR, as they had failed to implement adequate technical and organisational
    4 KB (461 words) - 14:26, 6 November 2023
  • DPC (Ireland) - IN-21-6-2 (category Article 32(1) GDPR)
    implement appropriate technical and organisational measures pursuant to Article 32(1) GDPR applies equally to controllers and processors. As the Controller identified
    8 KB (1,091 words) - 09:46, 23 March 2023
  • IMY (Sweden) - DI-2021-4664 (category Article 32(1) GDPR)
    in Article 5 GDPR. One of these principles is the requirement of security under Article 5(1)(f) GDPR (‘integrity and confidentiality’). Article 32 GDPR
    21 KB (2,284 words) - 14:03, 9 November 2022
  • ANSPDCP (Romania) - 17-03-2023/2 (category Article 32(1) GDPR)
    encryption or pseudonymisation. As a result, it found a violation of Article 32(1) and 32(2) GDPR and imposed a fine of RON19,646 (approximately Є4,000). Share
    5 KB (619 words) - 15:41, 17 March 2023
  • ANSPDCP (Romania) - Fine to Farmacia Ardealul SRL (category Article 32(1)(b) GDPR)
    investigation. The DPA found that the controller had violated Article 32(1)(b), (d) and 32(2) GDPR because they had not implemented adequate technical and organizational
    5 KB (572 words) - 09:37, 6 July 2023
  • ANSPDCP (Romania) - Fine against Condor SA (category Article 32(1) GDPR)
    data of its current and former employees, in violation of Articles 32(1), (2) and (4) GDPR. A data subject filed a claim before the Romanian DPA (ANSPDCP)
    5 KB (598 words) - 15:20, 30 March 2022
  • security. The DPA therefore held that the controller violated Article 32(1)(b), (c) and 32(2) GDPR. The DPA fined the controller approximately €5,000 (24,566
    5 KB (623 words) - 15:12, 28 September 2022
  • ANSPDCP (Romania) - 26.09.2023 (category Article 32(1)(b) GDPR)
    violations of Articles 32(1)(b) and 32(1)(d) GDPR, as well as a breach of Article 4(5) of Law 506/2004. In regards to Article 32 GDPR, the DPA found that
    5 KB (543 words) - 14:07, 18 October 2023
  • DPC - Tusla Child and Family Agency (category Article 32(1) GDPR)
    infringements of Article 32(1) and Article 33(1). * The DPC ordered Tusla to bring its processing operations into compliance with Article 32(1) of the GDPR by implementing
    6 KB (761 words) - 21:06, 24 February 2021
  • Datatilsynet (Denmark) - 2020-442-8099 (category Article 32(1) GDPR)
    not taken place in accordance with the rules in Article 32 (1) of the Data Protection Regulation [1]. 1. Below is a more detailed review of the case and
    16 KB (2,376 words) - 13:19, 18 May 2022
  • ICO (UK) - Nottinghamshire County Council (category Article 32(1) GDPR)
    reprimanded Nottinghamshire County Council under Article 58(2)(b) (UK) GDPR, for infringing Article 32(1) (UK) GDPR. Share your comments here! Share blogs or
    10 KB (1,349 words) - 13:54, 25 October 2023
  • DPC (Ireland) - DPC ref: IN-20-4-1 (category Article 32(1) GDPR)
    fined a teaching council €60,000 for violations of Articles 5(1)(f), 32(1) and 33(1) GDPR by failing to notify a data breach in due time, and lacking appropriate
    5 KB (602 words) - 08:39, 3 March 2022
  • ANSPDCP (Romania) - Fine against Bitfactor SRL (category Article 32(1)(b) GDPR)
    laid down in Article 5(1)(f) GDPR. In this context, the DPA referred to Article 25(1) GDPR (data protection by design) and Recital 78 GDPR. As a result
    6 KB (708 words) - 08:12, 6 October 2022
  • DPC (Ireland) - Meta Platforms (category Article 32(1) GDPR)
    Meta Platforms complied with the requirements of Articles 5(1)(f), 5(2), 24(1) and 32(1) GDPR in relation to the processing of personal data relevant to
    5 KB (572 words) - 08:47, 11 October 2022
  • measures. The DPA therefore held that the controller violated Article 32(1) and (2) GDPR and fined the controller €20,000. The Romanian DPA only publishes
    6 KB (679 words) - 14:38, 29 November 2022
  • Datatilsynet (Denmark) - 2022-441-12449 (category Article 32(1) GDPR)
    relatively high. 4.1. Article 32 of the Data Protection Regulation It follows from the data protection regulation article 32, subsection 1, that the data controller
    18 KB (2,636 words) - 15:38, 31 August 2022
  • Datatilsynet (Denmark) - 2021-442-14071 (category Article 32(1) GDPR)
    with the rules in the data protection regulation[1] article 32, subsection 1 and Article 33, subsection 1. Below follows a closer review of the case and
    17 KB (2,465 words) - 14:29, 27 July 2022
  • by UCD infringe Articles 5(1)(f)- 5(1)(e) and 33(1) GDPR? The DPC held that UCD infringed: - Articles 5(1)(f) and 32(1) GDPR by failing to process personal
    5 KB (626 words) - 16:35, 28 October 2021
  • Datatilsynet (Denmark) - 2019-431-0037 (category Article 28(1) GDPR)
    municipalities has not complied with Article 28 (1) of the Data Protection Ordinance. Article 32 (3) (f), in accordance with Article 32, as the company has not implemented
    18 KB (2,710 words) - 16:34, 6 December 2023
  • NAIH (Hungary) - NAIH-2894-3/2021 (category Article 32(1)(a) GDPR)
    Jurisdiction: Hungary Relevant Law: Article 32(1)(a) GDPR Article 32(1)(b) GDPR Article 32(2) GDPR Article 33(1) GDPR Article 34(1) GDPR Type: Investigation Outcome:
    6 KB (656 words) - 09:33, 28 July 2021
  • Datatilsynet (Denmark) - 2021-431-0149 (category Article 32(1) GDPR)
    regulation, article 4, no. 12. 3.1. Article 32 of the Data Protection Regulation It follows from the data protection regulation article 32, subsection 1, that
    20 KB (3,122 words) - 09:25, 23 May 2023
  • BayLfD (Bavaria) - 221 C 578/22 (category Article 32(1) GDPR)
    enough level of protection pursuant to Article 32(1) GDPR, the data subject claimed damages pursuant to Article 82(1) GDPR. The controller argued to the contrary
    12 KB (1,617 words) - 10:31, 23 November 2022
  • Datatilsynet (Denmark) - 2021-423-0235 (category Article 32(1) GDPR)
    not taken place in accordance with the rules in Article 32 (1) of the Data Protection Regulation. 1. [1] Regulation (EU) 2016/679 of the European Parliament
    20 KB (2,922 words) - 12:53, 18 May 2022
  • Datatilsynet (Denmark) - 2021-431-0126 (category Article 32(1) GDPR)
    AULA itself. 3.1. Article 32 of the Data Protection Regulation It follows from the data protection regulation article 32, subsection 1, that the data controller
    21 KB (3,154 words) - 08:44, 14 September 2022
  • DPC (Ireland) - IN-21-2-5 (category Article 32(1) GDPR)
    to Article 5(1)(f) GDPR. Secondly, the technical and organisational measures taken to ensure security of processing pursuant to Article 32(1) GDPR. Thirdly
    13 KB (1,849 words) - 02:28, 23 February 2023
  • Datatilsynet (Denmark) - 2020-31-4326 (category Article 32(1) GDPR)
    down in Article 32(1) of the GDPR. The EDPS also finds grounds to order Joga to bring the processing of personal data into line with Article 32(1) of the
    13 KB (1,976 words) - 15:32, 10 November 2021
  • Datatilsynet (Denmark) - 2021-441-9489 (category Article 32(1) GDPR)
    not taken place in accordance with the rules in Article 32 (1) of the Data Protection Regulation [1]. 1. Below is a more detailed review of the case and
    12 KB (1,659 words) - 13:36, 6 July 2022
  • Datatilsynet (Denmark) - 2021-442-11601 (category Article 32(1) GDPR)
    accordance with the rules in Article 32 (1) of the Data Protection Regulation. 1 and Article 5, para. Article 5 (2) 1, letter f. [1] Regulation (EU) 2016/679
    11 KB (1,561 words) - 11:19, 8 April 2022
  • violated security obligations under GDPR by not encrypting a USB flash drive which contained personal data, and Article 33(1) GDPR by not reporting the data breach
    8 KB (1,031 words) - 13:32, 18 May 2022
  • Datatilsynet (Denmark) - 2021-431-0163 (category Article 32(1) GDPR)
    security numbers. 3.1. Article 32 of the Data Protection Regulation It follows from the data protection regulation article 32, subsection 1, that data controllers
    26 KB (3,912 words) - 10:46, 22 November 2023
  • Datatilsynet (Denmark) - 2021-431-0144 (category Article 32(1) GDPR)
    The Danish DPA reprimanded a processor for violating Article 32(1) GDPR by storing user passwords in plain text and allowing access to its system via single-factor
    21 KB (3,249 words) - 15:39, 31 August 2022
  • Datatilsynet (Denmark) - 2020-431-0115 (category Article 32(1) GDPR)
    violate the GDPR by using video surveillance on its premises. However, the DPA reprimanded the fitness centre for violating Article 32(1) GDPR by storing
    23 KB (3,372 words) - 07:34, 7 September 2022
  • without hiding the other recipients' email addresses, violating Article 32(1)(b) GDPR. SC Interactions Marketing SRL is a company providing Customer-R
    4 KB (458 words) - 14:38, 22 June 2022
  • Datatilsynet (Denmark) - 2020-442-8862 (category Article 32(1) GDPR)
    requirements of Article 34(2) and Article 33(3) GDPR. The DPA expressed serious criticism to the controller for violating Article 32(1) GDPR. Moreover, it
    24 KB (3,735 words) - 17:29, 23 February 2022
  • Datatilsynet (Denmark) - 2021-441-10210 (category Article 32(1) GDPR)
    in accordance with the rules in Article 32 (1) of the Data Protection Regulation [1]. Article 32 (1) and Article 24 (1) 1. Below is a more detailed review
    14 KB (1,992 words) - 20:39, 26 July 2022
  • Rb. Den Haag - SGR 20/1516 (category Article 32(1) GDPR)
    The Court went on to state that Article 32 GDPR cannot be considered as a completely open standard: Article 32(1) GDPR specifies technical and organizational
    14 KB (2,003 words) - 10:07, 10 September 2021
  • Datatilsynet (Denmark) - 2022-442-21566 (category Article 32(1) GDPR)
    former employees. 3.1. Article 32 of the Data Protection Regulation It follows from the data protection regulation article 32, subsection 1, that the data controller
    14 KB (2,130 words) - 08:15, 21 June 2023
  • IMY (Sweden) - DI-2019-3375 (category Article 32(1) GDPR)
    no legal basis. This was a breach of Article 5(1) GDPR, Article 6(3) GDPR, Article 9(1) GDPR and Article 9(3) GDPR as well as Swedish health care legislation
    15 KB (1,735 words) - 08:36, 29 July 2021
  • ICO (UK) - Ministry of Justice (1) (category Article 32(1) GDPR)
    following infringements of the UK GDPR: 1Article 5(1)(f) - Security and Article 32(1)(d) & (2) which state: Article 5(1)(f) Personal data shall be processed
    13 KB (1,758 words) - 23:34, 1 June 2023
  • Datatilsynet (Denmark) - 2021-442-12991 (category Article 32(1) GDPR)
    Agency's decision 3.1. Article 32 of the Data Protection Regulation It follows i.a. Article 32 (1) of the Data Protection Regulation 1, that the data controller
    12 KB (1,782 words) - 15:27, 11 May 2022
  • Datatilsynet (Norway) - 23/00708 (category Article 32(1) GDPR)
    with the GDPR, thus violating Article 32(1) GDPR and Article 32(2) GDPR, see also Article 5(2) GDPR, Article 24(1) GDPR and Article 24(2) GDPR, as well
    59 KB (8,718 words) - 14:50, 20 December 2023
  • ANSPDCP (Romania) - Raiffeisen Bank SA (category Article 32(1) GDPR)
    violating Article 32(4) jo Article 32(1) and (2) GDPR (security of processing). In addition, a fine of €5,000 for violating Article 25(1) GDPR (data protection
    14 KB (1,905 words) - 15:22, 29 November 2022
  • Datatilsynet (Denmark) - 2022-432-0079 (category Article 32(1) GDPR)
    recommended this. 3.1. Article 32 of the Data Protection Regulation It follows from the data protection regulation article 32, subsection 1, that the data controller
    20 KB (2,996 words) - 22:52, 5 July 2023
  • Datatilsynet (Denmark) - 2021-441-10244 (category Article 32(1) GDPR)
    accordance with the rules in the Data Protection Ordinance [1] Article 32 (1). 1 and Article 25, para. 1. Below is a more detailed review of the case and a justification
    19 KB (2,832 words) - 14:47, 27 July 2022
  • Datatilsynet (Denmark) - 2021-442-13989 (category Article 32(1) GDPR)
    security, cf. Article 4, no. 12 of the Data Protection Regulation. 3.1. Article 32 of the Data Protection Regulation It follows from Article 32 (1) of the Data
    16 KB (2,351 words) - 15:51, 1 June 2022
  • Datatilsynet (Denmark) - 2020-441-6990 (category Article 32(1) GDPR)
    accordance with the rules in Article 32 (1) of the Data Protection Regulation [1]. 1 and Article 24, para. Article 32 (1) 1. Below is a more detailed review
    18 KB (2,838 words) - 10:22, 20 October 2021
  • Datatilsynet (Denmark) - 2021-441-9356 (category Article 32(1) GDPR)
    Ordinance [1] Article 32 (1). 1. The Danish Data Protection Agency also finds that Coop Danmark A / S has acted in accordance with Article 33 (1) of the Data
    14 KB (2,142 words) - 12:58, 14 June 2022
  • Datatilsynet (Denmark) - 2023-432-0025 (category Article 32(1) GDPR)
    processing personal data in violation of Article 5(2) GDPR, Article 5(1)(f) GDPR, Article 24(1) GDPR and Article 32(1) GDPR. The DPA also requested the controller
    31 KB (4,795 words) - 15:40, 12 December 2023
  • Datatilsynet (Denmark) - 2021-432-0063 (category Article 32(1) GDPR)
    about one party to a proceeding with another party, in violation of Article 32(1) GDPR. The Agency of Family Law (the controller) is a public authority that
    35 KB (5,141 words) - 14:34, 28 September 2022
  • Persónuvernd (Iceland) - 2022020333 (category Article 32(1) GDPR)
    appropriate security of the personal data under Article 5(2) and 32(1) GDPR. Pursuant Article 58(2)(c) GDPR, it asked the data controller to take measures
    19 KB (2,799 words) - 13:19, 8 March 2023
  • Datatilsynet (Denmark) - Unknown (category Article 32(1) GDPR)
    was clear to the DPA that the principle of privacy by design under Article 25(1) GDPR had not been considered. Better testing of the platform before launching
    19 KB (2,823 words) - 13:59, 24 January 2024
  • Persónuvernd (Island) - 2023030483 (category Article 32(1) GDPR)
    DPA concluded that the controller acted in violation of Article 5(1)(f) GDPR and Article 32 GDPR. Share your comments here! Share blogs or news articles
    20 KB (3,159 words) - 11:04, 15 January 2024
  • ANSPDCP (Romania) - Vodafone România SA (category Article 32(1)(b) GDPR)
    Romania SA, the data controller, violation Article 29 GDPR, Article 32(1)(b) GDPR, Article 32(2) GDPR, Article 32(4) GDPR The DPA fined the data controller €2
    5 KB (600 words) - 18:47, 21 September 2022
  • ANSPDCP (Romania) - 13.11.2023 (category Article 32(1)(b) GDPR)
    in breach of Articles 32(1)(b), 32(2) and 32(4) GDPR. Firstly, the DPA held that the controller had breached Article 32(1)(b) GDPR (confidentiality, integrity
    6 KB (726 words) - 13:57, 22 November 2023
  • IMY (Sweden) - DI-2021-3422 (category Article 32(1) GDPR)
    email containing a file with personal data, resulting in a breach of Article 32(1) GDPR. The Swedish DPA received complaints alleging that on January 20 2021
    53 KB (6,098 words) - 10:26, 29 November 2023
  • Datatilsynet (Denmark) - 2021-31-4596 (category Article 32(1) GDPR)
    accordance with the rules in the Data Protection Ordinance [1], Article 32 (1). 1, and Article 33, para. 1. The Danish Data Protection Agency also finds grounds
    22 KB (3,525 words) - 12:17, 2 February 2022
  • ANSPDCP (Romania) - Realmedia Network SA (category Article 32(1)(b) GDPR)
    were impacted. The DPA held that the controller violated Articles 32(1)(b) and 32(2) GDPR for not implementing adequate technical and organizational measures
    5 KB (463 words) - 18:55, 14 September 2022
  • ANSPDCP (Romania) - Fine against IKEA ROMÂNIA SA (category Article 32(1)(b) GDPR)
    the confidentiality of the personal data, in breach of Article 32(1)(b) GDPR and Article 32(2) GDPR. The DPA emphasised, referring to recital 38, that children
    5 KB (673 words) - 08:46, 3 November 2021
  • Datatilsynet (Norway) - 21/03177 (category Article 32(1)(b) GDPR)
    under Article 32(1)(b) GDPR and Article 5 GDPR, and for having published personal data on their website without lawful grounds under Article 6 GDPR and Article
    7 KB (747 words) - 10:57, 20 May 2022
  • LG München I - 5 O 5853/22 (category Article 32(1) GDPR)
    organizational measures pursuant to Article 32 GDPR. The court held that the controller violated Article 32(1) GDPR, which requires appropriate technical
    31 KB (5,017 words) - 15:08, 20 October 2023
  • personal data from its clients through Whatsapp, in violation of Article 32(1)(b), (2) and (4) GDPR. The Ing Bank NV branch in Bucarest, as a controller, notified
    5 KB (512 words) - 15:01, 29 September 2023
  • Datatilsynet (Norway) - 20/02165 (category Article 32(1)(b) GDPR)
    Norwegian Health Records Act (pasientjournalloven) and Article 32(1)(b) and (d) GDPR (cf. Article 5 GDPR). The DPA fined Moss municipality NOK 500,000 (€47
    24 KB (3,436 words) - 07:38, 4 October 2021
  • Datatilsynet (Denmark) - 2021-441-9224 (category Article 32(1) GDPR)
    the information processed, cf. Article 5 (1) of the Data Protection Regulation. Article 32 (1) (d) and Article 32 (1) 1. When choosing a response, the
    23 KB (3,533 words) - 16:47, 1 June 2022
  • security and confidentiality for personal data, in breach of Article 32(1)(b) and Article 32(2) GDPR. The DPA further noted that the controller did not reply
    5 KB (555 words) - 12:40, 20 July 2022
  • ANSPDCP (Romania) - Valoris Center S.R.L. (category Article 32(1)(b) GDPR)
    Valoris did not fulfill its obligations laid down in Article 29, Article 32(1)(b), and Article 32(4) GDPR. Even if the employee of Valoris was not allowed
    5 KB (624 words) - 15:10, 15 December 2021
  • IDPC (Malta) - CPD/COMP/280/2023 (category Article 32(1)(b) GDPR)
    ensure appropriate safeguards according to Article 5(1)(f) GDPR. This is further regulated in Article 32(1) GDPR. The controller did not prove that they implemented
    15 KB (1,805 words) - 10:08, 13 November 2023
  • instructions, Article 32(4) GDPR. The controller also failed to implement necessary measures meant to ensure the confidentiality of data, Article 32(1)(b) GDPR
    8 KB (976 words) - 11:53, 19 November 2021
  • provisions of Article 32(1)(b) GDPR and Article 32(2) GDPR. The DPA fined the processor €2,000 for this data breach. Under the Article 58(2)(d) GDPR it was decided
    8 KB (948 words) - 16:44, 15 November 2022
  • ANSPDCP (Romania) - Alpha Bank România SA (category Article 32(1)(b) GDPR)
    pursuant to Article 32(4) and Article 29 GDPR. The DPA therefore held that the controller violated Article 29 and Article 32(1)(b), (2), and (4) GDPR and fined
    6 KB (707 words) - 12:43, 7 September 2022
  • LG Ravensburg - 2 O 228/22 (category Article 32(1) GDPR)
    meaning of Article 4 no. 7 of the GDPR.1,000 euros from Art. 82 (1) GDPR due to various violations of the GDPR. 22 1. The defendant violated Art. 32 (1) GDPR
    26 KB (4,057 words) - 13:39, 11 April 2024
  • Datatilsynet (Norway) - 20/03500 (category Article 32(1)(b) GDPR)
    two-factor authentication, thus breaching Article 32(1)(b) GDPR and Article 32(1)(d), cf. Article 5(1)(f) GDPR. For this, the DPA fined the Parliament about
    32 KB (4,520 words) - 12:01, 28 June 2022
  • result, the DPA held that the controller violated Article 29, Article 32(1)(b), and Article 32(2) GDPR. The DPA fined the processor €3,000 (RON 14,825.70)
    6 KB (676 words) - 06:36, 21 July 2022
  • IMY (Sweden) - IMY-2022-695 (category Article 32(1) GDPR)
    constituted special categories of data according to article 9(1) GDPR. According to Article 5(2) GDPR the data controller is responsible for implementing
    43 KB (5,076 words) - 09:32, 21 November 2023
  • data without a legal base, in breach of Article 32(1)(b), Article 32(2), Article 5(1)(a), and Article 6(1) GDPR. Following a data breach, the controller
    6 KB (708 words) - 17:20, 3 November 2021
  • NAIH (Hungary) - NAIH-2732-2-2023 (category Article 32(1)(b) GDPR)
    controller violated Article 5(1) GDPR in Article 24 GDPR and Article 25 GDPR, as well as Article 32(1)(b) GDPR and Article 32(2) GDPR, and instructed the
    9 KB (1,101 words) - 15:14, 26 April 2023
  • Datatilsynet (Denmark) - 2021-442-12924 (category Article 32(1) GDPR)
    security, cf. Article 4, no. 12 of the Data Protection Regulation. 3.1. Article 32 of the Data Protection Regulation It follows from Article 32 (1) of the Data
    29 KB (4,593 words) - 07:34, 11 April 2022
  • Datatilsynet (Norway) - 20/02144 (category Article 32(1) GDPR)
    appropriate level of security in accordance with Article 32 GDPR. One of the requirements under Article 32(1) GDPR is to identify risks associated with the processing
    38 KB (5,449 words) - 14:08, 18 January 2023
  • APD/GBA (Belgium) - 117/2021 (category Article 32(1) GDPR)
    decision that there is of infringements of Article 32(1), (2) and (4) of the GDPR and of 24(1) of the GDPR due to taking insufficient measures to ensure
    35 KB (4,931 words) - 12:59, 9 November 2021
  • Datatilsynet (Norway) - 20/02376 (category Article 32(1) GDPR)
    of personal data follow from Article 5 (1) of the Privacy Regulation. We refer to Article 5 (1) (a), (b), (c) and (f): 3 1. Personal data shall a) is processed
    38 KB (5,620 words) - 07:40, 4 October 2021
  • DPC - C-19-X-XXX Ryanair DAC - November 2020 (category Article 32(1) GDPR)
    of Art. 32(1) and (4) GDPR.” 32. Article 32 of the GDPR relates to the security of processing of personal data. More specifically, Article 32(1) of the
    35 KB (4,975 words) - 20:43, 5 May 2021
  • AEPD (Spain) - E/12707/2022 (category Article 32(1) GDPR)
    documentation. The Spanish DPA concluded that there was a breach of Article 5(1)(f) and 32(1) of the GDPR. The access to the third parties’ personal data constituted
    35 KB (5,522 words) - 14:57, 19 October 2023
  • Datatilsynet (Denmark) - 2021-423-0234 (category Article 32 GDPR)
    appropriate technical and organisational measures, as required by Article 32(1) GDPR, to ensure the proper administration of welfare. In summer 2021, the
    14 KB (2,094 words) - 11:21, 26 January 2022
  • AEPD (Spain) - PS/00388/2022 (category Article 32(1) GDPR)
    has not violated the article 15 of the GDPR, infringement typified in article 83.5 a) of the GDPR. IV. Secondly, article 32 of the GDPR "Security of treatment"
    72 KB (11,730 words) - 08:54, 19 July 2023
  • UODO (Poland) - DKN.5131.8.2022 (category Article 32(1) GDPR)
    the laptop theft, in breach of Article 32(1) GDPR. Moreover, the DPA found a violation of Articles 24(1) and 25(1) GDPR because the controller failed to
    48 KB (7,609 words) - 12:24, 23 November 2022
  • APD/GBA (Belgium) - 165/2023 (category Article 32(1) GDPR)
    violation of: 1. Article 5.1.f) and 5.2 of the GDPR, Article 24.1 of the GDPR, Article 25.1 of the GDPR and Articles 32.1 and 32.2 GDPR; 2. Articles 35.1, 35.2
    67 KB (9,908 words) - 11:09, 10 January 2024
  • VG Frankfurt am Main - 5 L1281/22.F (category Article 32(1)(a) GDPR)
    insufficiently secured; the legal requirements of Article 5 (1) (f) GDPR and Article 32 (1) (a) GDPR have been complied with. The German data protection
    25 KB (3,840 words) - 13:34, 4 August 2022
  • APD/GBA (Belgium) - 52/2024 (category Article 32(1)(b) GDPR)
    breach of Articles 5(1)(a), 5(1)(b) and 6 GDPR. Regarding the principle of integrity and confidentiality, Articles 5(1)(f) and 32(1)(b) GDPR establish that the
    21 KB (3,024 words) - 09:26, 17 April 2024
  • ICO (UK) - HIV Scotland (category Article 32(1) GDPR)
    under the GDPR. 14. By Article 57(1) of the GDPR, it is the Commissioner'task to monitor and enforce the application of the GDPR. 15. By Article 58(2)(d)of
    55 KB (6,916 words) - 07:27, 26 October 2021
  • Datatilsynet (Denmark) - 2018-41-0013 (category Article 32(1) GDPR)
    were consent cf. Article 9(2)(a) GDPR and Article 6(1)(a) GDPR. The DPA referred to Article 4(11) GDPR, Article 7 GDPR and Recital 32 regarding the conditions
    47 KB (7,748 words) - 12:51, 22 June 2022
  • IMY (Sweden) - DI-2021-1905 (category Article 32(1) GDPR)
    Trygg-Hansa SEK 35 million (around €3 million) for breaching Article 5(1) GDPR and Article 32 GDPR. In April 2022, Moderna Försäkringar was acquired by Trygg-Hansa
    60 KB (7,023 words) - 08:49, 15 September 2023
  • Datatilsynet (Norway) - 23/00708-28 (category Article 5(1)(f) GDPR)
    data minimisation principles (Article 5(1)(f) GDPR and Article 5(1)(c) GDPR) and security requirements under Article 32(1) GDPR. The DPA held that there were
    6 KB (650 words) - 12:27, 3 April 2024
  • requirements by Article 13 of the GDPR with regard to employees, a non-compliance with measures prescribed by Article 32.1 of the GDPR, as well as non-compliance
    60 KB (8,610 words) - 11:12, 16 June 2021
  • NAIH (Hungary) - NAIH-1855-4/2022 (category Article 32(1)(a) GDPR)
    the data subjects. 1) A) The Controller has not respected Article 32, paragraph (1), point (a) and(b) and paragraph (2) of that article of Regulation (EU)
    50 KB (7,405 words) - 13:58, 28 November 2022
  • ICO (UK) - Mermaids (category Article 32(1) GDPR)
    approximately €29,250 on Mermaids for its violation of Article 5(1)(f), Article 32(1) and Article 32(2) of the GDPR. Share your comments here! Share blogs or news
    58 KB (7,695 words) - 09:00, 28 July 2021
  • IMY (Sweden) - DI-2018-22697 (category Article 32(1) GDPR)
    refers infringements of Article 5 (1) (a) and 5.1 c and SEK 50,000 (fifty thousand) infringements of Article 32 (1) and Article 32 (4) of the Data Protection
    85 KB (9,808 words) - 12:01, 15 September 2021
  • Datatilsynet (Norway) - 18/02140 (category Article 32(1)(a) GDPR)
    technical and organisational measures required by Article 5(1)(f) and Article 32(1)(a) and Article 32(1)(b). This case got a lot of media attention in Norway
    54 KB (8,041 words) - 12:50, 26 January 2022
  • not incur major costs of implementation which under Article 32(2) GDPR makes a breach of 32(1) GDPR more likely. Despite the fact that not all data was
    79 KB (9,390 words) - 09:30, 27 November 2023
  • Datatilsynet (Denmark) - 2019-441-3399 (category Article 32 GDPR)
    in accordance with Article 32 (2) of the Regulation. 2nd 3.3. Article 33 (1) of the Data Protection Regulation 1 and Article 34 (1). 1 The Data Inspectorate
    27 KB (4,231 words) - 16:38, 6 December 2023
  • UODO (Poland) - DKN.5130.2559.2020 (category Article 32(1) GDPR)
    provisions of Article 5(1)(f) GDPR, Article 5(2) GDPR, Article 24(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR by: (a) failing
    62 KB (9,906 words) - 09:02, 11 October 2022
  • Datainspektionen - DI-2019-9432 (category Article 32(1) GDPR)
    current personal data processing has violated Article 5 (1) (f), Article 32.1 and 32.2 and Article 33.1 and 33.5 of the Data Protection Regulation. The
    59 KB (8,959 words) - 11:43, 7 April 2022
  • DVI (Latvia) - Nacionālajam veselības dienestam (category Article 32(1)(b) GDPR)
    based on Article 3, paragraph 2, Article 5, paragraph 1 a), f) of GDPR subsection, Article 6(1), Article 9(2), Article 58(2)(d), GDPR Article 23 and Article
    22 KB (3,276 words) - 11:46, 26 July 2023
  • Datainspektionen - DI-2019-3839 (category Article 32(1) GDPR)
    is more specifically regulated in Article 5(1)(f) and Article 32 of the General Data Protection Regulation. Article 32(1) states that the appropriate measures
    60 KB (9,524 words) - 11:43, 7 April 2022
  • ICO (UK) - Cabinet Office (category Article 32(1) GDPR)
    in the sum of £500,000. Breaches of GDPR Contravention of Article 5(1)(f) of the GDPR 47. Article 5(1)(f) of the GDPR has been contravened as the Cabinet
    79 KB (10,566 words) - 10:48, 7 December 2021
  • contrary to Article 32(1)(d) GDPR. When calculating the financial penalties, the DPA considered the factors described in Article 83(2) GDPR to decide to
    8 KB (981 words) - 14:03, 23 November 2022
  • processor’s actions in determining that the controller violated Article 5(1)(f), 32(1), and 32(2) GDPR. The DPA issued a € 2,800,000 fine. In doing so, it balanced
    62 KB (9,678 words) - 10:45, 13 March 2024
  • HDPA (Greece) - 24/2022 (category Article 5(1)(a) GDPR)
    principles of legality, transparency and security under Article 5(1)(a) and (f) GDPR, and Article 32(1)(2) GDPR, as well as failure to satisfy the right of access
    8 KB (1,087 words) - 16:32, 15 November 2022
  • Datainspektionen - DI-2019-3844 (category Article 32(1) GDPR)
    personal data in violation of Article 5 (1) (f) and (2) and Article 32 (1) and (2) of the Data Protection Regulation by 1. Aleris Sjukvård AB has not carried
    91 KB (11,182 words) - 11:43, 7 April 2022
  • UODO - DKN.5112.1.2020 (category Article 32(1)(b) GDPR)
    controller under Article 24(1) GDPR, Article 25 (1) GDPR, Article 32(1)(b) GDPR and Article 32(1)(d) GDPR and Article 32 GDPR#2"Article 32(2) GDPR. Share blogs
    89 KB (14,285 words) - 12:21, 10 September 2021
  • Datainspektionen - DI-2019-7024 (category Article 32(1) GDPR)
    schooling than necessary is contrary to Article 32 (1) the Data Protection Regulation. According to Article 32 (1), the Board of Education shall include
    70 KB (11,103 words) - 11:43, 7 April 2022
  • Datainspektionen - DI-2019-3841 (category Article 32(1) GDPR)
    found that the Healthcare committee violated Article 5(1)(f), Article 5(2), Article 32(1) and Article 32(2). The DPA investigated the logging practices
    91 KB (11,084 words) - 11:43, 7 April 2022
  • Datainspektionen - DI-2019-3845 (category Article 32(1) GDPR)
    restrictions on access to patient records as a breach of Article 5(1)(f), Article 32(1) and Article 32(2). During the supervisory inspection, the caregiver
    93 KB (11,610 words) - 11:43, 7 April 2022
  • WSA Warszawa - II SA/Wa 2826/19 (category Article 32(1)(b) GDPR)
    4. [Article 5 GDPR#1f|Article 5(1)(f)]] in conjunction with Article 5(2), i.e. the principles of integrity and confidentiality, and Article 32 GDPR by failing
    75 KB (12,225 words) - 23:47, 7 December 2021
  • Article 5 GDPR (category GDPR Articles) (section (1) Principles)
    consent under Article 6(4) GDPR and further processing for a compatible purpose under Article 6(4) GDPR. See the commentary on Article 6(4) GDPR for details
    51 KB (6,355 words) - 08:25, 18 April 2024
  • UODO (Poland) - DKN.5131.12.2020 (category Article 32(1) GDPR)
    controller under Article 24(1) GDPR to ensure that appropriate technical and organisational measures are put in place, in accordance with Article 32 GDPR, and that
    74 KB (11,896 words) - 15:14, 7 March 2023
  • Persónuvernd (Island) - 2020061844 (category Article 32(1)(b) GDPR)
    paragraph 1. Article 32 and f-points 1. paragraph Article 5 of regulation (EU) 2016/679, cf. also paragraph 1 Article 27 and number 6. Paragraph 1 Article 8 Act
    87 KB (14,501 words) - 09:37, 19 July 2023
  • process personal data securely, in violation of Articles 5(1)(f) GDPR and Article 32(1)(b) and (d) GDPR. Two aspects of the decisions are interesting. First
    86 KB (13,819 words) - 21:32, 8 February 2024
  • Datainspektionen - DI-2019-3840 (category Article 32(1) GDPR)
    processes personal data in violation of Article 5 (1) (f) and 5.2 and Article 32 (1) and (2) of the Data Protection Regulation 1 by Sahlgrenska University Hospital
    87 KB (13,573 words) - 11:43, 7 April 2022
  • UODO (Poland) - DKN.5130.2215.2020 (category Article 32(1) GDPR)
    sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and sec. 3, art. 32 sec. 1 and 2 and article. 34 sec. 1, as well as art. 83 sec. 1-3 and
    110 KB (17,650 words) - 12:27, 29 April 2022
  • WSA Warsaw (Poland) - II SA/Wa 2559/19 (category Article 32(1)(d) GDPR)
    with art. 5 sec. 1 lit. f, art. 5 sec. 2, art. 6 sec. 1, art. 7 sec. 1, art. 24 sec. 1, art. 25 sec. 1, art. 32 sec. 1 lit. b and art. 32 sec. 2, art. 58
    90 KB (14,642 words) - 11:12, 18 November 2020
  • AEPD (Spain) - PS/00250/2021 (category Article 32(1)(b) GDPR)
    complained party, by the alleged violation of Article 32 of the RGPD, Article 5.1.f) of the RGPD, typified in the Article 83.5 of the RGPD. FOURTH: Notified the
    40 KB (6,262 words) - 10:43, 7 July 2021
  • AEPD (Spain) - PS/00080/2022 (category Article 32(1)(b) GDPR)
    under Article 5(1)(f) GDPR. Furthermore, the controller was responsible for implementing appropriate security measures according to Article 32(1)(b) GDPR
    47 KB (7,265 words) - 10:05, 21 July 2022
  • UODO (Poland) - DKN.5112.1.2020 (category Article 32(1)(b) GDPR)
    of the case (Article 107 § 3 of the Code of Administrative Procedure in connection with Article 77 § 1, Article 80, Article 8 § 1 and Article 11 of the Code
    110 KB (17,607 words) - 15:35, 3 January 2023
  • UODO (Poland) - DKN.5130.3114.2020 (category Article 32(1) GDPR)
    satellite platform operator €250,000 for violating Article 24(1),Article 32(1), and Article 32(2) GDPR for not implementing appropriate technical and organisational
    105 KB (16,833 words) - 13:48, 15 November 2021
  • Consequently, the DPA found a violation of Article 5(1)(c) and (e), Article 25(2), Article 32(1)(d) and Article 32(2) GDPR. Share your comments here! Share blogs
    51 KB (7,788 words) - 07:42, 29 March 2023
  • possible "legitimate interest" under Article 6(1)(f) GDPR. Equally to Article 6(1)(c) GDPR, Article 6(2) and (3) GDPR require that Union or Member State
    108 KB (17,005 words) - 15:39, 18 March 2024
  • failure to implement these measures infringes Articles 5(1)(f) and 32(1) of the GDPR. 5.35 Article 32(1)(d) specifies that appropriate technical and organisational
    142 KB (23,134 words) - 15:51, 19 July 2021
  • these reasons, the DPA found violations of Article 5(1)(c) and (e) and Article 32(1)(b) and (d) and 32(2) GDPR, imposing a fine of €240,000. Share your comments
    63 KB (10,048 words) - 09:42, 2 August 2023
  • SG Hamburg - S 39 AS 517/23 (category Article 32 GDPR)
    explicitly requested – the processing pursuant to Article 6(1)(a) GDPR. The controller could not use Article 32(1) GDPR to refuse to act on the request, either.
    4 KB (475 words) - 11:43, 4 October 2023
  • AEPD (Spain) - PS/00509/2021 (category Article 32 GDPR)
    the proceedings. Hence, the GDPR was considered to be applicable. Accordingly, the DPA found a violation of Article 32(1) GDPR regarding the security of
    80 KB (11,947 words) - 14:51, 4 October 2022
  • UODO (Poland) - DKN.5131.22.2021 (category Article 32(1)(b) GDPR)
    that the controller breached Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1)(b) and (d), and Article 32(2) GDPR due to a lack of a reliably
    68 KB (10,909 words) - 14:47, 25 October 2021
  • DPC (Ireland) - IN-20-7-2 (category Article 32 GDPR)
    infringed the principle of integrity and confidentiality of Article 5(1)(f) GDPR and Article 32(1) GDPR by failing to ensure appropriate security of the personal
    5 KB (553 words) - 15:49, 23 March 2023
  • infringement of Article 33(1) GDPR, a fine of €145,600 for infringement of Article 34(1) GDPR, and a fine of €316,800 for infringement of Article 5(1)(f) GDPR. In
    153 KB (24,570 words) - 15:11, 26 March 2024
  • AP (The Netherlands) - 4.02.2021 (category Article 32 GDPR)
    most" ten online registrations via this mechanism. Pursuant to Article 32(1) of the GDPR, controllers are obliged to take appropriate technical and organisational
    57 KB (8,053 words) - 17:07, 12 December 2023
  • flows by the SA pursuant to Article 58(2) GDPR or failure to provide access in violation of Article 58(1) GDPR. Article 83(6) GDPR is a superfluous provision
    55 KB (7,622 words) - 14:04, 7 November 2023
  • “personal data breach” under Article 4(12) GDPR. Issue 1 concerned the question whether the controller had infringed Article 33 GDPR in the manner in which it
    6 KB (723 words) - 16:24, 6 April 2022
  • CNIL (France) - SAN-2023-025 (category Article 6(1)(a) GDPR)
    the data subjects, therefore breaching Article 6 GDPR, as well as Article 5(1)(b) GDPR. Thirdly, Article 30 GDPR stipulates that the controller must keep
    53 KB (8,418 words) - 11:21, 6 February 2024
  • Article 28 GDPR (category GDPR Articles) (section (c) Measures required by Article 32 GDPR)
    mechanism referred to in Article 63 GDPR (Article 28(8) GDPR). The Commission has made use of its power under Article 28(7) GDPR and published standard contractual
    72 KB (9,140 words) - 13:12, 2 June 2023
  • This behaviour was in violation of Article 31 GDPR. Thirdly, Company B was found to be in violation of Article 32(1) GDPR. This provision imposes an obligation
    55 KB (9,079 words) - 16:57, 6 December 2023
  • AEPD (Spain) - EXP202102433 (category Article 5(1)(f) GDPR)
    IMPOSE D.C.C.C., with NIF ***NIF.1, for a violation of article 32.1 of the GDPR, typified in article 83.4, a) of the GDPR, a fine of €2,000 (two a thousand
    35 KB (5,473 words) - 05:14, 26 April 2023
  • DPC (Ireland) - 05/SIU/2018 (category Article 32 GDPR)
    accessed the CCTV cameras, thereby infringing Article 32(1) GDPR. The Council also violated Sections 71(1)(f), 72(1) and 78 of the 2018 Act by failing to implement
    13 KB (1,414 words) - 15:11, 14 March 2023
  • obligations were applicable, therefore violating Article 33 and Article 34 GDPR. According to Article 32(1) GDPR, controllers and processors should implement
    10 KB (1,225 words) - 12:13, 24 March 2022
  • UODO (Poland) - DKN.5131.31.2022 (category Article 5(1) GDPR)
    controller €5,400 for infringements of Articles 5(1)(f) and 5(2) GDPR as well as Article 25(1) and Article 32(1) GDPR. First, the controller did not ensure adequate
    71 KB (11,306 words) - 10:51, 22 January 2024
  • Article 25 GDPR (category GDPR Articles) (section (1) Data protection by design)
    affected since, under Article 28(1) GDPR, a controller shall only use processors providing the same standards under Article 25 GDPR. Manufacturers or producers
    43 KB (4,675 words) - 06:43, 16 June 2023
  • Article 58 GDPR (category GDPR Articles) (section (1) Investigative powers)
    access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), notification (Article 19 GDPR) or data
    46 KB (5,825 words) - 11:12, 7 November 2023
  • further details see Article 14(1)(d) GDPR. Similar to the ex-ante information in Article 13(1)(e) and 14(1)(e) GDPR, Article 15(1)(c) GDPR requires the controller
    73 KB (9,896 words) - 15:46, 18 March 2024
  • IDPC (Malta) - CDP/IMI/LSA/22/2021 (category Article 15(1) GDPR)
    pursuant to Article 32(1) GDPR. The DPA held that the controller infringed Article 12(3) GDPR, when it failed to reply to an access request within one (1) month
    18 KB (2,190 words) - 09:57, 23 May 2023
  • APD/GBA (Belgium) - 136/2023 (category Article 5(1)(f) GDPR)
    violating Article 5(1)(f) GDPR, Article 5(1)(a) GDPR, Article 5(2) GDPR, Article 12 GDPR, Article 13 GDPR, Article 14 GDPR, Article 24(1) GDPR, and Article
    58 KB (9,184 words) - 16:49, 12 December 2023
  • will not have to submit another request for erasure under Article 17(1)(b) GDPR. Article 7(4) GDPR provides some useful guidance on the factors to be taken
    31 KB (3,489 words) - 16:00, 8 March 2024
  • provided for in Article 6(1)(a) GDPR or, as the case may be, Article 9(2)(a) GDPR, and consent is withdrawn according to Article 7(3) GDPR, data must be
    61 KB (8,488 words) - 15:47, 18 March 2024
  • agreement on joint responsibility as required under Article 26(1) of the GDPR. Article 33(1) GDPR outlines that controllers (as defined above) have an
    54 KB (6,536 words) - 08:22, 16 June 2023
  • found a violation of Article 25 GDPR, the obligation to implement data protection by design and by default, Article 32(1)(b) GDPR, the responsibility "to
    7 KB (866 words) - 14:23, 21 December 2022
  • exercise on their behalf all rights foreseen under Articles 77 and 78 GDPR and Article 20 of L. 4624/2019. The mandate shall be given with a specific written
    23 KB (2,039 words) - 08:15, 25 April 2024
  • APD/GBA (Belgium) - 81/2023 (category Article 6(1)(e) GDPR)
    infringement of Article 5 (1) (a) and (2), Article 6 (1) GDPR and Article 24 GDPR 2. there is no infringement of Article 5 of the Act of 21 March 2007 until 1 regulation
    31 KB (4,462 words) - 12:25, 3 July 2023
  • DSB (Austria) - 2022-0.930.971 (category Article 89 GDPR)
    in accordance with Article 32 Paragraph 1 GDPR by the applicant in an appropriate manner in accordance with Article 32 Paragraph 1 GDPR to be secured, e
    31 KB (4,726 words) - 08:13, 16 November 2023
  • Article 39 GDPR (category GDPR Articles) (section (1) DPO's Tasks)
    from any of the GDPR’s protections. → You can find all related decisions in Category:Article 39 GDPR Just as Article 38 GDPR, Article 39 GDPR also shows similarities
    23 KB (2,165 words) - 15:10, 27 July 2023
  • codes of conduct on the basis of Article 41 of Regulation 2016/679 and of a certification body on the basis of Article 43 of Regulation 2016/679; To ensure
    9 KB (993 words) - 07:10, 28 July 2022
  • violation of Article 24 GDPR. Moreover, the DPA stressed that controllers must be able to demonstrate that they obtained consent, pursuant to Article 7(1) GDPR
    245 KB (40,390 words) - 14:30, 21 June 2023
  • the competent supervisory authority of such a breach. Article 34(1) GDPR differs from Article 33 GDPR. Instead of having to notify the supervisor authority
    37 KB (3,962 words) - 15:20, 16 June 2023
  • Article 14 GDPR (category Article 14 GDPR) (section Relationship with Article 13 GDPR)
    additional benefit of Article 14(1)(d) GDPR may be questionable, if one agrees that Article 14(1)(c) (see commentary on Article 13(1)(c) GDPR) already requires
    47 KB (5,644 words) - 17:49, 5 March 2024
  • Article 12 GDPR (category GDPR Articles) (section (1) Clear and transparent communication)
    under Article 13 should not be too long. Article 12 GDPR may be limited by Union or national Law in accordance with Article 23 GDPR. Article 12(1) GDPR
    76 KB (11,304 words) - 08:37, 4 March 2024
  • Persónuvernd (Iceland) - 2020010355 (category Article 5(1)(f) GDPR)
    failed to comply with the provisions of Article 32(1)(b) GDPR, Article 32(1)(d) GDPR and Article 5(1)(f) GDPR. Furthermore, InfoMentor did not ensure sufficient
    44 KB (7,217 words) - 10:04, 12 May 2021
  • difference between Article 42(1) GDPR and Article 42(2) GDPR is that in the former, the applicant for certification is subject to the GDPR, while in latter
    27 KB (2,452 words) - 14:26, 28 July 2023
  • Article 26 GDPR (category GDPR Articles) (section (1) Joint controllership)
    mentioned in Article 26(1), but also encompasses other obligations of controllers under the GDPR. EDPB: This extends to various obligations under the GDPR, including
    37 KB (3,915 words) - 12:49, 24 May 2023
  • Article 81 GDPR (category GDPR Articles) (section Scope of Article 81 GDPR)
    explicit wording of Article 81 GDPR does not limit its application to proceedings instigated either under Article 78 GDPR or Article 79 GDPR. Secondly, the
    27 KB (2,619 words) - 14:52, 16 November 2023
  • Article 99 GDPR (category Article 99 GDPR)
    shall apply from 25 May 2018. There is no relevant recital for Article 99 GDPR. Article 99 GDPR sets out the dates of the Regulation's entry into force and
    12 KB (295 words) - 08:25, 19 October 2023
  • relevance of Article 29 GDPR were rooted in the fact that Article 28(3)(b) GDPR already seems to cover much of the scope of Article 29 GDPR. More specifically
    13 KB (674 words) - 13:15, 2 June 2023
  • Article 94 GDPR (category Article 94 GDPR)
    under the GDPR. → You can find all related decisions in Category:Article 94 GDPR Kühling, Raab, in Kühling, Buchner, GVO BDSG, Article 94 GDPR, margin numbers
    13 KB (530 words) - 09:40, 3 October 2023
  • Article 40 GDPR (category GDPR Articles) (section (1) Drawing up codes of conduct)
    up. Indeed, the wording of Article 40(1) establishes that they “shall encourage” this (emphasis added). Article 40(1) GDPR clarifies that codes of conduct
    44 KB (5,008 words) - 14:50, 28 July 2023
  • Article 96 GDPR (category Article 96 GDPR)
    protected by Article 96 GDPR if it is found to be incompatible with other GDPR provisions. → You can find all related decisions in Category:Article 96 GDPR It follows
    13 KB (450 words) - 08:22, 19 October 2023
  • the GDPR neither to the ZVOPOKD (for ex. Slovene Intelligence and Security Agency) for these the ‘2007’ ZVOP-1 is still fully applicable and GDPR does
    10 KB (1,242 words) - 10:51, 6 February 2024
  • Article 97 GDPR (category Article 97 GDPR)
    recitals for Article 97 GDPR. Article 97 GDPR imposes a "comprehensive reporting obligation" upon the Commission. The first paragraph of Article 97 GDPR sets out
    16 KB (778 words) - 08:24, 19 October 2023
  • Article 87 GDPR (category Article 87 GDPR)
    process them. This was already the case under Article 8(7) of the DPD, the precursor of Article 87 GDPR. In many Member States, the processing of NIN and
    15 KB (660 words) - 09:37, 1 December 2023
  • commentary to Article 60 GDPR, Article 61 GDPR, Article 62 GDPR, Article 63 GDPR, Article 64 GDPR, Article 65 GDPR, Article 66 GDPR and Article 56 GDPR. The SA
    60 KB (7,796 words) - 20:12, 1 April 2024
  • the parties. Section 100 of the Slovak Data Protection Act implements Article 77 GDPR. The complaint shall include (Section 100 (3)): The name, surname, correspondence
    9 KB (1,006 words) - 07:13, 7 July 2021
  • Article 74 GDPR (category Article 74 GDPR) (section (1) Tasks of the Chair)
    decisions in Category:Article 74 GDPR For more on this point, see Article 72 GDPR. Dix in Kühling, Buchner, DS-GVO BDSG, Article 74 GDPR, margin number 7 (C
    15 KB (808 words) - 09:44, 17 October 2023
  • Article 76 GDPR (category Article 76 GDPR) (section (1) Confidentiality, Where Necessary)
    in the EDPB's Rules of Procedure (“RoP”). Article 33(1) RoP stipulates that in “accordance with Art 76 (1) GDPR”, discussions of the Board and of expert
    15 KB (787 words) - 08:17, 19 October 2023
  • Article 59 GDPR (category GDPR Articles)
    accordance with Article 58(2) [GDPR]”. These is a reference to the information that SAs must keep in internal records according to Article 57(1)(u) GDPR. The report
    15 KB (718 words) - 15:31, 19 October 2023
  • Article 67 GDPR (category Article 67 GDPR)
    Category:Article 67 GDPR See EDPB, State of Play - IMI for GDPR purposes, 27 June 2018 (available here). See EDPB, 2019 Annual Report, Section 4.3.1 (available
    15 KB (810 words) - 16:13, 2 November 2023
  • Article 10 GDPR (category GDPR Articles)
    from Article 6(1) GDPR and comply with the principles enshrined in Article 5 GDPR. Additionally, the processing will still be subject to other GDPR provisions
    17 KB (1,768 words) - 15:41, 18 March 2024
  • Article 8 GDPR (category GDPR Articles) (section (1) Material scope)
    the information society service(s)." According to Article 4(25) GDPR, which in turn refers to Article 1(1) of Directive (EU) 2015/1535, an "information society
    19 KB (1,335 words) - 13:56, 24 October 2023
  • Article 48 GDPR (category GDPR Articles)
    subject to the GDPR or, in cases where they are not established in the EU, act within the material and territorial scope of the GDPR. Article 48 GDPR refers to
    14 KB (716 words) - 15:19, 28 April 2022
  • Article 63 GDPR (category Article 63 GDPR)
    to in Article 46(2)(d) GDPR, contractual clauses referred to in Article 46(3)(a) GDPR, or binding corporate rules within the meaning of Article 47 GDPR
    15 KB (851 words) - 06:55, 29 April 2022
  • Article 44 GDPR (category GDPR Articles)
    important to note that Article 13(1)(f) GDPR, Article 14(1)(f) GDPR, Article 15(1)(c) GDPR and Article 15(2) GDPR, make specific reference to transfers of personal
    21 KB (1,831 words) - 08:51, 27 March 2023
  • Article 19 GDPR (category GDPR Articles)
    of Article 15(1)(c) GDPR, which permits in certain cases that the information provided is limited to "categories of recipient[s]": Article 15 GDPR is a
    19 KB (1,436 words) - 12:35, 12 May 2023
  • Article 93 GDPR (category Article 93 GDPR) (section (1) Implementing acts)
    unlike delegated acts made under Article 92 GDPR. Article 93(2) GDPR explicitly provides for the application of Article 5 of Regulation (EU) No 182/2011
    17 KB (1,096 words) - 08:19, 19 October 2023
  • Article 75 GDPR (category Article 75 GDPR) (section (1) The Secretariat)
    Protection Regulation (GDPR), Article 75 GDPR, p. 1105 (Oxford University Press 2020). Dix, in Kühling, Buchner, DS-GVO BDSG, Article 75 GDPR, margin number 6
    20 KB (1,347 words) - 14:21, 17 October 2023
  • Article 69 GDPR (category Article 69 GDPR) (section (1) The Board shall act independently)
    proposed amendments to the GDPR (pursuant to Article 70(1)(b) GDPR). Although not explicitly mentioned in Article 69(2) GDPR, the requirement that the Board
    18 KB (1,327 words) - 12:36, 14 December 2023
  • Article 71 GDPR (category Article 71 GDPR) (section (1) Obligation to prepare an annual report)
    practices published under Article 70(3) GDPR. Though Article 70(3) GDPR already obliges the EDPB to make these public, Article 71(2) GDPR ensures that the public
    15 KB (1,196 words) - 08:15, 19 October 2023
  • Article 98 GDPR (category Article 98 GDPR)
    accordance with Article 98'. → You can find all related decisions in Category:Article 98 GDPR The CJEU has yet to rule on Article 98 GDPR. Nonetheless, the
    15 KB (943 words) - 09:58, 8 November 2023
  • Article 50 GDPR (category GDPR Articles)
    exchange of knowledge between them. This way, Article 50 GDPR expands the exhortation under Article 57(1)(g) GDPR that calls for cooperation between EU DPAs
    17 KB (1,142 words) - 15:41, 28 April 2022
  • establishes an EU-wide penalty regime for violations under Article 83 GDPR, Article 84(1) GDPR dispenses with complete harmonisation. It does, however, provide
    19 KB (1,477 words) - 14:12, 7 November 2023
  • Article 31 GDPR (category GDPR Articles) (section Supporting provision to Article 58 GDPR)
    falls outside the scope of Article 57 GDPR should be deemed inadmissible for the purposes of Article 31 GDPR. Article 31 GDPR can be read as a supporting
    22 KB (2,042 words) - 14:29, 20 November 2023
  • Article 43 GDPR (category GDPR Articles) (section (1-5) The certification body)
    Recital 167 GDPR and Article 291 TFEU, the aim of implementing acts is to “ensure uniform conditions for implementing” the GDPR. In its GDPR Certification
    22 KB (1,634 words) - 14:40, 28 July 2023
  • Article 16 GDPR (category GDPR Articles)
    However, Article 5(1)(d) GDPR gives the controller some leeway to continue processing inaccurate data - see more details under Article 5(1)(d) GDPR. Article
    23 KB (2,489 words) - 23:24, 6 March 2024
  • Article 66 GDPR (category Article 66 GDPR) (section (1) Adoption of provisional measures)
    binding decision under Article 66 GDPR, at the request of the Hamburg SA which adopted provisional measures under Article 66(1) GDPR, based on its consideration
    20 KB (1,590 words) - 16:11, 2 November 2023
  • Article 95 GDPR (category Article 95 GDPR)
    situation, Article 95 GDPR will not be relevant, and the GDPR applies as normal. Notably, Recital 173 GDPR, which relates to Article 95 GDPR, omits reference
    20 KB (1,539 words) - 08:21, 19 October 2023
  • Article 73 GDPR (category Article 73 GDPR) (section (1) Chair, deputy chairs and their election)
    simple majority principle under Article 72(1) GDPR would have applied regardless of Article 73(1) GDPR. In addition, the GDPR explicitly legislates for a simple
    19 KB (1,530 words) - 14:23, 12 October 2023
  • categories of data established in Article 9(2)(a) GDPR, Article 9(2)(c) GDPR, Article 9(2)(g) GDPR and Article 9(2)(i) GDPR directly correlate with a specific
    44 KB (5,905 words) - 14:00, 24 October 2023
  • Article 68 GDPR (category Article 68 GDPR) (section (1) Legal personality)
    decisions pursuant to Article 65 GDPR (Article 70(1)(t) GDPR). Article 68 GDPR is the first of nine Articles (Articles 68-76 GDPR) governing the EDPB set
    20 KB (1,632 words) - 10:01, 11 October 2023
  • first glance, Article 92 GDPR's wording seems to be in conflict with Article 290(1) TFEU, but in actuality it is not. Article 92(2) GDPR must be read in
    19 KB (1,525 words) - 08:18, 19 October 2023
  • accordance with Article 58(1) GDPR. Article 90 GDPR was drafted with a view to regulate potential conflicts between the application of the GDPR on the one hand
    18 KB (1,599 words) - 12:26, 29 April 2022
  • Article 64 GDPR (category Article 64 GDPR) (section (1) A mandatory opinion of the EDPB)
    64(2) GDPR). The remaining paragraphs of Article 64(3)-(8) GDPR lay down substantive rules and a detailed procedure for the EDPB’s opinions. Article 64(1) GDPR
    23 KB (2,079 words) - 16:07, 2 November 2023
  • Article 77 GDPR (category GDPR Articles) (section (1) Right to a formal complaint)
    compliance with the GDPR under Article 58(2)(d) GDPR or even ban it under Article 58(2)(f) GDPR. Therefore, complaints under Article 77 GDPR should extend to
    33 KB (3,641 words) - 09:51, 19 March 2024
  • Regulation (GDPR): A Commentary, Article 38 GDPR, p. 707 (Oxford University Press 2020). Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number
    29 KB (2,951 words) - 14:19, 25 July 2023
  • Article 62 GDPR (category Article 62 GDPR) (section (1) The power to conduct joint operations)
    framework of voluntary cooperation provided for in Article 62(1) GDPR is partly supplemented by Article 62(2) GDPR, which contains several cases in which joint
    22 KB (1,915 words) - 13:46, 15 January 2024
  • Article 27 GDPR (category GDPR Articles) (section (1) Conditions for applicability)
    with the GDPR (Article 31 GDPR). Direct liability of the representative is limited to the obligations set out in Article 30 and Article 58(1)(a) GDPR. Article
    25 KB (2,418 words) - 14:11, 24 May 2023
  • request (Article 61(5) GDPR), the requesting SA may adopt a provisional measure on the territory of its Member State under Article 55(1) GDPR. If the SA
    24 KB (2,181 words) - 11:46, 15 January 2024
  • controller is subject, under Article 6(1)(c) GDPR. In line with the general objectives of the GDPR, as outlined in Article 1 GDPR Article 16 TFEU, SAs are also
    27 KB (2,604 words) - 14:24, 16 January 2024
  • resolution mechanism under Article 65 GDPR in connection with Article 63 GDPR is triggered (Article 60 (4) GDPR). Article 60(2) GDPR clarifies that also in
    35 KB (4,017 words) - 16:04, 18 March 2024
  • leeway exists only in cases of Article 64(2) GDPR but not the context of Article 70(2) GDPR. According to Article 70(3) GDPR, the EDPB is obligated to “forward
    27 KB (3,038 words) - 12:19, 11 October 2023
  • Article 86 GDPR (category Article 86 GDPR) (section The GDPR remains applicable)
    Press 2020). Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1090. Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1090. CJEU
    22 KB (2,177 words) - 10:01, 19 March 2024
  • Article 72 GDPR (category Article 72 GDPR) (section (1) Principle of simple majority)
    within the meaning of Article 72(1) GDPR. The GDPR does not contain detailed content requirements for the RoP. Article 74(2) GDPR only stipulates that the
    22 KB (2,266 words) - 08:26, 17 October 2023
  • Article 46 GDPR (category GDPR Articles) (section (1) Scope)
    access (Article 15 GDPR), rectification (Article 16 GDPR), deletion (Article 17 GDPR), restriction of processing (Article 18 GDPR), objection (Article 21 GDPR)
    34 KB (3,646 words) - 08:53, 27 March 2023
  • Article 47 GDPR (category GDPR Articles) (section (1) Binding Corporate Rules)
    other DPAs concerned. The BCR Lead the submits, following Article 64(1) GDPR and Article 64(4) GDPR, a draft decision to the EDPB. The EDPB, in turn, issues
    29 KB (2,823 words) - 15:15, 28 April 2022
  • Article 80 GDPR (category GDPR Articles) (section Requirements under Article 80(1) GDPR)
    complaint under Article 77(1) GDPR on behalf of the data subject and to represent the them before all supervisory authorities (“SA”) (Article 4(21) GDPR). Secondly
    26 KB (2,575 words) - 15:50, 9 November 2023
  • Article 91 GDPR (category Article 91 GDPR) (section (1) Conditions for the Derogation to Apply)
    Regulation (GDPR), Article 91 GDPR, p. 1263 (Oxford University Press 2020). Tosoni, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article
    25 KB (2,482 words) - 10:04, 19 March 2024
  • between Article 21(3) GDPR and Article 17 GDPR on the right to erasure must be considered. The tight relationship between Article 21(3) and Article 17(1)(c)
    49 KB (5,993 words) - 06:22, 16 June 2023
  • will then go to the Court of Justice (CJEU) for a final decision. Article 64 states: 1.   The Court of Justice shall have jurisdiction to hear all disputes
    8 KB (1,078 words) - 12:58, 10 May 2024
  • Article 2 GDPR (category GDPR Articles) (section (1) Material scope)
    elements in Article 2(1) are fulfilled, the GDPR applies unless the processing falls under one of the exemptions named in Article 2(2)(a) to (d) GDPR. The first
    34 KB (4,652 words) - 12:07, 12 November 2023
  • deadline of Article 36(1) GDPR, and it is still disputed whether the outcome of the procedure rather resembles that of Article 58(3)(a) GDPR or Article 58(3)(b)
    31 KB (3,646 words) - 08:51, 21 July 2023
  • proceedings under Article 79(1) GDPR where no subjective rights under the GDPR are concerned. For example, a data subject cannot use Article 79(1) GDPR to bring
    31 KB (3,550 words) - 11:11, 29 November 2023
  • Article 41 GDPR (category GDPR Articles) (section (1) The monitoring body)
    clear from the wording of Article 41(1) GDPR. Article 41(1) GDPR does not define accreditation. Nonetheless, Article 41(2) GDPR provides a criterion against
    30 KB (2,720 words) - 14:02, 28 July 2023
  • the basis of (i) its legitimate interest (Article 6(1)(f) GDPR) or (ii) the public interest (Article 6(1)(e) GDPR). Hence, data subjects may find themselves
    32 KB (3,730 words) - 08:43, 7 March 2024
  • into force of the GDPR. Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1073. Spiecker et al., GDPR Article-by-Article Commentary (2023)
    33 KB (3,748 words) - 14:25, 7 November 2023
  • Article 88 GDPR (category Article 88 GDPR) (section (1) May, by law or by collective agreements)
    opening clause under Article 88(1) GDPR, any rules introduced must meet the criteria imposed by Article 88(2) GDPR. Lastly, Article 88(3) GDPR imposes an obligation
    32 KB (3,228 words) - 13:32, 30 November 2023
  • the SAs' tasks, please refer to Article 57 GDPR and for their powers please refer to Article 58 GDPR. See Recital 122 GDPR. In this respect, reference should
    29 KB (2,894 words) - 23:06, 1 April 2024
  • reliance on Article 6(1)(f) GDPR or at least exercise the right to object under Article 21 GDPR. If the legal basis is Article 6(1)(f) GDPR (i.e. 'legitimate
    71 KB (9,532 words) - 13:30, 6 March 2024
  • Article 49 GDPR (category GDPR Articles) (section (1) Derogations for Specific Situations)
    According to the final paragraph in Article 49(1) GDPR, when none of the derogations described above (Article 49(1)(a-g) GDPR) is applicable, transfers to third
    29 KB (3,500 words) - 08:54, 27 March 2023
  • which would be competent under Article 55(1) GDPR, as provided in Article 56 GDPR in connection with Article 60 GDPR. For more information see commentary
    35 KB (3,971 words) - 21:34, 1 April 2024
  • categories of data listed under Article 9(1) GDPR. There have been conflicting arguments as to whether Article 22(1) GDPR lays down a right or a general
    31 KB (4,768 words) - 06:24, 16 June 2023
  • Article 1 GDPR (category GDPR Articles) (section (1) Subject-matter)
    the application of the GDPR. You can find further details about the territorial scope in Article 3 GDPR. According to Article 1(2), the Regulation generally
    28 KB (3,831 words) - 16:21, 14 March 2024
  • Hence, Article 89(2) and (3) GDPR also allow for specific derogation to the GDPR for these purposes, as further detailed below. Article 89(1) GDPR provides
    29 KB (3,695 words) - 13:44, 21 March 2024
  • or infringes the GDPR or any other applicable laws, including national ones. See commentary under Article 77 GDPR. Article 78(1) GDPR establishes both
    30 KB (3,874 words) - 10:46, 7 December 2023
  • Article 65 GDPR (category GDPR Articles) (section (1) Dispute resolution mechanism)
    lead SA (“LSA”) (Article 65(1)(b) GDPR), and where a SA is not following an opinion of the EDPB (Article 6(1)(c) GDPR). Article 65(1)(a) GDPR addresses the
    33 KB (4,185 words) - 16:09, 2 November 2023
  • access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), notification obligation
    44 KB (4,896 words) - 06:25, 16 June 2023
  • Article 3 GDPR (category GDPR Articles) (section (1) Establishment in the Union)
    the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 16 (available here) referring to Article 1(1)(b) Directive (EU) 2015/1535
    37 KB (4,635 words) - 13:29, 24 October 2023
  • surveillance cameras, it was therefore in breach of Article 37(1)(b) GDPR by not having a DPO. Article 37(1) GDPR specifies three conditions in which the designation
    43 KB (4,904 words) - 12:59, 21 July 2023
  • the establishment of SAs are set out in Article 51(1) and 52 GDPR, Article 54(1)(a) GDPR repeats that these should be legislated for through a Member State's
    34 KB (3,649 words) - 13:19, 30 October 2023
  • Article 35 GDPR (category GDPR Articles) (section (1) Mandatory DPIA)
    must also be involved in the drafting of the DPIA under Article 35(2) GDPR and Article 39(1)(c) GDPR, and their advice should be recorded by the controller
    52 KB (7,297 words) - 08:05, 18 July 2023
  • Article 45 GDPR (category GDPR Articles) (section (1) Adequacy Decision)
    with the support of the EDPB in accordance with Article 70(1)(b) GDPR. According to Article 45(5) GDPR, the continued monitoring referred to in paragraph
    43 KB (5,641 words) - 14:58, 28 April 2022
  • Article 56 GDPR (category GDPR Articles) (section Without prejudice to Article 55 GDPR)
    processing), Article 57 GDPR (tasks of SAs), Article 58 GDPR (powers of SAs), as well as Article 65 GDPR (dispute resolution by the board), Article 63 GDPR (consistency
    55 KB (7,446 words) - 22:28, 1 April 2024
  • Article 20 GDPR (category GDPR Articles) (section (1) Right to data portability)
    consent pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1); and (b) the processing is
    40 KB (5,349 words) - 07:05, 1 June 2023
  • this purpose (Article 52(4)(5)(6) GDPR). Elements of SAs' complete independence are also addressed in Article 53 GDPR and Article 54 GDPR. The CJEU in the
    47 KB (5,594 words) - 22:45, 1 April 2024
  • of such processing (see Article 5(1)(b) GDPR), the requirement to have a legitimate basis laid down by law (see Article 6(1) GDPR), the right to access and
    48 KB (5,978 words) - 15:57, 1 February 2024
  • APD/GBA (Belgium) - 15/2023 (category Article 5(1) GDPR)
    regard resources. II.1. Article 5 (1) (a) and (2) of the GDPR and Article 6 (1) of the GDPR II.1.1. Article 5 (1) a) and Article 6 (1) GDPR with regard to legality
    105 KB (15,883 words) - 15:05, 8 March 2023
  • ICO (UK) - Tuckers Solicitors LLP (category Article 5(1)(f) GDPR)
    for by Article 51 of the GDPR. 17. By Article 57(1) of the GDPR, it is the Commissioner's task to monitor and enforce the application of the GDPR. 18. By
    87 KB (10,588 words) - 14:32, 16 March 2022
  • Datatilsynet (Denmark) - 2023-420-0001 (category Article 32 GDPR)
    as pupils and parents) and so high security measures under Article 32 GDPR and Article 25 GDPR are required. The Danish DPA observed a number of personal
    67 KB (10,296 words) - 15:15, 31 January 2024
  • EDPB - Binding Decision 1/2020 - 'Twitter' (category Article 5(1)(f) GDPR)
    infringements of Article 5(1)(f), Article 24, and Article 32 GDPR, and to the objection of the IT SA on the possible infringement of Article 5(2) GDPR, the EDPB
    183 KB (30,819 words) - 09:50, 20 January 2023
  • elements. Infringement of Article 6 and 9 GDPR qualifies for the maximum amount for administrative fines as set out in Article 83(5) GDPR: 20,000,000 € or 4%
    18 KB (2,375 words) - 16:17, 6 December 2023
  • ISWEB violated Article 28(2) GDPR and Article 28(4) GDPR as a processor on behalf of the hospitals and Article 28(1) GDPR and Article 28(3) GDPR as controller
    99 KB (16,015 words) - 16:16, 1 June 2022
  • AEPD (Spain) - EXP202305587 (category Article 5(1)(f) GDPR)
    sanction for both Article 5(1)(f) and 32 GDPR in this case would constitute a double violation of the GDPR, when in fact Article 5(1)(f) GDPR is merely a concretion
    285 KB (44,507 words) - 11:21, 30 April 2024
  • AEPD (Spain) - EXP202205206 (category Article 5(1)(f) GDPR)
    the RGPD and Article 32 of the GDPR, typified in Article 83.5 of the GDPR and Article 83.4 of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd
    263 KB (41,516 words) - 09:29, 24 April 2024
  • the Member States. Example: Article 6(1)(a) GDPR Example: Not Art. 6 Abs 1 Lit a GDPR or Article 6 GDPR or GDPR Article 6, Sec 1(a) Recitals are also not
    17 KB (2,510 words) - 13:56, 24 April 2023
  • HDPA (Greece) - 32/2020 (category Article 5(1) GDPR)
    pertaining to human dignity (Article 2(1) Greek Constitution) and to the right to freely form one's personality (Article 5(1) Greek Constitution). The HDPA
    12 KB (1,464 words) - 15:37, 6 December 2023
  • CNIL (France) - SAN-2020-012 (category Article 26(1) GDPR)
    in the same article 83. 111. Article 83 of the GDPR, as referred to in Article 20, paragraph III, of the Data Protection Act, provides: 1. Each supervisory
    93 KB (14,936 words) - 17:09, 6 December 2023
  • AEPD (Spain) - EXP202205353 (category Article 5(1)(f) GDPR)
    the alleged violation of article 5.1.f) of the GDPR and article 32 of the GDPR, typified in article 83.5 and 83.4 of the GDPR. The initiation agreement
    22 KB (3,386 words) - 16:05, 13 December 2023
  • AEPD (Spain) - EXP202100764 (category Article 5(1)(f) GDPR)
    setting a penalty of €1,000 (one thousand euros). SAW Article 32 of the GDPR Article 32 “Security of processing” of the GDPR establishes: "1. Taking into account
    34 KB (5,184 words) - 13:22, 13 December 2023
  • CNIL (France) - SAN-2022-019 (category Article 32 GDPR)
    the DPA determined that the legal grounds of Article 6(1)(b), 6(1)(c), Article 6(1)(d) and Article 6(1)(e) GDPR were not applicable in this case. It also
    11 KB (1,452 words) - 17:03, 6 December 2023
  • Datatilsynet (Denmark) - 2018-32-0357 (category Article 5(1)(a) GDPR) (section 1. Decision)
    The heading of Article 6(1) and the wording “has given” in Article 6(1)(a) support this interpretation. It follows logically from Article 6 and Recital
    65 KB (9,767 words) - 16:22, 6 December 2023
  • AEPD (Spain) - EXP202102430 (category Article 32 GDPR)
    by article 32.1 of the Regulation (EU) 2016/679. (…) V Without prejudice to the provisions of article 83.5 of the RGPD, the aforementioned article provides
    33 KB (4,835 words) - 13:26, 13 December 2023
  • CNIL (France) - SAN-2020-014 (category Article 32 GDPR)
    breach of Article 32 of the GDPR has occurred. B. On the failure to notify the data breach to the CNIL 32. Pursuant to Article 33 (1) of the GDPR, in the
    26 KB (4,050 words) - 17:10, 6 December 2023
  • AEPD (Spain) - EXP202105644 (category Article 5(1)(f) GDPR)
    controller €80,000: €50,000 for the violation of Article 5(1)(f) GDPR and €30,000 for the violation of Article 32 GDPR. The original fine of €80,000 was reduced
    27 KB (4,121 words) - 15:06, 13 December 2023
  • Vodafone S.p.A in violation of the following GDPR provisions: Article 5(1) and Article 5(2) and Article 25(1): for failing to implement control systems of
    7 KB (810 words) - 15:52, 6 December 2023
  • AEPD (Spain) - EXP202201746 (category Article 5(1)(f) GDPR)
    infringement of Article 32 GDPR. Therefore, the Spanish DPA issued a warning sanction for each violation of Article 5(1)(f) and Article 32 GDPR. AEPD highlighted
    62 KB (9,703 words) - 13:05, 13 December 2023
  • APD/GBA (Belgium) - 53/2020 (category Article 5(1)(a) GDPR)
    comply with section 5.1(b) of the MDR, and for failure to comply with section 5.1(a) of the MDR. and 5.1(b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the MDR read
    35 KB (5,853 words) - 16:58, 12 December 2023
  • HDPA (Greece) - 30/2020 (category Article 4(1) GDPR)
    powers under Article 58(2) GDPR and impose on the respondent the responsibility to restore the fulfilment of Article 5(1)(a) GDPR and of Article 5(1)(b-f) GDPR
    20 KB (2,519 words) - 15:36, 6 December 2023
  • LAG Düsseldorf - 12 Sa 186/19 (category Article 9 GDPR)
    to a claim under Article 82 (1) GDPR, which he could also base on Article 823 (1) BGB in conjunction with Article 2 (1) and Article 1 (1) GG. The defendant
    120 KB (20,753 words) - 17:06, 7 March 2022
  • artistic or literary purposes, only Article 24, Article 26, Article 28, Article 29, Article 32, and Article 40- Article 43 applies, following § 3. Special
    8 KB (1,064 words) - 12:53, 23 June 2023
  • meaning that no violation of Article 5(1)(e) GDPR could be established. Integrity and confidentiality - Article 5(1)(f) GDPR As explained above, the DPA
    429 KB (58,279 words) - 09:12, 2 November 2022
  • UODO (Poland) - ZSPU.421.3.2019 (category Article 5(1)(a) GDPR)
    provided for in Article 5(1)(a), (e) and (f), Article 5(2), Article 24(1) and (2), Article 28(3), Article 30(1)(d) and (f) and Article 32(1) of the General
    58 KB (9,357 words) - 10:02, 17 November 2023
  • Paragraph 24 of Schedule 2 states that the GDPR provisions Article 13(1) to (3), Article 14(1) to (4) and Article 15(1) to (3) do not apply to personal data
    14 KB (2,011 words) - 15:42, 25 November 2020
  • regulation's article 5, subsection 2, cf. Article 5, subsection 1, letters c and f, and Article 5, subsection 1, letter a, cf. Article 6, subsection 1, and Article
    75 KB (11,733 words) - 16:33, 21 August 2022
  • OLG Schleswig - 17 U 15/21 (category Article 6(1)(e) GDPR) (section Article 6(1)(e) GDPR)
    processing by the defendant can only be Article 6 (1) sentence 1 lit e) DSGVO (see b) or Article 6 (1) sentence 1 lit f) DSGVO (see c), the requirements
    51 KB (8,215 words) - 09:55, 13 May 2022
  • Hoge Raad - 21/00241 (category Article 6(1)(c) GDPR)
    accordance with the provisions of Article 6(1)(c), Article 6(1)(f) GDPR, or both provisions? 2.     Does the answer to Question 1 mean: a)      that the person
    29 KB (4,605 words) - 17:00, 15 December 2021
  • LG Köln - 28 O 138/22 (category Article 82 GDPR)
    Sections 1004 analogously, Section 823 (1) and (2) BGB in conjunction with Article 6 (1) GDPR and Article 17 GDPR. Claims under data protection law could
    39 KB (6,362 words) - 14:01, 22 June 2023
  • APD/GBA (Belgium) - 149/2023 (category Article 5(1)(a) GDPR)
    to in Article 5(1) LRN, under which the controller did not fall in. Therefore, the controller breached Article 5(1)(a) GDPR and Article 6(1) GDPR, in conjunction
    113 KB (17,325 words) - 08:50, 19 March 2024
  • CJEU - C-61/19 - Orange Romania (category Article 6(1)(a) GDPR)
    has consented to processing of his or her data (Art 7 (1) GDPR). This is equally true under Article 7(a) of the Directive 95/46, which required that the
    8 KB (1,074 words) - 13:50, 11 August 2022
  • GDPR, Article 9 GDPR, Article 10 GDPR, Article 30 GDPR and Article 34 GDPR, as well as the provision of the PDPA governing processing of personal data
    10 KB (1,440 words) - 08:54, 17 January 2020
  • not necessarily meet the requirements of Article 32 GDPR. To what extent are the provisions in Article 32 GDPR obligatory and thus, not subject to the preferences
    30 KB (4,562 words) - 15:27, 6 December 2023
  • Datatilsynet (Denmark) - 2019-32-0910 (category Article 5(1)(c) GDPR)
    “type-ahead” search function on the municipality’s website under Article 6(1)(e) GDPR. It also found that the purpose of this function was to offer a better
    10 KB (1,528 words) - 16:23, 6 December 2023
  • Datatilsynet (Denmark) - 2018-32-0232 (category Article 5(1)(c) GDPR)
    be processed in accordance with Article 6 (2) of the Data Protection Regulation. 1 (a) to (f). Pursuant to Article 6 (1) of the Data Protection Regulation
    13 KB (1,990 words) - 16:22, 6 December 2023
  • Datatilsynet (Denmark) - 2020-32-1733 (category Article 5(1)(d) GDPR)
    the rules in the Data Protection Regulation [1], cf. Article 6 (1). Article 17 (1) (e) and Article 17 (1) 3, letter b. However, the Danish Data Protection
    16 KB (2,377 words) - 16:39, 6 December 2023
  • Datatilsynet (Denmark) - 2019-32-0709 (category Article 5(1)(a) GDPR)
    accordance with Article 6 (1) 1, letter a, if the processing is necessary for the performance of a contract in accordance with Article 6 (1). 1, letter b, if
    24 KB (3,763 words) - 16:23, 6 December 2023
  • HDPA (Greece) - 52/2021 (category Article 32(2) GDPR)
    processor €30,000 under Article 58(2) GDPR and Article 83(4) GDPR for the breach of Article 32(2), Article 32(4) GDPR and Article 28(3) GDPR. As for the controller
    8 KB (861 words) - 10:00, 22 December 2021
  • based on a legitimate interest under Article 6(1)(f) GDPR, so that the principle of lawfulness under Article 5(1)(a) GDPR is violated. This is due to the fact
    24 KB (3,579 words) - 12:05, 7 July 2021
  • Datatilsynet (Denmark) - 2019-32-0639 (category Article 5(1)(a) GDPR)
    breaching Articles 12(1), 14(1)(c), 14(2) and 14(3) GDPR. In addition, Datatilsynet also issued criticism in relation to Article 5(1)(a) GDPR for the controller’s
    26 KB (4,157 words) - 16:23, 6 December 2023
  • HDPA (Greece) - 42/2021 (category Article 5(1)(d) GDPR)
    Applicable provisions Article 5.1.d: Principle of accuracy Article 5.1.f: Principle of integrity and confidentiality Article 32: Processing security Summary
    5 KB (483 words) - 08:42, 29 September 2021
  • VDAI - NVSC vs UAB (category Article 5(1)(a) GDPR)
    Articles 5, 13, 24, 32, 35 and 58(2)(f) GDPR. UAB IT Solutions Success was fined €3,000 for violating Articles 5, 13, 24, 32 and 35 GDPR. The Lithuanian DPA
    11 KB (1,573 words) - 09:18, 17 November 2023
  • Datatilsynet (Denmark) - 2019-41-0028 (category Article 32 GDPR)
    . That Krifa - in accordance with Article 5 (1) of the Data Protection Regulation. 2, cf. Article 32 (1) (f), cf. 1 and 2 - has demonstrated that a risk
    24 KB (3,947 words) - 16:24, 6 December 2023
  • LfDI (Baden-Württemberg) - 2019 (category Article 5(1)(f) GDPR)
    and violated Article 5(1)(f) GDPR. It also did not process personal data with an appropriate level of security, as required by Article 32 GDPR. The company
    3 KB (190 words) - 10:17, 17 November 2023
  • ANSPDCP (Romania) - 04.03.2021 (category Article 5(1)(f) GDPR)
    infringement of Article 32 GDPR in conjunction with Article 5(1)(f) GDPR? The Romanian DPA (ANSPDCP) found that the controller violated Article 32 GDPR as they
    7 KB (1,035 words) - 15:19, 13 December 2023
  • Datatilsynet (Denmark) - 2019-41-0026 (category Article 32 GDPR)
    the law firm - in accordance with Article 5 (1) of the Data Protection Regulation. 2, cf. Article 32 (1) (f), cf. 1 and 2 - has demonstrated that a risk
    13 KB (1,916 words) - 16:24, 6 December 2023
  • Datatilsynet (Denmark) - 2019-41-0029 (category Article 32 GDPR)
    with the requirements of Article 32 (2) of the Data Protection Regulation. 1 and Article 5 (1). 2, cf. Article 32 (1) (f), cf. 1 and 2. It is clear, among
    18 KB (2,699 words) - 16:25, 6 December 2023
  • Commissioner (Cyprus) - 11.17.001.010.064 (category Article 5(1)(f) GDPR)
    case the data subject. Violation of Article 24(1) GDPR The DPA determined that the controller violated Article 24(1) GDPR, because the controller did not implement
    6 KB (664 words) - 09:41, 30 November 2022
  • BAC (Bulgaria) - 2606/2021 (category Article 32 GDPR)
    CPDP issued NRA an order under Article 58(2)(d) supra Article 57(1)(a) and Article 83(2)(a), (c), (d), (f) and (g) of the GDPR for undertaking suitable technical
    13 KB (1,761 words) - 09:58, 14 December 2023
  • AEPD (Spain) - PS/00390/2019 (category Article 32 GDPR)
    II Article 6.1 of the GDPR establishes the assumptions that allow the processing of personal data to be considered lawful. Article 32 of the GDPR provides
    12 KB (1,838 words) - 14:34, 13 December 2023
  • ANSPDCP (Romania) - Actamedica SRL (category Article 15(1) GDPR)
    of processing. This lead to a security incident, in breach of Article 28(1) and 32 GDPR, for which the controller was fined RON 9,836.6 (approximately
    7 KB (900 words) - 15:23, 13 December 2023
  • DSB (Austria) - D130.073/0008-DSB/2019 (category Article 32 GDPR)
    user registrations, the respondent violated Article 5 GDPR, Article 6 GDPR, and Article 32 GDPR, and § 1 para 1 DSG (the Austrian Data Protection Act), which
    25 KB (3,605 words) - 13:59, 12 May 2023
  • AEPD (Spain) - PS/00322/2020 (category Article 5(1)(f) GDPR)
    data integrity, security and confidentiality under Article 5(1)(f) GDPR. For the violation of Article 32, the AEPD issued the law firm with a reprimand and
    26 KB (3,840 words) - 14:28, 13 December 2023
  • ANSPDCP (Romania) - S.C. Marsorom S.R.L. (category Article 5(1)(e) GDPR)
    limitation principle enshrined in Article 5(1)(e) GDPR, and also failed to fulfill its obligation under Articles 25 and 32 GDPR. Consequently, the DPA issued
    4 KB (391 words) - 15:20, 13 December 2023
  • Datatilsynet (Denmark) - 2019-32-0988 (category Article 5(1)(e) GDPR)
    Agency's decision 3.1. Authorization to record telephone conversations 3.1.1. Pursuant to Article 9 (1) of the Data Protection Regulation 1, there is in principle
    45 KB (7,151 words) - 16:24, 6 December 2023
  • AEPD (Spain) - EXP202204631 (category Article 5(1)(f) GDPR)
    comes regulated in article 32 of the GDPR. II Article 5.1.f) of the GDPR Article 5.1.f) of the GDPR establishes the following: "Article 5 Principles relating
    36 KB (5,485 words) - 13:19, 13 December 2023
  • HDPA (Greece) - 4/2022 (category Article 5(1)(a) GDPR)
    under Article 35(7) GDPR, for not complying with the principle of transparency under Article 5(1) GDPR and for not anonymising the data under Article 25(1)
    11 KB (1,274 words) - 10:37, 23 February 2022
  • AEPD (Spain) - EXP202200399 (category Article 5(1)(f) GDPR)
    Spanish DPA fined a magazine company €31,200 for violating Articles 5(1)(f), 32, and 33 GDPR because of a personal data security breach caused by vulnerabilities
    10 KB (1,343 words) - 13:13, 13 December 2023
  • AEPD (Spain) - EXP202104873 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    24 KB (3,512 words) - 10:43, 13 December 2023
  • Datatilsynet (Norway) - 20/02291 (category Article 5(1)(f) GDPR)
    patient data cf. Article 32 GDPR and Article 5(1)(f) GDPR and inadequate internal controls cf. Article 24 GDPR and Article 5(2) GDPR. Østfold Hospital
    45 KB (6,645 words) - 14:40, 28 March 2022
  • TGI Paris - N° 14/07224 (category Article 5(1)(d) GDPR)
    offered and / or concluded after July 1, 2016, articles L.211-1, L.212-3, L.212-1, L.241-1, R.212-1 / 1 °, L .111-1, L.111-2, L.111-3, L.221-5, L.221-6,
    392 KB (67,730 words) - 15:27, 17 March 2022
  • Datatilsynet (Norway) - 21/00480 (category Article 5(1)(f) GDPR)
    municipality €409,768 (NOK 4,000,000) for breaches of Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack led to highly
    31 KB (4,380 words) - 06:12, 14 March 2023
  • AEPD (Spain) - PS/00099/2022 (category Article 5(1)(f) GDPR)
    controller with €10,000 for the violation of Article 5(1)(f) GDPR and €25,000 for the violation of Article 32 GDPR. There is a pattern in the Spanish DPA resolutions
    38 KB (5,920 words) - 12:43, 13 December 2023
  • AZOP (Croatia) - Decision 31-05-2022 (category Article 32 GDPR)
    Data Protection Agency, OIB: 28454963989 based on Article 57 paragraph 1 and Article 58 paragraph 1 of Regulation (EU) 2016/679 of the European Parliament
    17 KB (2,433 words) - 15:45, 30 October 2023
  • HDPA (Greece) - 38/2019 (category Article 4(1) GDPR)
    consent valid? The HDPA found that: 1) The telephone number constitutes personal data according to Article 4(1) GDPR as the owner can be indirectly identified
    4 KB (347 words) - 15:37, 6 December 2023
  • AP (The Netherlands) - z2018-02009 (category Article 32 GDPR)
    (hereinafter: the GDPR) applies on 25 May 2018 become. The GDPR imposes the same obligation in Article 32, paragraph 1, as it applied under Article 13 6. The UWV
    33 KB (5,112 words) - 17:10, 12 December 2023
  • Guarantor no. 1/2019 are met. Pursuant to Article 78 of the Regulation, Article 152 of the Code and Article 10 of Legislative Decree no. 150 of 1 September
    20 KB (3,133 words) - 15:53, 6 December 2023
  • AEPD (Spain) - E/06179/2019 (category Article 32 GDPR)
    for a possible personal data breach affecting confidentiality, as per Article 32 GDPR. The decision is the consequence of the notification of a possible personal
    6 KB (386 words) - 13:40, 13 December 2023
  • AEPD (Spain) - PS/00335/2020 (category Article 5(1)(f) GDPR)
    protocols. This therefore breached Article 5(1)(f) GDPR and Article 32 GDPR. The initial sanction for infringing Article 5(1)(f) was a fine of €5000 and the
    34 KB (5,427 words) - 14:30, 13 December 2023
  • Datatilsynet (Denmark) - 2019-431-0048 (category Article 28(1) GDPR)
    municipalities has not complied with Article 28 (1) of the Data Protection Regulation. Article 32 (3) (f), cf. Article 32, as the company has not implemented
    18 KB (2,633 words) - 16:36, 6 December 2023
  • AEPD (Spain) - PS/00247/2019 (category Article 32(2) GDPR)
    employee of the entity - infringes Article 32. 2 and 32.4 of the RGPD, an infringement punishable under Article 83.4.a of the GDPR. Assessing the circumstances
    39 KB (6,720 words) - 14:22, 13 December 2023
  • Datatilsynet (Denmark) - 2019-431-0036 (category Article 32 GDPR)
    without implementing the appropriate security measures as required by Article 32 GDPR. The server was internally classified as an internal developer box and
    14 KB (1,696 words) - 16:30, 6 December 2023
  • unlawfully, as it breached Articles 5 and 6(1) GDPR. For this violation, the DPA used its powers under Article 82(5)(a) and fined the association with €500
    6 KB (779 words) - 15:16, 13 December 2023
  • destruction. As an effect, the processor has been fined RON 7 331,85 (approx EUR 1 500). Share your comments here! Share blogs or news articles here! The decision
    4 KB (508 words) - 15:17, 13 December 2023
  • AEPD (Spain) - EXP202200471 (category Article 5(1)(f) GDPR)
    the violation of Article 5(1)(f) GDPR and €30,000 for the violation of Article 32 GDPR. According to the national legislation (Article 76(2)(b) LOPDGDDon
    40 KB (6,014 words) - 13:21, 13 December 2023
  • AEPD (Spain) - PS/00212/2019 (category Article 32 GDPR)
    typified in article 83.4 of the RGPD and is qualified as serious in article 73.1 g) of the LOPDPGDD for prescription purposes.III Article 58.Article 58.2 of
    17 KB (2,518 words) - 14:11, 13 December 2023
  • AP (The Netherlands) - 24.03.2020 (category Article 32 GDPR)
    volition investigation into CP&A's compliance with Article 9, as well as Article 32 GDPR. Since Article 9 GDPR prohibits the processing of special categories
    48 KB (7,461 words) - 17:04, 12 December 2023
  • AEPD (Spain) - EXP202104006 (category Article 5(1)(f) GDPR)
    party, respectively. III Article 5.1.f) of the GDPR Article 5.1.f) “Principles relating to processing” of the GDPR establishes: "1. The personal data will
    31 KB (4,578 words) - 12:11, 6 March 2024
  • AEPD (Spain) - EXP202201718 (category Article 32 GDPR)
    functions assigned to the control authorities in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) 2016/679 (General Data Protection
    10 KB (1,503 words) - 10:35, 13 December 2023
  • Personvernnemnda (Norway) - 2022-13 (21/00481) (category Article 5(1)(f) GDPR)
    controller) about €352,555 (NOK 4,000,000) for violating Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack led to highly
    45 KB (6,913 words) - 12:13, 15 March 2023
  • controller under the GDPR. The data controller did not process personal data with an appropriate level of security, as required by article 32, read in conjunction
    34 KB (4,967 words) - 15:46, 6 December 2023
  • AEPD (Spain) - PS/00280/2022 (category Article 5(1)(f) GDPR)
    with NIF C28328508, for an infringement of article 5.1.f) of the RGPD and for a second infringement of article 32 of the RGPD, typified respectively in articles
    30 KB (4,551 words) - 11:51, 9 February 2023
  • HDPA (Greece) - 36/2022 (category Article 5(1)(a) GDPR)
    the Article 33 GDPR. The DPA also ordered the controller to communicate the data breach to the affected data subjects pursuant to Article 34 GDPR. The
    11 KB (1,522 words) - 09:35, 13 September 2022
  • AEPD (Spain) - E/08158/2019 (category Article 32 GDPR)
    domicile in AV. DE AMERICA, NUM 9, PORTAL A, PISO -1, PTA. 1 - 28022 MADRID. RESULT OF THE INVESTIGATION 1: Once a request for information has been made to
    14 KB (2,108 words) - 13:41, 13 December 2023
  • AEPD (Spain) - PS/00185/2020 (category Article 32 GDPR)
    security of processing (Article 32 GDPR), the transparency principle (Article 13 GDPR) and its information duties related to cookies (Article 22(2) of the Spanish
    20 KB (3,162 words) - 14:08, 13 December 2023
  • Guarantor pursuant to Article 166(7) of the Code" (Article 16(1) of the Regulation of the EDPS). 16(1) of the Garante's Regulation No. 1/2019). In this regard
    24 KB (3,672 words) - 15:54, 6 December 2023
  • AEPD (Spain) - PS/00389/2019 (category Article 32 GDPR)
    reports concerning workers of the respondent. Is it compliant with Article 32 of the GDPR to leave at sight in the street data concerning the medical reports
    31 KB (4,819 words) - 14:34, 13 December 2023
  • AEPD (Spain) - EXP202105669 (category Article 5(1)(f) GDPR)
    regulated in article 32 of the GDPR, which regulates the security of the treatment. IV. Article 5.1.f) of the GDPR Article 5.1.f) of the GDPR establishes
    45 KB (6,998 words) - 12:58, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/32/4 (category Article 5(1) GDPR)
    basis of Article 58(2)(b) of the GDPR because its processing activities infringed Articles 5(1)(a)(b) and (c), 6(1), 12(1)-(5), 15(1) and 17(1) of the GDPR
    75 KB (12,586 words) - 10:10, 17 November 2023
  • Datatilsynet (Denmark) - 2022-63-0003 (category Article 5(1)(f) GDPR)
    police. The DPA assessed the appropriate sanctions in accordance with Article 83(2) GDPR and suggested a fine of approximately €67,000 (DKK 500,000). The DPA
    6 KB (769 words) - 08:12, 3 August 2022
  • Court of Appeal of Brussels - 2022/AR/292 (category Article 5(1)(f) GDPR)
    companies that use the TC-string? (Article 4(1) GDPR) 2) a) Is IAB a (joint) controller (Article 4(7) GDPR and Article 24(1) GDPR)? b) Does it matter whether
    6 KB (675 words) - 09:55, 14 December 2023
  • AZOP (Croatia) - Decision 05-10-2023 (category Article 32 GDPR)
    privacy policies, which is contrary to Article 12 paragraph 1 of the GDPR and, in this regard, to Article 13 paragraphs 1 and 2; 5. For the recording of telephone
    13 KB (1,934 words) - 20:55, 1 November 2023
  • AEPD (Spain) - PS/00187/2020 (category Article 5(1)(f) GDPR)
    by the alleged violation of Article 32 of the RGPD, Article 5.1.f) of the RGPD, Article 25 of the RGPD, typified in Article 83.5 of the RGPD. FOURTH: On
    51 KB (7,770 words) - 14:08, 13 December 2023
  • ANSPDCP (Romania) - SC CNTAR TAROM SA (category Article 32 GDPR)
    data security, finding the violation of the provisions of art. 32 para. (4), art. 32 para. (1) lit. b) and par. (2) of the General Regulation on Data Protection
    3 KB (380 words) - 15:21, 13 December 2023
  • a violation of Article 5(1)(b) GDPR. As a result, the DPA issued a reprimand to the controller in accordance with Article 58(2)(b) GDPR. Generally, a controller
    20 KB (2,859 words) - 13:11, 13 March 2024
  • CNIL (France) - MED-2019-025 (category Article 5(1)(c) GDPR)
    two-months period to comply with the GDPR. The controller had two months to comply with Articles 5(1)(c), 13, 28, 30(1) and 32 GDPR. In its latest order, the CNIL
    23 KB (3,471 words) - 17:07, 6 December 2023
  • AEPD (Spain) - EXP202208091 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    40 KB (6,014 words) - 13:24, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.001 (category Article 5(1)(f) GDPR)
    obligation under the articles5 (1) (f), 5 (2), 15, 32 and 33 of the Regulation, as well as article 33 (1) (y) of Law 125 (1) / 2018and she was asked to submit
    61 KB (9,412 words) - 16:52, 6 December 2023
  • CNIL (France) - SAN-2022-022 (category Article 17(1)(a) GDPR)
    ensure the security of personal data (Article 32 GDPR) The DPA held that the controller violated Article 32 GDPR because of several reasons. Password requirements:
    59 KB (9,623 words) - 17:03, 6 December 2023
  • APD/GBA (Belgium) - 19/2020 (category Article 5(1)(b) GDPR)
    f) GDPR) (and the obligations arising from it – Article 32 GDPR) and the principle of purpose (Article 5 § 1 b) GDPR) which the principle of security guarantees
    39 KB (6,246 words) - 16:55, 12 December 2023
  • APD/GBA (Belgium) - 19/2021 (category Article 32 GDPR)
    right to object under Article 21(2) GDPR in conjunction with Article 12(1) GDPR, Article 12(2) GDPR, Article 13 GDPR and Article 14 GDPR. Telenet asked for
    10 KB (1,290 words) - 16:55, 12 December 2023
  • Datatilsynet (Norway) - 20/01626 (category Article 5(1)(a) GDPR)
    processing as per Article 5(1)(b), nor legal grounds as per Article 6. In sum, the DPA found that NIF had breached Article 5(1)(a), (c) and (f), Article 6, and Article
    50 KB (8,081 words) - 18:52, 5 March 2022
  • AEPD (Spain) - PS/00129/2022 (category Article 32 GDPR)
    typified in the article 83.5 of the RGPD, and for the violation of article 32 of the RGPD, classified in the article 83.4 of the GDPR. The aforementioned
    22 KB (3,420 words) - 12:59, 13 December 2023
  • HDPA (Greece) - 9/2024 (category Article 5(1)(a) GDPR)
    violation of Article 32 GDPR in ten cases due to inadequate security measures. Similarly, Plegma Net was found to be in violation of Article 32 GDPR in ten cases
    102 KB (17,186 words) - 13:46, 26 April 2024
  • ascertained, that pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor no. 1/2019, this measure should
    34 KB (5,420 words) - 15:51, 6 December 2023
  • AEPD (Spain) - E/08452/2019 (category Article 32 GDPR)
    violation of security. 1.1. Categories of affected: Aid applicants (minors and their representatives). 1.2. Number of records: 100 1.3. Committed personal
    11 KB (1,651 words) - 13:42, 13 December 2023
  • APD/GBA (Belgium) - 170/2023 (category Article 32 GDPR)
    action under article 100, § 1, 1° of the st LCA, since no violation of the GDPR can be found in this regard. In accordance with article 108, § 1 of the LCA
    24 KB (3,525 words) - 15:29, 26 January 2024
  • pursuant to art. 32, paragraph 1, GDPR - the nature, context and purposes, it emerges that the sharing of the agicwhistle \ spadmin user: 1. has never provided
    115 KB (18,595 words) - 11:30, 16 August 2022
  • AEPD (Spain) - PS/00254/2019 (category Article 32 GDPR)
    infringement of Article 32.1 of the GDPR typified as a serious infringement in Article 73 f) of the LOPDGDD and in Article 83.4 of the GDPR. For its part
    39 KB (6,341 words) - 14:23, 13 December 2023
  • AEPD (Spain) - PS/00448/2020 (category Article 5(1)(f) GDPR)
    €150,000 on Xfera Móviles S.A. (defendant) for infringing Article 17, 32, 5(1)(f) GDPR and Article 21 LSSI. The fine was imposed after investigating two complaints
    45 KB (7,217 words) - 14:40, 13 December 2023
  • Datatilsynet (Denmark) - 2020-441-4364 (category Article 5(1)(a) GDPR)
    complied with Article 32 (1) of the Data Protection Regulation. 1 and 2, Article 33, para. Article 34 (3) (d) 1 and 2, and Article 5, para. 1, letter a. The
    33 KB (5,347 words) - 16:39, 6 December 2023
  • Council of State - 251.378 (category Article 28(1) GDPR)
    ruling and the GDPR; breach of Article 28 GDPR (the choice of a the processor does not provide sufficient guarantees); breach of Article 32 GDPR (lack of appropriate
    40 KB (6,324 words) - 15:34, 1 September 2021
  • AP (The Netherlands) - 04.11.2019 (category Article 32 GDPR)
    companies Menzis and VGZ € 50.000 for insufficient security measures under Article 32 GDPR. Translated summary by the AP (The Netherlands): In 2018, the Authority
    36 KB (5,914 words) - 17:13, 12 December 2023
  • breach of Article 28 paragraphs 3 and 4 of the GDPR is clear. 2. On the breach of the obligation to ensure data security 49. According to Article 32 of the
    56 KB (9,069 words) - 17:02, 6 December 2023
  • AEPD (Spain) - E/05724/2019 (category Article 32 GDPR)
    domicile in AV. DE AMERICA, NUM 9, PORTAL A, PISO -1, PTA. 1 - 28022 MADRID. RESULT OF THE INVESTIGATION 1: Once a request for information has been made to
    14 KB (2,124 words) - 13:40, 13 December 2023
  • APD/GBA (Belgium) - 22/2020 (category Article 5(1)(f) GDPR)
    provisions of Article 5.1 of the AVG, but concerns the entire AVG. 31. The aforementioned follows from the merger of Article 5.2 of the AVG and Article 24.1 of the
    35 KB (5,526 words) - 16:56, 12 December 2023
  • AEPD (Spain) - PS/00268/2022 (category Article 5(1)(f) GDPR)
    infringement of Article 5.1.f) of the RGPD, Article 33 of the RGPD, Article 25 of the RGPD and Article 32 of the RGPD, typified in Article 83.5 of the RGPD
    63 KB (9,551 words) - 12:33, 13 December 2023
  • CNIL (France) - SAN-2024-002 (category Article 5(1)(e) GDPR)
    purpose constituted a breach of Article 5(1)(e) GDPR. Secondly, the CNIL indicated that the controller breached Article 13 GDPR by failing to include the right
    56 KB (8,757 words) - 14:12, 28 February 2024
  • in the tax information portals had in any case violated Article 5(1)(a) GDPR and Article 32 GDPR, because the large-scale and permanent publication of personal
    44 KB (6,893 words) - 10:28, 25 March 2024
  • ensure the security of personal data pursuant to Article 32 of the GDPR Article 32 of the Rules provides: 1. Taking into account the state of knowledge, the
    69 KB (11,007 words) - 17:10, 6 December 2023
  • DSB (Austria) - 2021-0.586.257 (category Article 4(1) GDPR)
    identifier) pursuant to Article 4(1) of the GDPR. c) Combination with other elements The fulfillment of Article 4(1) of the GDPR becomes even more apparent
    108 KB (17,097 words) - 13:52, 12 May 2023
  • AEPD (Spain) - E/08205/2019 (category Article 5(1)(f) GDPR)
    administrative procedure according to the provisions of article 114.1.c) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations
    17 KB (2,577 words) - 13:42, 13 December 2023
  • CNIL (France) - 2023-089 (category Article 5(1)(f) GDPR)
    during the implementation of the processing, in line with Article 5(1)(f) GDPR and Article 32 GDPR. Additionally, regarding the access to personal data and
    23 KB (3,397 words) - 17:12, 6 December 2023
  • identify the customers, while the customers' name only is not sufficient. Article 87 GDPR regulates the processing of a national identity number. This is also
    12 KB (1,810 words) - 13:07, 3 March 2024
  • Datatilsynet (Norway) - 20/01896 (category Article 6(1)(f) GDPR)
    rating without a legal basis under Article 6(1)(f) GDPR and for not adhering to the accountability principle as per Article 5(2). The DPA also requires that
    28 KB (4,387 words) - 18:58, 5 March 2022
  • AEPD (Spain) - PS/00029/2020 (category Article 5(1)(f) GDPR)
    required by Article 35(3)(b). The AEPD also held that there had a been a violation of Article 32 because of a failure to comply with GDPR security measure
    44 KB (6,943 words) - 13:49, 13 December 2023
  • the data processed (Article 5, paragraph 1, letter d) of the Regulation), nor in terms of safety and integrity (Article 5, paragraph 1, letter f) of the
    50 KB (8,001 words) - 15:52, 6 December 2023
  • processing carried out is in violation of Article 5(1)(f) GDPR, Article 25(1) GDPR, Article 32 GDPR and Article 35 GDPR. Especially, the controller cannot exclude
    119 KB (19,123 words) - 11:29, 16 August 2022
  • the Guarantor pursuant to Article 166, paragraph 7, of the Code "(Article 16, paragraph 1, of the Guarantor Regulation no. 1/2019). In this regard, taking
    83 KB (13,648 words) - 11:30, 16 August 2022
  • AEPD (Spain) - PS/00028/2022 (category Article 5(1)(f) GDPR)
    confidentiality. Second, the DPA found a violation of Article 32 GDPR. The DPA held Article 32 GDPR requires the controller to have a complete protocol that
    58 KB (9,301 words) - 12:39, 13 December 2023
  • AZOP (Croatia) - Decision 18-05-2023 (category Article 6(1) GDPR)
    was fined €380,000 for violating Articles 6(1), 13(1) and (2), and 25(1) and (2) and 32(1)(a) and (d) GDPR. A sports betting agency, acting as the controller
    9 KB (1,276 words) - 15:25, 30 October 2023
  • Datatilsynet (Denmark) - 2020-432-0034 (category Article 5(1)(f) GDPR)
    of Article 5 of the Data Protection Regulation. Article 6 (1) (a) and (c) and Article 6 (1) 1, letter e, and the Data Protection Act § 11, para. 1. However
    40 KB (6,369 words) - 16:39, 6 December 2023
  • APD/GBA (Belgium) - 05/2021 (category Article 5(1)(f) GDPR)
    of 25,000 euros (Article 83, paragraph 2 GDPR; Article 100, §1, 13 ° WOG and Article 101 WOG). 18 55. Taking into account article 83 GDPR and the case law
    60 KB (9,281 words) - 16:50, 12 December 2023
  • CNIL (France) - SAN-2022-020 (category Article 5(1)(e) GDPR)
    obligations arising from Article 5(1)(e) of the GDPR. D. On the breach of the transparency obligation 36. Article 12(1) of the GDPR provides that "the controller
    59 KB (9,566 words) - 17:03, 6 December 2023
  • APD/GBA (Belgium) - 07/2021 (category Article 5(1) GDPR) (section Complaint to defendant 1)
    infringement of Article 5.1 b) in conjunction with Article 6.4. AVG, on article 5.1 a) in conjunction with article 6.1. AVG and on article 5.1 c) GDPR has been
    72 KB (11,208 words) - 16:51, 12 December 2023
  • AP (The Netherlands) - 31.05.2021 (category Article 32 GDPR)
    evaluated its own security measures. The AP emphasised that under Article 32(1) and (2) GDPR, the more ‘sensitive’ data are, the greater threat the data poses
    106 KB (14,502 words) - 17:09, 12 December 2023
  • AZOP (Croatia) - Decision 04-07-2022 (category Article 6(1) GDPR)
    space. The DPA found a violation of Article 6(1) GDPR and ordered the controller, pursuant to Article 58(2)(d) GDPR, to adjust the location of the cameras
    14 KB (2,038 words) - 15:20, 30 October 2023
  • CJEU - C-77/21 - Digi (category Article 5(1)(b) GDPR)
    regarding Articles 5(1)(b) GDPR and 5(1)(e) GDPR and held that national courts had to determine, using the factors of Article 6(4) GDPR, whether further processing
    49 KB (7,800 words) - 09:22, 5 January 2024
  • Datatilsynet (Norway) - 20/01949 (category Article 5(1)(d) GDPR)
    transparency, cf. Article 5(1)(a), and accuracy, cf. Article (5)(1)(d), they hadn't recorded the processing activity as required in Article 30, hadn't conducted
    49 KB (7,572 words) - 16:14, 6 December 2023
  • AEPD (Spain) - PS/00024/2019 (category Article 5(1)(f) GDPR)
    the principle of confidentiality, namely Article 5(1)(f) GDPR, and thus, it did not comply with Article 5(2) GDPR referred as the principle of "proactive
    53 KB (8,593 words) - 13:47, 13 December 2023
  • GHAL - 200.307.462 (category Article 10 GDPR)
    process the data under Article 10 GDPR. The Court rejected an argument from Brein that article 6:162 BW could be used besides Articles 32 and 33 UAVG to provide
    28 KB (4,573 words) - 10:04, 14 December 2023
  • regulation[1] article 5, subsection 2, cf. Article 5, subsection 1, letters c and f, and Article 5, subsection 1, letter a, cf. Article 6, subsection 1, and
    117 KB (18,075 words) - 10:19, 12 September 2022
  • the different violations described above. The fine was applied pursuant pre-GDPR legislation, owing to the fact that the breaches and the following notification
    27 KB (4,203 words) - 15:49, 6 December 2023
  • CNIL (France) - SAN-2020-009 (category Article 5(1)(a) GDPR)
    requirements of Article 13 of the Regulation. C. On the breach relating to cookies 69. Article 82 of the Data Protection Act (Article 32.II in a wording
    48 KB (7,404 words) - 17:09, 6 December 2023
  • AEPD (Spain) - PS/00473/2019 (category Article 32 GDPR)
    the article 43.1 of said Law. C / Jorge Juan, 6 www.aepd.es 28001 - Madrid sedeagpd.gob.es Page 12 12/12 II Article 85 of Law 39/2015, of October 1, of
    35 KB (5,635 words) - 14:41, 13 December 2023
  • APD/GBA (Belgium) - 15/2021 (category Article 15(1) GDPR)
    (see “1.2.4- As regards the complaint according to which the defendant hadless time than the complainant to prepare his arguments ”).1.1.1. Place1.1.1.1.-
    85 KB (13,724 words) - 16:52, 12 December 2023
  • LG Magdeburg - 9 O 1571/20 (category Article 6(1) GDPR)
    Manifestation of the general right of personality, Article 2 Paragraph 1 GG in conjunction with Article 1 Paragraph 1 GG, or from Section 823 Paragraph 2 BGB in
    27 KB (4,216 words) - 13:26, 8 January 2024
  • CNIL (France) - SAN-2020-008 (category Article 5(1)(e) GDPR)
    Articles 5-1 e), 12, 13, 15, 17, 21, 32 and 33 of the RGPD, Article L34-5 of the French Post and Electronic Communications Code and Article 82 (formerly 32.II)
    104 KB (16,646 words) - 17:09, 6 December 2023
  • CE - N° 433311 (category Article 5(1)(e) GDPR)
    company for faulty website security (article 32 GDPR) and violation of the storage limitation principle (article 5(1)(e) GDPR). After a complaint in 2018, the
    18 KB (2,677 words) - 09:50, 10 September 2021
  • AEPD (Spain) - EXP202210237 (category Article 6(1) GDPR)
    fact that the processing of the controller relied on Article (6)(1)(b) GDPR and Article 6(1)(c) GDPR as legal basis affects the holding of the DPA since
    32 KB (4,780 words) - 10:44, 13 December 2023
  • Articles 5(1)(a), 12(1) and 13(1)(c) GDPR within three months, to refer not only to information provided on data processed pursuant to Article 6(1)(b) GDPR, but
    53 KB (8,413 words) - 14:10, 30 January 2023
  • LG Essen - 6 O 190/21 (category Article 33 GDPR)
    the controller's premises, constituting a violation of Article 24, Article 25(1), or Article 32 GDPR. The alleged loss of the data did not occur at the controller's
    28 KB (4,596 words) - 18:30, 18 November 2021
  • HDPA (Greece) - 44/2019 (category Article 5(1) GDPR)
    internal compliance and accountability according to Article 5(1) GDPR, Article 5(2) GDPR and Article 6(1) GDPR. Since the company had totally ignored the its
    127 KB (21,184 words) - 15:39, 6 December 2023
  • APDCAT (Catalonia) - PS 49/2019 (category Article 5(1)(a) GDPR)
    out by the school). Article 9 GDPR, for having processed biometric data without any valid ground from Article 9(2). Article 13 GDPR, for not having informed
    38 KB (5,760 words) - 08:26, 8 September 2021
  • OLG Hamm - 7 U 19/23 (category Article 82 GDPR)
    Art. 82 Para. 1, Para. 2, Art. 5 Para. 1 lit. a Var. 1, Article 6 paragraph 1 subparagraph. 1 lit. 1, Article 6 paragraph 1 subparagraph. 1 lit. a, Art.
    130 KB (21,874 words) - 09:43, 15 February 2024
  • asked whether the joint control of data in accordance with Article 4(7) and Article 26(1) GDPR must be interpreted 'exclusively' as involving deliberately
    9 KB (1,234 words) - 12:48, 25 January 2024
  • AEPD (Spain) - PS/00044/2020 (category Article 13 GDPR)
    of article Article 24.1, and in relation to the obligations referred to in the previous section, The information obligation provided for in Article 5 of
    39 KB (6,270 words) - 13:51, 13 December 2023
View (previous 500 | ) (20 | 50 | 100 | 250 | 500)