Search results

From GDPRhub
  • Court of Appeal of Brussels - 2020/AR/1111 (category Article 58(2) GDPR)
    ofcontroller (article 4.7 of the GDPR), the scope of the GDPR (article3.1 of the GDPR), the right to erasure (article 17 of the GDPR) and its powers (article 58.2of
    37 KB (5,919 words) - 08:54, 20 August 2021
  • CNIL (France) - SAN-2024-002 (category Article 5(1)(e) GDPR)
    ". 26. Article D. 213-1 of the same code provides that "[t]he amount mentioned in article L. 213-1 is set at 120 euros" and article D. 213-2 provides
    56 KB (8,757 words) - 14:12, 28 February 2024
  • AEPD (Spain) - PS/00275/2019 (category Article 5(1)(f) GDPR)
    regard to paragraph (k) of Article 83.2 of the GDPR, the LOPDGDD, Article 76, 'Sanctions and corrective measures', provides: '2.k) of Regulation (EU) 2016/679
    21 KB (3,335 words) - 14:25, 13 December 2023
  • analyse the criteria set out in Article 83.2 of the GDPR. 61. As regards the nature and seriousness of the breach (Article 83(2)(a) of the RGPD), it points
    55 KB (9,079 words) - 16:57, 6 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.222 (category Article 58 GDPR)
    Based information provided and the authority granted by Article 58 and 83 GDPR, as well as Article 24(b) of National Law 125(I)/2018, the DPA came to the
    16 KB (2,438 words) - 09:07, 9 June 2023
  • AEPD (Spain) - PS/00093/2019 (category Article 5(1)(f) GDPR)
    parties (Article 83.2.k of the RGPD in relation to Article 76.2.b of the LOPDGDD) - The turnover or activity figure of the entity (article 83.2.a, of the
    37 KB (5,995 words) - 13:58, 13 December 2023
  • a, 13.1.c, 13.2.d, 13.2.a and 13.2.e between 15 June and 2 December 2020 as regards departures. (b) infringements that took place from 2 December 2020
    206 KB (30,485 words) - 09:54, 14 December 2023
  • AEPD (Spain) - EXP202103878 (category Article 6(1) GDPR)
    Articles 57(1) and 58(2) GDPR for the processing of personal data without the consent of the data subject, as foreseen in Article 6 GDPR. Firstly, the DPA
    20 KB (3,035 words) - 10:33, 13 December 2023
  • HDPA (Greece) - 51/2021 (category Article 22 GDPR)
    more details. Article 2: Substantive scope Article 2.2.c: Exclusively personal or domestic activity Article 3: Territorial scope Article 4.1: Personal
    9 KB (1,168 words) - 15:30, 6 December 2023
  • AEPD (Spain) - PS/00034/2020 (category Article 5(1)(f) GDPR)
    in accordance with the provisions of Article 58.2 of the RGPD and in articles 47 and 48.1 of the LOPDGDD. II Article 6.1 of the RGPD, establishes the cases
    18 KB (2,727 words) - 13:50, 13 December 2023
  • AEPD (Spain) - PS/00010/2020 (category Article 83(2)(b) GDPR)
    regard to article 83.2 (k) of the RGPD, the LOPDGDD, article 76, "Sanctions and corrective measures", provides: "2. In accordance with Article 83(2)(k) of
    22 KB (3,523 words) - 13:45, 13 December 2023
  • AEPD (Spain) - PS/00076/2021 (category Article 6(1) GDPR)
    mentioned by the claimant. FOUNDATIONS OF LAW I By virtue of the powers that article 58.2 of the RGPD recognizes to each authority of control, and as established
    15 KB (2,292 words) - 13:56, 13 December 2023
  • RESOLVES: FIRST: IMPOSE D. A.A.A. (BEINNOVA.ES) with NIF.:***NIF.1, a sanction of 2,000 euros (two thousand euros), for violation of article 21 of the LSSI. SECOND:
    14 KB (2,070 words) - 13:43, 13 December 2023
  • AEPD (Spain) - PS/00280/2022 (category Article 5(1)(f) GDPR)
    clients. v Article 58.2 of the RGPD provides the following: "Each control authority will have of all the following corrective powers indicated below: d) order
    30 KB (4,551 words) - 11:51, 9 February 2023
  • AEPD (Spain) - PS/00278/2019 (category Article 83(2) GDPR)
    infringement.In relation to Article 83(2)(k) of the GDPR, the LOPDGDD, in its Article 76, "Sanctions and corrective measures", states that: "2. In accordance with
    23 KB (3,672 words) - 14:25, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.001 (category Article 5(2) GDPR)
    addition to or instead of the measures referred to in Article 58 ( 2 ) (a) to (h) andin Article 58 ( 2 ) (j). When making an administrative decisionas well
    61 KB (9,412 words) - 16:52, 6 December 2023
  • AEPD (Spain) - PS/00235/2020 (category Article 6(1) GDPR)
    agent of *** TELEPHONE. 2 that processed the request to change the owner. FOUNDATIONS OF LAW I By virtue of the powers that article 58.2 of the RGPD recognizes
    24 KB (3,766 words) - 14:21, 13 December 2023
  • APD/GBA (Belgium) - 39/2020 (category Article 5(1)(f) GDPR)
    their rights'. 91. The rights referred to in Article 14(1)(c), (d) and (e) and in Article 14(2)(a), (b), (d) and (g) AVG such information shall not be required
    62 KB (10,509 words) - 16:58, 12 December 2023
  • AP (The Netherlands) - 4.02.2021 (category Article 8 GDPR)
    The interpretation of article 13 of the Wbp is no different from that of article 32 of the GDPR, described in paragraphs 2.3.2 and 2.3.3. Also in the period
    57 KB (8,053 words) - 17:07, 12 December 2023
  • AEPD (Spain) - PS/00059/2020 (category Article 28 GDPR)
    violation of article 21 of the LSSICE, classified as serious in article 38.3.d) and c) of said rule, for the alleged infringement of article 48.1.b) of the
    287 KB (48,336 words) - 13:53, 13 December 2023
  • AEPD (Spain) - EXP202104875 (category Article 5(1)(f) GDPR)
    gob.es 4/19 FUNDAMENTALS OF LAW Yo By virtue of the powers that article 58.2 of the GDPR recognizes to each control authority, and as established in articles
    54 KB (8,451 words) - 13:35, 13 December 2023
  • ANSPDCP (Romania) - 12.01.2023 (category Article 32(2) GDPR)
    Hence, the controller violated Articles 32(1)(b) and 32(2) GDPR. Pursuant to its Article 58(2) GDPR statutory powers, the DPA ordered the controller to implement
    5 KB (613 words) - 15:13, 13 December 2023
  • AEPD (Spain) - PS/00333/2019 (category Article 58(2) GDPR)
    infringement of article 5.1(b), as defined in Article 83(5)(a) and considered for the purposes of the statute of limitations in Article 72(1)(a), a fine
    16 KB (2,625 words) - 14:29, 13 December 2023
  • AEPD (Spain) - PS/00028/2022 (category Article 5(1)(f) GDPR)
    " Regarding section k) of article 83.2 of the GDPR, the LOPDGDD, article 76, "Sanctions and corrective measures", provides: "2. In accordance with the provisions
    58 KB (9,301 words) - 12:39, 13 December 2023
  • AEPD (Spain) - PS/00334/2020 (category Article 6(1) GDPR)
    Sections b), d) and i) of article 58.2 of the RGPD provide the following: C / Jorge Juan, 6 www.aepd.es 28001 - Madrid sedeagpd.gob.es 4/6 “2 Each supervisory
    16 KB (2,328 words) - 14:30, 13 December 2023
  • is contrary to the EU General Data Protection Regulation (GDPR). Article 54.1 (d) of the GDPR states that the period of employment of an official at the
    46 KB (7,394 words) - 14:08, 21 March 2024
  • HDPA (Greece) - 35/2023 (category Article 4(12) GDPR)
    violation of Article 33 GDPR. 11. Based on the above, the Authority considers that there is a case to exercise the v the article 58 par. 2 of the GDPR corrective
    52 KB (8,460 words) - 10:54, 10 January 2024
  • AEPD (Spain) - EXP202200429 (category Article 5(1)(c) GDPR)
    infringement of article 5.1.c) of the GDPR, in accordance with article 83.5.a) of the GDPR and 72.1.a) of the LOPDGDD. 2-That in application of article 58.2.c) of
    56 KB (9,356 words) - 10:43, 13 December 2023
  • sanctions (articles 58, par. 2, lett. I and 83 of the Regulations; art. 166, paragraph 7, of the Code). The Guarantor, pursuant to art. 58, par. 2, lett. i) and
    50 KB (8,001 words) - 15:52, 6 December 2023
  • AEPD (Spain) - PS/00101/2020 (category Article 6 GDPR)
    the LSSI, typified as mild in article 38.4.d) of said norm.C / Jorge Juan, 6www.aepd.es28001 - Madridsedeagpd.gob.es Page 2 2/5FOURTH: The Support service
    13 KB (1,871 words) - 13:59, 13 December 2023
  • APD/GBA (Belgium) - 02/2021 (category Article 6 GDPR)
    Compétence de la Chambre de Résolution des Litiges (Article 2 AVG ; Article 4 WOG) 55. Conformément à l'article 2, paragraphe 1, de l'AVG, le règlement s'applique
    96 KB (15,396 words) - 16:50, 12 December 2023
  • APD/GBA (Belgium) - 81/2020 (category Article 5(2) GDPR)
    period allotted to it to do so (Article 15.1 combined with Article 12.3. of GDPR as well as Article 12.2. of the GDPR (obligation to facilitate the exercise
    127 KB (21,484 words) - 17:01, 12 December 2023
  • HDPA (Greece) - 55/2021 (category Article 33 GDPR)
    (EU) 2016/679, according to article 58 par. 2 i of the GCP in combination with the article 83 par. 4 and 5 of GKPD and article 39 par. 1 of law 4624/2019
    65 KB (10,533 words) - 10:28, 27 January 2022
  • ANSPDCP (Romania) - 27.12.2022 (category Article 32(2) GDPR)
    would have been required by Article 29 GDPR. Moreover, in violation of Article 32(1)(b), Article 32(2), and Article 34(4) GDPR, the controller had not implemented
    6 KB (790 words) - 15:13, 13 December 2023
  • AEPD (Spain) - PS/00366/2019 (category Article 5(1)(d) GDPR)
    authorities an infringement of Article 5 (1) (d) GDPR? The AEPD agreed to impose a penalty for infringement of Article 5 (1) (d) for lack of accuracy in the
    29 KB (4,583 words) - 14:32, 13 December 2023
  • Datatilsynet (Denmark) - 2019-441-3399 (category Article 33(2) GDPR)
    accordance with Article 32 (2) of the Data Protection Regulation. First 3.2. Article 32 (2) of the Data Protection Regulation 2 Article 32 (2) of the Regulation
    27 KB (4,231 words) - 16:38, 6 December 2023
  • right to erasure (“right to be forgotten”) of Article 17 GDPR and Article 19 of Regulation 2018/1725. Under GDPR, such prolonged and unrestricted data retention
    61 KB (9,971 words) - 14:28, 4 January 2024
  • Datatilsynet (Norway) - 20/04401 (category Article 6(1) GDPR)
    legal action basis, cf. the Privacy Ordinance Article 6 No. 1 letter f. 2. Pursuant to Article 58 (2) (d) of the Privacy Regulation, the EAS / Elektro
    40 KB (5,988 words) - 19:04, 5 March 2022
  • AEPD (Spain) - TD/00164/2020 (category Article 12 GDPR)
    AEPD considers that this could lead to a sanction, in accordance with article 58(2) GDPR. Share your comments here! Share blogs or news articles here! The
    17 KB (2,571 words) - 14:51, 13 December 2023
  • APD/GBA (Belgium) - 38/2021 (category Article 5 GDPR)
    consent of the 10 complainant (article 6.1 a) of the GDPR combined with article 7 of the GDPR), (2) article 6.1 c) of the GDPR in that the publication results
    73 KB (11,604 words) - 16:57, 12 December 2023
  • AEPD (Spain) - PS/00227/2019 (category Article 6(1)(a) GDPR)
    to Article 83(2)(k) of the RGPD, the LOPDGDD, in its Article 76, 'Sanctions and corrective measures', states that "In accordance with Article 83(2)(k)
    36 KB (5,821 words) - 14:20, 13 December 2023
  • UODO (Poland) - DKN.5131.31.2021 (category Article 34(2) GDPR)
    minor one." 2) Observance of the measures previously applied in the same case, referred to in Art. 58 sec. 2 of Regulation 2016/679 (Article 83(2)(i) of Regulation
    105 KB (17,237 words) - 09:22, 10 May 2023
  • Datatilsynet (Norway) - 20/01879 (category Article 24 GDPR)
    highly sensitive personal data exposed, thus breaching Article 32(1)(b) GDPR and Article 32(2), cf. Article 24. An employee in a municipal health care center
    30 KB (4,302 words) - 18:53, 5 March 2022
  • AN - 578/2021 (category Article 5(1)(d) GDPR)
    for the fulfillment of this obligation. For its part, art. 58.2.i) of the RGPD provides: "2. Each control authority will have all the following corrective
    26 KB (4,277 words) - 09:18, 26 July 2021
  • AEPD (Spain) - PS/00232/2020 (category Article 6(1) GDPR)
    " Regarding section k) of article 83.2 of the RGPD, the LOPDGDD, article 76, "Sanctions and corrective measures", provides: "2. In accordance with the provisions
    29 KB (4,386 words) - 14:20, 13 December 2023
  • AEPD (Spain) - EXP202105333 (category Article 6(1) GDPR)
    information”, article 83.2 f) of the GDPR. (IV) "The non-existence of benefits obtained through the infringement", article 83.2 k) of the GDPR and 76.2 c) of the
    49 KB (7,973 words) - 13:25, 13 December 2023
  • AEPD (Spain) - PS/00014/2020 (category Article 6(1) GDPR)
    the conditions of lawfulness of the treatment in article 6 of Regulation (EU) 2016/679. ” V Article 58.2 of the RGPD provides the following: “Each supervisory
    21 KB (3,441 words) - 13:46, 13 December 2023
  • AEPD (Spain) - PS/00026/2021 (category Article 21 GDPR)
    processor, Vamavi Phone SL, had violated Article 48(1) LGT, Article 21 GDPR in link with Article 23 LOPDGDD and Article 28 GDPR by making a commercial call on behalf
    33 KB (5,185 words) - 13:48, 13 December 2023
  • CNPD (Luxembourg) - Délibération n° 21FR/2021 (category Article 5(1)(c) GDPR)
    company was not compliant with Article 13 GDPR. The CNPD held that the controller infringed Article 5(1)(c) GDPR and Article 13 GDPR and decided to: - impose
    52 KB (7,520 words) - 13:13, 20 July 2021
  • violation of Articles 14(2)(f), 17(1)(c) and 21(1) GDPR, on the following grounds. Firstly, the DPA found a violation of Article 14(2)(f) GDPR, as the controller
    6 KB (850 words) - 15:11, 13 December 2023
  • AEPD (Spain) - PS/00430/2018 (category Article 4(7) GDPR)
    RIBADEDEVA ( *** POSITION 1 ) according with the provisions of article 58.2 d) of the GDPR, so that you can withdraw the copy of the sentence Exposed from the FACEBOOK
    40 KB (6,508 words) - 14:39, 13 December 2023
  • of Articles 5(1)(a), 6 and 28(3) GDPR and adopted an administrative fine on the basis of Articles 58(2)(i) and 83 GDPR. The total amount of the fine took
    49 KB (7,758 words) - 15:44, 6 December 2023
  • UODO (Poland) - DKE.561.2.2020 (category Article 58(1)(e) GDPR)
    Procedure (Journal of Laws of 2020, item 256) and Article 7(1) and (2), Article 60, Article 101, Article 103 of the Act on the Protection of Personal Data
    27 KB (4,390 words) - 09:50, 17 November 2023
  • AEPD (Spain) - PS/00390/2019 (category Article 32 GDPR)
    of EUR 2,000 (two thousand euros) on B.B.B., with IFRN ***NIF.1, for an infringement of Article 32 GDPR, as defined in Article 83.4 of the GDPR. SECOND:Notify
    12 KB (1,838 words) - 14:34, 13 December 2023
  • APD/GBA (Belgium) - 11/2019 (category Article 5(1)(b) GDPR)
    1(e) and 5.2 of the DGPS and Article 6 of the DGPS; 2.the defendant has not complied with the obligations imposed by sections 12.1. and 12.2. of the DGPS
    24 KB (3,844 words) - 16:51, 12 December 2023
  • AEPD (Spain) - PS/00179/2020 (category Article 32(1) GDPR)
    as established in article 5 of the GDPR. The security of personal data is regulated in articles 32, 33 and 34 of the GDPR. III The GDPR defines personal
    100 KB (16,401 words) - 14:07, 13 December 2023
  • AEPD (Spain) - PS/00113/2019 (category Article 58(2)(b) GDPR)
    the defendant for an infringement of Article 5(1)(a) GDPR a warning penalty in accordance with Article 58(2)(b) GDPR. Share your comments here! Share blogs
    23 KB (3,836 words) - 14:01, 13 December 2023
  • UODO (Poland) - DKN.5112.13.2020 (category Article 58(1)(b) GDPR)
    on the GEOPORTAL2 was not in line with the principle of lawfulness in Article 5(1)(a) GDPR, as none of the conditions of Article 6 GDPR were satisfied.
    60 KB (9,755 words) - 09:58, 17 November 2023
  • AZOP (Croatia) - Decision 17-05-2022 (category Article 6 GDPR)
    consent, in line with Article 6(1)(a) GDPR. The Court recalled that Article 31 of the Croatian Law on the Implementation of the GDPR stipulates that the
    15 KB (2,261 words) - 15:55, 30 October 2023
  • AEPD (Spain) - PS/00273/2020 (category Article 17 GDPR)
    DPA (AEPD) imposed a €1000 fine on a beauty salon for breaching Article 17 GDPR and Article 21 LSSI. The salon sent a marketing SMS to a client months after
    15 KB (2,337 words) - 14:24, 13 December 2023
  • (possible) fraud. This resulted in a breach of Article 5(1)(a) GDPR and Article 6(1) GDPR in conjunction with Article 8 of the Dutch Personal Data Protection
    49 KB (7,201 words) - 17:06, 12 December 2023
  • APD/GBA (Belgium) - 71/2020 (category Article 4(1) GDPR)
    of the judgment article 6, d) and article 6, e) of the GBA law, but this should be read as article 6.1. d) and Article 6.1. e) of the GDPR. Decision on the
    79 KB (12,260 words) - 17:00, 12 December 2023
  • AEPD (Spain) - PS/00031/2020 (category Article 21 GDPR)
    alleged infringement of Article 48.1.b) of the Law LGT, classified as "minor" in Article 78.11) of the aforementioned Law LGT.2, NAME B.B.B. as instructor
    15 KB (2,411 words) - 13:49, 13 December 2023
  • AEPD (Spain) - TD/00293/2021 (category Article 4(1) GDPR)
    considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with article 58.2 of the GDPR. SECOND: NOTIFY this resolution to D. A.A.A
    13 KB (1,878 words) - 13:37, 13 December 2023
  • Korkein hallinto-oikeus (Finland) - KHO:2023:56 (category Article 5(1)(c) GDPR)
    Protection Regulation) Article 5, paragraph 1, subparagraph c, Article 25, Article 58, paragraph 2, subparagraph d, and Article 87, Section 29, subsection
    45 KB (5,016 words) - 14:14, 21 March 2024
  • to art. 58, par. 2, of the GDPR. 6. Adoption of the injunction order for the application of the pecuniary administrative sanction (Articles 58, paragraph
    57 KB (9,144 words) - 15:55, 6 December 2023
  • Court of Appeal of Brussels - 2020/AR/813 (category Article 5(1)(c) GDPR)
    Therefore the controller violated Article 5(1)(a) and (2), Article 6(1), Article 12(1), Article 13(1)(b) and (c) GDPR. The DPA imposed a fine of €50.000
    85 KB (12,340 words) - 15:30, 19 August 2022
  • UODO (Poland) - DKN.5101.25.2020 (category Article 32(1)(d) GDPR)
    to Art. 58 sec. 2 lit. b) and e), in connection with Art. 5 sec. 1 lit. f, art. 24 sec. 1, art. 25 sec. 1, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 33
    63 KB (10,088 words) - 09:52, 17 November 2023
  • AEPD (Spain) - PS/00197/2020 (category Article 58(2) GDPR)
    6(1)(b), 5(1)(b) and 5(1)(c) GDPR? The Spanish DPA (AEPD) deemed itself competent under Article 58(2) GDPR in conjunction with Article 47 of the Spanish Data
    129 KB (21,793 words) - 14:09, 13 December 2023
  • AEPD (Spain) - PS/00417/2019 (category Article 37 GDPR)
    2020.IV Article 83.7 of the RGPD establishes that: “ Without prejudice to the corrective powersof supervisory authorities under Article 58 (2), each Member
    16 KB (2,298 words) - 14:36, 13 December 2023
  • Camera" (which processes image and voice) according to Article 5(1)(a) GDPR and Article 6(1) GDPR? The ANSPDCP found that the staff of the General Directorate
    7 KB (906 words) - 15:22, 13 December 2023
  • VGH München – 11 ZB 19.991 (category Article 23(1)(d) GDPR)
    also be subject to the provisions of Article 6.1(e) DSGVO in conjunction with Article 6.1(b) DSGVO. Article 2, 28.2 no. 2 BayDSG without the consent of the
    31 KB (5,184 words) - 17:19, 15 April 2023
  • AEPD (Spain) - PS/00251/2020 (category Article 37(1)(b) GDPR)
    company result in a breach of Article 37 GDPR? The Spanish DPA (AEPD) found that Conseguridad SL had violated Article 37(1)(b) GDPR by not having designated
    15 KB (2,245 words) - 14:22, 13 December 2023
  • is maintained under Article 6.1 b) to f) of the GDPR and therefore in Article 6.1.c) invoked in the species. Article 6.1 of the GDPR in fact reproduces
    73 KB (11,238 words) - 16:59, 12 December 2023
  • violated Article 12 GDPR, as it did not facilitate the data subject´s exercise of their rights, especially the right to erasure under Article 17 GDPR. In view
    87 KB (14,525 words) - 15:45, 6 December 2023
  • BVwG - W245 2252208-1/36E and W245 2252221-1/30E (category Article 46(2)(c) GDPR)
    80 Para. 2 GDPR does not exist. Contrary to the view of the BB, the data at issue in the proceedings are not personal i.S.d. GDPR. The BF2 explained that
    158 KB (26,392 words) - 08:25, 7 June 2023
  • AEPD (Spain) - TD/00233/2020 (category Article 17 GDPR)
    the offense considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with art. 58.2 of the GDPR. SECOND: NOTIFY this resolution
    17 KB (2,670 words) - 14:46, 13 December 2023
  • APD/GBA (Belgium) - 63/2020 (category Article 12(4) GDPR)
    zoekopdracht op naam van de klager. 2. Op 14 november 2019 wordt de klacht ontvankelijk verklaard op grond van de artikelen 58 en 60 WOG en wordt de klacht op
    20 KB (2,982 words) - 17:00, 12 December 2023
  • AEPD (Spain) - PS/00191/2020 (category Article 5(1)(c) GDPR)
    constitute a breach of Article 5(1)(c) GDPR? The AEPD held, that the actions of the defendant constitute an infringement of Article 5(1)(c) GDPR " Data Minimisation
    20 KB (2,973 words) - 14:09, 13 December 2023
  • AZOP (Croatia) - Decision 21-01-2022 (category Article 5(1)(a) GDPR)
    controller thus also violated Article 14 GDPR. However, the DPA did not use any of their corrective powers as listed in Article 58(2) GDPR. Share your comments
    18 KB (2,722 words) - 15:26, 30 October 2023
  • should have applied Article 35 GDPR. In light of the above, the Italian DPA used its corrective powers under Article 58(2)(c) and 83 GDPR and fined the controller
    87 KB (14,104 words) - 15:45, 6 December 2023
  • AEPD (Spain) - PS/00149/2020 (category Article 6 GDPR)
    in the Home Agreement.FUNDAMENTALS OF LAWIBy virtue of the powers that article 58.2 of the RGPD recognizes to each authority ofcontrol, and as established
    19 KB (2,795 words) - 14:06, 13 December 2023
  • AEPD (Spain) - PS/00004/2020 (category Article 5(1)(c) GDPR)
    document dated 12/19/19.FUNDAMENTALS OF LAWIBy virtue of the powers that article 58.2 of the RGPD recognizes to each authori-control, and as established in
    18 KB (2,798 words) - 13:44, 13 December 2023
  • AEPD (Spain) - PS/00285/2020 (category Article 13 GDPR)
    new page gina *** URL.2, in which information is provided in accordance with those stipulated in the article Article 13 of the GDPR. Regarding the complaint
    19 KB (2,923 words) - 14:26, 13 December 2023
  • AEPD (Spain) - EXP202315744 (category Article 17 GDPR)
    data protection officer, article 39 of the RGPD attributes to him the function of cooperate with said authority. Article 58.2 of the RGPD confers on the
    20 KB (3,052 words) - 08:17, 16 April 2024
  • AEPD (Spain) - PS/00329/2020 (category Article 37 GDPR)
    43; " Article 83.7 of the RGPD indicates: “Without prejudice to the corrective powers of the control authorities by virtue of the Article 58 (2), each
    13 KB (2,002 words) - 14:29, 13 December 2023
  • AEPD (Spain) - PS/00326/2020 (category Article 37(1)(a) GDPR)
    www.aepd.es 28001 - Madrid sedeagpd.gob.es 2/5 FOUNDATIONS OF LAW I By virtue of the powers that article 58.2 of the RGPD recognizes to each authority of
    14 KB (1,992 words) - 14:29, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/5553 (category Article 12(3) GDPR)
    request under Article 15 and with the one month deadline under Article 12(3). Was Google Ireland Ltd in breach of its obligations under GDPR Article 15(1) and
    27 KB (4,279 words) - 10:12, 17 November 2023
  • AEPD (Spain) - EXP202201681 (category Article 13 GDPR)
    imposition of measures, according to article 58.2 d) of the GDPR. Along with it and In accordance with article 58.2 of the GDPR, it was also indicated that the
    195 KB (30,495 words) - 12:40, 13 December 2023
  • (articles 58, paragraph 2, letter i and 83 of the Regulation; article 166, paragraph 7, of the Code). The violation of articles 5, paragraph 2, letter f)
    55 KB (8,833 words) - 15:54, 6 December 2023
  • comply with GDPR Article 12 (1) and GDPR Article 5 (2) of the provisions of paragraph 2, and he did not even mention the Data Subject 2. Based on GDPR Article
    69 KB (11,255 words) - 10:08, 17 November 2023
  • AEPD (Spain) - PS/00152/2020 (category Article 58(2)(b) GDPR)
    foundation was responsible for violating Article 33 GDPR, and issued it with a warning pursuant to Article 58(2)(b) GDPR. The AEPD did not find the former Secretary
    27 KB (4,243 words) - 14:06, 13 December 2023
  • (art. 58, par. 2, lett. i and 83 of the Regulation; art. 166, par. 7, of the Code). Pursuant to Articles 58(2)(i) and 83 of the Regulation and Article 166
    20 KB (3,133 words) - 15:53, 6 December 2023
  • AEPD (Spain) - PS/00274/2019 (category Article 5(1)(f) GDPR)
    for the allegedinfringement of article 5.1.f) of the RGPD, sanctioned in accordance with the provisions of theArticle 58.2.a) of the aforementioned RGPD
    37 KB (5,700 words) - 14:24, 13 December 2023
  • CNIL (France) - SAN-2020-015 (category Article 32(1) GDPR)
    private doctor for violating Article 32 GDPR by making his patients' health data freely accessible on the web, and Article 33 GDPR by not notifying the DPA
    29 KB (4,374 words) - 16:03, 19 January 2024
  • AEPD (Spain) - PS/00368/2020 (category Article 21 GDPR)
    company, Iberdrola Clientes, S.A.U for infringing Article 21 GDPR, Article 48(1)(b) LGT, and Article 23(4) LOPDGDD. The initial proposed fine was €10000
    21 KB (3,137 words) - 14:33, 13 December 2023
  • AEPD (Spain) - PS/00279/2020 (category Article 6 GDPR)
    for the violation of Article 6 GDPR and € 4 000 for the violation of article 13, under the power conferred by Article 83(5) GDPR. Share your comments here
    21 KB (3,123 words) - 14:25, 13 December 2023
  • APD/GBA (Belgium) - 141/2021 (category Article 38(6) GDPR)
    regard by the Respondent. (a) Principle of accuracy (Article 5.1(d) of the AVG), accountability (Article 5.2 of the AVG), transparency information, communication
    90 KB (14,937 words) - 12:35, 3 August 2022
  • Helsingin hallinto-oikeus (Finland) - H6072/2021 (category Article 6(1)(f) GDPR)
    applicant's demands and given Google LLC an order in accordance with Article 58, paragraph 2, subsection c of the General Data Protection Regulation to comply
    61 KB (9,876 words) - 21:38, 24 March 2024
  • CNIL (France) - SAN-2020-009 (category Article 5(1)(a) GDPR)
    of a link to this information. This was a violation of Article 12. Based on Article 13(2)(a) GDPR and WP29 guidelines on transparency, the CNIL noted that
    48 KB (7,404 words) - 17:09, 6 December 2023
  • 17 Para. 1 lit. d GDPR. The data protection authority therefore makes ex officio use of its power under Art. 58 Para. 2 lit. g GDPR (on the admissibility
    33 KB (5,254 words) - 13:33, 12 May 2023
  • CNIL (France) - SAN-2022-011 (category Article 12 GDPR)
    individuals complies with Article 14 of the GDPR. 2 On breaches in connection with the exercise of rights 28. Under Article 12 of the GDPR: "1. The controller
    48 KB (7,525 words) - 17:02, 6 December 2023
  • "accept all" button be considered a breach of GDPR Article 4(11) and Article 7, read in conjunction with GDPR Article 5(3) -Privacy while the data controller
    120 KB (19,650 words) - 09:00, 6 April 2022
  • AEPD (Spain) - PS/00439/2019 (category Article 5(1)(c) GDPR)
    the violation considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, of according to art. 58.2 of the GDPR.
    21 KB (2,946 words) - 14:40, 13 December 2023
  • APD/GBA (Belgium) - 36/2021 (category Article 5(1) GDPR)
    approved appeal of Article 5(1)(a), Article 12(1), Article 13(1) and Article 13(2). The appeal for Article 5(1)(c), Article 6(1) and Article 8 GDPR was not approved
    62 KB (9,417 words) - 16:57, 12 December 2023
  • correct processing [...]" (Article 6(1)(c) and (e)). 2, RGPD), with the consequence that the provision contained in Article 19, paragraph 3, of the Code
    31 KB (5,041 words) - 15:49, 6 December 2023
  • UODO (Poland) - ZSPR.421.19.2019 (category Article 31 GDPR)
    with Article 31, Article 58(1)(e) and (f) in connection with Article 83(1-3) and Article 83(5)(e) of Regulation 2016/679 of the European Parliament and of
    29 KB (4,698 words) - 10:02, 17 November 2023
  • be 2,000 euros (two thousand euros), without prejudice to what Sulte of the instruction of the present file. WHAT: in accordance with article 58.2 of the
    34 KB (5,222 words) - 12:58, 13 December 2023
  • AEPD (Spain) - PS/00461/2019 (category Article 83(2)(a) GDPR)
    fine on the defendant and stated he has to comply with Article 5(1)(c) and Article 83(2)(a)(b) GDPR. Share your comments here! Share blogs or news articles
    15 KB (2,366 words) - 14:41, 13 December 2023
  • UODO (Poland) - ZSPR.421.7.2019 (category Article 12(2) GDPR)
    connection with Article 5 paragraph 1 point a, Article 5 paragraph 2, Article 6 paragraph 1, Article 7 paragraph 3, Article 12 paragraph 2, Article 17 paragraph
    60 KB (9,815 words) - 10:02, 17 November 2023
  • APD/GBA (Belgium) - 82/2020 (category Article 6(1) GDPR)
    dossier werden toegevoegd. 2. Motivering 2.1. De bevoegdheid van de Inspectiedienst en de Geschillenkamer en de omvang van het dossier 2.1.1. Het verzoek van
    124 KB (18,772 words) - 17:01, 12 December 2023
  • AEPD (Spain) - EXP202201987 (category Article 15 GDPR)
    considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with art. 58.2 of the GDPR. SECOND: NOTIFY this resolution to D. A.A.A.
    21 KB (3,290 words) - 10:50, 13 December 2023
  • AEPD (Spain) - PS/00206/2020 (category Article 6 GDPR)
    of a person (article 83.2 b).- Basic personal identifiers are affected (name, a number ofidentification, the line identifier) ​​(article 83.2 g).- Section
    20 KB (3,078 words) - 14:10, 13 December 2023
  • AEPD (Spain) - PS/00405/2020 (category Article 6(1)(a) GDPR)
    event of an infringement of the precepts of the GDPR. Article 58.2 of the RGPD provides the following: “2 Each supervisory authority shall have all the following
    20 KB (3,047 words) - 14:35, 13 December 2023
  • AEPD (Spain) - PS/00172/2020 (category Article 6(1) GDPR)
    other hand, in accordance with the provisions of the aforementioned article 58.2 d) of the RGPD, according to which each supervisory authority may 'order
    38 KB (6,160 words) - 14:06, 13 December 2023
  • AEPD (Spain) - PS/00502/2020 (category Article 21 GDPR)
    registered on the Robinson List in breach of Article 48(1)(b) LGT and Article 21 GDPR in conjunction with Article 23(4) LOPDGDD. Avilon Center SL made an voluntary
    23 KB (3,590 words) - 14:45, 13 December 2023
  • processing, in order to avoid their illegal disclosure, reported to art. 58 para. (2) lit. d) of the RGPD).
    3 KB (290 words) - 15:17, 13 December 2023
  • VG Regensburg - RN 9 K 19.1061 (category Article 2 GDPR)
    of personal data mentioned in Article 2 (2) GDPR are not relevant. Contrary to the plaintiff's view, Article 2(2)(d) GDPR does not apply in the present
    94 KB (15,537 words) - 09:09, 25 August 2020
  • the processing of personal data of the data subject (Article 5(1)(a) GDPR; Article 6 and Article 8 of the Italian Legislative Decree No. 101 of August
    66 KB (10,708 words) - 11:29, 16 August 2022
  • APD/GBA (Belgium) - 11/2024 (category Article 5(2) GDPR)
    4 and article 15 of the GDPR (right of access), for reasons set out below. Furthermore, in accordance with article 58.2.c) of the GDPR and article 95, §
    26 KB (3,856 words) - 08:51, 19 March 2024
  • analyzes the criteria set by Article 83.2 of the GDPR: - As to the nature and seriousness of the violation [article 83.2 a) of the GDPR], with regard to breaches
    81 KB (11,895 words) - 16:58, 6 December 2023
  • BAC (Bulgaria) - № 11179 (category Article 5(1)(c) GDPR)
    principle of data minimisation - art. 5, § 1, b. "c" of the GDPR, respectively Art. 2, para. 2, item 3 (revoked) of LPPD ,and the processing is excessive
    13 KB (1,908 words) - 13:41, 15 September 2021
  • AEPD (Spain) - EXP202202837 (category Article 83(2) GDPR)
    (Considering 40 GDPR), Article 6.1 of the GDPR is therefore applicable and not RD 1720/2007 used by the defendant. Thus, the aforementioned article 6.1 GDPR establishes
    58 KB (8,995 words) - 13:00, 13 December 2023
  • AEPD (Spain) - EXP202102778 (category Article 6(1)(f) GDPR)
    violation of Article 6.1 of the GDPR, typified in Article 83.5 of the GDPR. SECOND: APPOINT as instructor C.C.C. and, as secretary, D.D.D., indicating
    84 KB (13,036 words) - 13:26, 13 December 2023
  • AEPD (Spain) - PS/00123/2020 (category Article 5(1)(f) GDPR)
    the supervisory authority with pursuant to article 58 (2), or failure to provide access in breach of article 58, Paragraph 1." The defendant could also specify
    21 KB (3,254 words) - 14:02, 13 December 2023
  • regarding Article 6(1) GDPR and consent requirements regulated previously to GDPR. The fact that the infringements related to Article 25 GDPR did not include
    440 KB (73,154 words) - 09:44, 12 May 2021
  • AEPD (Spain) - TD/00263/2020 (category Article 13 GDPR)
    considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with art. 58.2 of the GDPR. SECOND: NOTIFY this resolution to D.A.A.A. and
    22 KB (3,544 words) - 14:48, 13 December 2023
  • AEPD (Spain) - PS/00134/2019 (category Article 5(1)(a) GDPR)
    violation of article 5.1 a) of the RGPD, ofin accordance with article 83.5 of the RGPD, a fine of APPEARANCE, in accordancewith article 58.2.b) of the RGPD
    26 KB (4,034 words) - 14:04, 13 December 2023
  • AEPD (Spain) - TD/00109/2020 (category Article 15 GDPR)
    pursuant to Article 21(1); and no other legitimate grounds for processing prevail, or the data subject to oppose processing under Article 21(2); (d) the personal
    19 KB (3,100 words) - 14:50, 13 December 2023
  • AEPD (Spain) - PS/00127/2020 (category Article 13 GDPR)
    information duty included in Article 13 GDPR. Is this a violation of Article 13 GDPR? The AEPD held that there had been a violation of Article 13. According to the
    35 KB (5,363 words) - 14:02, 13 December 2023
  • HDPA (Greece) - 12/2022 (category Article 5(2) GDPR)
    13. See Opinion of OE article 29, 2/2017, p. 18. 13See. Opinion of OE article 29, 2/2017, p. 28. 14 See. Opinion of OE article 29, 2/2017, pp. 28-29. 12
    46 KB (7,390 words) - 08:07, 1 April 2022
  • Datatilsynet (Norway) - 20/01626 (category Article 5(1)(a) GDPR)
    processing as per Article 5(1)(b), nor legal grounds as per Article 6. In sum, the DPA found that NIF had breached Article 5(1)(a), (c) and (f), Article 6, and Article
    50 KB (8,081 words) - 18:52, 5 March 2022
  • AEPD (Spain) - PS/00065/2020 (category Article 13 GDPR)
    is based on Article 6(1)(a) or Article 9(2)(a) or Article 9(2)(b); or (c) where the processing is based on Article 6(1)(a) or Article 9(2)(a), the existence
    61 KB (9,973 words) - 13:55, 13 December 2023
  • Datatilsynet (Denmark) - 2019-431-0052 (category Article 13(2) GDPR)
    page. The injunctions are notified pursuant to Article 58 (1) of the Data Protection Regulation. 2, letter d. The deadline for compliance with the orders
    27 KB (4,300 words) - 16:36, 6 December 2023
  • data subject’s consent under Article 6(1)(a) GDPR, which in turn meets the conditions for consent laid out in Article 7 GDPR. The AEPD highlighted that this
    58 KB (8,665 words) - 16:10, 1 February 2022
  • Datatilsynet (Denmark) - 2019-441-1578 (category Article 34 GDPR)
    pursuant to Article 58 ( 1) of the Data Protection Regulation [1] . 2 (e). The content of the notification must comply with the requirements of Article 34 of
    21 KB (2,901 words) - 16:37, 6 December 2023
  • AEPD (Spain) - EXP202200367 (category Article 5(1)(a) GDPR)
    (hereinafter claimant 2). C.C.C. (hereinafter claimant 3). D.D.D. (hereinafter claimant 4). E.E.E. (hereinafter claimant 5). F.F.F. and D.D.D. (hereinafter claimants
    57 KB (8,117 words) - 10:35, 13 December 2023
  • 11, 148, 150, and Article 5, Chapter IV and Article 83. 4 2.8 Chapter IV, Section 2 addresses security of personal data. Article 32 GDPR provides: 1. Taking
    130 KB (21,195 words) - 13:52, 25 April 2021
  • regarding Article 6(1) GDPR and consent requirements regulated previously to GDPR. The fact that the infringements related to Article 25 GDPR did not include
    457 KB (75,575 words) - 09:36, 12 May 2021
  • procedure for the adoption of the measures referred to in Article 58, paragraph 5, of the Code. 2, of the RGPD and inviting the above mentioned Municipality
    25 KB (3,911 words) - 15:51, 6 December 2023
  • CPDP (Bulgaria) - PNN-01-433/2019 (category Article 6(1)(a) GDPR)
    the commission considers that the corrective measures under Art. 58, § 2 (a), (b), (c), (d), (e), "f", "g", "h" and "j" of the Regulation are inapplicable
    18 KB (2,987 words) - 16:49, 6 December 2023
  • Datatilsynet (Norway) - 20/02274 (category Article 5(2) GDPR)
    to delete the contents of the e-mail box, cf. article 17 No. 1 letter e. 2. Pursuant to Article 58 (2) (d) of the Privacy Regulation, this is imposed Radio
    47 KB (7,661 words) - 18:54, 5 March 2022
  • NAIH (Hungary) - NAIH/2020/2555 (category Article 4(2) GDPR)
    pursuant to Article 58 (2) (b) of the General Data Protection Regulation because its data processing activities violated Article 5 (1) (d) of the General
    33 KB (5,033 words) - 10:12, 17 November 2023
  • Norges Høyesterett - 2021-2403-A (category Article 9(2)(a) GDPR)
    other two conditions of Article 6 (1) (f) of the GDPR are not met. (26) The second condition of Article 6 (1) (f) of the GDPR is that the processing of
    46 KB (7,024 words) - 06:18, 6 March 2022
  • Personvernnemnda (Norway) - PVN-2023-05 (category Article 6(1) GDPR)
    controller) under Article 33 GDPR. On the 7 December 2023, the Norwegian DPA imposed a reprimand on the municipality under Article 58(2)(b) GDPR, for processing
    34 KB (5,375 words) - 10:07, 17 November 2023
  • AEPD (Spain) - PS/00057/2020 (category Article 7 GDPR)
    as per Article 22(2) of the Spanish Law on Information Society Services (LSSI) —this is the Spanish law regulating cookies, connected to Article 13 of the
    31 KB (4,757 words) - 13:52, 13 December 2023
  • BVwG - W274 2232028-1/3E (category Article 5 GDPR)
    is only determined by Article 5 et seqq. GDPR. A violation of Article 13 or 14 GDPR can be fined under Article 83(5) GDPR but it does not affect the lawfulness
    32 KB (5,232 words) - 09:40, 10 September 2021
  • AEPD (Spain) - PS/00190/2020 (category Article 5(1)(f) GDPR)
    violation of article 5.1.f) of the RGPD, typified in article 83.5 of the GDPR. C / Jorge Juan, 6 www.aepd.es 28001 - Madrid sedeagpd.gob.es 2/5 FOURTH: On
    14 KB (2,143 words) - 14:09, 13 December 2023
  • Datatilsynet (Norway) - 20/01516 (category Article 5 GDPR)
    the Personal Data Act § 26 second paragraph, cf. Article 58 (2) (i) of the Privacy Regulation, cf. Article 83, to pay a infringement fee to the Treasury of
    26 KB (3,885 words) - 08:43, 7 May 2022
  • by virtue of the powers that article 58.2 of the RGPD recognizes each Control Authority and, as established in arts. 47, 64.2 and 68.1 of the LOPDGDD Law
    45 KB (7,313 words) - 10:32, 13 December 2023
  • APD/GBA (Belgium) - 37/2020 (category Article 17 GDPR)
    provided for in Article 56(1), read in conjunction with Article 56(2), read in conjunction with Article 56(3), read in conjunction with Article 56(4), read
    131 KB (22,429 words) - 16:57, 12 December 2023
  • AEPD (Spain) - PS/00274/2020 (category Article 21 GDPR)
    Raise Marketing violated the data subject's right to object (Article 21 GDPR and Article 23 LOPDGDD). The DPA fined Raise Marketing €1500 for this violation
    16 KB (2,544 words) - 14:25, 13 December 2023
  • Datatilsynet (Norway) - 20/02147 (category Article 5 GDPR)
    the lack of security routines, thus breaching Article 32(1)(b) cf. Article 5 GDPR, Article 35 and Article 24(1), respectively. Teachers at two junior high
    24 KB (3,591 words) - 18:57, 5 March 2022
  • AEPD (Spain) - E/00113/2019 (category Article 4(11) GDPR)
    timetable" "B.- In accordance with Article 67 of the GDPR, the Inspectorate of the AEPD, in accordance with Article E/0113/2019, carried out the following
    27 KB (4,497 words) - 13:38, 13 December 2023
  • LG Essen - 6 O 190/21 (category Article 33 GDPR)
    violated Article 34(2) GDPR, because he only informed the data subject of the alleged data loss. However, the information obligations of Article 34 GDPR provide
    28 KB (4,596 words) - 18:30, 18 November 2021
  • ANSPDCP (Romania) - S.C. Viva Credit IFN S.A. (category Article 12(3) GDPR)
    measure was also applied to him, based on the provisions of art. 58 para. (2) lit. d) of the General Regulation on Data Protection, which is obliged to
    4 KB (565 words) - 15:20, 13 December 2023
  • HDPA (Greece) - 53/2022 (category Article 5(1)(a) GDPR)
    violation of article 13 of Regulation (EU) 2016/679, in accordance with article 58 par. 2 i' of the GDPR in combination with article 83 par. 5 of the GDPR. The
    50 KB (8,004 words) - 04:49, 14 December 2022
  • AEPD (Spain) - PS/00116/2020 (category Article 13 GDPR)
    cookies, as per Article 22(2) Spanish Law on Information Society Services (LSSI). This law regulates cookies, connected to Article 13 GDPR. The decision
    16 KB (2,380 words) - 14:01, 13 December 2023
  • OGH - 6Ob159/20f (category Article 12(1) GDPR)
    under Article 15 GDPR to the defendant and requested i.a. information on concrete recipients of their personal data under Article 15(1)(c) GDPR. The defendant
    22 KB (3,310 words) - 07:44, 5 October 2021
  • penalty payments pursuant to Article 58(2) opening words and under (d) of the AVG, Article 16(1) of the UAVG and Article 5:32(1) of the Awb. This means
    38 KB (6,339 words) - 17:14, 12 December 2023
  • APD/GBA (Belgium) - 55/2021 (category Article 25(2) GDPR)
    data on the basis of Article 6.1.e GDPR ? - Did the administration sharing confidential data with a third party violates article 25 GDPR ? - Should the administration
    81 KB (13,211 words) - 16:59, 12 December 2023
  • CNIL (France) - SAN-2020-056 (category Article 5(1)(d) GDPR)
    is based on Article 9(2)(i) of the GDPR as mentioned above. 34. However, certain data referred to in the PIA are not mentioned in Article 2 of the draft
    43 KB (6,847 words) - 17:11, 6 December 2023
  • Hoge Raad - ECLI:NL:PHR:2023:935 (category Article 5(1)(c) GDPR)
    has engaged another real estate agent for the sale. 2 Process flow First instance 2.1 2.2 2.3 2.4 2.5 PME summoned [plaintiff] on May 9, 2018 (see also
    103 KB (17,620 words) - 10:13, 29 November 2023
  • AEPD (Spain) - PS/00194/2020 (category Article 6 GDPR)
    COMPANY.1, through a single partner and administrator, D.D.D. being the object so- cial and commercial activity of this company, the same as that of my sponsored
    33 KB (5,338 words) - 14:09, 13 December 2023
  • Datatilsynet (Norway) - 20/01790 (category Article 5(1)(a) GDPR)
    section 1 of the Personal Data Act, cf. the Privacy Ordinance, Article 58 no. 2 letter i, cf. article 83, is imposed on Coop Finnmark SA, org.nr. 981 397 568
    49 KB (7,646 words) - 07:56, 7 March 2022
  • AEPD (Spain) - EXP202305050 (category Article 58(1) GDPR)
    monitoring the application of the GDPR and that, in Spain, one of these authorities is the AEPD. Also, according to Article 58(2) GDPR and the provisions of the
    57 KB (9,217 words) - 10:44, 13 December 2023
  • Court of Appeal of Brussels - 2019/AR/1006 (category Article 16 GDPR)
    accordance with Article 4(1) GDPR, according to the DPA. The Court of Appeal of Brussels held that, in accordance with Article 16 GDPR, the data subject
    59 KB (9,290 words) - 09:10, 5 May 2024
  • AEPD (Spain) - TD/00085/2020 (category Article 12 GDPR)
    serious infringement, which will be sanctioned in accordance with art. 58 (2) of the GDPR. Share your comments here! Share blogs or news articles here! The
    17 KB (2,654 words) - 14:50, 13 December 2023
  • APD/GBA (Belgium) - 03/2021 (category Article 24(2) GDPR)
    policies regulating this, they failed to comply to Article 24(1) and (2) GDPR and Article 25(1) and (2) GDPR. No fine was imposed, but a reprimand and clear
    32 KB (4,880 words) - 16:50, 12 December 2023
  • IP - 0610-376/2020/35 (category Article 58(2)(a) GDPR)
    pursuant to Article 54 of ZVOP-1, points (a), (d) and (f) of Article 58 (2) of the General Regulation, Articles 29 and 32 of the ZIN and Article 221 ZUP,
    110 KB (17,995 words) - 11:15, 22 April 2021
  • AEPD (Spain) - EXP202101314 (category Article 15 GDPR)
    comply with this decision will be sanctioned as an infringement of Article 58(2) GDPR. Share your comments here! Share blogs or news articles here! The
    18 KB (2,693 words) - 13:31, 13 December 2023
  • Regulation) Article 1, paragraph 2, Article 5, Article 6, paragraph 1, subparagraph f, Article 17(1)(a), (c) and (d), Article 17(3)(a), Article 21(1) Judgments
    60 KB (9,713 words) - 13:07, 26 March 2024
  • AEPD (Spain) - TD/00013/2021 (category Article 12(6) GDPR)
    the offense considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with art. 58.2 of the GDPR. SECOND: NOTIFY this resolution
    19 KB (3,027 words) - 14:48, 13 December 2023
  • AEPD (Spain) - PS/00374/2018 (category Article 5(1)(c) GDPR)
    present proceedings. LEGAL FOUNDATIONS I By virtue of the powers that Article 58.2 of the RGPD grants to each supervisory authority, and as established
    18 KB (2,711 words) - 13:43, 13 December 2023
  • APD/GBA (Belgium) - 10/2019 (category Article 5(1)(b) GDPR)
    to, or instead of, the measures referred to in Article 58(2)(a), (b), (c), (d) and (e), (f) and (g). (a) to (h), and (j). In deciding whether to impose an
    32 KB (5,190 words) - 16:51, 12 December 2023
  • CE - N° 430810 (category Article 6(1)(a) GDPR)
    application must be dismissed. D E C I D E : ---------- Article 1: The intervention of the PDU - What to choose is allowed. Article 2: The request of the company
    42 KB (6,800 words) - 09:50, 10 September 2021
  • AEPD (Spain) - PS/00128/2020 (category Article 9(2)(b) GDPR)
    an infringement of article 13 of the RGPD, typified in article 83.5.b) of the RGPD, a warning sanction in accordance with article 77.2 of the LOPDGDD. SECOND:
    39 KB (5,912 words) - 14:02, 13 December 2023
  • APD/GBA (Belgium) - 73/2020 (category Article 5 GDPR)
    accordance with article 15 AVG (section 2.1) - data processing officer (section 2.2) - cookie policy (section 2.3) - health data processing (section 2.4) - camera
    93 KB (14,040 words) - 17:00, 12 December 2023
  • AEPD (Spain) - PS/00477/2019 (category Article 6 GDPR)
    provisions of article 68 of the LOPDGDD and article 64.2 of the LPACAP (in this case, of the different corrective powers provided for in article 58.2 of the RGPD
    566 KB (93,179 words) - 13:43, 13 December 2023
  • AEPD (Spain) - EXP202202889 (category Article 12 GDPR)
    with the provisions of section 2 of article 56 in relation to section 1 f) of article 57, both of the GDPR; and in article 47 of the LOPDGDD. SECOND: In
    20 KB (3,077 words) - 10:46, 13 December 2023
  • APD/GBA (Belgium) - 136/2022 (category Article 4(1) GDPR)
    processing on the merits in accordance with article 98 et seq. WOG, to: - on the basis of article 58.2, c) AVG and article 95, 1.5° WOG to the controller order
    19 KB (2,700 words) - 08:49, 29 June 2023
  • AEPD (Spain) - PS/00235/2019 (category Article 6(1)(a) GDPR)
    responsible for resolving this procedure, in accordance with Article 58.2 of the GDPR in Article 47 of the Organic Law on Data Protection. II The joint assessment
    24 KB (4,074 words) - 14:21, 13 December 2023
  • not under a legal obligation to process these data. Article 29 of the Croatian Labour Act and Article 5(4) of the Labour Law Rulebook (Official Gazette,
    17 KB (2,660 words) - 15:35, 30 October 2023
  • AZOP (Croatia) - Decision 10-08-2023 (category Article 5 GDPR)
    this the AZOP held that the controller acted contrary to Article 5(1)(a) GDPR and Article 6 GDPR. Moreover, the AZOP reiterated the fact that the pictures
    19 KB (2,955 words) - 16:29, 5 December 2023
  • specified in Article 83 of the GDPR. 92. 92. Firstly, the restricted formation emphasises that, in this case, the criterion provided for in Article 83(2)(a) of
    73 KB (11,864 words) - 17:03, 6 December 2023
  • EDPB - Binding Decision 1/2020 - 'Twitter' (category Article 4(24) GDPR)
    infringements of Article 5(1)(f), Article 24, and Article 32 GDPR, and to the objection of the IT SA on the possible infringement of Article 5(2) GDPR, the EDPB
    183 KB (30,819 words) - 09:50, 20 January 2023
  • NAIH (Hungary) - NAIH/2020/2729/15 (category Article 5(1)(b) GDPR)
    with Article 2 (1) of the General Data Protection Regulation the general data protection regulation applies to data processing. According to Article 4 (1)
    58 KB (9,071 words) - 10:12, 17 November 2023
  • Datatilsynet (Norway) - 20/02172 (category Article 6(1)(f) GDPR)
    legal basis, cf. the Privacy Ordinance Article 6 (1) (f). 2. Pursuant to the Privacy Ordinance art. 58 No. 2 letter d is imposed LINDSTRAND TRADING AS to
    28 KB (4,155 words) - 18:57, 5 March 2022
  • AEPD (Spain) - PS/00436/2021 (category Article 13(2) GDPR)
    area on the facade of the PUB ***PUB.1. Likewise, in accordance with article 58.2.d) of the RGPD, the claimed party was ordered to proceed to place the
    20 KB (3,085 words) - 12:24, 13 December 2023
  • AN - SAN 3073/2022 (category Article 5(1)(c) GDPR)
    order to guarantee the right to union activity in the company (art. 2.1 d) and art. 2.2 d), the employer must, on the one hand, guarantee the right to information
    34 KB (5,374 words) - 14:21, 24 November 2022
  • AEPD (Spain) - PS/00315/2020 (category Article 28 GDPR)
    graduation established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 The
    62 KB (10,401 words) - 14:35, 21 November 2023
  • AEPD (Spain) - PS/00148/2019 (category Article 6 GDPR)
    his mobile phone: to “the Pack”, to which all the defendants belong except D.D.D., in addition more than other people and to "Enjoy SFC." In these WhatsApp
    48 KB (7,550 words) - 14:05, 13 December 2023
  • AEPD (Spain) - PS/00185/2020 (category Article 13 GDPR)
    of processing (Article 32 GDPR), the transparency principle (Article 13 GDPR) and its information duties related to cookies (Article 22(2) of the Spanish
    20 KB (3,162 words) - 14:08, 13 December 2023
  • AEPD (Spain) - PS/00006/2022 (category Article 12 GDPR)
    violation of the Article 12 of the GDPR, in conjunction with Article 17 of the GDPR. V Classification of the infringement of article 12 of the GDPR The aforementioned
    54 KB (8,870 words) - 10:43, 13 December 2023
  • data subject (art / e83.2.c of the GDPR} d) Any violation committed by the controller or processor (article 83.2.e of the GDPR} e) The degree of cooperation
    51 KB (7,792 words) - 11:43, 24 January 2022
  • accountability (Article 5 (2) and 24 (1), (2) GDPR), privacy by design (Article 25 (1) GDPR) and as controller towards its data processors (Article 28 GDPR). Consequently
    144 KB (23,155 words) - 15:46, 6 December 2023
  • AEPD (Spain) - PS/00187/2020 (category Article 5(1)(f) GDPR)
    as indicated in article 25.2 of the RGPD. In this sense, it is meant that the indeterminacy referred to in the article 25.2 of the GDPR refers to the default
    51 KB (7,770 words) - 14:08, 13 December 2023
  • APD/GBA (Belgium) - 07/2021 (category Article 5(1) GDPR) (section Complaint to defendant 2)
    infringement of Article 5.1 b) in conjunction with Article 6.4. AVG, on article 5.1 a) in conjunction with article 6.1. AVG and on article 5.1 c) GDPR has been
    72 KB (11,208 words) - 16:51, 12 December 2023
  • AEPD (Spain) - EXP202200999 (category Article 6(1) GDPR)
    processing is based on consent under Article 6(1)(a) GDPR, the consent must meet the requirements of, among others, Article 7 GDPR. The DPA observed deficiencies
    51 KB (7,867 words) - 13:10, 13 December 2023
  • HDPA (Greece) - 25/2022 (category Article 5(2) GDPR)
    according to Article 21 paragraph 2 , d) the personal data were processed unlawfully…”. 3. In addition, according to article 4 par. 2 of the GDPR as processing
    48 KB (7,803 words) - 13:29, 11 October 2022
  • AEPD (Spain) - TD/00044/2021 (category Article 17 GDPR)
    the offense considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with art. 58.2 of the GDPR. C / Jorge Juan, 6 www.aepd
    22 KB (3,465 words) - 13:30, 13 December 2023
  • AEPD (Spain) - EXP202104873 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    24 KB (3,512 words) - 10:43, 13 December 2023
  • AEPD (Spain) - PS/00324/2019 (category Article 13 GDPR)
    present sanctioning procedure. LEGAL GROUNDS I By virtue of the powers that article 58.2 of the RGPD recognizes to each control authority, and according to what
    22 KB (3,480 words) - 14:28, 13 December 2023
  • AEPD (Spain) - PS/00381/2019 (category Article 5(1)(f) GDPR)
    infringement of Article 5.1.f) of the RGPD, typified in Article 83.5 of the RGPD, a warning sanction in accordance with the provisions of Article 77.2 of the LOPDGDD
    22 KB (3,479 words) - 14:33, 13 December 2023
  • AEPD (Spain) - TD/00054/2020 (category Article 12 GDPR)
    commission of the offence referred to in Article 72.1.m) of the LOPDGDD, which will be sanctioned in accordance with Article 58.2 of the RGPD. SECOND: TO NOTIFY
    22 KB (3,500 words) - 14:50, 13 December 2023
  • processing carried out is in violation of Article 5(1)(f) GDPR, Article 25(1) GDPR, Article 32 GDPR and Article 35 GDPR. Especially, the controller cannot exclude
    119 KB (19,123 words) - 11:29, 16 August 2022
  • APD/GBA (Belgium) - 75/2023 (category Article 12(2) GDPR)
    Authority. II.5.2. Established infringement of Article 5(1)(a) j° Article 6(1)(f) and Article 12(2) GDPR in conjunction with Article 17 (1) GDPR. II.5.2.1. Administrative
    77 KB (11,604 words) - 08:55, 29 June 2023
  • APD/GBA (Belgium) - 33/2020 (category Article 5 GDPR)
    by the defendant under Article 6(1) GDPR? Did the controller infringe the data minimisation principle under Article 5(1)(c) GDPR? Did the controller commit
    39 KB (6,551 words) - 16:56, 12 December 2023
  • AEPD (Spain) - PS/00198/2019 (category Article 5(1) GDPR)
    virtue of the powers that Article 58.2 of the RGPD grants to each control authority, and in accordance with the provisions of Article 47 of Organic Law 3/2018
    12 KB (1,686 words) - 14:09, 13 December 2023
  • AP (The Netherlands) - 24.03.2020 (category Article 4(15) GDPR)
    unlawfully. 2.4 Administrative fine Pursuant to Article 58, paragraph 2, preamble, in conjunction with Article 83, paragraph 4, of the GDPR and article 14, third
    48 KB (7,461 words) - 17:04, 12 December 2023
  • have entered into a breacha / 'article 14.1-2 combined' article 12.3, article 6, article 5.1, c) and articles 5.2 and 24.1-2 of the RGPO. It is therefore
    72 KB (11,389 words) - 08:59, 20 August 2021
  • Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned a Luxembourg
    26 KB (3,862 words) - 17:41, 25 June 2022
  • CNIL (France) - SAN-2020-013 (category Article 6 GDPR)
    derogant rule, based on the interpretation of Article 95 GDPR in the line of the Rec (173) GDPR and Article 1(2) and 15a of the ePrivacy Directive. The CNIL
    82 KB (13,424 words) - 17:10, 6 December 2023
  • AEPD (Spain) - PS/00028/2021 (category Article 5(1)(c) GDPR)
    to the claim. mado, for violation of the content of art. 5.1 c) GDPR. Article 58 section 2 of the RGPD provides the following: Each authority of control
    25 KB (3,876 words) - 13:48, 13 December 2023
  • The DPA first requested an overview of such processing (equivalent to Article 30 GDPR) for purposes related to the Norwegian Execution of Sentences Act, details
    16 KB (2,010 words) - 14:32, 8 November 2022
  • CNIL (France) - SAN-2020-003 (category Article 5(1)(c) GDPR)
    articles 5-1-c), 5 -1 e), 13, 32 and 35-1 of the GDPR; no breach of Article 6 of the GDPR and of Directive 2002/58 / EC of the Parliament and of the Council known
    61 KB (10,028 words) - 17:09, 6 December 2023
  • IP - 0712-1/2020/1408 (category Article 15 GDPR)
    person, using Article 15 as their basis. The Slovenian DPA (IP) was asked for an opinion concerning the scope of GDPR Article 15. Within the GDPR, an individual
    10 KB (1,575 words) - 13:37, 10 August 2021
  • VG Hannover - 10 A 502/19 (category Article 5(1)(a) GDPR)
    VwGO) .191. The legal basis for the dispute is Article 58 (2) (d) of the General Data Protection Regulation (GDPR), Regulation no and to repeal RL 95/46 / EG
    41 KB (6,779 words) - 12:35, 24 November 2021
  • Datatilsynet (Norway) - 20/01627 (category Article 4(1) GDPR)
    treatment of personal data, cf. the Personal Data Act § 2 and the Privacy Ordinance article 2 no. 1. 4.2. Assessment of legal basis The next question is whether
    45 KB (6,973 words) - 05:12, 15 September 2022
  • relation to contraventions of the UK-GDPR, section 168 DPA 2018 provides that "non-material damage" in Article 82 GDPR includes distress. In relation to breaches
    61 KB (8,986 words) - 08:40, 22 February 2022
  • OLG Dresden - 4 U 1905/21 (category Article 12(5)(b) GDPR)
    § 8 clause 2 of the GTC agreed between the parties (according to § 8 b paragraph 2 MB/KK). 52 § 8 b para. 2 MB/KK violates §203 sentence 2 VVG and is therefore
    40 KB (6,325 words) - 16:12, 18 May 2022
  • AEPD (Spain) - PS/00099/2022 (category Article 5(1)(f) GDPR)
    number of personal data. (Article 76.2.b) The balance of the circumstances contemplated in article 83.2 of the RGPD and the Article 76.2 of the LOPDGDD, with
    38 KB (5,920 words) - 12:43, 13 December 2023
  • whether Art. 15 GDPR applies to the investigation files at all, since according to Art. 2 Para. 2 d GDPR, Section 2a Para. 4 AO, the GDPR does not apply
    97 KB (16,519 words) - 09:57, 22 February 2023
  • AEPD (Spain) - EXP202208091 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    40 KB (6,014 words) - 13:24, 13 December 2023
  • AEPD (Spain) - PS/00114/2019 (category Article 6(1) GDPR)
    third parties (article 83.2.k, of the RGPD in relation to article 76.2.b, of the LOPDGDD) The continued nature of the infraction (article 83.2.k of the RGPD
    60 KB (10,197 words) - 14:01, 13 December 2023
  • AEPD (Spain) - PS/00268/2020 (category Article 13 GDPR)
    Policy on their website (Article 13 GDPR) and for the absence of a reject button on the second layer of their Cookie Policy (Article 22(2) LSSI). The claimant
    17 KB (2,700 words) - 14:23, 13 December 2023
  • personal data and information under Article 15 GDPR in his Google account, Google has not violated Article 15 GDPR concerning this data/information. As
    107 KB (17,615 words) - 09:42, 10 September 2021
  • to criminal investigations, pursuant to Article 2(2)(d) GDPR. The second problem was the fact that Article 9 GDPR prohibited the processing of genetic and
    110 KB (18,000 words) - 08:01, 5 June 2023
  • UODO (Poland) - DKN.5130.2024.2020 (category Article 32(2) GDPR)
    art. 58 sec. 2 lit. i) in connection with Art. 5 sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and 3 and article. 32 sec. 1 and 2, as well
    75 KB (12,104 words) - 09:58, 17 November 2023
  • BVwG - W211 2230221-1 (category Article 15(1)(c) GDPR)
    Court's request for preliminary ruling regarding the interpretation of Article 15(1)(c) GDPR is published. The data subject filed a complaint with the Austrian
    19 KB (2,825 words) - 09:42, 26 November 2021
  • APD/GBA (Belgium) - 17/2020 (category Article 12(3) GDPR)
    a bank was subject to the GDPR in its capacity as a controller and should have answered access requests under Article 15 GDPR.   The complainants are clients
    52 KB (8,603 words) - 16:55, 12 December 2023
  • AEPD (Spain) - TD/00182/2019 (category Article 15 GDPR)
    the infringement considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with article 58.2 of the RGPD. SECOND: TO NOTIFY
    18 KB (2,922 words) - 14:51, 13 December 2023
  • AEPD (Spain) - PS/00110/2020 (category Article 7 GDPR)
    with "APERCIBIMIENTO" for an infraction of article 7)of the RGPD, in accordance with the provisions of article 58.2) of the aforementioned RGPD.NINTH: Following
    32 KB (4,992 words) - 14:00, 13 December 2023
  • DVI (Latvia) - SIA "TET" (category Article 5(1)(d) GDPR)
    violation of Article 5(1)(a), (b), (d) and (e) GDPR. Furthermore, there was no legal basis for these processing operations under Article 6(1) GDPR. The DPA
    114 KB (17,942 words) - 15:46, 2 November 2022
  • AEPD (Spain) - TD/00325/2019 (category Article 56(2) GDPR)
    the infringement considered in article 72.1.m) of the LOPDGDD, which will be sanctioned, in accordance with article 58.2 of the RGPD. SECOND: TO NOTIFY
    17 KB (2,691 words) - 14:52, 13 December 2023
  • Personvernnemnda (Norway) - 2021-13 (20/01874) (category Article 24(2) GDPR)
    cf. Article 58, paragraph 2, letter i, cf. Article 83. Both infringements of Article 6 and Article 13 may be sanctioned with a fee, cf. Article 85, paragraph
    48 KB (7,804 words) - 18:49, 5 March 2022
  • IMY (Sweden) - IMY 2023-8336 (category Article 58(2)(b) GDPR)
    of: 1) Article 12(2) GDPR, by not enabling the data subject to exercise their right to rectification stated in Article 16 GDPR. Article 12(2) GDPR thus includes
    5 KB (572 words) - 15:53, 28 February 2024
  • AEPD (Spain) - PS/00388/2020 (category Article 7 GDPR)
    violation of article 22.2) of the LSSI, Regarding the "Cookies Policy" on the website of its ownership. In addition, in accordance with article 58.2 of the RGPD
    52 KB (8,471 words) - 14:33, 13 December 2023
  • accuracy and updating of data as provided in Art 5 par 1 let d GDPR. Following Art 58 2 c and g GDPR, the Guarantor finds the data subject´s complaint well-founded
    17 KB (2,544 words) - 12:49, 19 June 2023
  • personal data (Article 9 GDPR)? Does the data controller have a legitimate interest to process credit card data of recurring purchasers under Article 6(1)(f)
    19 KB (2,790 words) - 09:50, 10 September 2021
  • AEPD (Spain) - TD/00251/2021 (category Article 15 GDPR)
    es 2/7 FOUNDATIONS OF LAW FIRST: The Director of the Spanish Agency for Data Protection, in accordance with the provisions of section 2 of article 56 in
    20 KB (3,142 words) - 13:31, 13 December 2023
  • APD/GBA (Belgium) - 61/2023 (category Article 58(2)(f) GDPR)
    ensure compliance with the GDPR. It therefore violated Articles 5(2) and 24 GDPR. Consequently, on the basis of Article 58(2)(f) GDPR and in accordance with
    10 KB (1,134 words) - 11:55, 5 July 2023
  • the size of the infringement fee. 2 Decision on infringement fines 1. Pursuant to the Privacy Ordinance Article 58 no. 2 letter i, and after an assessment
    43 KB (6,983 words) - 09:09, 21 August 2022
  • AEPD (Spain) - PS/00299/2019 (category Article 7 GDPR)
    as per Article 22(2) of the Spanish Law on Information Society Services (LSSI) —this is the Spanish law regulating cookies, connected to Article 13 GDPR
    21 KB (3,202 words) - 14:54, 13 December 2023
  • OLG Frankfurt am Main - 13 U 206/20 (category Article 17(1) GDPR)
    by the plaintiff pursuant to Article 82(1) GDPR, since there have been violations of Article 6(1)(a) GDPR and Article 34 GDPR. The defendant also breached
    44 KB (7,334 words) - 09:02, 17 March 2022
  • DSB (Austria) - D122.844/0006-DSB/2018 (category Article 12(5) GDPR)
    under Article 15 GDPR and demanded free access to the historic bank transaction data. The bank argued that this would be a misuse of Article 15 GDPR and
    19 KB (2,936 words) - 13:55, 12 May 2023
  • UODO (Poland) - DOKE.561.1.2023 (category Article 58(1)(a) GDPR)
    sec. 1 lit. a) and ... h), art. 58 sec. 2 lit. i), art. 83 sec. 1-2 and Art. 83 sec. 5 lit. e) in connection with art. 58 sec. 1 lit. a) and e) of Regulation
    45 KB (7,312 words) - 21:50, 8 August 2023
  • CNIL (France) - SAN-2021-003 (category Article 4(2) GDPR)
    broad definitions of processing and personal data laid down by Article 4(1) and (2) GDPR. The DPA then quotes ECJ, 11 December 2014, Ryneš, case C-212/13
    39 KB (6,015 words) - 17:11, 6 December 2023
  • AEPD (Spain) - TD/00129/2020 (category Article 4(2) GDPR)
    recording is "processing" of "personal data" within the meaning of Article 4(1) and 4(2) GDPR. Therefore, the data subject has the right to request access to
    22 KB (3,422 words) - 14:50, 13 December 2023
  • BVerfG - 1 BvR 276/17 (category Article 17 GDPR)
    violation of the general right of personality under Article 1.1, Article 2.1 of the Basic Law (Article 7, Article 8 of the Basic Law) was to be taken into account
    127 KB (21,367 words) - 16:00, 22 March 2022
  • AEPD (Spain) - PS/00071/2020 (category Article 5(1)(a) GDPR)
    highest amount. " Article 83.7 of the RGPD indicates: “Without prejudice to the corrective powers of the control authorities under article 58 (2), each Member
    45 KB (7,267 words) - 13:56, 13 December 2023
  • security of the data, in violation of Article 32(1) and (2) GDPR and warned the controller for a violation of Article 25(1) GDPR. The DPA fined the controller
    6 KB (788 words) - 08:33, 31 May 2023
  • VwGH - Ro 2021/04/0033 (category Article 58(2)(f) GDPR)
    to Article 4(11) GDPR and Article 7 GDPR and that no other legal basis can be considered and the aforementioned processing is therefore unlawful. 2) the
    36 KB (5,727 words) - 11:02, 7 April 2022
  • Datatilsynet (Norway) - 20/01772 (category Article 9(2)(d) GDPR)
    line with Article 17(1)(d) GDPR, the controller was obliged to delete data processed unlawfully, unless the exception of Article 17(3) GDPR (fulfillment
    53 KB (7,945 words) - 10:46, 24 January 2023
  • AEPD (Spain) - PS/00245/2019 (category Article 5(1)(a) GDPR)
    Articles 5(1)(a) GDPR and 13 GDPR. On the other hand, they disagreed with the infringement of Article 5(1)(a) GDPR in relation to Article 9(1) GDPR with regard
    116 KB (18,941 words) - 14:21, 13 December 2023
  • CPDP (Bulgaria) - PPN- 01-197/2022 (category Article 5(1)(a) GDPR)
    Motivated by the above and on the basis of Article 38, Paragraph 3 of the GDPR, in connection with Article 58, §2 of Regulation (EU) 2016/679, the Commission
    36 KB (5,922 words) - 08:02, 18 April 2024
  • accountability pursuant to Article 5(2) UK GDPR because it failed to demonstrate compliance with Article 5(1)(a) and (c) UK GDPR principles of lawfulness
    129 KB (17,281 words) - 14:57, 10 April 2024
  • AEPD (Spain) - PS/00474/2020 (category Article 21 GDPR)
    781 254 D2D_Casmar 964 800 099 D2D_Casmar 912 303 310 D2D_Casmar 910 888 516 D2D_Solivesa 910 120 123 D2D_Three-Quarters Full S.L. 919 034 107 D2D_Three-Quarters
    38 KB (5,945 words) - 12:14, 9 June 2021
  • AEPD (Spain) - PS/00193/2021 (category Article 58(2) GDPR)
    of article 6.1) typified in the Article 83.5.a) of the aforementioned RGPD. SECOND: APPOINT D. C.C.C. as instructor. and as secretary to Mrs. D.D.D., indicating
    27 KB (4,223 words) - 10:01, 22 September 2021
  • NAIH (Hungary) - NAIH-2020/2204/8 (category Article 24(2) GDPR)
    Section 2 (2) and (4) a may apply the legal consequences set out in the General Data Protection Regulation. Pursuant to Article 58 (2) (b), (d) and (i)
    60 KB (9,820 words) - 10:08, 17 November 2023
  • UODO (Poland) - DKE.561.20.2022 (category Article 58(1)(a) GDPR)
    pursuant to Article 83(5)(e) GDPR. Second, the DPA considered the non-compliance with the summons to breach breach of Article 58(1)(a) and (e) GDPR. The delay
    43 KB (6,878 words) - 10:55, 10 January 2024
  • CNPD (Portugal) - Deliberaçao 2024/137 (category Article 58(2)(f) GDPR)
    this respect, Article 58(2)(d) of the Treaty on the Functioning of the European Union provides In this regard, Article 58(2) of the GDPR lists the different
    49 KB (7,923 words) - 14:36, 3 April 2024
  • (c) and (d) GDPR. Hence, pursuant to Article 58(2)(f) GDPR, the DPA prohibited the controller from further disseminating data concerning the complainant
    31 KB (4,659 words) - 15:22, 12 December 2023
  • violated Articles 5(2), 24 and 25(1) GDPR. At last, the DPA established a violation of Article 5(2), Article 24 and Article 13 GDPR, for failing to provide
    131 KB (21,176 words) - 12:52, 20 December 2022
  • AEPD (Spain) - EXP202207270 (category Article 19 GDPR)
    making the identification of a person easier. The DPA referred to Article 4(2) GDPR which defines the concept of processing. Publishing a person's image
    26 KB (3,901 words) - 13:19, 13 December 2023
  • complaint; b. give notice to the second defendant, pursuant to Article 58(2)(a) AVG and Article 100(1)(5) WOG, that it will not take part in the proceedings
    92 KB (14,873 words) - 09:03, 20 August 2021
  • AEPD (Spain) - EXP202303130 (category Article 5(1)(f) GDPR)
    provisions of article 5.1.f) of the RGPD and article 32 of the GDPR, violations classified in article 83.5 of the GDPR and article 83.4 of the GDPR respectively
    38 KB (5,842 words) - 14:16, 18 October 2023
  • CNIL (France) - SAN-2022-022 (category Article 12(3) GDPR)
    obligations arising from Article 32 of the GDPR. D. On the failure to document any personal data breach 72. According to Article 33(5) of the GDPR: "The controller
    59 KB (9,623 words) - 17:03, 6 December 2023
  • UODO (Poland) - DKN.5131.11.2020 (category Article 58(2)(e) GDPR)
    in Art. 58 sec. 2 of Regulation 2016/679 (Article 83 (2) (i) of Regulation 2016/679) - in this case, the measures referred to in Art. 58 sec. 2 of Regulation
    51 KB (8,179 words) - 12:07, 11 August 2021
  • AEPD (Spain) - PS/00388/2022 (category Article 32(1) GDPR)
    has not violated the article 15 of the GDPR, infringement typified in article 83.5 a) of the GDPR. IV. Secondly, article 32 of the GDPR "Security of treatment"
    72 KB (11,730 words) - 08:54, 19 July 2023
  • art. 58, par. 2, lett. i), and 83, par. 3, of the same Regulation. 5. Corrective measures (art. 58, par. 2, letter d), of the Regulation). Art. 58, par
    34 KB (5,239 words) - 10:47, 28 June 2022
  • AEPD (Spain) - PS/00301/2020 (category Article 5(1)(d) GDPR)
    B28905784, for an infringement of the article 5.1.d) of the GDPR, in accordance with article 83.5 a) of the GDPR, with a fine of 10,000 euros (ten honey
    28 KB (4,554 words) - 11:33, 30 June 2021
  • DSB (Austria) - DSB-D130.1174 (category Article 3 GDPR)
    of November 12, 2019, p. 18). D.1.2. On Art. 3 Paragraph 2 Letter b GDPR (“D.1.2. On Article 3 Paragraph 2, Letter b, GDPR (“Behaviour Observation”) Regardless
    86 KB (14,497 words) - 13:42, 3 April 2024
  • AP (The Netherlands) - 24.02.2022 (category Article 13(1)(e) GDPR)
    data 9 2.1.1 Factual findings 9 2.1.2Legal assessment 9 2.2 Controller and processor(s) 10 2.2.1 Factual findings 10 2.2.2Legal assessment 12 2.3Security
    179 KB (22,957 words) - 17:07, 12 December 2023
  • Datatilsynet (Denmark) - 2020-431-0075 (category Article 58(2) GDPR)
    powers under Article 58(2) GDPR, the DPA reprimanded the controller for violations of Articles 5(1)(e), 6(1)(f), 12(1) and 13(1)(d) GDPR. Share your comments
    66 KB (10,335 words) - 14:38, 25 October 2022
  • identification of corrective and resolving solutions (Article 5 , par. 2 and art.83, par. 2, letters c) and d) of the Regulation); - the Company immediately demonstrated
    45 KB (7,200 words) - 08:46, 28 July 2021
  • accordance with Article 60 of the AVG. No objections to this were submitted. 2. Legal Framework 2.1 Scope of the AVG Pursuant to Article 2(1) of the AVG
    77 KB (12,915 words) - 17:15, 12 December 2023
  • BVwG - W256 2227693-1 (category Article 6(1)(a) GDPR)
    powers under Article 58 Paragraph 2 lit d and f GDPR. Both the remedial authority of the instruction standardized in Art. 58 Paragraph 2 lit d GDPR and the
    51 KB (8,327 words) - 14:04, 14 December 2023
  • inconvenience caused to the complainant. (d) it respects the laws of the EU and Cyprus and fully complies with the GDPR. 2.4. On 8 July 2022, I had issued a warning
    25 KB (3,740 words) - 13:31, 16 October 2023
  • WSA Warsaw (Poland) - II SA/Wa 2559/19 (category Article 58(2) GDPR)
    in Art. 58 sec. 2 lit. ah and lit. j GDPR, instead of an administrative fine, it should be indicated that pursuant to Art. 58 sec. 2 lit. and GDPR, each
    90 KB (14,642 words) - 11:12, 18 November 2020
  • Datatilsynet (Norway) - 20/02165 (category Article 32(1)(d) GDPR)
    Norwegian Health Records Act (pasientjournalloven) and Article 32(1)(b) and (d) GDPR (cf. Article 5 GDPR). The DPA fined Moss municipality NOK 500,000 (€47
    24 KB (3,436 words) - 07:38, 4 October 2021
  • breach of Article 5(1)(a), Article 5(1)(d), Article 5(2), Article 6 GDPR and 129 of the Code. The data controller also breached Article 12(2), Article 15 GDPR
    61 KB (9,720 words) - 22:42, 22 November 2022
  • AEPD (Spain) - PS/00177/2021 (category Article 13 GDPR)
    event of an infringement of the precepts of the GDPR. Article 58.2 of the RGPD provides the following: “2 Each supervisory authority shall have all the following
    29 KB (4,484 words) - 12:28, 7 July 2021
  • BVwG - W101 2213581-1 (category Article 58 GDPR)
    DSG §24 paragraph 1 DSG §24 paragraph 5 GDPR Art17 GDPR Art4 GDPR Art5 GDPR Art58 GDPR Art6 VwGVG §28 paragraph 2 saying W101 2213581-1/5E IN THE NAME OF
    48 KB (7,650 words) - 09:31, 23 February 2022
  • AEPD (Spain) - EXP202103983 (category Article 4(2) GDPR)
    specified period of time - Article 58.2 (i). According to Article 83(2) of the GDPR, the measure provided for in Article 58(2)(d) of the GDPR is compatible with
    28 KB (4,427 words) - 10:02, 16 June 2023
  • AEPD (Spain) - EXP202307898 (category Article 21 GDPR)
    criteria. tion established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of the Regulation (EU) 2016/679
    37 KB (5,591 words) - 14:51, 10 April 2024
  • measures specified below which the Company is ordered to take pursuant to Article 58(2)(d) of the Regulation: 1. drafting and publishing, on the Company's website
    57 KB (9,318 words) - 16:01, 19 April 2023
  • invitation to comply, breaching Article 12 GDPR, Article 15 GDPR, Article 16 GDPR, Article 17 GDPR and Article 18 GDPR. Thus, due to the aformentioned
    73 KB (11,856 words) - 13:54, 25 October 2023
  • processing. In accordance with Article 36 GDPR, the Garante must decide on the adequacy of the intended processing under the GDPR. After careful examination
    71 KB (11,426 words) - 15:49, 6 December 2023
  • AEPD (Spain) - PS/00375/2022 (category Article 5(1)(b) GDPR)
    €20,000 for breaching Article 32. However, the DPA did not request that the controller brings, in accordance with Article 58(2)(d), their processing behaviour
    55 KB (8,720 words) - 10:46, 18 January 2024
  • AEPD (Spain) - PS/00308/2021 (category Article 6 GDPR)
    the provisions of article 58.2.b) of the RGPD, for the alleged violation of article 6 of the RGPD, typified in article 83.5.b) of the GDPR SECOND: ORDER ORANGE
    24 KB (3,728 words) - 10:06, 18 August 2021
  • AEPD (Spain) - PS/00209/2019 (category Article 83(2) GDPR)
    imposed, taking into account the¬ relevant circumstances set out in Article 83.2 of the GDPR:(a) processing of the complainant’s data has been carried out locally;(b)
    26 KB (4,212 words) - 14:10, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.009.048 (category Article 58(2)(b) GDPR)
    data under Article 9 GDPR, which can only be lawful if one of the exceptions of Article 9(2) GDPR apply. With respect to Article 9(2)(h) GDPR, the DPC held
    44 KB (7,042 words) - 13:53, 31 January 2024
  • breach of Article 28 paragraphs 3 and 4 of the GDPR is clear. 2. On the breach of the obligation to ensure data security 49. According to Article 32 of the
    56 KB (9,069 words) - 17:02, 6 December 2023
  • APD/GBA (Belgium) - 18/2020 (category Article 5 GDPR)
    therefore of the opinion that no breach of Article 5.2 of the GDPR, Article 24.1 of the GDPR and Article 33 of the GDPR can be established. - As regards the
    55 KB (8,810 words) - 16:55, 12 December 2023
  • Guidelines, and therefore article 75 of the Italian Code, were also violated. With the power conferred by Article 58(2)(i) and 83 GDPR, the Italian DPA imposed
    54 KB (8,636 words) - 08:47, 28 July 2021
  • the dara subject's objection to be further contacted. Article 5(2), Article 24, and Article 25 GDPR for failing to implement suitable organisational measures
    87 KB (13,867 words) - 13:11, 28 September 2023
  • transparency from Article 5(1)(a) GDPR. Therefore, the controller violated the principle of accountability provided by Article 5(2) and 24 GDPR for the failure
    56 KB (8,922 words) - 10:20, 16 November 2022
  • WSA Warsaw (Poland) - II SA/Wa 310/20 (category Article 5(2) GDPR)
    surveillance, (2) breach of Article 5(1)(a), Article 5(1)(f), Article 5(2), Article 28(1), (3) and (10), Article 29, Article 83(1), (2), (3) and (5) in
    56 KB (8,906 words) - 14:16, 20 September 2021
  • pursuant to Article 13 of the GDPR for collaborators; Information pursuant to Article 13 of the GDPR for employees; Disclosure pursuant to Article 4, paragraph
    78 KB (12,604 words) - 09:01, 7 June 2023
  • NAIH (Hungary) - NAIH-4177-………./2021 (category Article 2(2)(c) GDPR)
    specified in Section 2 (2) defined in the General Data Protection Regulation may apply legal consequences. Pursuant to Article 58 (2) (b) GDPR, the supervisory
    43 KB (6,928 words) - 09:36, 26 November 2021
  • LAG Berlin-Brandenburg - 10 Sa 443/21 (category Article 15 GDPR)
    meaning of Article 4 No. 7 GDPR. However, the defendant cannot be accused of violating an obligation to provide information under Art. 15, 12 GDPR. Paragraph
    28 KB (4,527 words) - 15:58, 26 April 2022
  • violation of Article Article 5(1)(d) GDPR. In addition, the DPA also contested the controller's inadequate data retention time (breach of Article 5(1)(e) GDPR);
    69 KB (11,278 words) - 16:03, 22 February 2023
  • AEPD (Spain) - E/08210/2021 (category Article 4(22) GDPR)
    authority. Under Article 60 GDPR, the following DPAs were identified as “concerned supervisory authorities” under Article 4(22) GDPR: the Netherlands,
    29 KB (4,457 words) - 10:34, 13 December 2023
  • and (1)(e) of Article 6 GDPR. The violation of Article 2-ter of the Code is a direct consequence of the violation of Articles 5 and 6 GDPR. Finally, the
    49 KB (7,883 words) - 15:12, 13 July 2022
  • CNIL (France) - SAN-2020-008 (category Article 13(2)(a) GDPR)
    violation of Article 12 GDPR ? Are the following practices an infringement on data subjects' information right as described in Article 12 GDPR ? Spreading
    104 KB (16,646 words) - 17:09, 6 December 2023
  • AEPD (Spain) - PS/00209/2021 (category Article 83(2)(b) GDPR)
    with the criteria established in Article 83(2)(b) GDPR: negligent character of the infringement, and Article 83(2)(g) GDPR: categories of personal data affected
    19 KB (2,809 words) - 09:21, 1 September 2021
  • AEPD (Spain) - PS-00446-2023 (category Article 6(1) GDPR)
    for in art. 64.2 b) of law 39/2015, of 1 October and article 58.2.b) of the RGPD, the sanction that may apply for the violation of article 6.1 of the RGPD
    34 KB (5,141 words) - 09:28, 8 March 2024
  • VG Wiesbaden - 6 K 549/21.WI (category Article 58(2)(g) GDPR)
    to Art. 17 GDPR. There are none of the reasons set out in Article 17 (1) a to f GDPR. A right to erasure according to Art. 17 Para. 1 d GDPR is ruled out
    32 KB (5,175 words) - 08:40, 12 January 2022
  • party. Therefore, the controller breached Article 5(1)(a) GDPR, Article 6(1)(a) GDPR, Article 7 GDPR, and Article 130 of the Italian privacy code, since the
    51 KB (7,993 words) - 12:39, 6 February 2024
  • BVwG - W258 2247028-1 (category Article 58(2) GDPR)
    at www.bvwg.gv.at DECISIONS D A T U M 2 9 . 0 4 . 2 0 2 2 BUSINESS NUMBER W 2 5 8 2 2 4 7 0 2 8 - 1 / 1 1 E I M N A M E N D E R E P U B L I K ! The Federal
    27 KB (4,012 words) - 14:36, 2 July 2022
  • Commissioner (Cyprus) - 11.17.001.008.229 (category Article 5(2) GDPR)
    country, pursuant to Article 58(2)(f) and (j) of the Regulation; 2.20. the complainant requests that: 2.20.1. the complaint under Article 58 of the Regulation
    56 KB (8,616 words) - 15:31, 6 March 2024
  • Datatilsynet (Denmark) - 2019-32-0988 (category Article 9(2) GDPR)
    accordance with Article 58 (1) of the Data Protection Regulation. 2, letter d. According to the Data Protection Act, section 41, subsection 2, no. 5, is punishable
    45 KB (7,151 words) - 16:24, 6 December 2023
  • signs according to the indications set out in point 2 of this decision, (Article 58, paragraph 2, letter d) of the Regulation); apply a pecuniary administrative
    31 KB (4,916 words) - 10:32, 26 October 2022
  • effective beyond the processing prohibition in Article 58 (2) (f) of the GDPR. Article 58 of the GDPR replaced Article 28(3) of Directive 95/46/EC on the protection
    31 KB (4,797 words) - 10:46, 27 July 2021
  • AEPD (Spain) - PS/00224/2021 (category Article 5(1)(c) GDPR)
    specified period -article 58. 2 d)-. According to the provisions of article 83.2 of the RGPD, the measure provided for in article 58.2 d) of the aforementioned
    27 KB (4,172 words) - 16:37, 25 January 2022
  • having considered all of the corrective powers set out in Article 58(2): (i) Article 58(2)(d) – I have decided to order the HSE to bring its processing
    142 KB (23,134 words) - 15:51, 19 July 2021
  • materia di protezione dei dati personali”; and of Article 6(1)(c), Article 6(1)(e), Article 6(2) and Article 6(3)(b). The Italian DPA did not impose a fine
    75 KB (11,970 words) - 15:39, 3 December 2022
  • NAIH (Hungary) - NAIH-180-16/2022 (category Article 5(2) GDPR)
    Under Article 83 (2) and (5) of the General Data Protection Regulation: 2. Administrative fines shall be imposed in accordance with Article 58 (2), depending
    57 KB (9,033 words) - 16:35, 27 April 2022
  • controller €4,900,000 pursuant to Article 58(2)(i) GDPR. The controller was also ordered to make its several processing operations GDPR-compliant. The DPA also investigated
    133 KB (21,637 words) - 07:03, 7 March 2023
  • AEPD (Spain) - PS/00261/2021 (category Article 6(1) GDPR)
    criteria established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 may
    34 KB (5,536 words) - 19:04, 16 May 2022
  • AEPD (Spain) - PS/00140/2021 (category Article 5 GDPR)
    virtue of the powers that article 58.2 of the RGPD recognizes to each authority of control and as established in articles 47, 64.2 and 68.1 of the LOPDGDD
    28 KB (4,254 words) - 11:30, 16 June 2021
  • constitute 'data relating to health' in the sense of Article 4(15) GDPR. Pursuant to Article 9 GDPR, this special category of data can only be disclosed
    56 KB (9,044 words) - 11:16, 14 March 2023
  • CPDP (Bulgaria) - PNN-01-33/2022 (category Article 32 GDPR)
    the GDPR introduces a prohibition on their processing (Article 9(1) GDPR), while allowing for explicit and limitative exceptions (Article 9(2) GDPR). In
    71 KB (11,948 words) - 17:01, 8 February 2023
  • DPC (Ireland) - 05/SIU/2018 (category Article 2 GDPR)
    here is covered by the GDPR. For further information and relevant legal provisions, please see Article 2(2)(d) GDPR, Articles 1 and 2 LED, and Part 5 and
    13 KB (1,414 words) - 15:11, 14 March 2023
  • Persónuvernd (Iceland) - 2022020333 (category Article 5(2) GDPR)
    appropriate security of the personal data under Article 5(2) and 32(1) GDPR. Pursuant Article 58(2)(c) GDPR, it asked the data controller to take measures
    19 KB (2,799 words) - 13:19, 8 March 2023
  • OLG Köln - 6 U 58/23 (category Article 44 GDPR)
    plaintiff derives his legitimacy from Section 2 Paragraph 2 Sentence 1 No. 11 UKlaG or from Article 80 Paragraph 2 GDPR and only has to show that it concerns data
    118 KB (19,824 words) - 10:49, 6 February 2024
  • Region Lombardia violated Article 5(1)(a)(c) GDPR due to the dissemination not being necessary as well as Article 6(1)(c)(e) GDPR due to the absence of suitable
    77 KB (12,455 words) - 09:35, 15 September 2021
  • AEPD (Spain) - PS/00501/2021 (category Article 5(2) GDPR)
    processing of personal data of clients or third parties (article 83.2.k, of the RGPD in relation to article 76.2.b, of the LOPDGDD) It is appropriate to graduate
    26 KB (3,914 words) - 12:38, 2 February 2022
  • AEPD (Spain) - PS/00060/2021 (category Article 6(1) GDPR)
    complained party, by the alleged violation of Article 6.1 of the RGPD, typified in Article 83.5 a) of the GDPR. Said agreement was notified by post on March
    18 KB (2,739 words) - 10:39, 7 July 2021
  • DPA, the controller breached Article 157 (request for information and production of documents) in relation to Article 166(2) of the Code. Therefore, the
    30 KB (4,724 words) - 13:41, 2 November 2022
  • these reasons, the DPA found violations of Article 5(1)(c) and (e) and Article 32(1)(b) and (d) and 32(2) GDPR, imposing a fine of €240,000. Share your comments
    63 KB (10,048 words) - 09:42, 2 August 2023
  • art. 2, d. lgs. n. 81/2015 (as amended by art. 1, paragraph 1, letter a), nos. 1 and 2, d.l. 3.9.2019, n. 101, converted with modifications into l. 2.11
    235 KB (38,572 words) - 10:19, 20 July 2022
  • DSB (Austria) - D123.768/0004-DSB/2019 (category Article 85(2) GDPR)
    CFR Art11 para 1 ECHR Art10 para 1 GDPR Art4 no 2 GDPR Art4 no 7 GDPR Art85 para 1 GDPR Art85 para 2 Text GZ: DSB-D123.768/0004-DSB/2019 of 18.12.2019
    29 KB (4,637 words) - 13:57, 12 May 2023
  • NAIH (Hungary) - NAIH-175-12/2022 (category Article 5(2) GDPR)
    with Article 58 of the General Data Protection Regulation by alerting the controller or processor. Article 58 (2) (b), (d), (i), (f) and (g) GDPR: In the
    112 KB (17,918 words) - 08:55, 24 March 2022
  • workers. Therefore, the DPA found a violation of Article 5 GDPR, Article 6(1)(c) GDPR and Article 9 GDPR. The duration of the illegal data dissemination
    44 KB (6,633 words) - 15:46, 5 December 2023
  • Datatilsynet (Norway) - 20/03500 (category Article 5(2) GDPR)
    breaching Article 32(1)(b) GDPR and Article 32(1)(d), cf. Article 5(1)(f) GDPR. For this, the DPA fined the Parliament about €196,400 (NOK 2 million).
    32 KB (4,520 words) - 12:01, 28 June 2022
  • (articles 58, paragraph 2, letter i and 83 of the Regulation; article 166, paragraph 7, of the Code). The Guarantor, pursuant to articles 58, par. 2, lit.
    100 KB (16,086 words) - 17:05, 8 February 2023
  • VwGH - 2021/04/0030-4 (category Article 15(1)(d) GDPR)
    access under Article 15 GDPR and for violating the principles of data minimisation (Article 5(1)(c) GDPR), confidentiality (Article 5(1)(f) GDPR) and the controller’s
    92 KB (15,328 words) - 09:18, 14 May 2024
  • AEPD (Spain) - PS/00161/2021 (category Article 17(1) GDPR)
    the treatment is based in accordance with article 6, paragraph 1, letter a), or article Article 9, paragraph 2, letter a), and this is not based on another
    24 KB (3,756 words) - 11:38, 14 September 2021
  • APD/GBA (Belgium) - 35/2024 (category Article 4(2) GDPR)
    within the meaning of Article 100 of the WOG. 24. The Disputes Chamber has thus decided, on the basis of Article 58.2.c GDPR and Article 95, § 1, 5° WOG, to
    27 KB (4,006 words) - 10:14, 17 March 2024
  • Datatilsynet (Norway) - 18/04147 (category Article 5(1)(d) GDPR)
    violating Article 5(1) GDPR, Article 17(1)(a), Article 17(1)(d) and Article 25(1), cf. Article 5(1)(c), Article 5(1)(d), Article 5(1)(e) and Article 5(1)(f)
    47 KB (7,575 words) - 11:35, 18 November 2023
  • Court of Appeal of Brussels - 2020/AR/329 (category Article 77(2) GDPR)
    submits that Article 77 AVG 2, interpreted in the light of Articles 1, 51(1) and 57 AVG, recitals 7, 10 and 141 AVG, Article 8 Charter and Article 16 TFEU,
    48 KB (7,560 words) - 09:03, 20 August 2021
  • AEPD (Spain) - EXP202102433 (category Article 5(1)(f) GDPR)
    SECOND: IMPOSE D.C.C.C., with NIF ***NIF.1, for a violation of article 32.1 of the GDPR, typified in article 83.4, a) of the GDPR, a fine of €2,000 (two a
    35 KB (5,473 words) - 05:14, 26 April 2023
  • circumstances of the specific case (Article 58, paragraph 2, letter i), Regulation). 5. Injunction order. Pursuant to art. 58, par. 2, lett. i) of the Regulations
    180 KB (29,599 words) - 13:51, 28 July 2021
  • UODO (Poland) - DKE.561.23.2020 (category Article 58(2)(i) GDPR)
    and any information necessary for the performance of its tasks (Article 58 (1) (e) GDPR). Violation of the provisions, consisting in failure to provide
    33 KB (5,262 words) - 13:02, 16 June 2021
  • elementi essenziali richiesti dal Regolamento (artt. 6, par. 2 e 9) e dal Codice (artt. 2-ter e 2-sexies); TENUTO CONTO in particolare che, come ribadito nel
    15 KB (2,137 words) - 13:26, 23 June 2021
  • UODO (Poland) - DKN.5131.22.2021 (category Article 32(2) GDPR)
    that the controller breached Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1)(b) and (d), and Article 32(2) GDPR due to a lack of a reliably
    68 KB (10,909 words) - 14:47, 25 October 2021
  • AEPD (Spain) - EXP202104460 (category Article 7 GDPR)
    service in the terms required by article 22.2.”, and may be sanctioned with a fine of up to €30,000, in accordance with article 39 of the aforementioned LSSI
    31 KB (4,923 words) - 12:39, 13 December 2023
  • NAIH (Hungary) - NAIH-642-4/2022 (category Article 7(2) GDPR)
    80) for the breach of Articles 5(1)(b)(c) GDPR, 6(1) GDPR, 12(1) GDPR, 7(2) GDPR, 9(1) GDPR, 13 GDPR and 14 GDPR. Independent of any instructions from the
    73 KB (11,498 words) - 15:22, 29 August 2023
  • DSB (Austria) - 2022-0.858.901 (category Article 6(1) GDPR)
    165/1999 as amended: Article 4, Article 5, Article 6, Article 51, Paragraph 1, Article 57, Paragraph 1, Letters a and h, Article 58, Paragraph 1, Letter
    19 KB (2,904 words) - 12:53, 17 April 2024
  • Lastly, the DPA found a violation of Article 5(2) GDPR, Article 24(1) GDPR, Article 24(2) GDPR and Article 25 GDPR for failing to take adequate measures
    44 KB (6,773 words) - 08:38, 29 November 2023
  • ICO (UK) - HIV Scotland (category Article 32(2) GDPR)
    the GDPR. 14. By Article 57(1) of the GDPR, it is the Commissioner'task to monitor and enforce the application of the GDPR. 15. By Article 58(2)(d)of the
    55 KB (6,916 words) - 07:27, 26 October 2021
  • Regulation, pursuant to art. 58, par. 2, lett. i), and 83, par. 3, of the same Regulation. 5. Corrective measures (art. 58, par. 2, letter d), of the Regulation)
    90 KB (14,647 words) - 17:12, 8 November 2022
  • Therefore, the DPA confirmed a breach of Article 5(1)(a) GDPR, Article 6(1)(a) GDPR, Article 7 GDPR and of Article 130 of the Italian Privacy Code for having
    65 KB (10,464 words) - 09:48, 17 January 2024
  • APD/GBA (Belgium) - 79/2023 (category Article 5(1)(d) GDPR)
    Litigation Chamber decides: – on the one hand, on the basis of Article 58.2.a) of the GDPR and Article 95, § 1, 4° of the LCA, to issue a warning to the defendant
    31 KB (4,567 words) - 14:00, 5 July 2023
  • considered confirmed and it is necessary to enjoin Aesse, pursuant to art. 58, par. 2, lit. d) of the Regulation, if it intends in the future to direct the promotional
    52 KB (8,324 words) - 15:03, 9 May 2023
  • AEPD (Spain) - PS/00459/2020 (category Article 5 GDPR)
    criteria established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 The
    40 KB (6,380 words) - 08:15, 28 July 2021
  • consideration Article 9 GDPR, which establishes that data revealing a person’s sex life are special categories of personal data, and Article 85 GDPR, which establishes
    18 KB (2,622 words) - 13:18, 27 April 2022
  • or instead of the measures referred to in Article 58 paragraph 2 points a) to h) and Article 58 paragraph 2 point j). When deciding on the imposition of
    53 KB (8,451 words) - 22:10, 28 February 2024
  • UODO (Poland) - DKN.5110.12.2021 (category Article 33(1) GDPR)
    h), art. 58 sec. 2 lit. i), art. 83 sec. 1 and 2 and article. 83 sec. 4 lit. a) in connection with art. 33 paragraph 1 and art. 34 sec. 1 and 2 of the Regulation
    51 KB (8,343 words) - 14:16, 15 June 2022
  • AEPD (Spain) - PS-00507-2022 (category Article 58 GDPR)
    were initiated, based on Article 63 and Article 64 LPACAP and an infringement of Article 6(1) GDPR typified in Article 83(5) GDPR. After the proceedings
    49 KB (7,832 words) - 10:54, 22 January 2024
  • DSB (Austria) - 2023-0.227.168 (category Article 4(7) GDPR)
    subject to exercise further rights under the GDPR. Therefore, the DPA used its power under Article 58(2)(c) GDPR and ordered ELGA to provide the requested
    39 KB (6,150 words) - 14:23, 29 August 2023
  • AP (The Netherlands) - 16.06.2020 (category Article 4(12) GDPR)
    so that the violation is still continues. 2. Legal framework Pursuant to Article 2, paragraph 1, of the GDPR, this Regulation applies to all or part of
    54 KB (8,224 words) - 17:07, 12 December 2023
  • Datatilsynet (Denmark) - 2022-32-2939 (category Article 5(1)(b) GDPR)
    announced in accordance with the data protection regulation, article 58, subsection 2, letter d. The Danish Data Protection Authority must request confirmation
    19 KB (2,847 words) - 20:56, 20 May 2023
  • UODO (Poland) - DKN.5112.1.2020 (category Article 5(2) GDPR)
    in Art. 58 sec. 2 of Regulation 2016/679 (Article 83(2)(i) of Regulation 2016/679) - in this case, the measures referred to in Art. 58 sec. 2 of Regulation
    110 KB (17,607 words) - 15:35, 3 January 2023
  • personal data securely, in violation of Articles 5(1)(f) GDPR and Article 32(1)(b) and (d) GDPR. Two aspects of the decisions are interesting. First, the
    86 KB (13,819 words) - 21:32, 8 February 2024
  • AEPD (Spain) - PS/00119/2021 (category Article 6(1) GDPR)
    criteria established in the section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 also
    28 KB (4,459 words) - 14:26, 24 November 2022
  • (EU) 2016/679. With reference to item 2. Paragraph 2 Article 42 Act no. 90/2018 and point b of paragraph 2. Article 58 regulation (EU) 2016/679 is BL ehf
    17 KB (2,597 words) - 17:53, 22 December 2022
  • to art. 58, par. 2, lett. i) of the same Regulation. 5. Corrective measures (art. 58, par. 2, letter c), of the Regulations). Art. 58, par. 2, lett. c)
    64 KB (10,464 words) - 08:22, 14 October 2021
  • issuing the measures referred to in Article 58 of the Regulation. 2. The measures of the Garante referred to in Article 58 of the Regulation may also be adopted
    140 KB (23,084 words) - 09:22, 30 April 2024
  • UODO - DKN.5112.1.2020 (category Article 5(2) GDPR)
    controller under Article 24(1) GDPR, Article 25 (1) GDPR, Article 32(1)(b) GDPR and Article 32(1)(d) GDPR and Article 32 GDPR#2"Article 32(2) GDPR. Share blogs
    89 KB (14,285 words) - 12:21, 10 September 2021
  • IP (Slovenia) - 0611-608/2021/9 (category Article 4(2) GDPR)
    pursuant to Article 9 GDPR, and violated the principle of data minimisation, Article 5(1)(c) GDPR. The DPA ordered, pursuant to Article 58(2)(d), to bring
    23 KB (3,551 words) - 17:15, 23 February 2022
  • approximately €2.000 because it ignored the DPA's request to provide information regarding its processing operations in violation of Article 58(1) GDPR. A data
    4 KB (460 words) - 16:28, 15 December 2021
  • carry out an interest test and therefore breached Article 6(1) GDPR. Article 13(1) GDPR and Article 13(2) GDPR set out the processing circumstances and information
    62 KB (9,792 words) - 13:54, 5 October 2022
  • AEPD (Spain) - PS/00505/2021 (category Article 6(1) GDPR)
    sedeagpd.gob.es, 3/10 FOUNDATIONS OF LAW I By virtue of the powers that article 58.2 of the RGPD recognizes to each control authority, and according to the
    28 KB (4,283 words) - 09:43, 24 March 2022
  • Datainspektionen - DI-2020-1539 (category Article 9(1) GDPR)
    powers to be granted under Article 58 (2) (a) to (j), including reprimand, injunction and penalty fees. It follows from Article 58 (2) of the Data Protection
    23 KB (3,553 words) - 09:02, 13 May 2022
  • WSA Warszawa - II SA/Wa 607/20 (category Article 58(2)(b) GDPR)
    it and the applicants, i.e. on the basis of Article 6(1)(b) GDPR. However, pursuant to Article 17(3)(e) GDPR, the right to request from the controller the
    47 KB (7,617 words) - 09:33, 26 November 2021
  • Datatilsynet (Norway) - 21/02504 (category Article 5(2) GDPR)
    without a legal basis under Article 6(1) GDPR and for not adhering to the accountability principle as per Article 5(2) GDPR, cf. Article 24. The DPA also requires
    40 KB (5,993 words) - 05:16, 16 February 2022
  • AEPD (Spain) - EXP202204501 (category Article 5(1)(f) GDPR)
    officer. The DPA held that the controller violated Article 5(1)(f), 32, and 37 GDPR. Pursuant to Article 58(2)(d), it ordered the controller to bring processing
    57 KB (8,604 words) - 15:40, 20 March 2024
  • based on Articles 6(c) and 9(2)(b). The school did not specify the source of the legal obligation under Article 6(1)(c) GDPR, nor the source of the obligations
    24 KB (3,752 words) - 11:47, 9 November 2022
  • security and confidentiality for personal data, in breach of Article 32(1)(b) and Article 32(2) GDPR. The DPA further noted that the controller did not reply
    5 KB (555 words) - 12:40, 20 July 2022
  • duties under Article 13 GDPR, as the information allegedly provided to the data subject lacked the requirements laid down in said Article, and the relevant
    43 KB (6,766 words) - 14:59, 2 May 2023
  • AEPD (Spain) - PS/00180/2021 (category Article 6 GDPR)
    of a person (article 83.2 b). - Basic personal identifiers are affected (name, a number of identification, the line identifier) (article 83.2 g). C / Jorge
    26 KB (3,947 words) - 10:42, 21 July 2021
  • carried out on the basis of Article 6(1)(b) GDPR, as well as to fulfill a legal obligation pursuant to Article 6(1)(c) GDPR related to public entities’
    31 KB (4,945 words) - 16:11, 20 April 2022
  • the UK GDPR. 14. By Article 58(2)(d) of the UK GDPR the Commissioner has the power to notify controllers of alleged infringements of the UK GDPR. By Article
    54 KB (7,579 words) - 16:44, 7 May 2024
  • AEPD (Spain) - PS/00269/2019 (category Article 5(1)(f) GDPR)
    for violation of article 5.1.f) of the RGPD, typified in article 85.5.a) of the aforementioned RGPD, in accordance with article 77. 2 of the LOPDGDD. Once
    30 KB (4,761 words) - 14:24, 13 December 2023
  • AEPD (Spain) - PS/00188/2021 (category Article 6(1) GDPR)
    highest amount. " Article 58.2 of the RGPD provides: “Each control authority will have all of the following corrective powers listed below: d) order the person
    33 KB (5,242 words) - 11:42, 11 August 2021
  • HDPA (Greece) - 10/2024 (category Article 5(1)(f) GDPR)
    to Article 58(5)(a) and (b) of the General Data Protection Regulation, the imposition of a penalty in accordance with Article 58(3)(a) of the GDPR. 2(i)
    25 KB (3,916 words) - 14:34, 24 April 2024
  • CPDP (Bulgaria) - PNN-01-487/2021 (category Article 6(1)(a) GDPR)
    violated. When determining the type of corrective measure under Art. 58, § 2 of the GDPR, which should be imposed by the CPLD for the found violation, as mitigating
    27 KB (4,439 words) - 09:03, 9 February 2023
  • violation of Articles 5(1)(a) and (c) GDPR, as well as in breach of the adequate information requirements under Article 13 GDPR. Based on these infringements,
    15 KB (2,365 words) - 13:17, 23 February 2022
  • AEPD (Spain) - PS/00433/2021 (category Article 6(1) GDPR)
    alleged violation of article 6.1 of the RGPD, sanctioned in accordance with the provisions of article 83.5.b) of the aforementioned GDPR and considered for
    27 KB (4,079 words) - 12:37, 9 February 2022
  • DPC (Ireland) - IN-19-7-2 (category Article 5(1)(d) GDPR)
    ICB’s infringement of Article 25(1) of the GDPR warrants the imposition of an administrative fine pursuant to Article 58(2)(i) GDPR in addition to the reprimand
    5 KB (620 words) - 13:13, 19 May 2021
  • VG Ansbach - AN 14 K 20.00083 (category Article 58(2)(f) GDPR)
    areas pursuant to Article 58(2)(f) GDPR. The court held that the video surveillance was not lawful pursuant to Article 6(1)(a) GDPR as the data subjects
    36 KB (5,858 words) - 13:51, 16 May 2022
  • Datatilsynet (Denmark) - 2021-431-0144 (category Article 32(1) GDPR)
    with the data protection regulation, article 58, subsection 2, letter d. The deadline for compliance with the order is 2 September 2022. The Danish Data Protection
    21 KB (3,249 words) - 15:39, 31 August 2022
  • found the following infringements. Enel Energia violated Article 5(1)(f) GDPR and Article 32 GDPR where it failed to carry out an adequate assessment of
    208 KB (33,932 words) - 11:40, 17 April 2024
  • the art. 58, par. 2 of the Regulation, believes that it is not necessary to order corrective measures pursuant to art. 58, par. 2, letter. d), and provides
    52 KB (8,196 words) - 15:46, 27 March 2024
  • Datatilsynet (Denmark) - 2020-31-4326 (category Article 32(1) GDPR)
    failure to comply with an order issued by the DPA pursuant to Article 58(2)(d) of the GDPR. The following is a detailed description of the case and the
    13 KB (1,976 words) - 15:32, 10 November 2021
  • de-index an article about a criminal investigation on the data subject, as there was no public interest regarding the news, regardless of the article being accurate
    34 KB (5,428 words) - 09:03, 4 August 2022
  • Therefore, the controller was sanctioned with a €2,000 fine for violating Article 58(1) GDPR and Article 83(5) GDPR. The Romanian DPA rarely published full decisions
    4 KB (399 words) - 08:32, 27 October 2022
  • BlnBDI (Berlin) - 521.13874 (category Article 6(1)(a) GDPR)
    controller, Article 58(2)(b). Notably, the DPA's decision derives the right to a copy only from Article 15(1) GDPR, while other DPAs have held that Article 15(1)
    13 KB (1,811 words) - 09:06, 12 November 2021
  • AG Pfaffenhofen a. d. Ilm - 2 C 133/21 (category Article 14(2)(f) GDPR)
    violated Article 14 and Article 15 GDPR, since the controller did not give exact information where they had obtained the email-address from (Article 14(2)(f)
    28 KB (4,447 words) - 16:37, 13 January 2022
  • CNIL (France) - SAN-2023-025 (category Article 6(1)(a) GDPR)
    the data subjects, therefore breaching Article 6 GDPR, as well as Article 5(1)(b) GDPR. Thirdly, Article 30 GDPR stipulates that the controller must keep
    53 KB (8,418 words) - 11:21, 6 February 2024
  • AEPD (Spain) - PS/00483/2021 (category Article 13 GDPR)
    that art 58.2 of the RGPD and, as established in arts. 47, 64.2 and 68.1 of the LOPDGDD Law. For its part, sections 1) and 2), of article 58 of the RGPD
    41 KB (6,620 words) - 16:19, 20 April 2022
  • accounts of three of its former employees in violation of Article 5(1) GDPR and Article 13 GDPR. GEICO S.p.A., the controller, was the employer of the three
    90 KB (14,258 words) - 14:14, 3 January 2024
  • UODO (Poland) - DKN.5131.33.2021 (category Article 58(2)(e) GDPR)
    minor "; d) compliance with previously applied measures in the same case, referred to in Art. 58 sec. 2 of Regulation 2016/679 (Article 83 (2) (i) of Regulation
    81 KB (13,351 words) - 14:48, 2 March 2022
  • AEPD (Spain) - PS/00314/2021 (category Article 37 GDPR)
    supporting means of the compliance with what is required. In this sense, article 58.2 d) of the RGPD, states that each control authority may “order the person
    24 KB (3,489 words) - 12:05, 10 November 2021
  • NAIH (Hungary) - NAIH-5802-9/2022. (category Article 5(1)(a) GDPR)
    violated Article 14(1) and (2) GDPR. Because it failed to provide clear and transparent information, the controller also violated Article 12(1) GDPR. The DPA
    120 KB (19,907 words) - 10:48, 9 November 2022
  • AEPD (Spain) - PS/00324/2021 (category Article 5(1)(c) GDPR)
    personal data from Article 9 GDPR. According to the AEPD, even if the controller may had relied on the exemption on Article 9 GDPR(2)(f), since the data
    29 KB (4,546 words) - 17:47, 7 January 2022
  • accesses) (Article 83(2)(a) GDPR and Article 83(2)(g) GDPR). It also considered the cooperation of the controller to remedy the infringement (Article 83(2)(f)
    70 KB (11,425 words) - 13:47, 7 December 2022
  • interested party" (Article 6, paragraph 1, letters c) and e), 2 and 3, as well as articles 9, par. 2, lit. g) of the Regulation and 2-ter and 2-sexies of the
    157 KB (25,874 words) - 14:36, 27 June 2023
  • within the foreseen deadlines, under Article 12(1) GDPR, Article 12(2) GDPR, Article 12(3) GDPR and Article 12(4) GDPR. The DPA further stated that regarding
    42 KB (6,583 words) - 10:13, 13 October 2023
  • according to its faculties under Article 58(2)(a), Article 58(2)(b) and Article 58(2)(d), as well as Article 83(5) GDPR, Share your comments here! Share
    380 KB (62,114 words) - 15:20, 26 January 2022
  • AEPD (Spain) - PS/00043/2021 (category Article 58(2) GDPR)
    the planks). FOUNDATIONS OF LAW I In accordance with the powers that article 58.2 of (EU) 2016/679 (Regulation General Data Protection, hereinafter RGPD)
    23 KB (3,505 words) - 13:40, 27 April 2022
  • ICO (UK) - Cabinet Office (category Article 5(1)(f) GDPR)
    By Article 58(1)(d) of the GDPR, the Commissioner has the power to notify controllers of alleged infringements of the GDPR. By Article 58(2)(i), the Commissioner
    79 KB (10,566 words) - 10:48, 7 December 2021
  • right to object. 2.2.2. With reference to the dispute referred to in point 2), the violation of the provisions of Articles 5, para. 1 and 2, art. 6, par.
    142 KB (23,307 words) - 09:37, 28 October 2021
  • APD/GBA (Belgium) - 05/2021 (category Article 5(2) GDPR)
    of 25,000 euros (Article 83, paragraph 2 GDPR; Article 100, §1, 13 ° WOG and Article 101 WOG). 18 55. Taking into account article 83 GDPR and the case law
    60 KB (9,281 words) - 16:50, 12 December 2023
  • 32(2) GDPR. Finally, the Finnish DPA considered that the firm had failed to respect the principle of accountability enshrined in Article 5(2) GDPR, as
    153 KB (24,570 words) - 15:11, 26 March 2024
  • art. 58, par. 2, lett. i), and 83, par. 3, of the same Regulation and art. 166, paragraph 2, of the Code. 5. Corrective measures (art. 58, par. 2, letter
    222 KB (35,993 words) - 09:52, 20 October 2021
  • AEPD (Spain) - PS/00475/2021 (category Article 13 GDPR)
    of Article 6 GDPR, nor of Article 8 GDPR. There was also no violation of Article 9 GDPR, since the exception for explicit consent from Article 9(2)(a)
    64 KB (10,187 words) - 14:26, 24 November 2022
  • Article 9, Article 12 and Article 13 GDPR. The Italian DPA ordered the controller to bring processing operations into conformity with the provisions of
    89 KB (14,466 words) - 15:14, 20 February 2024
  • DSB (Austria) - 2021-0.187.619 (category Article 17(1)(d) GDPR)
    weeks pursuant to Article 17(1)(d) GDPR because the processing was unlawful under Article 6 GDPR and the exception of Article 17(3)(a) GDPR did not apply.
    25 KB (3,905 words) - 14:45, 11 May 2022
  • following Article 14 of Law No. 190/2018, the DPA fined the controller RON 10,000 (approximately €2,000) for violating Article 58(1)(a) and (e) GDPR. Share
    4 KB (501 words) - 14:23, 25 August 2021
  • IDPC (Malta) - CDP/54/2023 (category Article 5(2) GDPR)
    processing according to Article 4(2) GDPR and thus requires a legal basis according to Article 6(1) GDPR and comply with Article 5 GDPR. The controller did
    16 KB (2,429 words) - 14:21, 7 May 2024
  • provided for in Article 2, h) of Directive 95/46/EC. In particular, under these new requirements, article 4, paragraph 11 of the GDPR requires that the
    82 KB (13,428 words) - 17:02, 6 December 2023
  • AEPD (Spain) - PS/00178/2021 (category Article 5(1)(f) GDPR)
    criteria established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 The
    20 KB (3,078 words) - 14:26, 24 November 2022
  • APD/GBA (Belgium) - 47/2022 (category Article 13(2)(d) GDPR) (section 2. Legal basis)
    the meaning of Article 9 of the GDPR must indeed be based on Article 9.2 of the GDPR, read in conjunction with Article 6.1 of the GDPR. 24 This has been
    207 KB (31,357 words) - 14:21, 8 June 2022
  • DSB (Austria) - 2021-0.119.956 (category Article 15(2) GDPR)
    covered by Article 58 of the GDPR (cf. BVwG of May 28, 2020, GZ W211 221 6385-1). Point 2 is based on Article 58, paragraph 2, letter c, GDPR. The restriction
    50 KB (8,021 words) - 15:40, 18 January 2024
  • IP (Slovenia) - 0611-623/2021/10 (category Article 13(2) GDPR)
    out SARS-CoV-2 self-testing procedures is Article 6(1)(c) GDPR (the necessity to comply with a legal obligation) and Article 9(2)(h) GDPR, in conjunction
    30 KB (4,690 words) - 04:23, 23 June 2022
  • DSB (Austria) - 2023-0.603.142 (category Article 31 GDPR)
    their tasks (Article 58 Paragraph 1 Letter a GDPR). (Article 58 Paragraph One Litera a, GDPR). From this provision, taken together with Article 31 of the
    76 KB (12,550 words) - 09:24, 28 February 2024
  • Persónuvernd (Iceland) - no. 2020020909 (category Article 58(2)(g) GDPR)
    tölul. Articles 2.2.1. to record in the default register information that the debtor has been ordered to pay a debt by a court. In Article 2.1. The operating
    21 KB (3,099 words) - 10:00, 6 October 2021
  • AEPD (Spain) - PS/00362/2021 (category Article 5(1)(f) GDPR)
    accordance with the provisions of Article 58.2.b) of the RGPD, for the alleged violation of Article 32 of the RGPD, typified in article 83.4.a) of the RGPD. SECOND:
    31 KB (4,769 words) - 08:00, 8 September 2021
  • absence of a valid legal basis, in breach of Article 5(1)(a) and Article 6 GDPR, as well as Articles 2-ter and 2-sexies of the Italian Data Protection Code
    128 KB (20,516 words) - 12:43, 10 January 2023
  • AEPD (Spain) - EXP202211618 (category Article 6(1) GDPR)
    according to article 4.1 of the GDPR, it is personal data and its protection, therefore, is the subject of said Regulation. Article 4.2 of the GDPR defines
    33 KB (5,018 words) - 13:23, 2 August 2023
  • anonymized. Therefore, the DPA found a violation of Article 5(1)(a), (b), (c), and (e) and Article 12(1) GDPR. For the reasons above, the DPA imposed a fine
    122 KB (19,640 words) - 08:16, 3 August 2023
  • IMY (Sweden) - DI-2021-3399 (category Article 6(1) GDPR)
    follows from Article 58(2)(i) and Article 83(2) of the GDPR that the IMY has the power to impose administrative fines in accordance with Article 83. Depending
    54 KB (6,188 words) - 14:20, 1 March 2023
  • UODO (Poland) - DKN.5131.43.2022 (category Article 5(2) GDPR)
    the controller was in breach of Article 33(1) GDPR, Article 33(3) GDPR, Articles 34(1) and 34(2) GDPR, and Article 5(2) GDPR, Firstly, the Polish DPA held
    57 KB (9,261 words) - 08:13, 25 October 2023
  • AEPD (Spain) - PS/00189/2021 (category Article 6(1) GDPR)
    www.aepd.es 28001 - Madrid sedeagpd.gob.es 2/8 FOUNDATIONS OF LAW I By virtue of the powers that article 58.2 of the RGPD recognizes to each control authority
    23 KB (3,387 words) - 09:55, 22 September 2021
  • AEPD (Spain) - PS/00420/2021 (category Article 5(1)(f) GDPR)
    contemplated in article 83.2 of the RGPD and the Article 76.2 of the LOPDGDD, with respect to the infraction committed by violating the established in article 5.1
    31 KB (4,660 words) - 09:46, 22 June 2022
  • in the data controller" (Article 6, paragraph 1, letter e ), 2 and 3, and art. 9, par. 2, lett. g), of the Regulations; art. 2-ter of the Code, in the text
    59 KB (9,359 words) - 08:38, 16 November 2022
  • DSB (Austria) - DSB-D213.1759 (category Article 5(1)(c) GDPR)
    1.: Article 4, Article 5 Paragraph 1 Letter c, Article 6, Article 12 Paragraph 3, Article 51 Paragraph 1, Article 57 Paragraph 1 Letter f, Article 58 Paragraph
    72 KB (11,993 words) - 14:21, 10 April 2024
  • AEPD (Spain) - EXP202204836 (category Article 15 GDPR)
    in article 58.2 of the GDPR. Between They have the power to impose an administrative fine in accordance with the article 83 of the RGPD -article 58.2 i)-
    52 KB (8,320 words) - 13:18, 14 February 2024
  • in conditions of objective difficulty. Pursuant to its powers under Article 58 GDPR, the Italian DPA (Garante) issued a decision to fine the Mayor of Messina
    48 KB (7,887 words) - 11:56, 30 June 2021
  • (EU) No Article 5 (1) (a) and (b), Article 6 (1), Article 6 (4) Article 12 (1), Article 13, Article 21 (1) and (2), Article 24 (1), Article 25 Article 1 (1)
    147 KB (23,028 words) - 13:36, 28 February 2023
  • HDPA (Greece) - 28/2022 (category Article 12(3) GDPR)
    issued a reprimand (Article 58(2)(b) GDPR) to the controller for breach of those provisions and instructed (Article 58(2)(c) of the GDPR) it to satisfy the
    4 KB (397 words) - 15:02, 15 November 2022
  • CE - 451423 (category Article 55(1) GDPR)
    the provisions of Article 5(3) of Directive 2002/58/EC in presence of cross-border processing of personal data’;2) Directive 2002/ 58/EC contain an implicit
    51 KB (8,228 words) - 17:33, 11 January 2023
  • subject was unlawful, violating Article 12 in connection with Article 17. The DPA held that, with reference to Recital 148 GDPR, the infringement cannot be
    63 KB (10,108 words) - 14:38, 25 October 2022
  • AEPD (Spain) - E/13223/2021 (category Article 5 GDPR)
    Agency. FOUNDATIONS OF LAW I.- Competition: By virtue of the powers that article 58.2 of Regulation (EU) 2016/679, of the Parliament- European Act and of the
    19 KB (2,818 words) - 17:41, 23 February 2022
  • unlawful for the purposes of Articles 5(1)(a), 5(1)(c), 5(1)(d) GDPR, Article 9 GDPR, and Article 85 GDPR when read in line with domestic legislation. This was
    8 KB (928 words) - 08:31, 23 August 2023
  • DSB (Austria) - 2023-0.592.319 (category Article 58(2)(c) GDPR)
    the GDPR against the controller, the DPA issued a fine of €12.100 in accordance with Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR. Both
    80 KB (13,263 words) - 13:06, 17 May 2024
  • AEPD (Spain) - PS/00427/2021 (category Article 6(1) GDPR)
    of a person (article 83.2 b). - Basic personal identifiers are affected (name, a number identification, the line identifier) (article 83.2 g). - Section
    23 KB (3,593 words) - 16:23, 26 January 2022
  • Cour Administrative - 48964C (category Article 77(2) GDPR)
    company (D), noting in particular that: “(…) We therefore understand that Article 3(2) of the GDPR applies to processing activities performed by (D). Considering
    42 KB (6,557 words) - 14:16, 15 December 2023
  • place per Article 46(2) GDPR. For these violations, the DPA reprimanded the controller and ordered it to comply with the GDPR (specifically Article 46 GDPR)
    91 KB (14,906 words) - 14:39, 5 October 2022
  • AEPD (Spain) - EXP202202954 (category Article 5(1)(c) GDPR)
    established in article 5 of Regulation (EU) 2016/679. (…)”. VII Second unfulfilled obligation: violation of article 9.1 of the GDPR Article 9 of the GDPR states:
    34 KB (5,149 words) - 16:00, 20 March 2024
  • NAIH (Hungary) - NAIH-5114-35/2022 (category Article 58(2)(f) GDPR)
    legitimate interest. Based on Article 2 (1) of the GDPR, the GDPR must be applied to the data management in this case. GDPR Article 4, point 1: "personal data":
    146 KB (22,679 words) - 15:52, 3 May 2023
  • AEPD (Spain) - PS/00603/2021 (category Article 6(1) GDPR)
    online store had violated Article 6(1) GDPR. The AEPD also held that the online store had violated its obligation under Article 13 GDPR to provide data subjects
    41 KB (6,588 words) - 16:47, 27 April 2022
  • AEPD (Spain) - PS/00080/2022 (category Article 83(2)(a) GDPR)
    circumstances in relation to Article 5 and Articles 32 and 33 GDPR. First, there was the duration of the infringement under Article 83(2)(a) GDPR; second, there was
    47 KB (7,265 words) - 10:05, 21 July 2022
  • NAIH (Hungary) - NAIH-4447-6/2021 (category Article 17(1)(d) GDPR)
    Section 2 (2) in accordance with Article 58 (2) of the General Data Protection Regulation may apply legal consequences. Pursuant to Article 58 (2) (b), (c)
    88 KB (14,152 words) - 10:07, 28 September 2021
  • fairness and transparency, as stipulated by Article 5(1)(a) GDPR, Article 12(1) GDPR, as well as Article 13(2) GDPR due to the lack of information on the period
    111 KB (17,635 words) - 13:18, 13 September 2023
  • Datatilsynet (Norway) - 0/02422 (category Article 58(2)(i) GDPR)
    Articles 5(1)(a) and (e), 6(1), 12, 13, 15 and 17 GDPR. 2. Datatilsynet’s Decision Pursuant to Article 58(2)(i) GDPR, Datatilsynet issues an administrative fine
    162 KB (24,007 words) - 19:41, 15 February 2023
  • ICO (UK) - Nottinghamshire County Council (category Article 58(2)(b) GDPR)
    reprimanded Nottinghamshire County Council under Article 58(2)(b) (UK) GDPR, for infringing Article 32(1) (UK) GDPR. Share your comments here! Share blogs or
    10 KB (1,349 words) - 13:54, 25 October 2023
  • UODO (Poland) - DKN.5131.12.2020 (category Article 5(2) GDPR)
    controller violated Article 5(2) GDPR by not being able to demonstrate its compliance with the principles under Article 5(1) GDPR. For these violations
    74 KB (11,896 words) - 15:14, 7 March 2023
  • ISWEB violated Article 28(2) GDPR and Article 28(4) GDPR as a processor on behalf of the hospitals and Article 28(1) GDPR and Article 28(3) GDPR as controller
    99 KB (16,015 words) - 16:16, 1 June 2022
  • HDPA (Greece) - 6/2024 (category Article 5(2) GDPR)
    provision of article 58 par. 2 sec. i of the GDPR, effective, proportionate and dissuasive administrative money fine according to article 83 of the GDPR, both
    19 KB (3,000 words) - 13:44, 6 March 2024
  • OLG Stuttgart - 2 U 257/19 (category Article 13 GDPR)
    supervisory authorities (Article 58(2) DSGVO), in particular the fines to be imposed (Article 58(2)(i) DSGVO), for which Article 83 DSGVO contains a detailed
    52 KB (8,574 words) - 16:03, 10 March 2022
  • AEPD (Spain) - PS/00126/2021 (category Article 6(1) GDPR)
    negligence of the infringement (Article 83(2)(b) GDPR) the impact on basic personal identifiers (Article 83(2)(g) GDPR) Share your comments here! Share
    26 KB (3,922 words) - 13:10, 9 June 2021
  • AEPD (Spain) - PS/00480/2020 (category Article 5(1)(f) GDPR)
    accordance with article 58.2 of the RGPD: "2. Each supervisory authority shall have all the following corrective powers indicated below: d) order the person
    41 KB (6,468 words) - 17:16, 24 November 2021
  • HDPA (Greece) - 12/2024 (category Article 17 GDPR)
    60 of the GDPR does not apply the GDPR and, therefore, in accordance with the provisions of articles 55 para. 1, 2 para. 1 and 3 para. 2 GDPR and 13 para
    37 KB (5,933 words) - 16:53, 19 April 2024
  • AEPD (Spain) - PS/00200/2021 (category Article 6(1) GDPR)
    " Regarding section k) of article 83.2 of the RGPD, the LOPDGDD, article 76, "Sanctions and corrective measures", provides: "2. In accordance with the provisions
    23 KB (3,787 words) - 09:50, 5 August 2021
  • measures pursuant to art. 58, par. 2, of the Regulation. 4. Order of injunction. The Guarantor, pursuant to art. 58, par. 2, lett. i) of the Regulations
    50 KB (7,892 words) - 15:00, 28 September 2022
  • APD/GBA (Belgium) - 72/2021 (category Article 6(1)(e) GDPR)
    for by the GDPR (called grounds for justification by the complainant) and explains why it considers that neither Article 6.1.d) nor Article 6.1.e) is applicable
    57 KB (8,330 words) - 11:53, 30 June 2021
  • AEPD (Spain) - EXP202102529 (category Article 58(1) GDPR)
    these investigative actions. In light of provisions (Article 4 (15) GDPR, Article 9 GDPR, Article 6 GDPR) the vaccination of a person against Covid-19 implies
    42 KB (6,246 words) - 16:36, 9 January 2024
  • selection process, taking the storage limitation principle under Article 5(1)(e) GDPR into consideration. A data subject had entered a public competition
    23 KB (3,581 words) - 17:29, 9 March 2022
  • APD/GBA (Belgium) - 135/2022 (category Article 4(23) GDPR)
    held that the controller violated Article 12(1) GDPR, Article 12(2) GDPR, Article 15(1) GDPR and Article 15(3) GDPR. The controller had deleted the data
    39 KB (5,674 words) - 08:57, 29 June 2023
  • articles 58, par. 2, lit. i), and 83, par. 3, of the same Regulation and of the art. 166, paragraph 2, of the Code. 5. Corrective measures (Article 58, paragraph
    134 KB (21,837 words) - 11:37, 13 June 2023
  • AEPD (Spain) - PS/00111/2021 (category Article 5(1)(f) GDPR)
    constitute a severe and negligent violation (Article 83(2)(a) and (b) GDPR) of Articles 5(1)(f) and 32 GDPR, as the complainant's data was neither processed
    39 KB (6,095 words) - 10:08, 20 October 2021
  • APD/GBA (Belgium) - 99/2023 (category Article 17(1)(d) GDPR)
    to the GDPR in execution of article 2.1. of the GDPR. II.2. Regarding compliance with Article 6 of the GDPR (lawfulness) 24. Pursuant to Article 6 of the
    33 KB (5,012 words) - 14:07, 26 July 2023
  • controller according to the accountability principle laid down in Article 5(2) GDPR. For this reason, the DPA concluded that the call centre first contacted
    90 KB (14,621 words) - 09:55, 7 December 2022
  • IP - 07121-1/2020/428 (category Article 58 GDPR)
    such as an insurance company, should have an adequate legal basis under Article 6 GDPR to lawfully do so. An individual notified the IP about a car accident
    9 KB (1,211 words) - 11:57, 24 March 2022
  • AEPD (Spain) - EXP202213792 (category Article 5(1)(c) GDPR)
    finding likely violations of Article 5(1)(c), 8, 9, 13 and 35 GDPR. The AEPD found a likely violation of Article 35 GDPR. Article 35 GPDR requires that a data
    178 KB (27,656 words) - 12:28, 7 May 2024
  • IMY (Sweden) - DI-2021-10448, (category Article 58(2)(b) GDPR)
    that the controller did not violate Article 16 GDPR. Third, the DPA held that the controller had violated Article 15 GDPR because it only provided a reply
    10 KB (1,505 words) - 15:07, 7 February 2023
  • AEPD (Spain) - PS/00151/2021 (category Article 28(3) GDPR)
    2) of the LSSI, without detriment of what results from the instruction. WHAT: in accordance with article 58.2 of the RGPD, the corrective measure that
    53 KB (8,628 words) - 15:44, 13 July 2022
  • operations into compliance, pursuant to Article 58(2)(d) within 3 months. An administrative fine, pursuant to Articles 58(2)(i) and 83, addressed to WhatsApp
    830 KB (115,261 words) - 15:37, 22 February 2022
  • By Article 58(2)(d) of the GDPR the Commissioner has the power to notify controllers of alleged infringements of GDPR. By Article 58(2)(i) he has the power
    77 KB (9,347 words) - 07:39, 13 October 2022
  • NAIH (Hungary) - NAIH-7058-5/2022 (category Article 7(2) GDPR)
    unlawful. The processing violated Article 7(2) GDPR, Article 7(4) GDPR and Article 6(1)(a) GDPR. The controller was fined 2,000,000 HUF (approx. €5,080). In
    66 KB (10,499 words) - 08:55, 10 February 2023
  • CNIL (France) - SAN-2022-020 (category Article 3(2)(a) GDPR)
    Failure to ensure data protection by default (Article 25(2) GDPR) The DPA also found a violation of Article 25(2) GDPR regarding the controllers “X” icon at the
    59 KB (9,566 words) - 17:03, 6 December 2023
  • Italian DPA reprimanded a processor for having breached Article 5(1)(f) GDPR and Article 32 GDPR since, following a software update, the platform of a healthcare
    89 KB (14,492 words) - 12:52, 14 February 2024
  • AEPD (Spain) - PS-00393-2022 (category Article 13 GDPR)
    cookies. The Spanish DPA held the controller to have infringed Article 13 GDPR and Article 22.2 of the Law of Information Society Services and Electronic Commerce
    54 KB (8,094 words) - 10:51, 10 January 2024
  • AEPD (Spain) - EXP202207521 (category Article 6(1) GDPR)
    DIGITAL, S.L.U., with NIF B11514445, is ordered that by virtue of article 58.2.d) of the GDPR, within a period of 1 month, accredit having proceeded to comply
    54 KB (8,747 words) - 08:36, 30 August 2023
  • AEPD (Spain) - PS/00493/2020 (category Article 6(1) GDPR)
    criteria established in the section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679, also
    51 KB (8,261 words) - 15:29, 25 January 2022
  • fairness (Article 5(1)(a) GDPR). Thus by not providing sufficient information, the controller breached Article 5(1)(a) GDPR and Article 13 GDPR. Additionally
    41 KB (6,619 words) - 13:06, 18 January 2023
  • WSA Warsaw - II SA/Wa 1899/20 (category Article 58(2)(g) GDPR)
    to withdraw consent at any time; (c) breach of Article 17(1) and (2), in conjunction with Article 58(2)(g), of the DPA, by failing to apply them and omitting
    30 KB (4,806 words) - 10:59, 19 May 2021
  • AEPD (Spain) - PS/00078/2021 (category Article 5(1)(c) GDPR)
    criteria established in the section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679, also
    118 KB (19,187 words) - 17:08, 9 March 2022
  • CE - N° 433069 (category Article 4(11) GDPR)
    submissions made for an injunction and under Article L. 761-1 of the Code of Administrative Justice. D E C I D E D: Article 1: The request of the associations "La
    19 KB (2,936 words) - 14:44, 24 March 2022
  • by the art. 58, par. 2 of the Regulation, believes it is not necessary to order corrective measures pursuant to art. 58, par. 2, letter. d), and provides
    62 KB (9,678 words) - 10:45, 13 March 2024
  • CE - 449209 (category Article 55(1) GDPR)
    attacking. D E C I D E : -------------- Article 1: The request of the companies Google LLC and Google Ireland Limited is rejected. Article 2: This decision
    36 KB (5,595 words) - 16:12, 2 February 2022
  • AEPD (Spain) - EXP202300944 (category Article 4(11) GDPR)
    in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
    76 KB (11,351 words) - 09:28, 24 April 2024
  • NAIH (Hungary) - NAIH-2501-10/2022 (category Article 5(1)(a) GDPR)
    Protection Regulation paragraph and paragraph 2 of Article 7. II. The Authority based on Article 58 (2) point d) of the General Data Protection Regulation
    90 KB (14,299 words) - 13:52, 2 February 2023
  • First-tier Tribunal - 2023 UKFTT 778 GRC (category Article 5(1)(a) GDPR)
    the provision of information can be absolute by Section 2(2)(a) FOIA or qualified by section 2(2)(b) FOIA.  Where an exemption is qualified it is subject
    28 KB (4,450 words) - 15:12, 20 October 2023
  • AEPD (Spain) - EXP202213323 (category Article 5(1)(c) GDPR)
    Violation of article 35 of the GDPR................................................ ...................36 8.2. Violation of article 9 of the GDPR.........
    176 KB (27,432 words) - 07:43, 10 May 2024
View ( | ) (20 | 50 | 100 | 250 | 500)