Search results

From GDPRhub
  • HDPA (Greece) - 44/2019 (category Article 5(2) GDPR)
    internal compliance and accountability according to Article 5(1) GDPR, Article 5(2) GDPR and Article 6(1) GDPR. Since the company had totally ignored the its
    127 KB (21,184 words) - 15:39, 6 December 2023
  • APD/GBA (Belgium) - 06/2019 (category Article 58(2)(i) GDPR)
    c), Article 6.1., Article 13.1. c), Article 13.1. c), Article 13.1. e) and Article 13.2. a) of the DGPS pursuant to Article 101 of the ICA, to impose
    20 KB (3,137 words) - 16:51, 12 December 2023
  • AEPD (Spain) - PS/00268/2022 (category Article 5(1)(f) GDPR)
    infringement of Article 5.1.f) of the RGPD, Article 33 of the RGPD, Article 25 of the RGPD and Article 32 of the RGPD, typified in Article 83.5 of the RGPD
    63 KB (9,551 words) - 12:33, 13 December 2023
  • with Article 5 (1) (a) and Article 6 (1) (f) GDPR. Thus, the controller failed to comply with the accountability principle under Article 5 (2) GDPR. Second
    111 KB (17,604 words) - 13:08, 3 March 2024
  • associations even without legal personality" (see Article 2, Law 179/2017 which added paragraph 2-bis to Article 6 of Legislative Decree .lgs. 8 June 2001, n
    115 KB (18,595 words) - 11:30, 16 August 2022
  • Liability Law, 9 Article 156, the second and third paragraphs of Article 157, the first paragraph of Article 166, Article 168, Article 262, Article 269, 1. to
    90 KB (14,351 words) - 16:10, 6 December 2023
  • HDPA (Greece) - 53/2022 (category Article 6(1)(b) GDPR)
    violation of article 13 of Regulation (EU) 2016/679, in accordance with article 58 par. 2 i' of the GDPR in combination with article 83 par. 5 of the GDPR. The
    50 KB (8,004 words) - 04:49, 14 December 2022
  • Datatilsynet (Norway) - 20/01896 (category Article 5(2) GDPR)
    rating without a legal basis under Article 6(1)(f) GDPR and for not adhering to the accountability principle as per Article 5(2). The DPA also requires that
    28 KB (4,387 words) - 18:58, 5 March 2022
  • AEPD (Spain) - PS/00030/2020 (category Article 12 GDPR)
    installing a video surveillance camera system violating Article 22 LOPDGDD and Article 12 GDPR? The Spanish DPA found that the defendant could install
    19 KB (2,965 words) - 13:49, 13 December 2023
  • AEPD (Spain) - PS/00329/2020 (category Article 37 GDPR)
    43; " Article 83.7 of the RGPD indicates: “Without prejudice to the corrective powers of the control authorities by virtue of the Article 58 (2), each
    13 KB (2,002 words) - 14:29, 13 December 2023
  • HDPA (Greece) - 12/2022 (category Article 5(2) GDPR)
    13. See Opinion of OE article 29, 2/2017, p. 18. 13See. Opinion of OE article 29, 2/2017, p. 28. 14 See. Opinion of OE article 29, 2/2017, pp. 28-29. 12
    46 KB (7,390 words) - 08:07, 1 April 2022
  • privacy. Health data are special categories of data covered by Article 9 GDPR. According to Article 137 of the Italian Data Protection Code, health data can
    16 KB (2,409 words) - 15:44, 6 December 2023
  • right to privacy. Health data are sensitive data covered by Article 9 GDPR. According to Article 137 of the Italian Data Protection Code, health data can
    16 KB (2,352 words) - 15:44, 6 December 2023
  • right to privacy. Health data are sensitive data covered by Article 9 GDPR. According to Article 137 of the Italian Data Protection Code, health data can
    16 KB (2,324 words) - 15:45, 6 December 2023
  • Personvernnemnda (Norway) - PVN-2022-22 (category Article 83(2) GDPR)
    regulation article 83 no. 2 letters a to k. It is central to this assessment to look at the nature, severity and duration, cf. article 83 no. 2 letter a
    91 KB (14,440 words) - 10:06, 17 November 2023
  • Commissioner (Cyprus) - 11.17.001.010.045 (category Article 5(1)(c) GDPR)
    that the article’s publication was in violation of Article 5(1)(c) GDPR, Article 6(1)(f) GDPR, when read in line with Article 85 GDPR. Article 5(1)(c) outlines
    74 KB (12,375 words) - 10:07, 4 October 2023
  • UODO (Poland) - DKE.561.16.2020 (category Article 31 GDPR)
    Protection, pursuant to Article 83(3) and Article 83(4)(a) and Article 83(5)(e) of Regulation 2016/679, in conjunction with Article 103 of the Personal Data
    28 KB (4,490 words) - 09:51, 17 November 2023
  • AEPD (Spain) - PS/00024/2019 (category Article 5(2) GDPR)
    provisions of article 58.2.b) of the RGPD, a warning sanction for an infringement of article 5.1.f) of the RGPD, typified in article 83.5.a) of the RGPD
    53 KB (8,593 words) - 13:47, 13 December 2023
  • AEPD (Spain) - PS/00212/2019 (category Article 32 GDPR)
    established in article 83.2 of the RGPD2b) Basic personal identifiers are affected (name, identification number, line identifier), according to article 83.2 g) In
    17 KB (2,518 words) - 14:11, 13 December 2023
  • amount of the fine, the criteria specified in the same article 83". 91. Article 83 of the GDPR provides that "each supervisory authority shall ensure that
    56 KB (9,069 words) - 17:02, 6 December 2023
  • AEPD (Spain) - PS/00215/2020 (category Article 5(1)(c) GDPR)
    to"Process third party data" (art. 83.2 a) RGPD).- the intentionality or negligence in the infringement (art. 83.2 b) RGPD).For all these reasons, it is
    18 KB (2,721 words) - 14:11, 13 December 2023
  • AEPD (Spain) - PS/00340/2019 (category Article 58(2) GDPR)
    infraction of Article 6.1.a) of the RGPD, typified in Article 83.5 of the RGPD, a penalty of APPRECIATION, in accordance with the provisions of Article 58.2 RGPD
    23 KB (3,554 words) - 14:31, 13 December 2023
  • APD/GBA (Belgium) - 37/2021 (category Article 5(1)(b) GDPR)
    condition of necessity is maintained under Article 6.1 b) to f) of the GDPR. The article 6.1 of the GDPR replaces Article 7 of the Directive, without the relevant
    45 KB (6,780 words) - 16:57, 12 December 2023
  • 58, par. 2, lett. i and 83 of the Regulation; art. 166, par. 7, of the Code). Pursuant to Articles 58(2)(i) and 83 of the Regulation and Article 166 of the
    20 KB (3,133 words) - 15:53, 6 December 2023
  • AEPD (Spain) - PS/00479/2019 (category Article 5(1)(c) GDPR)
    minimisation principle related, as per Article 5(1)(c) GDPR, and the lack of transparent information, as per Article 12 GDPR. The decision is the consequence
    17 KB (2,541 words) - 14:43, 13 December 2023
  • reasons the Italian DPA, with the power conferred by Article 58(2)(d) and (f) and Article 83(3) and (5) GDPR, imposed to Fastweb multiple corrective measures
    131 KB (21,014 words) - 15:55, 6 December 2023
  • AEPD (Spain) - PS/00326/2020 (category Article 37(1)(a) GDPR)
    43; " Article 83.7 of the RGPD indicates: “Without prejudice to the corrective powers of the control authorities by virtue of the Article 58 (2), each
    14 KB (1,992 words) - 14:29, 13 December 2023
  • typified in article 83.5.a) of the aforementioned Regulation; for the alleged violation of article 22 of the RGPD, typified in the Article 83.5.b) of the aforementioned
    457 KB (75,575 words) - 09:36, 12 May 2021
  • AEPD (Spain) - PS/00416/2019 (category Article 6 GDPR)
    regulation as established in thearticle 2.2 of the RGPD and article 2.2.a) of the LOPDGDD. It says to article 2.2 of the RGPD:"2. This Regulation does not apply
    206 KB (32,869 words) - 14:36, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/1154/9 (category Article 6(1)(f) GDPR)
    (2) (f) and Article 14 (2) (g), Article 14 (1) andArticle 15 (1) (h) and Article 21 (1)infringement of Article 18 (1) (a) and (d).order the restriction
    192 KB (30,170 words) - 10:11, 17 November 2023
  • AEPD (Spain) - EXP202301529 (category Article 17 GDPR)
    violated the provisions of Article 17 of the GDPR and Article 21 of the GDPR and urge GLOBAL CAPITAL GROUP SPAIN, S.L. with NIF B87258091, so that, within
    20 KB (3,078 words) - 13:05, 13 December 2023
  • AEPD (Spain) - PS/00004/2020 (category Article 5(1)(c) GDPR)
    wrongoriented, so that the conduct is considered negligent to a slight degree (art. 83.2 b)RGPD).C / Jorge Juan, 6www.aepd.es28001 - Madridsedeagpd.gob.es Page 5 5/9Therefore
    18 KB (2,798 words) - 13:44, 13 December 2023
  • OLG Dresden - 4 U 1905/21 (category Article 12(5)(b) GDPR)
    § 8 clause 2 of the GTC agreed between the parties (according to § 8 b paragraph 2 MB/KK). 52 § 8 b para. 2 MB/KK violates §203 sentence 2 VVG and is therefore
    40 KB (6,325 words) - 16:12, 18 May 2022
  • UODO (Poland) - DKN.5112.7.2020 (category Article 58(2)(b) GDPR)
    and Article 60 of the Act of 10 May 2018 on the protection of personal data (Journal of Laws of 2019, item 1781) and pursuant to Article 58(2)(b) in connection
    29 KB (4,687 words) - 09:56, 17 November 2023
  • processing carried out is in violation of Article 5(1)(f) GDPR, Article 25(1) GDPR, Article 32 GDPR and Article 35 GDPR. Especially, the controller cannot exclude
    119 KB (19,123 words) - 11:29, 16 August 2022
  • AP (The Netherlands) - 4.02.2021 (category Article 8 GDPR)
    The interpretation of article 13 of the Wbp is no different from that of article 32 of the GDPR, described in paragraphs 2.3.2 and 2.3.3. Also in the period
    57 KB (8,053 words) - 17:07, 12 December 2023
  • UODO (Poland) - DKN.5130.2024.2020 (category Article 32(2) GDPR)
    Art. 83 sec. 2 of Regulation 2016/679, the circumstances: 1. Actions taken by KSSiP to minimize the damage suffered by data subjects (Article 83 (2) (c)
    75 KB (12,104 words) - 09:58, 17 November 2023
  • guarantees ”(Article 9, paragraph 2, letter b), of the Regulation). In any case, the dissemination of data relating to health is prohibited (art. 2-septies
    50 KB (8,001 words) - 15:52, 6 December 2023
  • Court of Appeal of Brussels - 2020/AR/813 (category Article 13(1)(b) GDPR)
    Therefore the controller violated Article 5(1)(a) and (2), Article 6(1), Article 12(1), Article 13(1)(b) and (c) GDPR. The DPA imposed a fine of €50.000
    85 KB (12,340 words) - 15:30, 19 August 2022
  • IMY (Sweden) - DI-2021-4355 (category Article 58(2)(b) GDPR)
    DI-2021-4355 5(6) Date:2023-01-19 Choice of intervention Article 58(2) and Article 83(2) of the GDPR give IMY the authority to impose an administrative fine
    28 KB (3,101 words) - 09:49, 7 June 2023
  • Personvernnemnda (Norway) - 2022-13 (21/00481) (category Article 58(2)(d) GDPR)
    infringement fee, cf. article 58 no. 2 letter i, cf. article 83. Violation of article 32 can be sanctioned with a fee, cf. article 83 no. 4 letter a. The
    45 KB (6,913 words) - 12:13, 15 March 2023
  • AEPD (Spain) - PS/00332/2020 (category Article 7 GDPR)
    The Spanish DPA (AEPD) fined Borjamotor, S.A. for infringing Article 7 GDPR and Article Article 21(1) of the Spanish Law on Information Society Services (LSSI)
    45 KB (6,853 words) - 14:29, 13 December 2023
  • UODO (Poland) - DKN.5130.2815.2020 (category Article 58(2)(b) GDPR)
    57(1)(a) and Article 58(2)(b) in connection with Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1) and (2) of 2 of Regulation EU 2016/679 of the European
    37 KB (5,819 words) - 09:58, 17 November 2023
  • CNIL (France) - SAN-2023-018 (category Article 31 GDPR)
    and to cooperate with the DPA, therefore violating Article 31 GDPR and Article 37(1)(a) GDPR. On 2 June 2021, the French DPA (“CNIL”) informed a French
    22 KB (3,384 words) - 13:25, 24 January 2024
  • over the right to access Article 15 GDPR. A citizen requested a copy of his personal data from a controller under Article 15 GDPR. The controller requested
    15 KB (2,321 words) - 16:01, 22 March 2022
  • to the criteria laid down by Article 83 paragraph 2 of the GDPR. With regard to the breach of Article L. 34-5 of the GDPR, the restricted committee considers
    69 KB (11,007 words) - 17:10, 6 December 2023
  • AEPD (Spain) - PS/00388/2020 (category Article 7 GDPR)
    opting for the of a higher amount, in accordance with article 83.5.b) of the RGPD. However, Article 58.2) of the RGPD provides that: “Each control authority
    52 KB (8,471 words) - 14:33, 13 December 2023
  • HDPA (Greece) - 35/2023 (category Article 4(12) GDPR)
    provision of article 58 par. 2 sec. i of the GDPR, effective, proportionate and dissuasive administrative money fine according to article 83 of the GDPR, both
    52 KB (8,460 words) - 10:54, 10 January 2024
  • a, 13.1.c, 13.2.d, 13.2.a and 13.2.e between 15 June and 2 December 2020 as regards departures. (b) infringements that took place from 2 December 2020
    206 KB (30,485 words) - 09:54, 14 December 2023
  • NAIH (Hungary) - NAIH/2020/2729/15 (category Article 5(1)(b) GDPR)
    with Article 2 (1) of the General Data Protection Regulation the general data protection regulation applies to data processing. According to Article 4 (1)
    58 KB (9,071 words) - 10:12, 17 November 2023
  • the meaning of Article 83 and recital 148 of the Regulation”. The Garante hence reprimanded Barclays pursuant to Article 58(2)(b) GDPR. Share your comments
    22 KB (3,235 words) - 15:55, 6 December 2023
  • AEPD (Spain) - EXP202200999 (category Article 6(1) GDPR)
    processing is based on consent under Article 6(1)(a) GDPR, the consent must meet the requirements of, among others, Article 7 GDPR. The DPA observed deficiencies
    51 KB (7,867 words) - 13:10, 13 December 2023
  • AEPD (Spain) - PS/00454/2019 (category Article 5(1)(c) GDPR)
    procedure to the claimed, by thealleged violation of Article 5.1.c) of the GDPR, typified in Article 83.5 of theRGPD. FIFTH: Consulted the database of this
    12 KB (1,832 words) - 14:41, 13 December 2023
  • APD/GBA (Belgium) - 28/2020 (category Article 21(2) GDPR)
    administrative fines set out in Article 83.5 of the AVG. 51. Taking into account the criteria contained in article 83.2 of the AVG as well as the case law
    27 KB (4,363 words) - 16:56, 12 December 2023
  • AZOP (Croatia) - Decision 05-07-2021 (category Article 32(1)(b) GDPR)
    activities further violated Article 32(1)(b) and (d) GDPR. Accordingly, the DPA, in accordance with its powers under Article 58 (2) GDPR, imposed an administrative
    5 KB (599 words) - 15:38, 30 October 2023
  • CNIL (France) - SAN-2020-013 (category Article 83 GDPR)
    derogant rule, based on the interpretation of Article 95 GDPR in the line of the Rec (173) GDPR and Article 1(2) and 15a of the ePrivacy Directive. The CNIL
    82 KB (13,424 words) - 17:10, 6 December 2023
  • UODO (Poland) - DKN.5112.13.2020 (category Article 58(1)(b) GDPR)
    on the GEOPORTAL2 was not in line with the principle of lawfulness in Article 5(1)(a) GDPR, as none of the conditions of Article 6 GDPR were satisfied.
    60 KB (9,755 words) - 09:58, 17 November 2023
  • IMY (Sweden) - DI-2019-9457 (category Article 32(1) GDPR)
    proportionate and dissuasive. The provided for in Article 83 (1) of the Data Protection Regulation. Article 83 (2) of the Data Protection Regulation sets out
    43 KB (4,600 words) - 17:08, 23 March 2022
  • 58, par. 2, lett. I and 83 of the Regulation; art. 166, paragraph 7, of the Code) The Guarantor, pursuant to art. 58, par. 2, lett. i), and 83 of the Regulations
    83 KB (13,648 words) - 11:30, 16 August 2022
  • CPDP (Bulgaria) - PNN-01-433/2019 (category Article 6(1)(a) GDPR)
    Commission, which entered into force. The circumstances under Art. 83, § 2, letters “b” and “i” of the Regulation are irrelevant as far as the administrator
    18 KB (2,987 words) - 16:49, 6 December 2023
  • BVwG - W214 2233132-1/13E (category Article 15(1)(c) GDPR)
    under Article 77 GDPR was very clear and limited in scope. However, the DSB went on to assert a violation of Article 12 GDPR and Article 15(1)(h) GDPR, acting
    47 KB (7,519 words) - 09:28, 13 February 2024
  • AEPD (Spain) - EXP202105669 (category Article 58(2)(d) GDPR)
    violation of article 5.1.f) of the GDPR, typified in article 83.5 of the GDPR, a warning sanction and for a violation of article 32 of the GDPR, typified
    45 KB (6,998 words) - 12:58, 13 December 2023
  • CNIL (France) - SAN-2023-025 (category Article 6(1)(a) GDPR)
    the data subjects, therefore breaching Article 6 GDPR, as well as Article 5(1)(b) GDPR. Thirdly, Article 30 GDPR stipulates that the controller must keep
    53 KB (8,418 words) - 11:21, 6 February 2024
  • AEPD (Spain) - EXP202208091 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    40 KB (6,014 words) - 13:24, 13 December 2023
  • concluded that the controller violated Article 32(1)(b), Article 32(1)(d), Article 32(2), and Article 32(4) GDPR. Therefore, the DPA decided to impose a
    6 KB (730 words) - 15:49, 30 October 2023
  • AEPD (Spain) - PS/00134/2019 (category Article 5(1)(a) GDPR)
    violation of article 5.1 a) of the RGPD, ofin accordance with article 83.5 of the RGPD, a fine of APPEARANCE, in accordancewith article 58.2.b) of the RGPD
    26 KB (4,034 words) - 14:04, 13 December 2023
  • IMY (Sweden) - DI-2021-5595 (category Article 5(1)(f) GDPR)
    proportionate and dissuasive. The provided for in Article 83 (1) of the Data Protection Regulation. Article 83 (2) of the Data Protection Regulation sets out
    47 KB (5,207 words) - 18:51, 21 March 2022
  • AEPD (Spain) - PS/00366/2019 (category Article 5(1)(d) GDPR)
    authorities an infringement of Article 5 (1) (d) GDPR? The AEPD agreed to impose a penalty for infringement of Article 5 (1) (d) for lack of accuracy in
    29 KB (4,583 words) - 14:32, 13 December 2023
  • AEPD (Spain) - PS/00477/2019 (category Article 6 GDPR)
    with provided for in article 58.2 of the RGPD, for the alleged violation of articles 13 and 14 of the RGPD, typified in article 83.5.b) of the aforementioned
    566 KB (93,179 words) - 13:43, 13 December 2023
  • Datatilsynet (Norway) - 20/01627 (category Article 4(1) GDPR)
    treatment of personal data, cf. the Personal Data Act § 2 and the Privacy Ordinance article 2 no. 1. 4.2. Assessment of legal basis The next question is whether
    45 KB (6,973 words) - 05:12, 15 September 2022
  • AEPD (Spain) - PS/00132/2022 (category Article 6(1) GDPR)
    (c) where the processing is based on Article 6(1)(a) or Article 6(1)(b) or Article 6(1)(c) of the GDPR Article 9(2)(a), the existence of the right to withdraw
    52 KB (8,416 words) - 12:59, 13 December 2023
  • AEPD (Spain) - PS/00082/2020 (category Article 5(1)(c) GDPR)
    IVWithout prejudice to the provisions of article 83 of the RGPD, the aforementioned Regulationprovides in its art. 58.2 b) the possibility of sanctioning with
    18 KB (2,749 words) - 13:57, 13 December 2023
  • AEPD (Spain) - PS/00235/2019 (category Article 6(1)(a) GDPR)
    mitigating points the points set out in Article 83.2 of the GDPR: (a) The treatment has been carried out ted.¬ b) There is no intention on the part of Vodafone
    24 KB (4,074 words) - 14:21, 13 December 2023
  • CNIL (France) - SAN-2020-008 (category Article 13(2)(a) GDPR)
    same Article 83. 181. Article 83 of the RGPD provides : 1. Each control authority shall ensure that administrative fines imposed under this Article for
    104 KB (16,646 words) - 17:09, 6 December 2023
  • CNIL (France) - SAN-2024-002 (category Article 5(1)(e) GDPR)
    breach of Article 13 (2) of the GDPR. 43. Consequently, the restricted panel considers that the company has committed a breach of Article 13 of the GDPR. It
    56 KB (8,757 words) - 14:12, 28 February 2024
  • APD/GBA (Belgium) - 141/2021 (category Article 38(6) GDPR)
    described in the conclusion (Article 83.2, c) AVG 83.2 (c) AVG); the absence of previous relevant infringements (Section 83.2 (e) AVG), as well as the cooperation
    90 KB (14,937 words) - 12:35, 3 August 2022
  • HDPA (Greece) - 55/2021 (category Article 33 GDPR)
    the provision of article 58 par. 2 par. i) of the IGC, an effective, proportionate and dissuasive administrative fine under Article 83 83 of the IGC both
    65 KB (10,533 words) - 10:28, 27 January 2022
  • meaning of article 4, opening words under 1, 2 and 15, of the AVG, article 10 of the AVG and article 1, preamble below and b, of the Wb and article 16 of the
    49 KB (7,201 words) - 17:06, 12 December 2023
  • NAIH (Hungary) - NAIH/2020/2000/5 (category Article 12(2) GDPR)
    specified in Section 2 (2), it may apply the legal consequences specified in the General Data Protection Decree. Pursuant to Article 58 (2) (b) of the General
    24 KB (3,815 words) - 10:11, 17 November 2023
  • AEPD (Spain) - PS/00197/2020 (category Article 5(1)(b) GDPR)
    Articles 6(1)(b), 5(1)(b) and 5(1)(c) GDPR? The Spanish DPA (AEPD) deemed itself competent under Article 58(2) GDPR in conjunction with Article 47 of the Spanish
    129 KB (21,793 words) - 14:09, 13 December 2023
  • BVerfG - 1 BvR 16/13 (category Article 17 GDPR)
    Human Rights. According to settled case-law, it follows from Article 1.2 and Article 59.2 of the Basic Law that there is an obligation to use the Human
    133 KB (21,944 words) - 15:59, 22 March 2022
  • UODO (Poland) - DKE.561.3.2020 (category Article 31 GDPR)
    lit. e) and f) and art. 58 sec. 2 lit. i) in connection with Art. 83 sec. 1 and 2, art. 83 sec. 4 lit. a) and art. 83 sec. 5 lit. e) Regulation of the
    51 KB (8,322 words) - 09:51, 17 November 2023
  • Moreover, the information provided as per Article 13 GDPR were not compliant with the requirements of Article 12 GDPR in light of the fact that TikTok services
    17 KB (2,519 words) - 15:55, 6 December 2023
  • APD/GBA (Belgium) - 33/2020 (category Article 5 GDPR)
    by the defendant under Article 6(1) GDPR? Did the controller infringe the data minimisation principle under Article 5(1)(c) GDPR? Did the controller commit
    39 KB (6,551 words) - 16:56, 12 December 2023
  • data within the meaning of Article 4, opening words and (1) of the AVG. Based on Article 2, paragraph 1 and Article 3, paragraph 2, of the AVG, the AVG applies
    38 KB (6,339 words) - 17:14, 12 December 2023
  • AEPD (Spain) - EXP202309109 (category Article 5(1)(c) GDPR)
    provisions of article 5.1.c) of the RGPD, it allows setting a penalty of 2,000 euros (two thousand euros). V Measures Article 58.2 of the GDPR establishes
    18 KB (2,733 words) - 13:18, 13 December 2023
  • AEPD (Spain) - E/08210/2021 (category Article 4(22) GDPR)
    authority. Under Article 60 GDPR, the following DPAs were identified as “concerned supervisory authorities” under Article 4(22) GDPR: the Netherlands,
    29 KB (4,457 words) - 10:34, 13 December 2023
  • HDPA (Greece) - 7/2023 (category Article 15 GDPR)
    data Article 9.2.a: Express consent Article 9.2.b: Fulfillment of labor law obligations, etc. Article 9.2.c: Protection of vital interests Article 9.2.d:
    9 KB (1,251 words) - 12:15, 8 May 2023
  • APD/GBA (Belgium) - 74/2020 (category Article 6(1)(f) GDPR)
    basis of Article 58, paragraph 2, point b) GDPR and Article 100, §1, 5 ° WOG to be reprimanded for the infringement of Article 25 (1) GDPR; b. on the basis
    82 KB (12,100 words) - 17:01, 12 December 2023
  • HDPA (Greece) - 51/2021 (category Article 22 GDPR)
    data Article 9.2.a: Explicit consent Article 9.2.b: Execution of labor law obligations etc. Article 9.2.c: Protection of vital interests Article 9.2.d: Edit
    9 KB (1,168 words) - 15:30, 6 December 2023
  • HDPA (Greece) - 56/2021 (category Article 13 GDPR)
    and Article of 11Law No. 3471/2006, in accordance with Article 13(58i2) of the GDPR in conjunction with Article 83(1)(a) of the GDPR. 5 of the GDPR, and
    54 KB (8,916 words) - 15:22, 22 February 2022
  • HDPA (Greece) - 9/2024 (category Article 5(1)(a) GDPR)
    cases G.B.6 (11 days delay in applying the Registry), G.B.8 (6 days), G.B.9 (3 days including a weekend), G.B.10 (4 days including a weekend) and G.B.11 (5
    102 KB (17,186 words) - 13:46, 26 April 2024
  • APD/GBA (Belgium) - 05/2021 (category Article 5(2) GDPR)
    of 25,000 euros (Article 83, paragraph 2 GDPR; Article 100, §1, 13 ° WOG and Article 101 WOG). 18 55. Taking into account article 83 GDPR and the case law
    60 KB (9,281 words) - 16:50, 12 December 2023
  • the processing of personal data of the data subject (Article 5(1)(a) GDPR; Article 6 and Article 8 of the Italian Legislative Decree No. 101 of August
    66 KB (10,708 words) - 11:29, 16 August 2022
  • AEPD (Spain) - PS/00120/2020 (category Article 13 GDPR)
    *** SCHOOL ), with NIF*** NIF. 1 , for a violation of Article 13 of the RGPD, typified in Article 83.5 of theRGPD, a penalty of Admonition .SECOND: NOTIFY
    31 KB (4,808 words) - 14:01, 13 December 2023
  • AP (The Netherlands) - 25.11.2021 (category Article 58(2)(i) GDPR)
    fairness principle, violating Article 5(1)(a) in conjunction with Article 6(1)(e) GDPR, and Article 6 in conjunction with Article 8 Personal Data Protection
    87 KB (11,601 words) - 17:08, 12 December 2023
  • APD/GBA (Belgium) - 07/2021 (category Article 5(1) GDPR) (section Complaint to defendant 2)
    infringement of Article 5.1 b) in conjunction with Article 6.4. AVG, on article 5.1 a) in conjunction with article 6.1. AVG and on article 5.1 c) GDPR has been
    72 KB (11,208 words) - 16:51, 12 December 2023
  • NAIH (Hungary) - NAIH/2020/5553 (category Article 12(3) GDPR)
    request under Article 15 and with the one month deadline under Article 12(3). Was Google Ireland Ltd in breach of its obligations under GDPR Article 15(1) and
    27 KB (4,279 words) - 10:12, 17 November 2023
  • CE - N° 430810 (category Article 6(1)(a) GDPR)
    ---------- Article 1: The intervention of the PDU - What to choose is allowed. Article 2: The request of the company Google LLC is rejected. Article 3: This
    42 KB (6,800 words) - 09:50, 10 September 2021
  • Datatilsynet (Norway) - 20/01865 (category Article 58(2)(b) GDPR)
    processing might be based on Article 6(1)(f) GDPR (legitimate interest) and - regarding health data - on Article 9(2)b) GDPR (fulfilling obligations under
    19 KB (2,942 words) - 09:03, 14 September 2023
  • CNIL (France) - SAN-2020-003 (category Article 5(1)(c) GDPR)
    same article 83. 97. Article 83 of the GDPR provides: 1. Each supervisory authority shall ensure that administrative fines imposed under this Article for
    61 KB (10,028 words) - 17:09, 6 December 2023
  • accordance with article 4.1 of the GDPR, is data personnel and their protection, therefore, is the subject of said Regulation. In article 4.2 The GDPR defines
    17 KB (2,461 words) - 13:22, 13 December 2023
  • AEPD (Spain) - PS/00430/2018 (category Article 4(7) GDPR)
    ( *** POSITION 1) for an infraction of Article 6.1.f) of the GDPR, in accordance with Article 83.5 of the GDPR ”. In the face of it, no allegations have
    40 KB (6,508 words) - 14:39, 13 December 2023
  • the fine, the criteria specified in the same article 83. " Article 83 of the GDPR, as referred to in Article 20, paragraph III, of the "Informatique et Libertés"
    82 KB (13,428 words) - 17:02, 6 December 2023
  • VSL (Slovenia) - 9267/2022 (category Article 12 GDPR)
    (ECHR) - Article 8 RS - Constitution, Laws, Agreements, Treaties Criminal Procedure Act (1994) - ZKP - Article 83, 83/2, 285e, 285e/1, 285e/2 Associated
    24 KB (3,757 words) - 16:27, 31 October 2023
  • APD/GBA (Belgium) - 04/2021 (category Article 5(1) GDPR)
    before May 25, 2018. 2.2. Consent and the lawfulness of the processing (Article 4, point 11, Article 6 (1) in conjunction with Article 7 GDPR) 121. With regard
    113 KB (18,732 words) - 16:50, 12 December 2023
  • AEPD (Spain) - PS/00385/2020 (category Article 58(2)(b) GDPR)
    opting for the higher amount, in accordance with article 83.5.b) of the RGPD. However, Article 58.2) of the RGPD provides that: “Each supervisory authority
    55 KB (8,967 words) - 14:33, 13 December 2023
  • CNIL (France) - SAN-2022-020 (category Article 3(2)(a) GDPR)
    Failure to ensure data protection by default (Article 25(2) GDPR) The DPA also found a violation of Article 25(2) GDPR regarding the controllers “X” icon at the
    59 KB (9,566 words) - 17:03, 6 December 2023
  • CNIL (France) - SAN-2019-001 (category Article 4(11) GDPR)
    comprehensible character, within the meaning of Article 12 of the GDPR, of the information provided for in Article 13 of the Regulation must be assessed. The
    90 KB (14,556 words) - 17:08, 6 December 2023
  • LG Magdeburg - 9 O 1571/20 (category Article 6(1) GDPR)
    that under Article 82 (1) and (2) GDPR, any person who has suffered material or non-material damage as a result of a violation of the GDPR is entitled
    27 KB (4,216 words) - 13:26, 8 January 2024
  • right to erasure (“right to be forgotten”) of Article 17 GDPR and Article 19 of Regulation 2018/1725. Under GDPR, such prolonged and unrestricted data retention
    61 KB (9,971 words) - 14:28, 4 January 2024
  • accordance with Article 60 of the AVG. No objections to this were submitted. 2. Legal Framework 2.1 Scope of the AVG Pursuant to Article 2(1) of the AVG
    77 KB (12,915 words) - 17:15, 12 December 2023
  • APD/GBA (Belgium) - 48/2021 (category Article 5(1)(a) GDPR)
    (listed in Article 57 of the GDPR) including that of dealing with complaints (article 57.1.f) of the GDPR) as well as a number of powers (article 58 of the
    43 KB (6,670 words) - 16:58, 12 December 2023
  • Datatilsynet (Norway)- 20/02254 (category Article 57(1)(a) GDPR)
    Communications Act § 2-7 b, which implement Article 5 (3) of the Communication Protection Directive, are lex specialis for the Privacy Regulation. Article 95 of the
    24 KB (3,498 words) - 16:14, 6 December 2023
  • Commissioner (Cyprus) - 11.17.001.007.220 (category Article 7(4) GDPR)
    administrative fine on the basis of Article 83 thereof. However, considering: (a) all the factors set out in Article 83 (2) of the GIP; (b) that, at all stages of
    56 KB (8,913 words) - 16:52, 6 December 2023
  • APD/GBA (Belgium) - 149/2023 (category Article 13(2) GDPR)
    of article 4.19 of the GDPR – (article 13.1. c) of the GDPR) and does not mention the data retention periods personal data processed (article 13.2. a)
    113 KB (17,325 words) - 08:50, 19 March 2024
  • not necessarily meet the requirements of Article 32 GDPR. To what extent are the provisions in Article 32 GDPR obligatory and thus, not subject to the preferences
    30 KB (4,562 words) - 15:27, 6 December 2023
  • AEPD (Spain) - EXP202103039 (category Article 13 GDPR)
    pursuant to Article 13 GDPR. In the present case, the controller omitted this obligation. The DPA therefore held that the controller violated Article 13 GDPR
    22 KB (3,385 words) - 13:35, 13 December 2023
  • DSB (Austria) - D122.844/0006-DSB/2018 (category Article 12(5) GDPR)
    under Article 15 GDPR and demanded free access to the historic bank transaction data. The bank argued that this would be a misuse of Article 15 GDPR and
    19 KB (2,936 words) - 13:55, 12 May 2023
  • AEPD (Spain) - PS/00422/2018 (category Article 2 GDPR)
    RETAIL S.L. for alleged infringement of Article 5.1 f) of the GDPR, in accordance with Article 83.5.a) of the GDPR- Initiate sanctioning procedure against
    25 KB (3,933 words) - 14:37, 13 December 2023
  • AP (The Netherlands) - 16.06.2020 (category Article 4(12) GDPR)
    so that the violation is still continues. 2. Legal framework Pursuant to Article 2, paragraph 1, of the GDPR, this Regulation applies to all or part of
    54 KB (8,224 words) - 17:07, 12 December 2023
  • AEPD (Spain) - PS/00100/2020 (category Article 13 GDPR)
    contrary to the legal provisions established in article 22.2 LSSI. This Infraction is classified as "minor" in Article 38.4 g) of the aforementioned Law, and may
    27 KB (4,296 words) - 13:59, 13 December 2023
  • CNIL (France) - SAN-2022-022 (category Article 12(3) GDPR)
    resulting from Article L. 34-5 of the CPCE and Article 7-1 of the GDPR. B. On the breaches relating to the exercise of rights 27. According to Article 12 of the
    59 KB (9,623 words) - 17:03, 6 December 2023
  • Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned a Luxembourg
    26 KB (3,862 words) - 17:41, 25 June 2022
  • APD/GBA (Belgium) - 38/2021 (category Article 5 GDPR)
    consent of the 10 complainant (article 6.1 a) of the GDPR combined with article 7 of the GDPR), (2) article 6.1 c) of the GDPR in that the publication results
    73 KB (11,604 words) - 16:57, 12 December 2023
  • DSB (Austria) - 2020-0.303.727 (category Article 85(2) GDPR)
    that Section 9 (1) GDPR contains a restriction to a certain professional group (“classic media companies”), although Article 85 (2) GDPR does not include
    21 KB (3,266 words) - 13:51, 12 May 2023
  • within the meaning of Article 4(15) GDPR and Article 9(1) GDPR. Processing of sensitive data requires a legal basis under Article 9(2) GDPR. In the present case
    13 KB (1,847 words) - 15:52, 11 December 2023
  • APD/GBA (Belgium) - 18/2020 (category Article 5 GDPR)
    therefore of the opinion that no breach of Article 5.2 of the GDPR, Article 24.1 of the GDPR and Article 33 of the GDPR can be established. - As regards the
    55 KB (8,810 words) - 16:55, 12 December 2023
  • AP (The Netherlands) - 24.02.2022 (category Article 13(1)(e) GDPR)
    data 9 2.1.1 Factual findings 9 2.1.2Legal assessment 9 2.2 Controller and processor(s) 10 2.2.1 Factual findings 10 2.2.2Legal assessment 12 2.3Security
    179 KB (22,957 words) - 17:07, 12 December 2023
  • AEPD (Spain) - PS/00005/2020 (category Article 5(1)(c) GDPR)
    against the defendant, for the alleged infringement of Article 5.1.c) of the RGPD, typified in Article 83.5 of the RGPD. FOURTH: On 06/02/20, this Agency received
    13 KB (1,795 words) - 13:47, 13 December 2023
  • infringements of Article 5(1)(c), Article 5(1)(e) and Article 6(1)(f) the DPC issued a reprimand to Airbnb pursuant to Article 58(2)(b) of the GDPR. In addition
    17 KB (2,411 words) - 09:25, 27 November 2023
  • Datatilsynet (Norway) - 17/01281 (category Article 58(2)(b) GDPR)
    Ordinance Article 6 No. 1 letter f for this processing. Our legal basis for decisions on reprimands is the Privacy Ordinance, Article 58, No. 2, letter b. ».
    38 KB (6,275 words) - 16:13, 6 December 2023
  • requirements of Article 6(1)(a) in conjunction with Article 7 GDPR, which cannot be superseded by relying on Article 6(1)(b) GDPR? Is Article 5(1)(c) GDPR (data
    122 KB (20,253 words) - 08:17, 19 August 2021
  • OLG Hamm - 7 U 19/23 (category Article 82 GDPR)
    contract (Article 6(1)(b) GDPR), nor could be based on legitimate interest of the controller (Article 6(1)(f) GDPR). Consent (Article 6(1)(a) GDPR) could
    130 KB (21,874 words) - 09:43, 15 February 2024
  • Court of Appeal of Brussels - 2022/AR/549 (category Article 17(3)(e) GDPR)
    out in point 56 Based on article 83 of the GDPR and articles 100, 13° and 101 of the LCA, a fine from 7500 EUR Under article 108, § l of the LCA, this
    37 KB (5,765 words) - 09:53, 14 December 2023
  • court referred to Article 43(1),(2) Law N. 158 (I)/1999, which is the Cypriot Law on General Principles of Administrative Law. Article 43(1) Law N. 158
    22 KB (3,496 words) - 12:08, 17 February 2022
  • VGH Baden-Württemberg - 1 S 397/19 (category Article 18(2) GDPR)
    force: "According to Article 16 sentence 1 GDPR, every data subject has the right to request the controller (see Article 4(7) GDPR) to correct incorrect
    112 KB (19,310 words) - 08:08, 23 June 2022
  • AEPD (Spain) - PS/00180/2020 (category Article 13 GDPR)
    as per Article 22(2) of the Spanish Law on Information Society Services (LSSI) — amongst others, the Spanish law regulating cookies — and Article 13 of
    38 KB (5,879 words) - 14:07, 13 December 2023
  • OLG Naumburg - 9 U 6/19 (category Article 9(2)(a) GDPR)
    there is no explicit consent by the customers as requested under Article 9(2)(a) GDPR and an implied consent cannot fulfill the provision’s requirement
    32 KB (5,236 words) - 16:00, 10 March 2022
  • AEPD (Spain) - PS/00473/2019 (category Article 5 GDPR)
    infractions of these Regulations ”and in 2.i), that of: “Impose an administrative fine pursuant to article 83, in addition to or instead of measures mentioned
    35 KB (5,635 words) - 14:41, 13 December 2023
  • BVerfG - 1 BvR 276/17 (category Article 17 GDPR)
    violation of the general right of personality under Article 1.1, Article 2.1 of the Basic Law (Article 7, Article 8 of the Basic Law) was to be taken into account
    127 KB (21,367 words) - 16:00, 22 March 2022
  • AEPD (Spain) - PS/00044/2020 (category Article 13 GDPR)
    (hereinafter, “the person claimed ”), by virtue of the complaint presented by B.B.B., (hereinafter,“ the claimant ”), and based on the following, BACKGROUND
    39 KB (6,270 words) - 13:51, 13 December 2023
  • 1-� L _JCourt of appeal Brussels-2021/AR/282- p. 3 ° - pursuant to Article 83 GDPR and Articles 100, 13 and 101 WOG, an administrative to impose a fine
    24 KB (3,393 words) - 09:25, 10 September 2021
  • ВАС - № 6759 (category Article 58(2)(b) GDPR)
    had been no violation of Article 32(4) GDPR, and in the alternative, that: in accordance with the provisions of Article 83(2) GDPR, the BGN 1500 fine should
    7 KB (822 words) - 10:09, 16 August 2021
  • Rb. Amsterdam - 8598127 KK EXPL 20-357 (category Article 5 GDPR)
    the data could be processed under the legitimate interest basis (ARTICLE 6(1)(f) GDPR). The tribunal weighted the different interests at stake and decided
    27 KB (4,437 words) - 09:17, 22 August 2020
  • (cf. Article 36 (2) no. 7 lit. a DPA) for the purposes of military self-protection (cf. Article 36 (1) DPA in conjunction with Article 2 (1) no. 2 MBG)
    28 KB (3,418 words) - 13:49, 12 May 2023
  • ANSPDCP (Romania) - Fine against La Santrade S.R.L. (category Article 83(5)(b) GDPR)
    with Article 12(2) and (3) GDPR. Hence, the controller received a warning for not respecting data subjects' rights (violation of Article 85(3)(b) GDPR)
    5 KB (537 words) - 13:31, 23 June 2021
  • AEPD (Spain) - PS-00563-2022 (category Article 83(2) GDPR)
    that a fine of €2,000 be set for the infringement of Article 13 GDPR as defined in Article 83(5) GDPR. Pursuant to Article 58(2)(d) GDPR the Spanish DPA
    8 KB (1,017 words) - 09:54, 18 January 2024
  • whether Art. 15 GDPR applies to the investigation files at all, since according to Art. 2 Para. 2 d GDPR, Section 2a Para. 4 AO, the GDPR does not apply
    97 KB (16,519 words) - 09:57, 22 February 2023
  • TGI Paris - N° 14/07224 (category Article 5(1)(b) GDPR)
    L.111-1, L.111- 2, L.121-17, L.121-19-4, L.121-83, L.121-84, L.132-1, L.133-2, L.135-1, L.141- 5, L.421-1, L.421-6, L.421-2 and R.111-2 and R.132-1 and
    392 KB (67,730 words) - 15:27, 17 March 2022
  • DSB (Austria) - 2023-0.603.142 (category Article 31 GDPR)
    accordance with Article 31 of the GDPR, Article 31, due to the security breach , GDPR. According to Article 83 Paragraph 4 Letter a of the GDPR, these two provisions
    76 KB (12,550 words) - 09:24, 28 February 2024
  • AEPD (Spain) - PS-00371-2021 (category Article 83(2) GDPR)
    according to Article 83(4)(a) GDPR. However, the AEPD imposed no fines in either of the two violations. Instead, according to Article 58(2)(d) GDPR, the AEPD
    46 KB (7,141 words) - 13:00, 18 January 2024
  • course of the audit proceeding to remedy the breaches of Article 38(1) GDPR and Article 39(1)(b) GDPR. The CNPD noted however that these measures were taken
    8 KB (868 words) - 07:39, 12 November 2021
  • AEPD (Spain) - PS/00080/2022 (category Article 83(2)(a) GDPR)
    circumstances in relation to Article 5 and Articles 32 and 33 GDPR. First, there was the duration of the infringement under Article 83(2)(a) GDPR; second, there was
    47 KB (7,265 words) - 10:05, 21 July 2022
  • APD/GBA (Belgium) - 12/2019 (category Article 4(11) GDPR)
    (EU) 2016/679, p. 41. 2.2.2 Obligations relating to consent ('opt-in') (Articles 5, 6(1)(a) and 4(11) in conjunction with Article 7 of the Data Protection
    107 KB (17,697 words) - 16:52, 12 December 2023
  • DVI (Latvia) - SIA "Fitsypro" (category Article 83(2) GDPR)
    on FPDAL Article 5, Part One, Clause 2, Article 23, GDPR Article 58, Clause 2, subparagraph i), AAL, Article 115, Part One, Clause 4, Article 151 Paragraph
    29 KB (4,404 words) - 07:53, 23 August 2023
  • KamR Stockholm - 2829-23 (category Article 13(2)(b) GDPR)
    the requirements on how it should be provided under Article 12 GDPR, Article 13 GDPR and Article 14 GDPR. The court of appeal disagreed with the court of
    9 KB (1,112 words) - 11:55, 15 May 2024
  • ВАС - 6307/27.06.2022 (category Article 83(2) GDPR)
    Articles 24 and 25 GDPR. The Bulgarian Data Protection Authority (CPDP) found a breach of Article 5(1)(a) GDPR and Article 5(1)(f) GDPR since the personal
    19 KB (2,875 words) - 10:08, 22 November 2022
  • Persónuvernd (Island) - 2021051091 (category Article 5(1)(b) GDPR)
    controller under Article 83 GDPR due to the controller’s violations of Article 5(1) GDPR, Article 6 GDPR, Article 12 GDPR and Article 13 GDPR. Share your comments
    7 KB (797 words) - 09:35, 27 March 2024
  • UODO (Poland) - DKN.5112.1.2020 (category Article 83(2) GDPR)
    accountability under Article 5(2) GDPR. Taking into account the above-discussed findings, the DPA also held that the controller violated Article 24(1) GDPR by not fulfilling
    110 KB (17,607 words) - 15:35, 3 January 2023
  • DSB (Austria) - 2023-0.592.319 (category Article 58(2)(c) GDPR)
    of the GDPR by the controller, the DPA issued a fine of €12.100 in accordance with Article 83(4) GDPR, Article 83(5) GDPR and Article 83(6) GDPR. Both the
    80 KB (13,210 words) - 09:09, 21 May 2024
  • WSA Warsaw - II SA/Wa 2378/20 (category Article 83(5)(b) GDPR)
    found that the company violated Article 7 (3) GDPR, Article 12 (2) GDPR, Article 17 (1)(b)GDPR and Article 24 (1) GDPR, by failing to implement appropriate
    92 KB (15,312 words) - 09:57, 10 September 2021
  • AEPD (Spain) - EXP202303130 (category Article 5(1)(f) GDPR)
    provisions of article 5.1.f) of the RGPD and article 32 of the GDPR, violations classified in article 83.5 of the GDPR and article 83.4 of the GDPR respectively
    38 KB (5,842 words) - 14:16, 18 October 2023
  • AEPD (Spain) - PS/00375/2022 (category Article 5(1)(b) GDPR)
    aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 also may be taken into account: a) The continuous
    55 KB (8,720 words) - 10:46, 18 January 2024
  • is maintained under Article 6.1 b) to f) of the GDPR and therefore in Article 6.1.c) invoked in the species. Article 6.1 of the GDPR in fact reproduces
    73 KB (11,238 words) - 16:59, 12 December 2023
  • LG Essen - 6 O 190/21 (category Article 33 GDPR)
    violated Article 34(2) GDPR, because he only informed the data subject of the alleged data loss. However, the information obligations of Article 34 GDPR provide
    28 KB (4,596 words) - 18:30, 18 November 2021
  • AEPD (Spain) - PS/00285/2020 (category Article 13 GDPR)
    new page gina *** URL.2, in which information is provided in accordance with those stipulated in the article Article 13 of the GDPR. Regarding the complaint
    19 KB (2,923 words) - 14:26, 13 December 2023
  • AEPD (Spain) - PS/00193/2021 (category Article 58(2) GDPR)
    criteria established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 The
    27 KB (4,223 words) - 10:01, 22 September 2021
  • NAIH (Hungary) - NAIH-1855-4/2022 (category Article 5(2) GDPR)
    violated the general Article 32, paragraph (1) and points a)-b) of the data protection regulation, as well as (2) of this article paragraph. 2. Measures taken
    50 KB (7,405 words) - 13:58, 28 November 2022
  • AEPD (Spain) - PS/00188/2021 (category Article 6(1) GDPR)
    1) and 17.1 of the RGPD typified in article 83.5.a) and 83.5b) of the aforementioned RGPD. SECOND: APPOINT D. B.B.B. as instructor. and as secretary to
    33 KB (5,242 words) - 11:42, 11 August 2021
  • BVwG - W176 2249328-1/4Z (category Article 83(4) GDPR)
    fine of EUR 2,000,000 on XXXX GmbH for these violations in accordance with Section 30 (1) and (2) DSG in conjunction with Article 83 (5) (a) GDPR. On the other
    18 KB (2,717 words) - 12:08, 5 August 2022
  • DSB (Austria) - 2023-0.420.407 (category Article 5(1)(b) GDPR)
    so-called household exception according to Article 2, Paragraph 2, Litera c, GDPR is not fulfilled. 3.1.2. Art. 83 Para. 5 lit worldwide annual turnover of
    35 KB (5,572 words) - 14:56, 27 March 2024
  • AEPD (Spain) - PS-00507-2022 (category Article 83(2) GDPR)
    were initiated, based on Article 63 and Article 64 LPACAP and an infringement of Article 6(1) GDPR typified in Article 83(5) GDPR. After the proceedings
    49 KB (7,832 words) - 10:54, 22 January 2024
  • accesses) (Article 83(2)(a) GDPR and Article 83(2)(g) GDPR). It also considered the cooperation of the controller to remedy the infringement (Article 83(2)(f)
    70 KB (11,425 words) - 13:47, 7 December 2022
  • UODO - DKN.5112.1.2020 (category Article 5(2) GDPR)
    controller under Article 24(1) GDPR, Article 25 (1) GDPR, Article 32(1)(b) GDPR and Article 32(1)(d) GDPR and Article 32 GDPR#2"Article 32(2) GDPR. Share blogs
    89 KB (14,285 words) - 12:21, 10 September 2021
  • LArbG Nürnberg - 4 Sa 201 22 (category Article 83(5)(b) GDPR)
    ignores the wording of Article 82 GDPR. To put this into perspective: Other than Article 82 GDPR, Article 77 GDPR actually only mentions GDPR violations by processing
    19 KB (2,972 words) - 05:25, 9 May 2023
  • AEPD (Spain) - EXP202206805 (category Article 83(2)(c) GDPR)
    criteria established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 may
    37 KB (5,879 words) - 07:09, 4 October 2023
  • VG Mainz - 1 K 584/19.MZ (category Article 58(2) GDPR)
    street. The DPA was allowed to issue a reprimand, Art. 58(2)(b) GDPR. On the basis of Art. 58(2)(f) GDPR, the DPA was not entitled to order the removal of camera
    58 KB (9,665 words) - 08:51, 25 November 2020
  • presented the matter Applicable law Article 4 (7) and (8), Article 28 (3), Article 58 (2) (b) and (i), Article 83 (1), (2), (4) (a) of the EU General Data
    40 KB (6,315 words) - 11:13, 22 September 2021
  • AEPD (Spain) - PS/00388/2022 (category Article 32(1) GDPR)
    has not violated the article 15 of the GDPR, infringement typified in article 83.5 a) of the GDPR. IV. Secondly, article 32 of the GDPR "Security of treatment"
    72 KB (11,730 words) - 08:54, 19 July 2023
  • AEPD (Spain) - PS/00362/2021 (category Article 83 GDPR)
    of Article 58.2.b) of the RGPD, for the alleged violation of Article 32 of the RGPD, typified in article 83.4.a) of the RGPD. SECOND: APPOINT B.B.B. as
    31 KB (4,769 words) - 08:00, 8 September 2021
  • NAIH (Hungary) - NAIH-180-16/2022 (category Article 5(2) GDPR)
    case (Article 83(2)(b)); as well as that the NAIH had already warned the controller about its processing activities previously (Article 83(2)(b)). However
    57 KB (9,033 words) - 16:35, 27 April 2022
  • ANSPDCP (Romania) - 06.03.2023 (category Article 83 GDPR)
    investigations. The DPA found that both companies had violated Article 32(1)b and c and 32(2) GDPR because they had not implemented adequate technical and organizational
    4 KB (441 words) - 14:42, 14 March 2023
  • AEPD (Spain) - PS/00200/2021 (category Article 6(1) GDPR)
    FIRST: IMPOSE Ms. B.B.B., with NIF *** NIF.1, for a violation of Article 6.1 of the RGPD, typified in Article 83.5 of the RGPD, a fine of 2,000 euros (two
    23 KB (3,787 words) - 09:50, 5 August 2021
  • AEPD (Spain) - EXP202103983 (category Article 4(2) GDPR)
    specified period of time - Article 58.2 (i). According to Article 83(2) of the GDPR, the measure provided for in Article 58(2)(d) of the GDPR is compatible with
    28 KB (4,427 words) - 10:02, 16 June 2023
  • Therefore, the DPA confirmed a breach of Article 5(1)(a) GDPR, Article 6(1)(a) GDPR, Article 7 GDPR and of Article 130 of the Italian Privacy Code for having
    65 KB (10,464 words) - 09:48, 17 January 2024
  • Datatilsynet (Norway) - 23/00708 (category Article 5(2) GDPR)
    violating Article 5(1)(f) GDPR, Article 32(1) GDPR, Article 32(2) GDPR, Article 32(4) GDPR, as well as Article 5(2) GDPR, Article 24(1) GDPR and Article 24(2)
    59 KB (8,718 words) - 14:50, 20 December 2023
  • UODO (Poland) - DKE.561.25.2020 (category Article 83(2) GDPR)
    August 2020 - until the date of this decision. 1.2. Intentional nature of the breach (Article 83 (2) (b) of Regulation 2016/679). In the opinion of the
    28 KB (4,344 words) - 11:02, 22 June 2021
  • AEPD (Spain) - PS/00433/2021 (category Article 6(1) GDPR)
    MEETING PUERTO C.B., with NIF E76518877, for a infringement of Article 6.1 of the RGPD, typified in article 83.5.b) of the RGPD, a fine of €2,000 (two thousand
    27 KB (4,079 words) - 12:37, 9 February 2022
  • UODO (Poland) - DKN.5131.11.2020 (category Article 83(2) GDPR)
    art. 58 sec. 2 lit. e) and lit. i), art. 83 sec. 1-2 and art. 83 sec. 4 lit. a) in connection with Art. 33 paragraph 1 and art. 34 sec. 1, 2 and 4 of Regulation
    51 KB (8,179 words) - 12:07, 11 August 2021
  • AEPD (Spain) - PS/00119/2021 (category Article 6(1) GDPR)
    criteria established in the section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 also
    28 KB (4,459 words) - 14:26, 24 November 2022
  • proceedings for potential GDPR violations to evaluate the possibility of applying a penalty as per Article 58(2) GDPR and Article 83 GDPR. In response, the controller
    38 KB (6,029 words) - 11:02, 13 March 2024
  • AEPD (Spain) - PS/00499/2022 (category Article 5(1)(c) GDPR)
    infringement of article 5.1.c) of the GDPR, typified in article 83.5 of the GDPR, and for the alleged infringement of article 13, typified in article 83.5.b) of the
    55 KB (8,912 words) - 13:18, 16 May 2023
  • AEPD (Spain) - EXP202102433 (category Article 5(1)(f) GDPR)
    relation to letter k) of article 83.2 of the GDPR, the LOPDGDD, in its Article 76, "Sanctions and corrective measures", establishes that: "2. In accordance with
    35 KB (5,473 words) - 05:14, 26 April 2023
  • NAIH (Hungary) - NAIH-642-4/2022 (category Article 5(1)(b) GDPR)
    €7,80) for the breach of Articles 5(1)(b)(c) GDPR, 6(1) GDPR, 12(1) GDPR, 7(2) GDPR, 9(1) GDPR, 13 GDPR and 14 GDPR. Independent of any instructions from
    73 KB (11,498 words) - 15:22, 29 August 2023
  • AEPD (Spain) - PS/00501/2021 (category Article 5(2) GDPR)
    of personal data of clients or third parties (article 83.2.k, of the RGPD in relation to article 76.2.b, of the LOPDGDD) It is appropriate to graduate
    26 KB (3,914 words) - 12:38, 2 February 2022
  • DSB (Austria) - D123.768/0004-DSB/2019 (category Article 85(2) GDPR)
    para 11 CFR Art11 para 1 ECHR Art10 para 1 GDPR Art4 no 2 GDPR Art4 no 7 GDPR Art85 para 1 GDPR Art85 para 2 Text GZ: DSB-D123.768/0004-DSB/2019 of 18.12
    29 KB (4,637 words) - 13:57, 12 May 2023
  • AEPD (Spain) - PS/00261/2021 (category Article 6(1) GDPR)
    violation of Article 6.1 of the RGPD, typified in Article 83.5 of the RGPD. FIFTH: Notification of the aforementioned start-up agreement, D. B.B.B., on behalf
    34 KB (5,536 words) - 19:04, 16 May 2022
  • based on Articles 6(c) and 9(2)(b). The school did not specify the source of the legal obligation under Article 6(1)(c) GDPR, nor the source of the obligations
    24 KB (3,752 words) - 11:47, 9 November 2022
  • portability, thereby violating Article 13(2)(b) GDPR. In light of the above, in accordance with Article 58(2)(i) GDPR and Article 83 GPDR, the AP considered it
    80 KB (11,628 words) - 11:41, 23 February 2024
  • AEPD (Spain) - PS-00446-2023 (category Article 6(1) GDPR)
    with NIF B09966508, for the alleged violation of article 6.1 of the RGPD, typified in the article 83.5.a) of the RGPD. SECOND: APPOINT B.B.B. Instructor
    34 KB (5,141 words) - 09:28, 8 March 2024
  • TS - 1039/2022 (category Article 18(1) GDPR)
    provided for in Article 18 GDPR. As explained by the Court, Article 18(1) GDPR, in particular in paragraph (d), is linked to Article 21(1) GDPR, which guarantees
    44 KB (6,561 words) - 14:24, 24 November 2022
  • AEPD (Spain) - PS/00189/2021 (category Article 6(1) GDPR)
    negligence in the offense (article 83.2 b). - Basic personal identifiers are affected (name, data bank, the line identifier) (article 83.2 g). That is why it is
    23 KB (3,387 words) - 09:55, 22 September 2021
  • AEPD (Spain) - PS/00177/2021 (category Article 13 GDPR)
    NIF B99514218, in accordance with the provisions of article 58.2.b) of the RGPD, for the alleged infraction 13 of the RGPD, typified in article 83.5.b)
    29 KB (4,484 words) - 12:28, 7 July 2021
  • Datatilsynet (Norway) - 18/02140 (category Article 32(1)(b) GDPR)
    security are set out in Chapter IV, Section 2. Here is Article 32 central. Article 32 (1) (a) and (b) states: Article 32. Safety of treatment 1. Taking into
    54 KB (8,041 words) - 12:50, 26 January 2022
  • principle of purpose limitation under Article 5(1)(b) GDPR and the principle of data minimisation pursuant to Article 5(1)(c) GDPR. Further, the DPA found that
    90 KB (14,258 words) - 14:14, 3 January 2024
  • WSA Warsaw (Poland) - II SA/Wa 2559/19 (category Article 32(1)(b) GDPR)
    in the form of obligations set out in Article 24 (1), Article 25 (1) and Article 32 (1) (b) and (b), Article 32 (2) of Regulation 2016/679), and moreover
    90 KB (14,642 words) - 11:12, 18 November 2020
  • procedure in Article 60(9) GDPR. Accordingly, the DPC removed its proposed “Finding 1” from its Final Decision (2.23). Issue 2 – Reliance on Article 6(1)(b) GDPR
    32 KB (4,686 words) - 14:17, 1 February 2023
  • AEPD (Spain) - PS/00324/2021 (category Article 5(1)(b) GDPR)
    personal data from Article 9 GDPR. According to the AEPD, even if the controller may had relied on the exemption on Article 9 GDPR(2)(f), since the data
    29 KB (4,546 words) - 17:47, 7 January 2022
  • parties (Article 83, paragraph 2, letter c) of the Regulation); 2. the absence of previous relevant violations committed by the data controller (Article 83,
    40 KB (6,513 words) - 13:47, 3 May 2023
  • AEPD (Spain) - PS/00427/2021 (category Article 6(1) GDPR)
    of a person (article 83.2 b). - Basic personal identifiers are affected (name, a number identification, the line identifier) (article 83.2 g). - Section
    23 KB (3,593 words) - 16:23, 26 January 2022
  • 5(1)(a) and 5(1)(f) GDPR, as well as Article 9 GDPR related to the processing of special categories of personal data, and Article 32 GDPR on the security of
    32 KB (5,041 words) - 18:17, 26 April 2022
  • AEPD (Spain) - PS/00476/2021 (category Article 6 GDPR)
    violation of art. 6 of the GDPR. IV Article 72.1 b) of the LOPDGDD states that “according to what is established in the article 83.5 of Regulation (EU) 2016/679
    26 KB (4,105 words) - 14:34, 13 April 2022
  • UODO (Poland) - DKN.5131.16.2021 (category Article 83(2) GDPR)
    33(3)(b), Article 33(3)(c), and Article 33(3)(d), as Article 34(2) GDPR prescribes. Therefore, the DPA decided to impose an administrative fine pursuant to
    88 KB (14,432 words) - 10:31, 24 November 2021
  • CNPD (Luxembourg) - Délibération n° 17FR/2021 (category Article 5(1)(c) GDPR)
    elements provided for in Article 83.2 of the GDPR:  As to the nature and seriousness of the violation (article 83.2.a) of the GDPR), the Restricted Training
    44 KB (6,212 words) - 08:28, 16 June 2021
  • AEPD (Spain) - PS/00060/2021 (category Article 6(1) GDPR)
    complained party, by the alleged violation of Article 6.1 of the RGPD, typified in Article 83.5 a) of the GDPR. Said agreement was notified by post on March
    18 KB (2,739 words) - 10:39, 7 July 2021
  • AEPD (Spain) - PS/00180/2021 (category Article 6 GDPR)
    of a person (article 83.2 b). - Basic personal identifiers are affected (name, a number of identification, the line identifier) (article 83.2 g). C / Jorge
    26 KB (3,947 words) - 10:42, 21 July 2021
  • UODO (Poland) - DKN.5112.5.2021 (category Article 5(2) GDPR)
    with GDPR provisions, this includes obtaining proof of consent in line with Article 7(1) GDPR. Especially in the context of Article 9(2)(a) GDPR, the explicit
    82 KB (13,363 words) - 14:11, 18 January 2023
  • AEPD (Spain) - PS/00420/2021 (category Article 5(1)(f) GDPR)
    violation of Article 5.1.f) of the RGPD and Article 32 of the RGPD, typified in Article 83.5 of the RGPD and Article 83.4, respectively, of the GDPR. SECOND:
    31 KB (4,660 words) - 09:46, 22 June 2022
  • UODO (Poland) - DKN.5131.33.2021 (category Article 83(2) GDPR)
    finally financial loss. 2. Intentional nature of the infringement (Article 83 (2) (b) of Regulation 2016/679). In line with the Article 29 Working Party's Guidelines
    81 KB (13,351 words) - 14:48, 2 March 2022
  • UODO (Poland) - DKN.5110.12.2021 (category Article 33(1) GDPR)
    art. 58 sec. 2 lit. i), art. 83 sec. 1 and 2 and article. 83 sec. 4 lit. a) in connection with art. 33 paragraph 1 and art. 34 sec. 1 and 2 of the Regulation
    51 KB (8,343 words) - 14:16, 15 June 2022
  • AEPD (Spain) - PS/00140/2021 (category Article 5 GDPR)
    serious negligent action (article 83.2 b) - Basic personal identifiers are affected (name, surname, domicile) (article 83.2 g) The balance of the circumstances
    28 KB (4,254 words) - 11:30, 16 June 2021
  • AEPD (Spain) - PS/00110/2020 (category Article 7 GDPR)
    Thus, the AEPD understood that the defendant has infringed Article 7 of the GDPR and Article 6(3) of the Spanish Law on Data Protection and Digital Rights
    32 KB (4,992 words) - 14:00, 13 December 2023
  • AEPD (Spain) - EXP202310910 (category Article 5(1)(c) GDPR)
    regulated in article 5.1.c) of the RGPD and other violation of article 13 of the GDPR. III Article 5.1 c) of the GDPR Article 5 of the GDPR “Principles
    44 KB (6,808 words) - 14:36, 21 May 2024
  • AEPD (Spain) - EXP202211618 (category Article 6(1) GDPR)
    NANDIVALE, S.L., with NIF B66070012, for a violation of the Article 6.1 of the GDPR, typified in Article 83.5.a) of the GDPR, a fine of 10,000 € (ten thousand
    33 KB (5,018 words) - 13:23, 2 August 2023
  • pursuant to Article 13 of the GDPR for collaborators; Information pursuant to Article 13 of the GDPR for employees; Disclosure pursuant to Article 4, paragraph
    78 KB (12,604 words) - 09:01, 7 June 2023
  • DSB (Austria) - 2022-0.585.764 (category Article 2(2)(c) GDPR)
    intent within the meaning of Art. 83 (2) lit. b GDPR. within the meaning of Article 83, Paragraph 2, Letter b, GDPR. 4. The following must be noted for
    77 KB (13,004 words) - 14:44, 9 May 2023
  • violation of Article 52 of the Code, for which an administrative sanction is provided for (Article 166, para 2 of the Code and Article 83(3) of the Regulation);
    30 KB (4,446 words) - 14:47, 13 June 2022
  • UODO (Poland) - DKN.5131.43.2022 (category Article 5(2) GDPR)
    the controller was in breach of Article 33(1) GDPR, Article 33(3) GDPR, Articles 34(1) and 34(2) GDPR, and Article 5(2) GDPR, Firstly, the Polish DPA held
    57 KB (9,261 words) - 08:13, 25 October 2023
  • Rb. Amsterdam - AMS 22/5458 (category Article 83(2) GDPR)
    whether DPG adequately facilitated the exercise of GDPR rights for the purposes of Article 12(2) GDPR. This provision obliges controllers to "facilitate
    27 KB (4,200 words) - 11:57, 13 September 2023
  • AEPD (Spain) - PS/00322/2021 (category Article 6(1)(a) GDPR)
    established in article 83.2 of the RGPD. Specifically, we are faced with several manifestly negligent actions, in accordance with article 83.2 b) of the RGPD
    52 KB (8,192 words) - 20:47, 22 February 2022
  • AEPD (Spain) - PS/00224/2021 (category Article 5(1)(c) GDPR)
    specified period -article 58. 2 d)-. According to the provisions of article 83.2 of the RGPD, the measure provided for in article 58.2 d) of the aforementioned
    27 KB (4,172 words) - 16:37, 25 January 2022
  • AEPD (Spain) - PS/00314/2021 (category Article 83(4)(a) GDPR)
    in accordance with article 37 of the Regulation (EU) 2016/679 and article 34 of this organic law. " SAW On the other hand, article 83.7 of the RGPD, which
    24 KB (3,489 words) - 12:05, 10 November 2021
  • invitation to comply, breaching Article 12 GDPR, Article 15 GDPR, Article 16 GDPR, Article 17 GDPR and Article 18 GDPR. Thus, due to the aformentioned
    73 KB (11,856 words) - 13:54, 25 October 2023
  • UODO (Poland) - DKN.5131.22.2021 (category Article 32(1)(b) GDPR)
    that the controller breached Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1)(b) and (d), and Article 32(2) GDPR due to a lack of a reliably
    68 KB (10,909 words) - 14:47, 25 October 2021
  • against the Company (Article 83, paragraph 2, letter e of the Regulation); 2) the common nature of the data processed (Article 83, paragraph 2, letter g of the
    46 KB (7,332 words) - 13:27, 3 May 2023
  • authorisation from the data subject. This breached Article 5(1)(a) GDPR, Article 6 GDPR, Article 13 GDPR, and Article 157 of the Italian Privacy Code. GFB One s
    30 KB (4,688 words) - 08:49, 15 November 2023
  • AEPD (Spain) - PS/00261/2020 (category Article 5(1)(c) GDPR)
    RGPD); as he points out Article 83.5 a) of the RGPD. -12 of the RGPD, in relation to 22 of the LOPDGDD, as indicated in article 83.5.b) of the RGPD. " FOURTH:
    54 KB (8,837 words) - 13:34, 16 June 2021
  • the UK GDPR and the DPA. They are obliged by Article 5(2) to adhere to the data processing principles set out in Article 5(1) of the UK GDPR. Article 5(2)
    54 KB (7,579 words) - 16:44, 7 May 2024
  • AEPD (Spain) - PS/00244/2021 (category Article 6 GDPR)
    a violation of article 6 of the RGPD. IV Article 72.1 b) of the LOPDGDD states that “depending on what is established in the Article 83.5 of Regulation
    13 KB (1,886 words) - 14:06, 13 October 2021
  • AEPD (Spain) - EXP202210101 (category Article 6(1) GDPR)
    of personal data of clients or third parties (article 83.2.k, of the RGPD in relation with article 76.2.b, of the LOPDGDD). While it is true that Orange's
    85 KB (13,823 words) - 12:51, 3 April 2024
  • fairness (Article 5(1)(a) GDPR). Thus by not providing sufficient information, the controller breached Article 5(1)(a) GDPR and Article 13 GDPR. Additionally
    41 KB (6,619 words) - 13:06, 18 January 2023
  • AEPD (Spain) - PS/00111/2021 (category Article 5(1)(f) GDPR)
    negligent action (article 83.2.b). Basic personal identifiers are affected, according to article 83.2.g). VII Therefore, in accordance with the foregoing, the
    39 KB (6,095 words) - 10:08, 20 October 2021
  • AEPD (Spain) - PS/00480/2020 (category Article 5(1)(f) GDPR)
    accordance with article 83.5.a) of the GDPR. - An infringement of article 13 of the RGPD, in accordance with article 83.5. b) of the RGPD. SECOND: By virtue
    41 KB (6,468 words) - 17:16, 24 November 2021
  • and transparency, as outlined in Article 5(1)(a) GDPR. In the exercise of its authority under Article 58(2)(f) GDPR, the DPA imposed a ban on the processing
    27 KB (4,036 words) - 13:37, 2 January 2024
  • NAIH (Hungary) - NAIH-1006-3/2022 (category Article 5(1)(b) GDPR)
    attenuating circumstance. [Article 83 (2) (f) of the General Data Protection Regulation] The Authority did not consider Article 83 (2) (c), (g), (i), (j) and
    66 KB (10,597 words) - 16:56, 18 May 2022
  • 58, paragraph 2, letters i and 83 of the Regulation; article 166, paragraph 7, of the Code). The Guarantor, pursuant to articles. 58, par. 2, letter. i)
    140 KB (23,084 words) - 09:22, 30 April 2024
  • AEPD (Spain) - PS/00356/2021 (category Article 5(1)(c) GDPR)
    Agency RESOLVES: FIRST: IMPOSE B.B.B., with NIF ***NIF.1, for an infraction of Article 5.1.c) of the RGPD, typified in Article 83.5 of the RGPD, a fine of €1
    18 KB (2,791 words) - 18:33, 1 February 2022
  • Datatilsynet (Norway) - 20/02165 (category Article 32(1)(b) GDPR)
    Norwegian Health Records Act (pasientjournalloven) and Article 32(1)(b) and (d) GDPR (cf. Article 5 GDPR). The DPA fined Moss municipality NOK 500,000 (€47
    24 KB (3,436 words) - 07:38, 4 October 2021
  • Personvernnemda (Norway) - 2022-03 (20/02375) (category Article 5(2) GDPR)
    whether an infringement fee shall be imposed pursuant to Article 83 no. 5, cf. Article 83 no. 2, and if a fee shall be imposed, how large the fee must be
    30 KB (4,786 words) - 16:29, 6 July 2022
  • constituting a breach of Article 12(2) GDPR and Article 12(3) GDPR, as well as Article 15 GDPR, Article 17 GDPR and Article 21(2) GDPR. Thus, the calls carried
    63 KB (9,986 words) - 12:04, 11 October 2023
  • AEPD (Spain) - PS/00505/2021 (category Article 6(1) GDPR)
    sedeagpd.gob.es, 8/10 In relation to letter k) of article 83.2 of the RGPD, the LOPDGDD, in its Article 76, “Sanctions and corrective measures”, establishes
    28 KB (4,283 words) - 09:43, 24 March 2022
  • Norway, and not the GDPR. The DPA does, however, refer to corresponding Articles in the GDPR: Articles 5(1)(b) and (c), as well as Article 17. Share blogs
    43 KB (6,983 words) - 09:09, 21 August 2022
  • personal data securely, in violation of Articles 5(1)(f) GDPR and Article 32(1)(b) and (d) GDPR. Two aspects of the decisions are interesting. First, the
    86 KB (13,819 words) - 21:32, 8 February 2024
  • prohibition to process sensitive data (Article 2-septies (8) of the Code and Article 9(4) GDPR). Pursuant to Article 83(3) GDPR, the DPA considered several aggravating
    41 KB (6,326 words) - 14:38, 20 December 2022
  • VwGH - Ra 2020/04/0187 (category Article 83 GDPR)
    under Article 83 GDPR and the question of the compatibility of § 30 Datenschutzgesetz (Austrian Data Protection Act - DSG) with Article 83 GDPR to the
    16 KB (2,370 words) - 14:56, 6 December 2023
  • regulation Article 58 (2) point b) states that the Customer has violated the general data protection Article 5(1)(b) and (c), Article 6, Article 5(2) and the
    62 KB (9,792 words) - 13:54, 5 October 2022
  • UODO (Poland) - DKN.5131.29.2022 (category Article 28(1) GDPR)
    well as art. 57 sec. 1 lit. a) and h), art. 58 sec. 2 lit. i), art. 83 sec. 1 and 2 and article. 83 sec. 4 lit. a) in connection with Art. 28 sec. 1, 3
    48 KB (7,612 words) - 09:46, 25 April 2024
  • UODO (Poland) - DKN.5131.34.2021 (category Article 33(1) GDPR)
    in Art. 83 sec. 2 of Regulation 2016/679, the circumstances: a) actions taken to minimize the damage suffered by the data subjects (Article 83 (2) and (c)
    61 KB (9,994 words) - 08:37, 14 September 2022
  • NAIH (Hungary) - NAIH-2501-10/2022 (category Article 5(1)(b) GDPR)
    point (c). Article 13 (2) point (c) of the General Data Protection Regulation General Data Protection Regulation Article 13 (1) (b), (e), (2) (b), (d), (e)
    90 KB (14,299 words) - 13:52, 2 February 2023
  • AEPD (Spain) - PS/00308/2021 (category Article 6 GDPR)
    the provisions of article 58.2.b) of the RGPD, for the alleged violation of article 6 of the RGPD, typified in article 83.5.b) of the GDPR SECOND: ORDER ORANGE
    24 KB (3,728 words) - 10:06, 18 August 2021
  • Authority during the investigation, the violation is not culpable (Article 83, paragraph 2, letters b) and f) of the Regulations). Due to the aforementioned elements
    56 KB (8,926 words) - 14:57, 14 July 2021
  • AEPD (Spain) - PS/00250/2021 (category Article 32(1)(b) GDPR)
    complained party, by the alleged violation of Article 32 of the RGPD, Article 5.1.f) of the RGPD, typified in the Article 83.5 of the RGPD. FOURTH: Notified the
    40 KB (6,262 words) - 10:43, 7 July 2021
  • AEPD (Spain) - EXP202300944 (category Article 4(11) GDPR)
    the object of the This claim is very high (article 76.2.b) of the LOPDGDD in relation to with article 83.2.k). Considering the exposed factors, in order
    76 KB (11,351 words) - 09:28, 24 April 2024
  • Datatilsynet (Norway) - 0/02422 (category Article 58(2)(i) GDPR)
    violation of Article 12(3) GDPR and Article 15 GDPR due to a failure to respond to an access request that was submitted around a month after the GDPR became
    162 KB (24,007 words) - 19:41, 15 February 2023
  • national rules applicable to workplace monitoring system as per Article 6(1)(b) and Article 88(2) GDPR. Since the controller is also a public entity subject to
    57 KB (9,035 words) - 19:11, 28 May 2024
  • APD/GBA (Belgium) - 82/2020 (category Article 6(1) GDPR)
    dossier werden toegevoegd. 2. Motivering 2.1. De bevoegdheid van de Inspectiedienst en de Geschillenkamer en de omvang van het dossier 2.1.1. Het verzoek van
    124 KB (18,772 words) - 17:01, 12 December 2023
  • ..........202 Article 83(2)(b): the intentional or negligent character of the infringement.............................211 Article 83(2)(c): any action
    830 KB (115,261 words) - 15:37, 22 February 2022
  • CNPD (Luxembourg) - Délibération n°16FR/2021 (category Article 5(1)(c) GDPR)
    elements provided for in Article 83.2 of the GDPR:  As to the nature and seriousness of the violation (article 83.2.a) of the GDPR), the Restricted Training
    51 KB (7,338 words) - 11:33, 16 June 2021
  • party. Therefore, the controller breached Article 5(1)(a) GDPR, Article 6(1)(a) GDPR, Article 7 GDPR, and Article 130 of the Italian privacy code, since the
    51 KB (7,993 words) - 12:39, 6 February 2024
  • CNPD (Luxembourg) - Délibération n° 11FR/2021 (category Article 5(1)(e) GDPR)
    the violation (article 83.2.a) of the GDPR), the Restricted Training notes that with regard to the breach of Article 5.1.e) of the GDPR, it constitutes
    60 KB (8,610 words) - 11:12, 16 June 2021
  • KG Berlin - 3 Ws 250/21 - 161 AR 64/21 (category Article 83 GDPR)
    following preliminary questions to the CJEU: (1) Is Article 83(4) to Article 83(6) GDPR of the GDPR to be interpreted as incorporating into national law
    38 KB (5,956 words) - 11:41, 21 January 2022
  • AEPD (Spain) - PS/00003/2021 (category Article 12(2) GDPR)
    pursuant to Article 58(2) GDPR. Moreover, it ordered the controller to bring its processing operations into compliance pursuant to Article 58(2)(d) GDPR. On sharing
    115 KB (18,312 words) - 11:58, 16 March 2022
  • AEPD (Spain) - PS/00459/2020 (category Article 5 GDPR)
    criteria established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 The
    40 KB (6,380 words) - 08:15, 28 July 2021
  • AEPD (Spain) - PS/00410/2020 (category Article 2(2)(c) GDPR)
    as established in article 2.2 of the RGPD and article 2.2.a) of the LO- PDGDD, the following should be noted: it says to article 2.2 of the RGPD: "two
    47 KB (7,334 words) - 17:00, 14 December 2022
  • and disadvantaged individuals on social media in violation of Article 5(1)(a) and (b) GDPR. Mr. Cateno De Luca, current Mayor of the City of Messina, posts
    48 KB (7,887 words) - 11:56, 30 June 2021
  • data for these purposes under Article 21(2) GDPR. Additionally, the data subject filed an access request under Article 15 GDPR. The data subject did not receive
    94 KB (14,814 words) - 14:42, 30 April 2024
  • AEPD (Spain) - EXP202307898 (category Article 21 GDPR)
    criteria. tion established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of the Regulation (EU) 2016/679
    37 KB (5,591 words) - 14:51, 10 April 2024
  • AEPD (Spain) - PS/00267/2021 (category Article 83(2)(e) GDPR)
    infringement of Article 83.5.b) of the RGPD and Article 74.c) of the LOPDGDD, for breach of the provisions of Article 12, paragraphs 2 and 3, of the RGPD
    193 KB (32,580 words) - 11:16, 15 June 2022
  • residence, and it fined the data controller €10,000 under Article 58(2)(i) GDPR and Article 83 GDPR. Share your comments here! Share blogs or news articles
    39 KB (6,150 words) - 07:57, 4 October 2023
  • in breach of Articles 5(1)(a) and 6 GDPR. Finally, the Italian DPA found a violation of Article 25(1) and (2) GDPR because the controller had not adopted
    152 KB (24,743 words) - 14:39, 21 March 2023
  • BVwG - W274 2232028-1/3E (category Article 5 GDPR)
    is only determined by Article 5 et seqq. GDPR. A violation of Article 13 or 14 GDPR can be fined under Article 83(5) GDPR but it does not affect the lawfulness
    32 KB (5,232 words) - 09:40, 10 September 2021
  • Persónuvernd - 2020010382 (category Article 83(2)(c) GDPR)
    the principles found in Article 5 GDPR, in this case Article 5(1)(f) GDPR. In addition, Persónuvernd highlighted Article 32 GDPR as operationalising the
    26 KB (4,190 words) - 13:08, 11 March 2020
  • NSS - 10 As 190/2020 - 39 (category Article 83(7) GDPR)
    body within the meaning of Article 83(7) GDPR. In interpreting what amounts to a public authority or body under Article 83(7) GDPR, the NSS held that such
    34 KB (5,374 words) - 04:32, 28 April 2022
  • 2019, GDPR Art. 37, para. 1; Döpfler , EU-GDPR and BDSG, 2nd edition 2020, GDPR Art. 37, marginal 1; Paal / Pauly, DS-GVO BDSG, 2nd ed. 2018, GDPR Art.
    48 KB (7,320 words) - 12:44, 4 October 2021
  • breach of the principle of purpose limitation (Article 5(b) GDPR) and of data minimization (Article 5(c) GDPR), since the accesses in question to the data
    122 KB (19,692 words) - 14:42, 10 January 2024
  • CNPD (Luxembourg) - Délibération n°24FR/2021 (category Article 5(1)(c) GDPR)
    the violation (article 83.2.a) of the GDPR), the Restricted Training notes that with regard to the breach of Article 5.1.c) of the GDPR, it constitutes
    58 KB (8,226 words) - 07:35, 22 July 2021
  • line with the GDPR were not adequate to the nature, context and risks of the processing carried out (breach of Article 5(2) and Article 24 GDPR). In determining
    69 KB (11,278 words) - 16:03, 22 February 2023
  • AEPD (Spain) - EXP202207270 (category Article 19 GDPR)
    violation of Article 19.1 of the LOPDGDD, typified in the Article 83.5 of the RGPD. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 2/8 FIFTH:
    26 KB (3,901 words) - 13:19, 13 December 2023
  • AEPD (Spain) - PS/00443/2021 (category Article 83(2) GDPR)
    established in its article 12.5. (…)” VII Penalty for violation of article 12 of the GDPR Without prejudice to the provisions of article 83 of the GDPR, the aforementioned
    40 KB (6,231 words) - 08:51, 16 March 2023
  • DPA, the controller breached Article 157 (request for information and production of documents) in relation to Article 166(2) of the Code. Therefore, the
    30 KB (4,724 words) - 13:41, 2 November 2022
  • AEPD (Spain) - PS/00301/2020 (category Article 5(1)(d) GDPR)
    troversies between those and any interested party. " Article 83.2.k) of the RGPD concurs, specified in article 76.2 b) of the LOPDGDD, for the usual treatment of
    28 KB (4,554 words) - 11:33, 30 June 2021
  • Article 9, Article 12 and Article 13 GDPR. The Italian DPA ordered the controller to bring processing operations into conformity with the provisions of
    89 KB (14,466 words) - 15:14, 20 February 2024
  • AEPD (Spain) - PS/00259/2020 (category Article 6(1)(f) GDPR)
    force of the RGPD. Regarding the mitigating effect of article 83.2.k) RGDP in relation to article 76.2. and) of the LOPDGDD, considers it irrelevant since
    158 KB (25,857 words) - 13:56, 14 July 2021
  • AEPD (Spain) - EXP202213792 (category Article 5(1)(c) GDPR)
    finding likely violations of Article 5(1)(c), 8, 9, 13 and 35 GDPR. The AEPD found a likely violation of Article 35 GDPR. Article 35 GPDR requires that a data
    178 KB (27,656 words) - 12:28, 7 May 2024
  • AEPD (Spain) - PS/00384/2020 (category Article 5(1)(f) GDPR)
    constituted an infringement of Article 5(1)(f) GDPR for violating the principle of confidentiality and Article 32 GDPR for failing to implement appropriate
    37 KB (5,788 words) - 15:05, 14 July 2021
  • UODO (Poland) - DKN.5131.49.2021 (category Article 33(1) GDPR)
    subject about it. 2. Intentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679); According to the Guidelines of the Article 29 Working Party
    63 KB (10,380 words) - 08:26, 17 October 2023
  • violated Articles 5(2), 24 and 25(1) GDPR. At last, the DPA established a violation of Article 5(2), Article 24 and Article 13 GDPR, for failing to provide
    131 KB (21,176 words) - 12:52, 20 December 2022
  • should rely on one of the legal basis under Article 6 and 9 GDPR. Specifically, Articles 9(2)(h) and 9(3) GDPR allow for processing of sensitive data for
    41 KB (6,305 words) - 11:34, 28 October 2022
  • AEPD (Spain) - EXP202207521 (category Article 6(1) GDPR)
    third parties. Article 83.2 g) GDPR: the categories of personal data affected by the infringement: image of the claimant. Article 76.2 b) LOPDGDD: "The
    54 KB (8,747 words) - 08:36, 30 August 2023
  • NAIH (Hungary) - NAIH-2727-2/2022. (category Article 5(1)(b) GDPR)
    and Article 58 (2) GDPR (b) condemns the Applicant for violating: - Article 5 (1) (a) and (b) of the GDPR, - Article 5 (2) of the GDPR, - Article 6 (1)
    79 KB (12,461 words) - 16:08, 22 June 2022
  • AEPD (Spain) - EXP202213323 (category Article 5(1)(c) GDPR)
    Violation of article 35 of the GDPR................................................ ...................36 8.2. Violation of article 9 of the GDPR.........
    176 KB (27,432 words) - 07:43, 10 May 2024
  • VwGH - Ro 2019/04/0229 (category Article 83 GDPR)
    May 2018 and Article 13(2) of the Data Protection Act (DSG) from 25 May 2018, Article 50b(2) for the period before 25 May 2018, Article 50b(2) for the period
    59 KB (8,848 words) - 12:41, 16 September 2021
  • Region Lombardia violated Article 5(1)(a)(c) GDPR due to the dissemination not being necessary as well as Article 6(1)(c)(e) GDPR due to the absence of suitable
    77 KB (12,455 words) - 09:35, 15 September 2021
  • accountability pursuant to Article 5(1)(a) and (2) GDPR and its responsibility as a controller under Article 24(1) and 25(1) GDPR. In addition to that, the
    68 KB (10,773 words) - 09:49, 15 May 2024
  • UODO (Poland) - DKN.5131.12.2020 (category Article 5(2) GDPR)
    controller violated Article 5(2) GDPR by not being able to demonstrate its compliance with the principles under Article 5(1) GDPR. For these violations
    74 KB (11,896 words) - 15:14, 7 March 2023
  • AEPD (Spain) - EXP202304633 (category Article 5(1)(f) GDPR)
    violation of the Article 5.1.f) of the RGPD and Article 32 of the RGPD, typified in Article 83.5 of the GDPR and Article 83.4 of the GDPR. SECOND: APPOINT
    106 KB (15,486 words) - 14:32, 15 May 2024
  • UODO (Poland) - DKN.5131.59.2022 (category Article 33(1) GDPR)
    of the infringements (Article 83(2)(a) of Regulation 2016/679), intentional or unintentional nature of the breaches (Article 83(2)(b) of Regulation 2016/679)
    108 KB (17,728 words) - 07:57, 25 April 2024
  • analyzes the criteria set by Article 83.2 of the GDPR: - As to the nature and seriousness of the violation (article 83.2 a) of the GDPR), with regard to concerns
    57 KB (8,374 words) - 08:31, 16 June 2021
  • itself (Article 83, paragraph 2, letter e) of the Regulation); - the Healthcare Company has behaved collaboratively with the Authority (Article 83, paragraph
    49 KB (7,823 words) - 16:26, 28 February 2023
  • AEPD (Spain) - PS/00043/2021 (category Article 83(2) GDPR)
    imposed in accordance with the following criteria established by article 83.2 of the RGPD: 2. Administrative fines will be imposed, depending on the circumstances
    23 KB (3,505 words) - 13:40, 27 April 2022
  • AEPD (Spain) - EXP202202309 (category Article 5(1)(f) GDPR)
    alleged violation of Article 5.1.f) of the RGPD and Article 32 of the GDPR, typified in Article 83.5 of the GDPR and Article 83.4 of the GDPR respectively. SIXTH:
    106 KB (16,925 words) - 12:14, 3 April 2024
  • AEPD (Spain) - PS/00178/2022 (category Article 4(2) GDPR)
    pursuent to Article 6 GDPR. In determining the amount of the fine, the DPA considered aggravating factors, as stipulated in Article 83(2)(a) GDPR, and mitigating
    59 KB (9,122 words) - 14:48, 22 September 2022
  • (such as: origin of data, disclosure and consent) (Article 83, paragraph 2, letter a of the Regulation); 2. the subjective dimension of the conduct, to be
    52 KB (8,324 words) - 15:03, 9 May 2023
  • AEPD (Spain) - PS/00030/2021 (category Article 28 GDPR)
    for a violation of Article 28 in relation to art. 24 both of the RGPD, typified in Article 83.4 of the RGPD and according to art. 83.2, with a fine of 100
    73 KB (11,933 words) - 09:33, 2 June 2021
  • 32(2) GDPR. Finally, the Finnish DPA considered that the firm had failed to respect the principle of accountability enshrined in Article 5(2) GDPR, as
    153 KB (24,570 words) - 15:11, 26 March 2024
  • fairness and transparency, as stipulated by Article 5(1)(a) GDPR, Article 12(1) GDPR, as well as Article 13(2) GDPR due to the lack of information on the period
    111 KB (17,635 words) - 13:18, 13 September 2023
  • provided in Article 5 GDPR, a lawful and transparent processing of personal data. Therefore, the DPA found a violation of Article 5(1)(a) and 13 GDPR. In view
    81 KB (13,367 words) - 11:39, 2 August 2023
  • considering that the controller violated Article 5 GDPR, Article 9 GDPR and Article 32 GDPR, as well as Article 2-septies(8) of the Italian Privacy Code
    47 KB (7,566 words) - 09:15, 28 February 2024
  • as an heir to her deceased father. The request was based on Article 15 GDPR and Article 2-terdecies of the Italian Data Protection Code which makes a special
    25 KB (3,777 words) - 07:58, 8 May 2024
  • and of the Council ((EU) 2016/679) Article 12(1), (2) and (6), Article 15(3), Article 58(2)(b) and (i), Article 83(1), (2), (5) and (6). Data Protection Act
    74 KB (11,917 words) - 06:52, 27 September 2023
  • sessions, within the Article 12(3) GDPR time limit. Moreover, the DPA declared that the therapist had breached Article 12(4) GDPR, as they did not inform
    46 KB (7,186 words) - 14:12, 18 October 2023
  • listed in Article 2(3) of that directive and Article 2(2) of that regulation, apply. 62 In particular, it should be noted that Article 9 of the GDPR and Article
    110 KB (18,000 words) - 08:01, 5 June 2023
  • violation of the GDPR, in particular Articles 12 and 15. Pursuant to its powers under Article 58(2)(i) GDPR, and in accordance with Article 83 GDPR, they imposed
    76 KB (12,273 words) - 13:52, 1 February 2023
  • AEPD (Spain) - PS/00393/2021 (category Article 5(1) GDPR)
    level of damages suffered fried; (art. 83.2 a) RGPD). - the intent or negligence in the infringement; (art. 83.2 b) RGPD), to the proce- to obtain images
    20 KB (2,998 words) - 14:20, 15 June 2022
  • NAIH (Hungary) - NAIH-3195-11/2022 (category Article 5(1)(b) GDPR)
    according to Article (1) point b) and Article 6 (1) ARC. Legal consequences 1. The Authority complies with Article 58 (2) point i) and Article 83 (2) of the
    78 KB (12,303 words) - 08:48, 23 February 2023
  • CNPD (Luxembourg) - Délibération n° 35FR/2021 (category Article 5(1)(c) GDPR)
    elements provided for in Article 83.2 of the GDPR:  As to the nature and seriousness of the violation (article 83.2.a) of the GDPR), the Restricted Training
    81 KB (11,748 words) - 10:59, 17 November 2021
  • AEPD (Spain) - EXP202207494 (category Article 5(1)(f) GDPR)
    PROGRESS, S.L., with NIF B76821586, for the alleged violation of article 5.1.f), typified in 83.5 GDPR. SECOND: APPOINT B.B.B. as instructor. and, as secretary
    26 KB (3,952 words) - 09:44, 14 February 2024
  • AEPD (Spain) - EXP202204836 (category Article 15 GDPR)
    established in article 58.2 of the GDPR. Between They have the power to impose an administrative fine in accordance with the article 83 of the RGPD -article 58.2
    52 KB (8,320 words) - 13:18, 14 February 2024
  • error by the authorized person in enveloping the reports (Article 83, paragraph 2, letter b) and d) of the Regulation); - the owner has fully collaborated
    24 KB (3,767 words) - 10:54, 23 March 2022
  • DSB (Austria) - 2023-0.583.644 (category Article 5(1)(a) GDPR)
    interest see Article 9, Paragraph 2, Letter f, Article 17, Paragraph 3, Letter e, Article 18, Paragraph 2, or Article 21, Paragraph one, GDPR; see ECJ of
    93 KB (15,554 words) - 10:04, 15 February 2024
  • methods. As a result, the DPA found violations of Article 5(1)(c) GDPR, Article 12 GDPR and Article 17 GDPR. The controller was fined €15,000. Regarding the
    35 KB (5,495 words) - 15:17, 19 March 2024
  • AEPD (Spain) - EXP202105363 (category Article 6(1) GDPR)
    that is the subject of this claim is undeniable (article 76.2.b) of the LOPDGDD in relation to article 83.2.k). The intentionality or negligence in the infringement
    104 KB (16,712 words) - 14:32, 15 May 2024
  • processing lack any applicable conditions found in Article 9(2) GDPR and was found in breach of Article 5(2) GDPR. Additionally, the Garante reiterated that the
    105 KB (16,849 words) - 11:58, 11 April 2024
  • AEPD (Spain) - PS/00178/2021 (category Article 5(1)(f) GDPR)
    criteria established in section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679 The
    20 KB (3,078 words) - 14:26, 24 November 2022
  • NAIH (Hungary) - NAIH-4137- 8/2022 (category Article 5(2) GDPR)
    the basis of Article 58 (2) point b) of the GDPR, the Applicant is condemned for having violated it Article 5 (1) point a), Article 12 (2) of the General
    75 KB (11,860 words) - 13:16, 19 October 2022
  • accountability principle, to facilitate the exercise of this right (Article 5(2) and Article 12(2) GDPR). For these reasons, the DPA found that the mere mention of
    52 KB (8,442 words) - 10:31, 27 June 2023
  • paragraph 2, letter i and 83 of the Regulation; article 166, paragraph 7, of the Code). The Guarantor, pursuant to articles 58, par. 2, lit. i) and 83 of the
    100 KB (16,086 words) - 17:05, 8 February 2023
  • art. 83, par. 2, of the Regulation; In the present case, the following are relevant: 1) the seriousness of the violations (Article 83, paragraph 2, letter
    90 KB (14,621 words) - 09:55, 7 December 2022
  • indicated in art. 83, par. 2, of the Regulations; In the case in question, the following are relevant: 1) the seriousness of the violation (Article 83, paragraph
    22 KB (3,423 words) - 14:22, 2 March 2022
  • measures, thereby violating Article 32 GDPR and the principle of accountability under Article 5(2) GDPR. In light of Article 83 GDPR and taking all the above
    6 KB (661 words) - 09:16, 14 February 2024
  • AEPD (Spain) - EXP202104896 (category Article 9(2) GDPR)
    -9.2 of the GDPR, in accordance with article 83.5.a) of the GDPR and article 72.1.e) of the LOPDGDD. “ "For the purposes specified in the art. 64.2 b)
    103 KB (17,238 words) - 13:27, 3 April 2023
  • carried out on the basis of Article 6(1)(b) GDPR, as well as to fulfill a legal obligation pursuant to Article 6(1)(c) GDPR related to public entities’
    31 KB (4,945 words) - 16:11, 20 April 2022
  • APD/GBA (Belgium) - 55/2021 (category Article 13(1)(b) GDPR)
    application of Article 17.3.b, the complainant cannot invokea reason provided for in article 17.1 or 17.2 for requesting the erasure of data concerning him.b) The
    81 KB (13,211 words) - 16:59, 12 December 2023
  • Datatilsynet (Norway) - 21/03126 (category Article 58(2)(i) GDPR)
    currently pending. Pursuant to Article 58(2)(i) GDPR and Article 83(4)(a) GDPR, the DPA imposed an administrative fine of €220,337 (NOK 2 500 000) against Argon
    133 KB (19,309 words) - 05:16, 24 March 2023
  • Persónuvernd (Island) - 2020061844 (category Article 32(1)(b) GDPR)
    designed programming. b. Subjective position According to number 2 Paragraph 1 Article 47 Act no. 90/2018, cf. point b, paragraph 2 Article 83 of Regulation (EU)
    87 KB (14,501 words) - 09:37, 19 July 2023
  • UODO (Poland) - DKN.5130.2215.2020 (category Article 32(2) GDPR)
    out in Art. 83 sec. 2 lit. c of the Regulation 2016/679. 2. The way in which the supervisory authority learned about the breach (Article 83 (2) (h) of Regulation
    110 KB (17,650 words) - 12:27, 29 April 2022
  • UODO (Poland) - DKN.5131.8.2022 (category Article 5(2) GDPR)
    the accountability principle referred to in Article 5(2) GDPR. Using its powers under Article 58(2)(i) GDPR and taking into account the gravity and duration
    48 KB (7,609 words) - 12:24, 23 November 2022
  • AEPD (Spain) - EXP202202960 (category Article 13 GDPR)
    violation of Article 35 of the GDPR, Article 32 of the GDPR and Article 13 of the GDPR, typified in Articles 83.5 of the RGPD and Article 83.4 of the RGPD
    149 KB (22,597 words) - 12:34, 3 April 2024
  • anonymized. Therefore, the DPA found a violation of Article 5(1)(a), (b), (c), and (e) and Article 12(1) GDPR. For the reasons above, the DPA imposed a fine
    122 KB (19,640 words) - 08:16, 3 August 2023
  • Datatilsynet (Norway) - 21/02293 (category Article 58(2) GDPR)
    calculating the fee, the elements in point 7.2 above must be weighted, cf. article 83 no. 2. In accordance with Article 83 no. 1, the infringement fee must be effective
    39 KB (5,691 words) - 08:12, 14 September 2022
  • Datatilsynet (Norway) - 20/03500 (category Article 5(2) GDPR)
    breaching Article 32(1)(b) GDPR and Article 32(1)(d), cf. Article 5(1)(f) GDPR. For this, the DPA fined the Parliament about €196,400 (NOK 2 million).
    32 KB (4,520 words) - 12:01, 28 June 2022
  • AEPD (Spain) - PS-00587-2021 (category Article 5(2) GDPR)
    to violation of article 5.1.f) of the GDPR. VII Classification of the violation of article 5.1.f) of the RGPD Article 83.5 of the GDPR provides the following:
    79 KB (12,131 words) - 15:30, 17 January 2024
  • Persónuvernd (Iceland) - 2020010355 (category Article 5(1)(f) GDPR)
    failed to comply with the provisions of Article 32(1)(b) GDPR, Article 32(1)(d) GDPR and Article 5(1)(f) GDPR. Furthermore, InfoMentor did not ensure sufficient
    44 KB (7,217 words) - 10:04, 12 May 2021
  • UODO (Poland) - DOKE.561.1.2023 (category Article 58(1)(a) GDPR)
    This is confirmed by the wording of Art. 83 sec. 2 lit. k). Other aggravating or mitigating factors (Article 83(2)(k) of Regulation 2016/679). The President
    45 KB (7,312 words) - 21:50, 8 August 2023
  • Datainspektionen - DI-2018-9274 (category Article 5(1)(b) GDPR)
    May 2018. 2.2 Follow-up of complaints 2 2.2.1 What has emerged during the proceedings During a control search on 8 June 2018 of complaint 2, the Data Inspectorate
    96 KB (12,267 words) - 11:43, 7 April 2022
  • breach of Article 5(1)(a), Article 5(1)(d), Article 5(2), Article 6 GDPR and 129 of the Code. The data controller also breached Article 12(2), Article 15 GDPR
    61 KB (9,720 words) - 22:42, 22 November 2022
  • integrate different corporate systems and procedures (Article 83, paragraph 2, letter b), of the Regulation); 2. the timely adoption of corrective measures, some
    74 KB (12,028 words) - 14:45, 8 March 2023
  • UODO (Poland) - DKN.5130.2559.2020 (category Article 5(2) GDPR)
    provisions of Article 5(1)(f) GDPR, Article 5(2) GDPR, Article 24(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR by: (a) failing
    62 KB (9,906 words) - 09:02, 11 October 2022
  • APD/GBA (Belgium) - 34/2020 (category Article 5(1)(b) GDPR)
    GDPR and Article 66.2 WOG); and • compliance with the transparency obligations (Article 12 GDPR) and the te provide information (Article 13 GDPR). Page
    82 KB (13,250 words) - 16:57, 12 December 2023
  • AEPD (Spain) - PS/00131/2020 (category Article 13 GDPR)
    provisions of article 13 of the RGPD. The RGPD, without prejudice to the provisions of its article 83, contemplates in its article Article 77 the possibility
    45 KB (6,923 words) - 08:41, 16 June 2021
  • HDPA (Greece) - 12/2021 (category Article 83(2) GDPR)
    the processing of personal data in accordance with art. 4 item 2 of the GCC. 2. Article 5 of the GPA sets out the processing principles governing processing
    18 KB (2,578 words) - 09:51, 12 May 2021
  • the dara subject's objection to be further contacted. Article 5(2), Article 24, and Article 25 GDPR for failing to implement suitable organisational measures
    87 KB (13,867 words) - 13:11, 28 September 2023
  • AEPD (Spain) - E/12707/2022 (category Article 5(1)(f) GDPR)
    for violating articles 6.1 and 32.1 of the RGPD, typified in article 83.5. a) and article 83.4.a) of the aforementioned RGPD. The aforementioned Proposal
    35 KB (5,522 words) - 14:57, 19 October 2023
  • subject was unlawful, violating Article 12 in connection with Article 17. The DPA held that, with reference to Recital 148 GDPR, the infringement cannot be
    63 KB (10,108 words) - 14:38, 25 October 2022
  • concluded that the controller breached Article 5 GDPR, Article 6 GDPR and Article 9 GDPR and Articles 2-ter as well as 2-septies (8) of the Code in the text
    51 KB (8,159 words) - 00:03, 18 January 2023
  • procedure (Article 83, paragraph 2, letter c), of the Regulation); 3. the absence of previous relevant violations committed by Ediscom (Article 83, paragraph
    169 KB (27,985 words) - 14:51, 25 April 2023
  • IMY (Sweden) - DI-2021-10488 (category Article 58(2)(b) GDPR)
    in violation of Article 12(3) of the GDPR. Choice of corrective measure It follows from Article 58(2)(i) and Article 83(2) of the GDPR that the IMY has
    18 KB (2,020 words) - 12:13, 12 October 2022
  • NAIH (Hungary) - NAIH-5802-9/2022. (category Article 5(1)(b) GDPR)
    category of higher fines according to Article 83 (5) point a) of the General Data Protection Regulation [GDPR Article 83 (2) point a) ], based on this, the maximum
    120 KB (19,907 words) - 10:48, 9 November 2022
  • (EU) No Article 5 (1) (a) and (b), Article 6 (1), Article 6 (4) Article 12 (1), Article 13, Article 21 (1) and (2), Article 24 (1), Article 25 Article 1 (1)
    147 KB (23,028 words) - 13:36, 28 February 2023
  • AEPD (Spain) - PS/00078/2021 (category Article 5(1)(c) GDPR)
    criteria established in the section 2 of the aforementioned article. 2. In accordance with the provisions of article 83.2.k) of Regulation (EU) 2016/679, also
    118 KB (19,187 words) - 17:08, 9 March 2022
  • WSA Warsaw (Poland) - II SA/Wa 310/20 (category Article 83(2) GDPR)
    surveillance, (2) breach of Article 5(1)(a), Article 5(1)(f), Article 5(2), Article 28(1), (3) and (10), Article 29, Article 83(1), (2), (3) and (5) in
    56 KB (8,906 words) - 14:16, 20 September 2021
  • AEPD (Spain) - EXP202305587 (category Article 5(1)(f) GDPR)
    the alleged violation of Article 5.1.f) of the RGPD and Article 32 of the RGPD, typified in Article 83.5 of the RGPD and Article 83.4 of the RGPD. C/ Jorge
    285 KB (44,507 words) - 11:21, 30 April 2024
  • AEPD (Spain) - EXP202205206 (category Article 5(1)(f) GDPR)
    alleged violation of Article 5.1.f) of the RGPD and Article 32 of the GDPR, typified in Article 83.5 of the GDPR and Article 83.4 of the GDPR. C/ Jorge Juan
    263 KB (41,516 words) - 09:29, 24 April 2024
  • the GDPR and the DPA. They are obliged by Article 5(2) to adhere to the data processing principles set out in Article 5(1) of the GDPR. Article 5(2) makes
    77 KB (9,347 words) - 07:39, 13 October 2022
  • these reasons, the DPA found violations of Article 5(1)(c) and (e) and Article 32(1)(b) and (d) and 32(2) GDPR, imposing a fine of €240,000. Share your comments
    63 KB (10,048 words) - 09:42, 2 August 2023
  • AEPD (Spain) - EXP202308002 (category Article 58(1) GDPR)
    UPMOBILE SOLUTIONS, S.L., with NIF B02682276, for a violation of Article 58.1 of the GDPR, typified in Article 83.5 of the GDPR, a fine of 500.00 euros (FIVE
    18 KB (2,653 words) - 14:03, 21 February 2024
  • the Regulation. Article 58(2)(i) and Article 83(3) of the Regulation and Article 166(2) of the Code. 4. CORRECTIVE MEASURES Article 58(2) provides the Garante
    134 KB (21,856 words) - 05:16, 25 May 2022
  • LG München - 31 O 16606/20 (category Article 5(1)(f) GDPR)
    pursuant to Article 82(1) GDPR, because controller violated Article 32(1) GDPR. The Court upheld the appeal and ordered the controller to pay € 2,500, - as
    25 KB (4,028 words) - 07:10, 8 February 2022
  • AEPD (Spain) - EXP202205850 (category Article 5(1)(c) GDPR)
    claimed party, for the alleged infringement of Article 5.1.c) of the GDPR, typified in Article 83.4 of the GDPR. Once the Initiation Agreement was notified
    29 KB (4,590 words) - 15:06, 19 April 2023
  • BVwG - W292 2267784-1 (category Article 56(1) GDPR)
    December 18, 2023 standard B-VG Art 130 Paragraph 1 Z1 B-VG Art 133 Paragraph 4 GDPR Art4 GDPR Art51 GDPR Art56 GDPR Art60 GDPR Art65 GDPR Art77 VwGVG §28 Paragraph
    67 KB (10,619 words) - 10:40, 22 January 2024
  • and (1)(e) of Article 6 GDPR. The violation of Article 2-ter of the Code is a direct consequence of the violation of Articles 5 and 6 GDPR. Finally, the
    49 KB (7,883 words) - 15:12, 13 July 2022
  • 58, par. 2, lett. I and 83 of the Regulation; art. 166, paragraph 7, of the Code). The Guarantor, pursuant to art. 58, par. 2, lett. i) and 83 of the Regulations
    64 KB (10,464 words) - 08:22, 14 October 2021
  • processing (Article 4, opening paragraph 7, GDPR). and that the AP is the competent supervisory authority (Article 56, first paragraph, GDPR). 5.2 Obligation
    55 KB (8,007 words) - 09:50, 24 January 2024
  • Articles 32 to 36 GDPR, including those regarding the notification of personal data breaches. In particular, pursuant to Article 33(2) GDPR in the event of
    52 KB (8,196 words) - 15:46, 27 March 2024
  • NAIH (Hungary) - NAIH-3734-15/2023 (category Article 38(2) GDPR)
    legislation (30) Based on Article 2 (1) of the GDPR, the GDPR must be applied to the data processing in this case. (31) Recital (47) GDPR: The data controller
    48 KB (7,721 words) - 11:09, 10 January 2024
  • IMY (Sweden) - DI-2021-4664 (category Article 58(2)(b) GDPR)
    data in breach of Article 32(1) of the GDPR. Choice of corrective measure It follows from Article 58(2)(i) and Article 83(2) of the GDPR that the IMY has
    21 KB (2,284 words) - 14:03, 9 November 2022
  • AEPD (Spain) - PS/00120/2021 (category Article 83(5)(b) GDPR) (section On Article 25 GDPR)
    violation of Article 5.1.c) of the GDPR, Article 6 of the GDPR, Article 9 of the GDPR, Article 12 of the GDPR, Article 35 of the RGPD, Article 13 of the RGPD
    337 KB (50,591 words) - 15:29, 5 August 2021
  • within the foreseen deadlines, under Article 12(1) GDPR, Article 12(2) GDPR, Article 12(3) GDPR and Article 12(4) GDPR. The DPA further stated that regarding
    42 KB (6,583 words) - 10:13, 13 October 2023
  • consider the factors identified above under Articles 83(2)(c), 83(2)(e), and 83(2)(f) of the GDPR mitigating. To account for the action taken by the HSE
    142 KB (23,134 words) - 15:51, 19 July 2021
  • NAIH (Hungary) - NAIH-7058-5/2022 (category Article 7(2) GDPR)
    unlawful. The processing violated Article 7(2) GDPR, Article 7(4) GDPR and Article 6(1)(a) GDPR. The controller was fined 2,000,000 HUF (approx. €5,080). In
    66 KB (10,499 words) - 08:55, 10 February 2023
  • Persónuvernd (Iceland) - 2020010611 (category Article 5(1)(a) GDPR)
    number when purchasing tickets in violation of Article 5(1) GDPR, Article 5(2) GDPR and Article 6 GDPR. A data subject issued a complaint with the Icelandic
    37 KB (6,136 words) - 16:05, 30 March 2022
  • Articles 17 and 6(1) GDPR. Pursuant to its powers under Article 58(2)(i) GDPR, and in accordance with Article 83 GDPR, it imposed an administrative fine of €10
    31 KB (4,943 words) - 15:30, 3 March 2023
  • AEPD (Spain) - PS-00393-2022 (category Article 13 GDPR)
    criteria established in the article 83.2 of the GDPR: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 11/18 "2. Administrative fines will be
    54 KB (8,094 words) - 10:51, 10 January 2024
  • AEPD (Spain) - PS/00267/2020 (category Article 6(1) GDPR)
    Accordingly, the Spanish DPA fined Amazon Road €2,000,000 for a violation of Article 6(1) GDPR, Article 10 GDPR and Article 10 LOPDGDD for requesting criminal record
    208 KB (33,882 words) - 14:25, 24 November 2022
  • AEPD (Spain) - PS/00413/2021 (category Article 5(1)(c) GDPR)
    letter k) of article 83.2 of the GDPR, the LOPDGDD, in its article Article 76, "Sanctions and corrective measures", establishes that: "2. In accordance
    69 KB (11,301 words) - 10:49, 23 March 2023
  • APDCAT (Catalonia) - PS 28/2021 (category Article 5(1)(f) GDPR)
    infringement provided for in Article 83.5.b) in relation to Article 13; i another offense under Article 83.4 (a) in relation to Article 25; all of them from Regulation
    42 KB (6,526 words) - 14:26, 24 November 2022
  • DSB (Austria) - 2021-0.586.257 (category Article 4(2) GDPR)
    website controller qualifies as controller (Article 4(7) GDPR) and Google LLC as processor (Article 4(8) GDPR) for data processing in connection with Google
    108 KB (17,097 words) - 13:52, 12 May 2023
  • the type of data) are: Article 9(2)(h) GDPR (necessary for the purposes of preventive or occupational medicine); Article 9(2)(i) GDPR (for reasons of public
    128 KB (20,856 words) - 12:32, 14 March 2023
  • of integrity outlined in Article 5(1)(f) GDPR and Article 32 GDPR. Moreover, the DPA found that relying on Article 6(1)(f) GDPR as legal basis for processing
    42 KB (6,554 words) - 12:35, 27 March 2024
  • IMY (Sweden) - DI-2019-6523 (category Article 13(1)(c) GDPR)
    contract (Article 6(1)(b) GDPR) and legitimate interests (Article 6(1)(f) GDPR), the DPA found that the controller violated Article 13(1)(c) GDPR by indicating
    17 KB (1,990 words) - 09:02, 8 May 2024
  • Persónuvernd (Iceland) - 2020092288 (category Article 5 GDPR)
    paragraph. Article 8, paragraphs 1 and 3 Article 9, Article 10, Article 17, Article 24 and Paragraph 3 Article 25 and the first paragraph. Article 27 Act no
    125 KB (20,768 words) - 13:06, 22 December 2021
  • CPDP (Bulgaria) - PPN- 01-197/2022 (category Article 5(1)(b) GDPR)
    §. 2, b. "i" of Regulation (EU) 2016/679, for violation of the provisions of Art. 5, § 1, b. "a" and b. "b", in relation to art. 6, § 1 of the GDPR, in
    36 KB (5,922 words) - 08:02, 18 April 2024
  • ICO (UK) - Cabinet Office (category Article 5(1)(f) GDPR)
    amount of the monetary penalty. Article 83(2) GDPR 56. The Commissioner has considered the factors set out in Article 83(2) GDPR in deciding whether to impose
    79 KB (10,566 words) - 10:48, 7 December 2021
  • UODO (Poland) - DKN. 5131.27.2022 (category Article 33(1) GDPR)
    art. 58 sec. 2 lit. e) and i), Art. 83 sec. 1 and sec. 2, art. 83 sec. 4 lit. a) in connection with Art. 33 paragraph 1 and art. 34 sec. 1, 2 and 4 of Regulation
    80 KB (13,127 words) - 07:57, 14 September 2022
  • Datainspektionen - DI-2019-7024 (category Article 5(1)(f) GDPR)
    specific way and within a specific period. Of point (i) of Article 58 (2) and Article 83 (2) of the Data Protection Regulation it appears that the Data
    70 KB (11,103 words) - 11:43, 7 April 2022
  • controller in violation of Article 5(1)(a) GDPR, Article 6 GDPR, and Article 13 GDPR. To begin with, in terms of Article 6 GDPR, the DPA rejected the controller's
    31 KB (4,724 words) - 11:01, 31 January 2024
  • issued a fine to the controller of €40,000 pursuant to Article 83(4) GDPR and Article 83(5) GDPR. Share your comments here! Share blogs or news articles
    6 KB (599 words) - 16:13, 5 December 2023
  • UODO (Poland) - DKN.5131.42.2022 (category Article 34(2) GDPR)
    court decisions. The DPA found a breach of Article 33 GDPR and Article 34(1) and (2) GDPR resulting in a fine of €2,324. Share your comments here! Share blogs
    95 KB (15,337 words) - 16:38, 19 March 2024
  • NAIH (Hungary) - NAIH-924-10/2021 (category Article 25(2) GDPR)
    information respect Article 57 (1) (a) and Article 58 (2) (b) of the General Data Protection Regulation and d), Article 83 (1), (2) and (5), and Infotv
    56 KB (8,760 words) - 13:16, 25 August 2021
  • AEPD (Spain) - PS/00050/2021 (category Article 35 GDPR)
    persons of article 9.1), indicates article 9.2 b) and 9.4) 2. Section 1 shall not apply when one of the circumstances occurs following: “B) the treatment
    81 KB (13,036 words) - 14:28, 24 November 2022
  • AEPD (Spain) - PS/00016/2022 (category Article 83(2) GDPR)
    of article 15 of the GDPR. V Classification of the infringement of article 15 of the GDPR The aforementioned infringement of article 15 of the GDPR supposes
    62 KB (9,829 words) - 14:09, 14 March 2023
  • NAIH (Hungary) - NAIH-13-10/2022 (category Article 5(1)(b) GDPR)
    Data Protection Regulation, Article 5 (1) points a) and b), Article 5 (2) and Article 15 (3). V.2. The Authority ex officio examined whether a data protection
    51 KB (8,202 words) - 14:49, 12 October 2022
  • ICO (UK) - Tuckers Solicitors LLP (category Article 5(1)(f) GDPR)
    By Article 58(2)(d) of the GDPR, the Commissioner has the power to notify controllers of alleged infringementof GDPR. By Article 58(2)(i) he has the power
    87 KB (10,588 words) - 14:32, 16 March 2022
  • controller. Pursuant to Article 5(2) GDPR, it was the controller's responsibility to make sure that measures were adopted to ensure GDPR compliance, which was
    133 KB (21,637 words) - 07:03, 7 March 2023
  • AEPD (Spain) - PS/00161/2021 (category Article 17(1) GDPR)
    on the part of the claimed entity, (section b). The balance of the circumstances contemplated in article 83.2 of the RGPD, with Regarding the offense committed
    24 KB (3,756 words) - 11:38, 14 September 2021
  • health (Article 83, paragraph 2, letter a) of the Regulation); b) the economic, organizational and professional conditions of the offender (Article 83, paragraph
    19 KB (2,912 words) - 12:00, 26 July 2023
  • pursuant to Article 77 GDPR. The DPA did not consider the processor’s actions in determining that the controller violated Article 5(1)(f) and Article 32 GDPR
    62 KB (9,678 words) - 10:45, 13 March 2024
  • ICO (UK) - HIV Scotland (category Article 32(2) GDPR)
    under the GDPR. 14. By Article 57(1) of the GDPR, it is the Commissioner'task to monitor and enforce the application of the GDPR. 15. By Article 58(2)(d)of
    55 KB (6,916 words) - 07:27, 26 October 2021
  • AEPD (Spain) - PS/00448/2021 (category Article 5(1)(c) GDPR)
    infringement of Article 5.1.c) of the RGPD, typified in Article 83.5 of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 2/6 FIFTH: Once
    16 KB (2,431 words) - 11:46, 25 January 2022
  • Lastly, the DPA found a violation of Article 5(2) GDPR, Article 24(1) GDPR, Article 24(2) GDPR and Article 25 GDPR for failing to take adequate measures
    44 KB (6,773 words) - 08:38, 29 November 2023
  • Commissioner (Cyprus) - 11.17.001.008.229 (category Article 5(2) GDPR)
    violation of Article 5(2) GPDR since the controller failed to demonstrate compliance with Article 5(1) GDPR and a violation of Article 44 GDPR since the controller
    56 KB (8,616 words) - 15:31, 6 March 2024
  • on the part of the Company in the causation of the event (Article 83, paragraph 2, letter b) of the Regulations); - the event occurred in the period of
    45 KB (7,200 words) - 08:46, 28 July 2021
  • Persónuvernd - 2020010428 (category Article 5(1)(f) GDPR)
    organization. b. A subjective attitude According to paragraph 2. Paragraph 1 Article 47 Act no. 90/2018, cf. paragraph 2 (b) Article 83 of Regulation (EU)
    47 KB (7,369 words) - 16:37, 19 March 2020
  • the processing was lawful within the meaning of Article 5(1)(a) GDPR. According to Article 88 GDPR, the GDPR is applicable without prejudice to more protective
    123 KB (20,446 words) - 14:39, 13 June 2023
  • AEPD (Spain) - PS/00372/2021 (category Article 83(5) GDPR)
    implementation of article 7.2.k) of this organic law’. VII Sanction for the infringement of Article 12 GDPR Without prejudice to Article 83 of the GDPR, Article 58 (2)
    81 KB (13,337 words) - 14:55, 22 February 2023
  • the company. Lastly, The DPA found a breach of Article 5(1)(a) GDPR and Article 12 GDPR and Article 13 GDPR regarding the sharing of patient clinical data
    96 KB (15,258 words) - 16:36, 19 March 2024
  • information stated in Article 13 GDPR. The data subject didn’t receive an answer within the time limits set in Article 12(3) GDPR. The data subject filed
    27 KB (4,317 words) - 08:06, 20 October 2022
  • DPC (Ireland) - 05/SIU/2018 (category Article 2 GDPR)
    here is covered by the GDPR. For further information and relevant legal provisions, please see Article 2(2)(d) GDPR, Articles 1 and 2 LED, and Part 5 and
    13 KB (1,414 words) - 15:11, 14 March 2023
  • NAIH (Hungary) - NAIH-6484-2-2022 (category Article 12(3) GDPR)
    redress. Therefore, the DPA declared an infringement of Article 12(3) GDPR and Article 12(4) GDPR. Additionally, the DPA held that the controller, whether
    66 KB (10,501 words) - 14:46, 12 October 2022
  • transparency from Article 5(1)(a) GDPR. Therefore, the controller violated the principle of accountability provided by Article 5(2) and 24 GDPR for the failure
    56 KB (8,922 words) - 10:20, 16 November 2022
  • defined in Article 4(15) GDPR. For the reasons stated above, the DPA found the controller in violation of Article 5 GDPR, Article 9 GDPR and Article 32 GDPR
    105 KB (17,072 words) - 13:27, 28 February 2024
  • point 2 of this decision, (Article 58, paragraph 2, letter d) of the Regulation); apply a pecuniary administrative sanction pursuant to art. 83 of the
    31 KB (4,916 words) - 10:32, 26 October 2022
  • DSB (Austria) - 2020-0.191.240 (category Article 4(1) GDPR)
    has a wider scope of applicability than Article 8 GRC (the latter only protects natural persons). As Article 16(2) TFEU leaves it to member states to grant
    66 KB (10,546 words) - 13:50, 12 May 2023
  • UODO (Poland) - DKE.561.20.2022 (category Article 58(1)(a) GDPR)
    pursuant to Article 83(5)(e) GDPR. Second, the DPA considered the non-compliance with the summons to breach breach of Article 58(1)(a) and (e) GDPR. The delay
    43 KB (6,878 words) - 10:55, 10 January 2024
  • CNIL (France) - SAN-2022-017 (category Article 21(2) GDPR)
    proportionate, and dissuasive per Article 83(1) GDPR, and so the EDPB adopted a binding resolution in accordance with Article 65 GDPR to settle the dispute. The
    59 KB (8,323 words) - 11:51, 31 August 2022
  • fairness and transparency under Article 5(1)(a) GDPR, as well as the data subject’s right to information under Articles 12 and 13 GDPR, and issued a fine of €10
    41 KB (6,671 words) - 16:56, 23 March 2022
  • further data dissemination on the controller for violating Article 5 GDPR and Article 12 GDPR. The case involves a complaint filed against Edizioni Proposta
    31 KB (4,659 words) - 15:22, 12 December 2023
  • NAIH (Hungary) - NAIH-3561-4/2022 (category Article 58(2)(j) GDPR)
    controller’s status as “data controller” was correct under Article 4(7) GDPR. Article 44 GDPR requires that the transfer of personal data to a third country
    13 KB (1,677 words) - 09:39, 14 November 2022
  • Regulation (Article 83, paragraph 2, letter c); d) the relevant organizational, economic and professional conditions of the offender (Article 83, paragraph
    64 KB (10,570 words) - 09:36, 9 August 2023
  • AEPD (Spain) - PS/00389/2021 (category Article 5(1)(c) GDPR)
    level of damages suffered fried; (art. 83.2 a) RGPD). - the intent or negligence in the infringement; (art. 83.2 b) RGPD), by not doing have adopted the
    16 KB (2,427 words) - 14:33, 1 February 2022
  • effective, proportionate and dissuasive" (Article 83, paragraph 1), the elements indicated in art. 83, par. 2, of the Regulation. Specifically, which aggravating
    43 KB (6,766 words) - 14:59, 2 May 2023
  • EFTA Court - Joined Cases E-11/19 and E-12/19 (category Article 58(2)(e) GDPR)
    been disclosed pursuant to Article 17(2) and Article 19; … – 8 – (i) to impose an administrative fine pursuant to Article 83, in addition to, or instead
    59 KB (8,242 words) - 10:47, 17 March 2021
  • UODO (Poland) - DKN.5131.31.2022 (category Article 5(2) GDPR)
    400 for infringements of Articles 5(1)(f) and 5(2) GDPR as well as Article 25(1) and Article 32(1) GDPR. First, the controller did not ensure adequate security
    71 KB (11,306 words) - 10:51, 22 January 2024
  • UODO (Poland) - DKN.5130.3114.2020 (category Article 83(2) GDPR)
    circumstances indicated in Article 83(2) of Regulation 2016/679, namely: 1. the unintentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679)
    105 KB (16,833 words) - 13:48, 15 November 2021
  • DVI (Latvia) - SIA “DEPO DIY” (category Article 83(5) GDPR)
    into account to determine a lower penalty. [15.2.] In accordance with Article 83, paragraph 2, subparagraph "b" of the Data Regulation, it is necessary to
    76 KB (12,073 words) - 12:49, 25 October 2022
  • (art. 83, par. 2, letter b) of the Regulation); 3) as an aggravating factor the degree of responsibility of the data controller (art. 83, par. 2, letter
    208 KB (33,932 words) - 11:40, 17 April 2024
  • Guidelines, and therefore article 75 of the Italian Code, were also violated. With the power conferred by Article 58(2)(i) and 83 GDPR, the Italian DPA imposed
    54 KB (8,636 words) - 08:47, 28 July 2021
  • Garante found a violation of the processing principle under Article 5(1)(f) GDPR and Article 32 GDPR related to the security of processing which was compromised
    129 KB (20,678 words) - 08:25, 8 May 2024
  • HDPA (Greece) - 13/2024 (category Article 83 GDPR)
    occurred for identification purposes, the controller cited Article 9(2)(b), (c), (g) and (j) GDPR as its legal basis. In a later communication, it clarified
    12 KB (1,511 words) - 16:01, 10 April 2024
  • relating to health (Article 83, paragraph 2, letter g) of the Regulation); 19 data subjects are involved (Article 83, paragraph 2, letter a) of the Regulation);
    59 KB (9,485 words) - 13:30, 29 March 2023
  • AEPD (Spain) - PS/00427/2020 (category Article 30 GDPR)
    Spanish city council for infringing Article 30 GDPR by not maintaining a record of its processing activities, and Article 31 of the Spanish Data Protection
    35 KB (5,459 words) - 12:40, 7 July 2021
  • AEPD (Spain) - PS/00377/2021 (category Article 5(1)(c) GDPR)
    sedeagpd.gob.es 2/9 alleged violation of Article 5.1.c) of the RGPD, typified in Article 83.5 of the GDPR. FIFTH: In accordance with article 73.1 of the LPCAP
    26 KB (3,949 words) - 12:44, 20 October 2021
  • IMY (Sweden) - DI-2021-10263 (category Article 5(1)(a) GDPR)
    comply with Article 5(2) GDPR. The DPA determined that the controller violated Article 15 GDPR. The DPA stated that Article 15(1)(c) GDPR must be interpreted
    20 KB (2,207 words) - 13:45, 9 January 2023
  • APD/GBA (Belgium) - 46/2022 (category Article 5(1)(a) GDPR)
    responsibility – article 5.2. of the GDPR) and to implement all the measures necessary for this purpose (Article 24 of the GDPR). 26. Pursuant to Article 5.1.a)
    86 KB (12,864 words) - 06:37, 23 February 2023
  • AEPD (Spain) - EXP202306257 (category Article 44 GDPR)
    EDREAMS, S.L. was ordered for a violation of the Article 44 of the GDPR, typified in Article 83.5 of the GDPR, adapt the activity of data processing carried
    83 KB (12,999 words) - 15:30, 6 March 2024
  • NAIH (Hungary) - NAIH-2857-20/2021 (category Article 83(2) GDPR)
    fines imposed pursuant to this Article are effective in each case, be proportionate and dissuasive. According to Article 83 (2) of the General Data Protection
    79 KB (12,495 words) - 11:03, 21 January 2022
  • art. 83, par. 2, of the Regulation. In the present case, the following are relevant: 1) the seriousness of the violations (article 83, paragraph 2, letter
    91 KB (14,709 words) - 13:02, 14 December 2022
  • HDPA (Greece) - 6/2024 (category Article 5(2) GDPR)
    provision of article 58 par. 2 sec. i of the GDPR, effective, proportionate and dissuasive administrative money fine according to article 83 of the GDPR, both
    19 KB (3,000 words) - 13:44, 6 March 2024
  • art. 83, par. 2, of the Regulation. In the present case, the following are relevant: 1) the seriousness of the violation (Article 83, paragraph 2, letter
    80 KB (12,843 words) - 06:02, 26 April 2023
  • NAIH (Hungary) - NAIH-5114-35/2022 (category Article 58(2)(f) GDPR)
    legitimate interest. Based on Article 2 (1) of the GDPR, the GDPR must be applied to the data management in this case. GDPR Article 4, point 1: "personal data":
    146 KB (22,679 words) - 15:52, 3 May 2023
  • APDCAT (Catalonia) - PS 57/2023 (category Article 5(1)(f) GDPR)
    for article 77.1 of the LOPDGDD, results from the application of the general sanctioning regime provided for in article 83 of the RGPD. Article 83.5 of
    52 KB (7,751 words) - 14:16, 17 April 2024
  • Datatilsynet (Norway) - 20/01893 (category Article 9(2) GDPR)
    receiving disability pension, in breach of Article 5(1)(c), Article 5(1)(e), Article 6(1), and Article 9(2) GDPR. The Norwegian Public Service Pension Fund
    40 KB (5,895 words) - 15:30, 12 January 2022
  • AEPD (Spain) - EXP202207199 (category Article 6 GDPR)
    Agency RESOLVES: FIRST: IMPOSE B.B.B., with NIF ***NIF.1, for a violation of Article 6 of the RGPD, typified in Article 83.5 a) of the RGPD, a fine of €4
    23 KB (3,550 words) - 10:03, 18 October 2023
  • 58, par. 2, lett. I and 83 of the Regulation; art. 166, paragraph 7, of the Code). The Guarantor, pursuant to art. 58, par. 2, lett. i) and 83 of the Regulations
    90 KB (14,647 words) - 17:12, 8 November 2022
  • Therefore, the DPA fined the controller €1,000 under Article 58(2)(i) GDPR, Article 83(5) GDPR and Article 166 of the Italian Privacy Code. Share your comments
    21 KB (3,135 words) - 07:35, 4 October 2023
  • UODO (Poland) - DKN.5131.3.2021 (category Article 34(2) GDPR)
    art. 58 sec. 2 lit. e) and i), Art. 83 sec. 1 and sec. 2, art. 83 sec. 4 lit. a) in connection with Art. 33 paragraph 1 and art. 34 sec. 1, 2 and 4 of Regulation
    129 KB (20,850 words) - 12:13, 7 July 2021
  • UODO (Poland) - DKE.561.23.2020 (category Article 83(2) GDPR)
    2019 - until the date of this decision. 2. Intentional or unintentional nature of the breach (Article 83 (2) (b) of Regulation 2016/679). Due to the fact
    33 KB (5,262 words) - 13:02, 16 June 2021
  • ICO (UK) - Mermaids (category Article 32(2) GDPR)
    By Article 58(2)(d) of the GDPR the Commissioner has the power to notify controllers of alleged infringements of GDPR. By Article 58(2)(i) she has the
    58 KB (7,695 words) - 09:00, 28 July 2021
  • to Articles 114 and 157 of the Privacy Code. Pursuant to Article 58(2)(i) GDPR and 83 GDPR, the DPA imposed an administrative fine of €6,000.00, and an order
    41 KB (6,437 words) - 12:47, 8 February 2023
  • decision, subject to an administrative sanction from the Garante under Article 83(5)(e) GDPR if the order is not complied with. Although the decision textually
    23 KB (3,581 words) - 17:29, 9 March 2022
  • APDCAT (Catalonia) - PS 54/2021 (category Article 83(4)(a) GDPR)
    provided for in article 83.5.a), in relation to article 5.1.f); and, another infringement provided for in Article 83.4.a), in relation to Article 35; all of
    22 KB (3,269 words) - 17:08, 30 March 2022
  • IMY (Sweden) - DI-2020-10547 (category Article 58(2)(b) GDPR)
    personal data in violation of Article 6(1) of the GDPR. Choice of corrective measure Pursuant to Article 58(2)(i) and Article 83(2) IMY has the authority to
    37 KB (4,294 words) - 15:52, 25 October 2022
  • the Regulations and 2-ter, 2-sexies as well as 2-septies, paragraph 8 of the Code; ORDER pursuant to art. 58, par. 2, lett. i) and 83 of the Regulations
    34 KB (5,366 words) - 08:09, 20 October 2022
  • to Article 88 GDPR, which holds that it is permissible for national laws to provide a greater standard of protection than already given by the GDPR with
    37 KB (5,802 words) - 09:38, 16 June 2023
  • App IO" declared by PagoPA. Through the authority identified in Article 58(2)(f) GDPR, the Italian DPA imposed on PagoPA S.p.A the following limitations:
    54 KB (8,704 words) - 13:10, 23 June 2021
  • AEPD (Spain) - EXP202204501 (category Article 5(1)(f) GDPR)
    in the Article 83.4 of the GDPR. - Has violated the provisions of Article 37 of the RGPD, an offense classified in the Article 83.4 of the GDPR. SECOND:
    57 KB (8,604 words) - 15:40, 20 March 2024
  • right. This amounted to a violation of Article 5 (1)(a), Article 12, Article 13, Article 14 GDPR and Article 21 GDPR. Therefore, on the basis of all the elements
    52 KB (8,589 words) - 20:01, 16 February 2022
  • ISWEB violated Article 28(2) GDPR and Article 28(4) GDPR as a processor on behalf of the hospitals and Article 28(1) GDPR and Article 28(3) GDPR as controller
    99 KB (16,015 words) - 16:16, 1 June 2022
  • light of this, the DPA found that the processor violated Article 5(1)(e), (1)(f) and Article 32 GDPR. For these violations, the processor was fined €25,000
    43 KB (6,870 words) - 19:12, 28 May 2024
  • the GDPR. Would judge otherwiseindeed contradict :o the wording of Article L2.2 in conjunction with Article 2.f) of the ePrivacy Directive,o Article 8 of
    67 KB (10,544 words) - 09:24, 10 September 2021
  • AEPD (Spain) - EXP202405119 (category Article 58(1) GDPR)
    established in article 83.2 of the RGPD, and with the provisions of article 76 of the LOPDGDD, regarding section k) of the aforementioned article 83.2 RGPD. Also
    22 KB (3,169 words) - 14:26, 28 May 2024
  • Rb. Noord-Nederland - C/ 18/189406/HA ZA 19-6 (category Article 32(2) GDPR)
    content: [article quoted] [article quoted] [article quoted] [article quoted] [article quoted] [article quoted] [article quoted] [article quoted] [article quoted]
    105 KB (18,002 words) - 16:24, 10 March 2022
  • VSRS - VSRS Sodba IV Ips 2/2021 (category Article 83 GDPR)
    administrative fine under Article 83 of the GDPR. For violations of Article 6 of the GDPR, the fifth paragraph of Article 83 of the GDPR prescribes an administrative
    30 KB (4,982 words) - 14:27, 17 September 2021
  • APD/GBA (Belgium) - 71/2022 (category Article 5(2) GDPR)
    12(2) and 21(2), (4) GDPR. Consequently, the DPA held that the controller violated Article 5(1)(a), (c), (2), 6(1), 12(2) and 21(2), (4) GDPR and, therefore
    69 KB (10,468 words) - 07:37, 9 June 2022
  • AEPD (Spain) - PS/00509/2021 (category Article 32 GDPR)
    protection by its article 2.2, without prejudice to the provisions of the sections 3 and 4 of this article. In this sense, article 2.2.d) of Regulation
    80 KB (11,947 words) - 14:51, 4 October 2022
  • AEPD (Spain) - PS/00347/2020 (category Article 5(1)(c) GDPR)
    one claimed for the alleged infringement tion of article 5.1.f) of the RGPD, contemplated in article 83.5.a) of the aforementioned Regulation- ment. FIFTH:
    26 KB (4,015 words) - 10:20, 19 May 2021
  • controller twenty days to remedy to the situation, pursuant to Article 58(2)(c) and Article 58(2)(g) GDPR. Share your comments here! Share blogs or news articles
    23 KB (3,665 words) - 14:05, 4 April 2023
  • according to its faculties under Article 58(2)(a), Article 58(2)(b) and Article 58(2)(d), as well as Article 83(5) GDPR, Share your comments here! Share
    380 KB (62,114 words) - 15:20, 26 January 2022
  • Commissioner (Cyprus) - 11.17.001.009.048 (category Article 58(2)(b) GDPR)
    data under Article 9 GDPR, which can only be lawful if one of the exceptions of Article 9(2) GDPR apply. With respect to Article 9(2)(h) GDPR, the DPC held
    44 KB (7,042 words) - 13:53, 31 January 2024
  • legal basis under Article 6(1) GDPR and in violation of transparency obligations in the privacy policy under Article 5(1)(a) and 13 GDPR. The DPA in the
    246 KB (39,598 words) - 09:26, 24 April 2024
  • Italian DPA reprimanded a processor for having breached Article 5(1)(f) GDPR and Article 32 GDPR since, following a software update, the platform of a healthcare
    89 KB (14,492 words) - 12:52, 14 February 2024
  • Datatilsynet (Norway) - 20/01813 (category Article 5(2) GDPR)
    safety for the processing of personal data under Article 32 GDPR, Article 24, Article 5(1)(f) and Article 5(2), as well as § 26(1) of the Personal Data Act
    36 KB (5,150 words) - 17:58, 31 October 2021
  • in the data controller" (Article 6, paragraph 1, letter e ), 2 and 3, and art. 9, par. 2, lett. g), of the Regulations; art. 2-ter of the Code, in the text
    59 KB (9,359 words) - 08:38, 16 November 2022
  • consideration Article 9 GDPR, which establishes that data revealing a person’s sex life are special categories of personal data, and Article 85 GDPR, which establishes
    18 KB (2,622 words) - 13:18, 27 April 2022
  • paragraph 2, letter i), and 83 of the Regulation; art. 166, paragraph 7, of the Code). The Guarantor, pursuant to articles 58, par. 2, lit. i), and 83 of the
    134 KB (21,837 words) - 11:37, 13 June 2023
  • Datatilsynet (Norway) - 20/02376 (category Article 32(2) GDPR)
    in place of the other sanctions referred to in Article 58 (2) (a) to (h) and (j), cf. Article 83 No. 2 first sentence. According to Proposition 148 of
    38 KB (5,620 words) - 07:40, 4 October 2021
  • APD/GBA (Belgium) - 47/2022 (category Article 5(1)(b) GDPR) (section 2. Legal basis)
    the meaning of Article 9 of the GDPR must indeed be based on Article 9.2 of the GDPR, read in conjunction with Article 6.1 of the GDPR. 24 This has been
    207 KB (31,357 words) - 14:21, 8 June 2022
  • APD/GBA (Belgium) - 31/2022 (category Article 5(1)(a) GDPR)
    of his personal data would be based 5. 1, a) GDPR, Article 6, Article 12.1 GDPR and Article 14.1 a) GDPR. 67. Moreover, a controller, in this case defendant
    84 KB (12,933 words) - 16:46, 12 December 2023
  • right to object. 2.2.2. With reference to the dispute referred to in point 2), the violation of the provisions of Articles 5, para. 1 and 2, art. 6, par.
    142 KB (23,307 words) - 09:37, 28 October 2021
View ( | ) (20 | 50 | 100 | 250 | 500)