Skip to main content
European Data Protection Board logo
Back Search Menu
Close menu

Main navigation

  • Home
  • Topics
  • Documents
  • Registers
  • Public consultations

Top navigation

  • About EDPB
  • News
  • Meetings
  • Contact
  • Guide for SMEs
EN

Select your language

  • BGбългарски
  • CSčeština
  • DAdansk
  • DEDeutsch
  • ELελληνικά
  • ESespañol
  • ETeesti
  • FIsuomi
  • FRfrançais
  • GAGaeilge
  • HRhrvatski
  • HUmagyar
  • ITitaliano
  • LTlietuvių
  • LVlatviešu
  • MTMalti
  • NLNederlands
  • PLpolski
  • PTportuguês
  • ROromână
  • SKslovenčina
  • SLslovenščina
  • SVsvenska
Close language switcher

Breadcrumb

  1. Home

Polish SA: administrative fine of EUR 4 500 for gastronomic entrepreneur for access hindering and failure to provide with the necessary information

Thu, 25/09/2025
Background information Date of final decision: 23 June 2025 National case Legal Reference(s): Article 31 (Co-operation with the supervisory authority) Decision: administrative fine Key words: administrative fine, Cooperation with the supervisory authority Summary of the Decision Origin of the case The case concerns a complaint to the President of the Personal Data Protection Office lodged by an individual in 2021 about irregularities in the processing of his or her personal data by an entrepreneur from Silesia voivodeship. That was the processing of the complainant’s biometric data by the
  • Read more about Polish SA: administrative fine of EUR 4 500 for gastronomic entrepreneur for access hindering and failure to provide with the necessary information

Polish SA: administrative fine of EUR 15 556 for University Children’s Clinical Hospital in Białystok for failing to implement appropriate technical and organisational measures

Thu, 25/09/2025
Background information Date of final decision: 17 June 2025 National case Legal Reference (s): Article 5 (Principles relating to processing of personal data), Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 32 (Security of processing) Decision: Administrative fine, Compliance order Key words: Administrative fine, Data protection by design and by default, Data security, Lawfulness of processing, Data subject rights Summary of the Decision Origin of the case The decision was issued in connection with a security incident which
  • Read more about Polish SA: administrative fine of EUR 15 556 for University Children’s Clinical Hospital in Białystok for failing to implement appropriate technical and organisational measures

Polish SA: administrative fine of 4 375 273 € for ING Bank Śląski S.A. for scanning customers’ identity cards without appropriate purpose analysis

Thu, 25/09/2025
Background information Date of final decision: 23 July 2025 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing) Decision: Administrative fine Key words: Administrative fine, Anti-Money Laundering, Data security, Lawfulness of processing, Data subject rights, Data protection by design and by default Summary of the Decision Origin of the case From 1 April 2019 to 23 September 2020, ING Bank Śląski (the Bank) scanned identity documents of customers and potential customers. It was not checked whether such actions
  • Read more about Polish SA: administrative fine of 4 375 273 € for ING Bank Śląski S.A. for scanning customers’ identity cards without appropriate purpose analysis

Polish SA: administrative fine of EUR 4 022 773 for McDonald’s Polska sp. z o.o. and EUR 43 680 for 24/7 Communication Sp. z o.o. for negligence in risk analysis and safeguards

Thu, 25/09/2025
Background information Date of final decision: 23 June 2025 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 28 (Processor), Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Article 38 (Position of the data protection officer) Decision: Administrative fine Key words: Administrative fine, Data processing agreement, Data security, Lawfulness of processing, Data subject rights
  • Read more about Polish SA: administrative fine of EUR 4 022 773 for McDonald’s Polska sp. z o.o. and EUR 43 680 for 24/7 Communication Sp. z o.o. for negligence in risk analysis and safeguards

Polish SA: administrative fine of EUR 1 170 for Social Welfare Centre and EUR 2 341 EUR for Mayor of Aleksandrów for ignoring the risk of ransomware attack

Thu, 25/09/2025
Background information Date of final decision: 03 June 2025 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 28 (Processor), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority) Decision: Administrative fine Key words: Administrative fine, Accountability, Data security, Lawfulness of processing, Data subject rights, Data protection by design and by default Summary of the
  • Read more about Polish SA: administrative fine of EUR 1 170 for Social Welfare Centre and EUR 2 341 EUR for Mayor of Aleksandrów for ignoring the risk of ransomware attack

Telemarketing: The Italian SA imposes fines of 3 million € on an energy company and € 850 000 on agencies involved

Thu, 25/09/2025
Background information Date of final decision: 10 April 2025 Cross-border case or national case: national case Controller: Acea Energia spa Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 7 (Conditions for consent), Article 13 (Information to be provided where personal data are collected from the data subject), Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 28 (Processor), Article 29 (Processing under the authority of the controller and processor)
  • Read more about Telemarketing: The Italian SA imposes fines of 3 million € on an energy company and € 850 000 on agencies involved

Biometrics for attendance recording. The Italian SA fines a high school

Tue, 16/09/2025
Background information Date of final decision: 10 July 2025 National case Controller: Magna PT S.p.A. Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 9 (Processing of special categories of personal data), Article 13 (Information to be provided where personal data are collected from the data subject) Decision: Administrative fine, Definitive ban on data processing Key words: Administrative fine, Principles relating to processing of personal data, Transparency, Retention time, Lawfulness of processing, Employment
  • Read more about Biometrics for attendance recording. The Italian SA fines a high school

Polish SA: administrative fine of EUR 7 800 for non-public health care centre in Pyskowice for failing to carry out appropriate risk analysis

Tue, 16/09/2025
Background information Date of final decision: 04 July 2025 National case Legal Reference (s): Article 5 (Principles relating to processing of personal data), Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 32 (Security of processing) Decision: Administrative fine Key words: Administrative fine, Data protection by design and by default, Data security, Lawfulness of processing, Data subject rights Summary of the Decision Origin of the case A doctor’s car was stolen while the doctor was seeing a patient during a home visit
  • Read more about Polish SA: administrative fine of EUR 7 800 for non-public health care centre in Pyskowice for failing to carry out appropriate risk analysis

Interplay between the DSA and the GDPR: EDPB adopts guidelines

Fri, 12/09/2025
Brussels, 12 September - During its September plenary meeting, the European Data Protection Board (EDPB) has adopted guidelines on the interplay between the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR). These are the first set of EDPB guidelines on the interplay between the GDPR and the EU’s recently adopted digital laws. The DSA aims to complement the rules of the GDPR to ensure the highest level of protection of fundamental rights in the digital space. Its main goal is to create a safer online environment in which the fundamental rights of all users, including
  • Read more about Interplay between the DSA and the GDPR: EDPB adopts guidelines

Greek SA: Imposition of fines on a telecommunications company and the data processor for personal data breach and insufficient security measures

Wed, 10/09/2025
Background information Date of decision: 25/06/2025 National case Controller: Vodafone S.A Legal References: GDPR: Article 5.1.d Principle of accuracy GDPR: Article 28: Processor GDPR: Article 29: Processing under the authority of the controller or processor GDPR: Article 32: Security of processing, Law 3471/2006 (National Law incorporating ePrivacy Directive 2002/58/EC) Decision: Infringement of the GDPR, fines imposed Key words: Data breach, Security of processing, Processor Summary of the Decision Origin of the case Α complaint was submitted to the Greek Supervisory Authority (SA) against
  • Read more about Greek SA: Imposition of fines on a telecommunications company and the data processor for personal data breach and insufficient security measures

Pagination

  • First page « First
  • Previous page ‹ Previous
  • …
  • Page 16
  • Page 17
  • Page 18
  • Page 19
  • Page 20
  • Page 21
  • Page 22
  • Page 23
  • Page 24
  • …
  • Next page Next ›
  • Last page Last »
Subscribe to
European Data Protection Board logo

Footer mainnavigation

  • Main menu items
    • Topics
    • Documents
    • Registers
    • Consultations
    • News
    • Meetings
  • About us menu items
    • Task and duties
    • Our members
    • EDPB Secretariat
    • Strategy and work programme
    • Legacy: Art. 29 Working Party

Footer

  • Career opportunities
  • Copyright
  • Cookies
  • General Data Protection Notice
  • Public access to documents
Coordinated Supervision Committee
The CSC ensures the coordinated supervision by data protection authorities.
CSC
Logo of Linkedin Logo of X
×

We use cookies

When you visit our website, if you give your consent, we will use cookies to allow us to collect data for aggregated statistics to improve our services and remember your choice for future visits.
If you don't want this, we will only use cookies to remember your choice for future visits (i.e., essential cookies).
If you don't select any of the two options, no cookies will be deployed, but the banner will re-appear every time you enter our website.
More information on cookies and data protection.