Skip to main content
European Data Protection Board logo
Back Search Menu
Close menu

Main navigation

  • Home
  • Topics
  • Documents
  • Registers
  • Public consultations

Top navigation

  • About EDPB
  • News
  • Meetings
  • Contact
  • Guide for SMEs
EN

Select your language

  • BGбългарски
  • CSčeština
  • DAdansk
  • DEDeutsch
  • ELελληνικά
  • ESespañol
  • ETeesti
  • FIsuomi
  • FRfrançais
  • GAGaeilge
  • HRhrvatski
  • HUmagyar
  • ITitaliano
  • LTlietuvių
  • LVlatviešu
  • MTMalti
  • NLNederlands
  • PLpolski
  • PTportuguês
  • ROromână
  • SKslovenčina
  • SLslovenščina
  • SVsvenska
Close language switcher

Breadcrumb

  1. Home

Data scraping: French SA fined KASPR €200 000

Thu, 09/01/2025
Background information Date of final decision: 5 December 2024 Cross-border LSA: France and CSAs: all SAs Legal Reference(s): Article 6 (Lawfulness of processing), Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 14 (Information to be provided where personal data have not been obtained from the data subject), Article 15 (Right to access by the data subject), Decision: Administrative fine and order Add here your free text for the decision Key words
  • Read more about Data scraping: French SA fined KASPR €200 000

EDPB opinion on AI models: GDPR principles support responsible AI

Wed, 18/12/2024
Brussels, 18 December - The European Data Protection Board (EDPB) has adopted an opinion* on the use of personal data for the development and deployment of AI models. This opinion looks at 1) when and how AI models can be considered anonymous, 2) whether and how legitimate interest can be used as a legal basis for developing or using AI models, and 3) what happens if an AI model is developed using personal data that was processed unlawfully. It also considers the use of first and third party data. The opinion was requested by the Irish Data Protection Authority (DPA) with a view to seeking
  • Read more about EDPB opinion on AI models: GDPR principles support responsible AI

Finnish SA: Administrative fine imposed on Posti for unlawful processing of personal data

Fri, 06/12/2024
Background information Date of final decision: 13 November 2024 National case Legal Reference (s): Article 6 (Lawfulness of processing), Article 13 (Information to be provided where personal data are collected from the data subject) Article 5 (Principles relating to processing of personal data) Article 25 (Data protection by design and by default) Decision: Administrative fine, Compliance order, Reprimand Key words: Administrative fine, Lawfulness of processing, Right to be informed Summary of the Decision Origin of the case The Finnish Supervisory Authority (SA) investigated the processing of
  • Read more about Finnish SA: Administrative fine imposed on Posti for unlawful processing of personal data

EDPB calls for coherence of digital legislation with the GDPR

Wed, 04/12/2024
Brussels, 04 December - During its December 2024 plenary, the European Data Protection Board (EDPB) adopted a statement on the second report of the European Commission on the application of the General Data Protection Regulation (GDPR).* In its statement, the EDPB welcomes the reports from the European Commission and the Fundamental Rights Agency**. Importantly, the EDPB underlines the importance of legal certainty and coherence of digital legislation with the GDPR, and recalls some of its ongoing initiatives to clarify the enforcement interplay of the GDPR with the AI Act, the EU Data
  • Read more about EDPB calls for coherence of digital legislation with the GDPR

EDPB clarifies rules for data sharing with third country authorities and approves EU Data Protection Seal certification

Tue, 03/12/2024
Brussels, 03 December - During its latest plenary, the European Data Protection Board (EDPB) published guidelines on Art.48 GDPR about data transfers to third country authorities and approved a new European Data Protection Seal. EDPB helps organisations assess data transfer requests by third country authorities In a highly interconnected world, organisations receive requests from public authorities in other countries to share personal data. The sharing of data can, for instance, be of help to collect evidence in the case of crime, to check financial transactions or approve new medications
  • Read more about EDPB clarifies rules for data sharing with third country authorities and approves EU Data Protection Seal certification

Polish SA: administrative fine of 330 000 € for a medical company after a hacker attack

Thu, 28/11/2024
Background information Date of final decision: 20 May 2024 National case Legal Reference (s): Article 5 (Principles relating to processing of personal data), Article 24 (Responsibility of the controller), Article 32 (Security of processing) Decision: Administrative fine, Compliance order Key words: Accountability, Administrative fine, Data subject rights, Hacker attack, National identification number, Responsibility of the controller or Sensitive data Summary of the Decision Origin of the case The IT infrastructure of the Company American Heart of Poland S.A. was attacked by hackers, who thus
  • Read more about Polish SA: administrative fine of 330 000 € for a medical company after a hacker attack

Polish SA: administrative fine of 210 € for failure to notify personal data breach to supervisory authority

Thu, 28/11/2024
Background information Date of final decision: 30 April 2024 National case Legal Reference: Article 33 (Notification of a personal data breach to the supervisory authority) Decision: Administrative fine Key words: Data subject rights, Personal data breach, Principles relating to processing of personal data, Data security, Responsibility of the controller Summary of the Decision Origin of the case The "Maraton" Sports Association from Gorlice organised a competition and published a list of participants on Facebook. The competitors gave their consent to the processing of their data. However, the
  • Read more about Polish SA: administrative fine of 210 € for failure to notify personal data breach to supervisory authority

Polish SA: fine of 9 300 € for Independent Public Health Care Centre after hacker attack

Thu, 28/11/2024
Background information Date of final decision: 13 June 2024 National case Legal references: Article 5 (Principles relating to processing of personal data), Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject). Decision: Administrative fine, Communication order personal data breach, Compliance order Summary of the Decision Origin of the case As a result of a hacking attack, the Centre lost access to patient and employee data. It only took
  • Read more about Polish SA: fine of 9 300 € for Independent Public Health Care Centre after hacker attack

Polish SA: administrative fine of 2 500 € for the way of collecting the data

Thu, 28/11/2024
Background information Date of final decision: 24 April 2024 National case Legal Reference (s): Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: Administrative fine, Communication order personal data breach Key words: Administrative fine, Data subject rights, Personal data breach, Accountability, Data security, Sensitive data Summary of the
  • Read more about Polish SA: administrative fine of 2 500 € for the way of collecting the data

Polish SA: administrative fine of 54 600 € for failure to implement appropriate technical and organisational measures to ensure a level of security

Thu, 28/11/2024
Background information Date of final decision: 29 April 2024 National case Legal Reference (s): Article 24 (Responsibility of the controller), Article 25 (Data protection by design and by default), Article 32 (Security of processing), Article 5 (Principles relating to processing of personal data) Decision: Administrative fine, Compliance order Key words: Administrative fine, Data subject rights, Personal data breach, Principles relating to processing of personal data, Data security, Responsibility of the controller Summary of the Decision Origin of the case An employee of the catering company
  • Read more about Polish SA: administrative fine of 54 600 € for failure to implement appropriate technical and organisational measures to ensure a level of security

Pagination

  • First page « First
  • Previous page ‹ Previous
  • …
  • Page 22
  • Page 23
  • Page 24
  • Page 25
  • Page 26
  • Page 27
  • Page 28
  • Page 29
  • Page 30
  • …
  • Next page Next ›
  • Last page Last »
Subscribe to
European Data Protection Board logo

Footer mainnavigation

  • Main menu items
    • Topics
    • Documents
    • Registers
    • Consultations
    • News
    • Meetings
  • About us menu items
    • Task and duties
    • Our members
    • EDPB Secretariat
    • Strategy and work programme
    • Legacy: Art. 29 Working Party

Footer

  • Career opportunities
  • Copyright
  • Cookies
  • General Data Protection Notice
  • Public access to documents
Coordinated Supervision Committee
The CSC ensures the coordinated supervision by data protection authorities.
CSC
Logo of Linkedin Logo of X
×

We use cookies

When you visit our website, if you give your consent, we will use cookies to allow us to collect data for aggregated statistics to improve our services and remember your choice for future visits.
If you don't want this, we will only use cookies to remember your choice for future visits (i.e., essential cookies).
If you don't select any of the two options, no cookies will be deployed, but the banner will re-appear every time you enter our website.
More information on cookies and data protection.