Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

53 fines found

Total: $1.8B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2022-11-24ÉLECTRICITÉ DE FRANCE€600KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 7 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. L. 34-5 CPCE

2022-08-19ACCOR SA€600KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information
--

Articles: Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. 32 GDPR, L. 34-5 CPCE

2019-11-21Futura Internationale€500KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 21 GDPR

2021-06-14Brico Prive€500KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) e) GDPR, Art. 13 GDPR, Art. 17 GDPR, Art. 32 GDPR, Art. 82 Loi informatique et libertés, Art. L. 34-5 CPCE

2019-11-21Futura Internationale€500KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
Futura Internationale was fined because after several individuals have complaine...

Futura Internationale was fined because after several individuals have complained that they were cold-called by the company even after they have expressly requested not to be called again. The reason why the fine was so high relative to similar cases and fines was that the CNIL determined that the company had received a large number of letters requesting to be taken off from the call lists but decided to ignore them. More so, Futura Internationale was found to store excessive information about customers and their health data. The company did also not inform their customers about the processing of their personal data and that all telephone conversations were recorded.

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 21 GDPR

2021-07-26Monsanto Corporation€400KGDPRFrench Data Protection Authority (CNIL)FranceInformation obligation non-compliance
--

Articles: Art. 14 GDPR, Art. 28 GDPR

2019-05-28SERGIC€400KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
The company was fined because of two reasons – the complete lack of security mea...

The company was fined because of two reasons – the complete lack of security measures, and excessive data storage. Regarding the former reason, personal data, including health cards, IDs, divorce judgments, and account statements were available online with no authentication procedure. Moreover, the company breached the data storage deadline it had in place and kept clients’ data for more than it should have.

Articles: Art. 32 GDPR

2021-11-04Régie autonome des transports parisiens€400KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR, Art. 5 (1) e) GDPR, Art. 5 (2) GDPR, Art. 32 GDPR

2019-05-28SERGIC€400KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2022-12-08FREE SAS€300KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 32 GDPR, Art. 33 GDPR

2021-12-28FREE MOBILE€300KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 12 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. 25 GDPR, Art. 32 GDPR

2020-08-05Spartoo€250KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) GDPR, Art. 13 GDPR, Art. 14 GDPR

2022-09-13GIE INFOGREFFE€250KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information
--

Articles: Art. 5 (1) e) GDPR, Art. 32 GDPR

2019-07-25Active Assurances€180KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-07-25Active Assurances€180KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
The company had allowed for personal data belonging to clients (including copies...

The company had allowed for personal data belonging to clients (including copies of the driver’s license) to be publicized online. Apparently, unauthorized access was detected, and the fault lies with the inappropriate security measures.

Articles: Art. 32 GDPR

2021-12-28SLIMPAY€180KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 28 GDPR, Art. 32 GDPR, Art. 34 GDPR

2022-07-07UBEEQO INTERNATIONAL€175KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR, Art. 12 GDPR

2021-01-27Unknown€150KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2023-03-16CITYSCOOT€125KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR, Art. 28 (3) GDPR, Art. 82 Loi informatique et libertés

2021-01-27Unknown€75KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2021-07-29Le Figaro€50KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) c)

2021-01-05Nestor SAS€20KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR, Art. 13 GDPR

2019-06-13Uniontrad Company€20KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 32 GDPR

2019-06-13Uniontrad Company€20KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
Complaints from the employees were received that they were unlawfully filmed in ...

Complaints from the employees were received that they were unlawfully filmed in the workspace. The company failed to observe the rules pertaining to the unlawful filming of employees all the time, and the necessity of providing information related to the data processing to the employees. The CNIL performed an audit in October 2018, and the company wasn’t observing the data protection laws. Therefore, fines were issued.

Articles: Art. 5 (1) c) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 32 GDPR

2020-12-07Perfomeclic€7KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) c), e) GDPR, Art. 14 GDPR, Art. 21 GDPR, Art. 28 GDPR, Art. L34-5 CPCE

PreviousPage 2 of 3Next