Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
151 fines found
Total: $190.9M
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2025-01-15 | Vodafone Germany | €45.0M | GDPR | Germany BfDI | Germany | data_breach | Vendor security failures and inadequate data controls.Vendor security failures and inadequate data controls. Articles: Art. 32 |
| 2025-01-01 | Vodafone Germany | €45.0M | GDPR | Germany BfDI | Germany | data_breach | Vendor security failures and inadequate data controls.Vendor security failures and inadequate data controls. Articles: Art. 32 |
| 2020-10-01 | H&M Hennes & Mauritz Online Shop A.B. & Co. KG | €32.3M | GDPR | Data Protection Authority of Hamburg | Germany | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-10-30 | Deutsche Wohnen SE | €14.5M | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Failure to comply with data processing principles | The company collected data from multiple tenants without providing the option to...The company collected data from multiple tenants without providing the option to remove that data once it was no longer required. This led to the company retaining personal data of tenants for years (salary statements, social security insurances, health insurances, tax insurances, bank statements). The Berlin Data Commissioner issued a fine of €14,500,000. Articles: Art. 5 GDPR, Art. 25 GDPR |
| 2021-01-08 | notebooksbilliger.de | €10.4M | GDPR | Data Protection Authority of Niedersachsen | Germany | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-12-09 | 1&1 Telecom GmbH | €9.6M | GDPR | The Federal Commissioner for Data Protection and Freedom of Information (BfDI) | Germany | Failure to implement sufficient measures to ensure information security | The telecom company 1&1 Telecom GmbH was fined with €9,550,000 after it cam...The telecom company 1&1 Telecom GmbH was fined with €9,550,000 after it came to light that sensitive customer information could be obtained by phone by anyone by just telling a client’s name and date of birth. This could have permitted anyone to obtain the personal information of any customer in case they knew their name and date of birth. The BfDI considered that the company failed to implement the necessary technical measures to ensure the protection of personal data. The BfDI further revealed that the fine was intended to be much larger but was eventually decreased due to the cooperation of the company during the investigation. Articles: Art. 32 GDPR |
| 2019-12-09 | 1&1 Telecom GmbH | €9.6M | GDPR | The Federal Commissioner for Data Protection and Freedom of Information (BfDI) | Germany | Failure to implement sufficient measures to ensure information security | --Articles: <a href="https://www.privacy-regulation.eu/en/32.htm">Art. 32 GDPR</a> |
| 2022-03-03 | BREBAU GmbH | €1.9M | GDPR | Data Protection Authority of Bremen | Germany | Failure to comply with data processing principles | --Articles: Art. 5 (1) GDPR, Art. 6 (1) GDPR, Art. 9 GDPR |
| 2020-06-30 | Allgemeine Ortskrankenkasse | €1.2M | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 32 GDPR |
| 2022-07-26 | Volkswagen | €1.1M | GDPR | Data Protection Authority of Saxony | Germany | nsufficient fulfilment of information obligations | --Articles: Art. 13 GDPR, Art. 28 GDPR, Art. 30 GDPR, Art. 35 GDPR |
| 2020-11-11 | 1&1 Telecom GmbH | €900K | GDPR | The Federal Commissioner for Data Protection and Freedom of Information (BfDI) | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2021-09-24 | Vattenfal Europe Sales GmbH | €900K | GDPR | Data Protection Authority of Hamburg | Germany | Insufficient data processing agreement | --Articles: Art. 12 GDPR, Art. 13 GDPR |
| 2022-07-28 | Hannoversche Volksbank | €900K | GDPR | Data Protection Authority of Saxony | Germany | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2022-09-20 | Unknown company | €525K | GDPR | Data Protection Authority of Berlin | Germany | Non-cooperation with Data Protection Authority | --Articles: Art. 38 (6) GDPR |
| 2021-03-10 | VfB Stuttgart 1893 AG | €300K | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (2) GDPR |
| 2019-12-02 | Unknown | €294K | GDPR | Data Protection Authority of Niedersachsen | Germany | Failure to comply with data processing principles | A company was fined with €294,000 because of the “unnecessarily long”...A company was fined with €294,000 because of the “unnecessarily long” storage and retention of personal data in the selection of personnel. During the selection process, even health data was requested, which was excessive according to the DPA. Articles: Art. 5 GDPR |
| 2019-12-02 | Unknown | €294K | GDPR | Data Protection Authority of Niedersachsen | Germany | Failure to comply with data processing principles | --Articles: Art. 5 GDPR |
| 2019-09-19 | Delivery Hero | €195K | GDPR | Data Protection Authority of Berlin | Germany | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR |
| 2019-09-19 | Delivery Hero | €195K | GDPR | Data Protection Authority of Berlin | Germany | Non-compliance with subjects' rights protection safeguards | The Company had retained the personal data of customers who had expressed their ...The Company had retained the personal data of customers who had expressed their desire to discontinue receiving emails from the company. Eight customers complained to have received such emails, despite not having solicited them. Moreover, the company refused to share information with five subjects regarding their rights to withdraw consent in the processing of personal information. Articles: Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR |
| 2019-12-03 | Rheinland-Pfalz Hospital | €105K | GDPR | Data Protection Authority of Rheinland-Pfalz | Germany | Non-compliance with lawful basis for data processing | The Data Protection Authority of Rheinland-Pfalz issued a fine of €105,000 after...The Data Protection Authority of Rheinland-Pfalz issued a fine of €105,000 after a hospital after a mixup of patients. As a consequence of this, wrong invoices were issues to the patients that released sensitive personal data. Articles: Art. 5 GDPR |
| 2019-12-03 | Rheinland-Pfalz Hospital | €105K | GDPR | Data Protection Authority of Rheinland-Pfalz | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-10-24 | Food company | €100K | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 GDPR, Art. 32 GDPR |
| 2019-10-24 | Food company | €100K | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Failure to implement sufficient measures to ensure information security | Upon creation of an applicant portal where interested parties could apply their ...Upon creation of an applicant portal where interested parties could apply their documents for a job, the food company failed to encrypt the applicant portal. The transmission of the data had no encryption and the data storage was completely unencrypted and offered no password-protected security systems. Moreover, the data was linked to Google, so anyone could find the applicants’ documents and retrieve them after a simple Google search. Articles: Art. 5 GDPR, Art. 32 GDPR |
| 2019-10-17 | Unknown | €80K | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Failure to implement sufficient measures to ensure information security | Because of insufficient data security mechanisms, a digital publication accident...Because of insufficient data security mechanisms, a digital publication accidentally disclosed personal health data related to several subjects. Articles: Art. 32 GDPR |
| 2019-07-30 | Unknown | €80K | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Failure to implement sufficient measures to ensure information security | Two companies working in finances didn’t follow the procedure when disposing of ...Two companies working in finances didn’t follow the procedure when disposing of personal data. Articles: Art. 32 GDPR |