Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

151 fines found

Total: $190.9M

DateCompanyFineRegulationAuthorityCountryTypeSummary
2025-01-15Vodafone Germany€45.0MGDPRGermany BfDIGermanydata_breach
Vendor security failures and inadequate data controls.

Vendor security failures and inadequate data controls.

Articles: Art. 32

2025-01-01Vodafone Germany€45.0MGDPRGermany BfDIGermanydata_breach
Vendor security failures and inadequate data controls.

Vendor security failures and inadequate data controls.

Articles: Art. 32

2020-10-01H&M Hennes & Mauritz Online Shop A.B. & Co. KG€32.3MGDPRData Protection Authority of HamburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2019-10-30Deutsche Wohnen SE€14.5MGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to comply with data processing principles
The company collected data from multiple tenants without providing the option to...

The company collected data from multiple tenants without providing the option to remove that data once it was no longer required. This led to the company retaining personal data of tenants for years (salary statements, social security insurances, health insurances, tax insurances, bank statements). The Berlin Data Commissioner issued a fine of €14,500,000.

Articles: Art. 5 GDPR, Art. 25 GDPR

2021-01-08notebooksbilliger.de€10.4MGDPRData Protection Authority of NiedersachsenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2019-12-091&1 Telecom GmbH€9.6MGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyFailure to implement sufficient measures to ensure information security
The telecom company 1&1 Telecom GmbH was fined with €9,550,000 after it cam...

The telecom company 1&1 Telecom GmbH was fined with €9,550,000 after it came to light that sensitive customer information could be obtained by phone by anyone by just telling a client’s name and date of birth. This could have permitted anyone to obtain the personal information of any customer in case they knew their name and date of birth. The BfDI considered that the company failed to implement the necessary technical measures to ensure the protection of personal data. The BfDI further revealed that the fine was intended to be much larger but was eventually decreased due to the cooperation of the company during the investigation.

Articles: Art. 32 GDPR

2019-12-091&1 Telecom GmbH€9.6MGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyFailure to implement sufficient measures to ensure information security
--

Articles: <a href="https://www.privacy-regulation.eu/en/32.htm">Art. 32 GDPR</a>

2022-03-03BREBAU GmbH€1.9MGDPRData Protection Authority of BremenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 (1) GDPR, Art. 6 (1) GDPR, Art. 9 GDPR

2020-06-30Allgemeine Ortskrankenkasse€1.2MGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 32 GDPR

2022-07-26Volkswagen€1.1MGDPRData Protection Authority of SaxonyGermanynsufficient fulfilment of information obligations
--

Articles: Art. 13 GDPR, Art. 28 GDPR, Art. 30 GDPR, Art. 35 GDPR

2020-11-111&1 Telecom GmbH€900KGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2021-09-24Vattenfal Europe Sales GmbH€900KGDPRData Protection Authority of HamburgGermanyInsufficient data processing agreement
--

Articles: Art. 12 GDPR, Art. 13 GDPR

2022-07-28Hannoversche Volksbank€900KGDPRData Protection Authority of SaxonyGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2022-09-20Unknown company€525KGDPRData Protection Authority of BerlinGermanyNon-cooperation with Data Protection Authority
--

Articles: Art. 38 (6) GDPR

2021-03-10VfB Stuttgart 1893 AG€300KGDPRData Protection Authority of Baden-WuerttembergGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (2) GDPR

2019-12-02Unknown€294KGDPRData Protection Authority of NiedersachsenGermanyFailure to comply with data processing principles
A company was fined with €294,000 because of the &#8220;unnecessarily long&#8221...

A company was fined with €294,000 because of the &#8220;unnecessarily long&#8221; storage and retention of personal data in the selection of personnel. During the selection process, even health data was requested, which was excessive according to the DPA.

Articles: Art. 5 GDPR

2019-12-02Unknown€294KGDPRData Protection Authority of NiedersachsenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR

2019-09-19Delivery Hero€195KGDPRData Protection Authority of BerlinGermanyNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR

2019-09-19Delivery Hero€195KGDPRData Protection Authority of BerlinGermanyNon-compliance with subjects' rights protection safeguards
The Company had retained the personal data of customers who had expressed their ...

The Company had retained the personal data of customers who had expressed their desire to discontinue receiving emails from the company. Eight customers complained to have received such emails, despite not having solicited them. Moreover, the company refused to share information with five subjects regarding their rights to withdraw consent in the processing of personal information.

Articles: Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR

2019-12-03Rheinland-Pfalz Hospital€105KGDPRData Protection Authority of Rheinland-PfalzGermanyNon-compliance with lawful basis for data processing
The Data Protection Authority of Rheinland-Pfalz issued a fine of €105,000 after...

The Data Protection Authority of Rheinland-Pfalz issued a fine of €105,000 after a hospital after a mixup of patients. As a consequence of this, wrong invoices were issues to the patients that released sensitive personal data.

Articles: Art. 5 GDPR

2019-12-03Rheinland-Pfalz Hospital€105KGDPRData Protection Authority of Rheinland-PfalzGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-10-24Food company€100KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 32 GDPR

2019-10-24Food company€100KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
Upon creation of an applicant portal where interested parties could apply their ...

Upon creation of an applicant portal where interested parties could apply their documents for a job, the food company failed to encrypt the applicant portal. The transmission of the data had no encryption and the data storage was completely unencrypted and offered no password-protected security systems. Moreover, the data was linked to Google, so anyone could find the applicants&#8217; documents and retrieve them after a simple Google search.

Articles: Art. 5 GDPR, Art. 32 GDPR

2019-10-17Unknown€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
Because of insufficient data security mechanisms, a digital publication accident...

Because of insufficient data security mechanisms, a digital publication accidentally disclosed personal health data related to several subjects.

Articles: Art. 32 GDPR

2019-07-30Unknown€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
Two companies working in finances didn’t follow the procedure when disposing of ...

Two companies working in finances didn’t follow the procedure when disposing of personal data.

Articles: Art. 32 GDPR

Page 1 of 7Next