Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

151 fines found

Total: $190.9M

DateCompanyFineRegulationAuthorityCountryTypeSummary
2019-12-09Rapidata GmbH€10KGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyNo data protection officer appointed
--

Articles: Art. 37 GDPR

2023-01-01Magdeburg University Hospital€9KGDPRData Protection Authority of Sachsen-AnhaltGermanyFailure to notify DPA of a data breach
--

Articles: Art. 33 GDPR

2022-01-01Police officer€7KGDPRData Protection Authority of HessenGermanyUnknown
--

Articles: Unknown

2020-01-01Unknown€7KGDPRData Protection Authority of BavariaGermanyNon-cooperation with Data Protection Authority
--

Articles: Art. 58 (1) f) GDPR

2022-01-01Pharmacy€7KGDPRThe DPA of BremenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR

2019-01-23Small shipping company€5KGDPRData Protection AuthorityGermanyhttps://dataprivacy.foxrothschild.com/2019/01/articles/european-union/hessian-dpa-fines-shipping-company-for-missing-data-processing-agreement/
--

Articles: Art. 28 of the GDPR

2022-09-21Unknown€5KGDPRData Protection Authority of Baden-WuerttembergGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2021-01-01Private individual€5KGDPRData Protection Authority of SaxonyGermanyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 (1) GDPR

2019-01-23Small shipping company€5KGDPRData Protection AuthorityGermanyhttps://dataprivacy.foxrothschild.com/2019/01/articles/european-union/hessian-dpa-fines-shipping-company-for-missing-data-processing-agreement/
The data controller company lacked a data processing agreement with the Spanish ...

The data controller company lacked a data processing agreement with the Spanish service provider.

Articles: Art. 28 of the GDPR

2018-12-17Kolibri Image Regina und Dirk Maass GbR€5KGDPRData Protection Authority of HamburgGermanyFailure to collect sufficient data processing consent
This fine was apparently withdrawn. The case concerned the Kolibri Image who lod...

This fine was apparently withdrawn. The case concerned the Kolibri Image who lodged a complaint that a service provider did not want to sign a processing agreement. Afterward, the Kolibri Image was fined because it didn’t have any processing agreement with the service provider. However, the company argued that the service provider was not a processor, and therefore the fine was unreasonable and unwarranted.

Articles: Art. 28 (3) GDPR

2018-12-17Kolibri Image Regina und Dirk Maass GbR€5KGDPRData Protection Authority of HamburgGermanyFailure to collect sufficient data processing consent
--

Articles: Art. 28 (3) GDPR

2022-01-01Covid-19 Test Center€3KGDPRData Protection Authority of HamburgGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) GDPR

2019-02-05Private individual€3KGDPRData Protection Authority of Sachsen-AnhaltGermanyNon-compliance with lawful basis for data processing
A private person sent several emails containing the email addresses of several s...

A private person sent several emails containing the email addresses of several subjects, and each subject could see other recipients of that email. In the person’s mailing list, more than 131 email addresses had been found. He was accused of ten such offenses.

Articles: Art. 6 GDPR, Art. 5 GDPR

2019-02-05Private individual€3KGDPRData Protection Authority of Sachsen-AnhaltGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 5 GDPR

2019-01-01Restaurant€2KGDPRData Protection Authority of SaarlandGermanyFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR

2019-01-01Restaurant€2KGDPRData Protection Authority of SaarlandGermanyFailure to comply with data processing principles
The video surveillance cameras had been misused, clearly not in accord with the ...

The video surveillance cameras had been misused, clearly not in accord with the data minimization principle.

Articles: Art. 5 (1) c) GDPR

2021-01-01Police Officer€2KGDPRData Protection Authority of BerlinGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2022-01-01Covid-19 test center€2KGDPRData Protection Authority of HessenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), f) GDPR, Art. 6 (1) GDPR

2019-05-09Police Officer€1KGDPRData Protection Authority of Baden-WuerttembergGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2022-01-01Covid-19 Test Center€1KGDPRData Protection Authority of HamburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) c) GDPR

2019-05-09Police Officer€1KGDPRData Protection Authority of Baden-WuerttembergGermanyNon-compliance with lawful basis for data processing
The police officer acted outside the boundaries of the law when he used the Cent...

The police officer acted outside the boundaries of the law when he used the Central Traffic Information System to find out the personal data of the license plate of an unknown person. Moreover, he then proceeded with a SARS inquiry, gathering personal data of the injured parties (mobile and home phone numbers). The police officer then contacted the wounded party. These actions were done outside his lawful prerogatives, and it is an infringement of personal data. However, he acted not in trying to exercise official duties but to satisfy personal inquiries. Therefore, the police department is not to blame.

Articles: Art. 6 GDPR

2022-01-01Covid-19 Test Center€1KGDPRData Protection Authority of HamburgGermanyFailure to comply with data processing principles
--

Articles: Art. 17 GDPR

2022-01-01Physician€1KGDPRData Protection Authority of HamburgGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) GDPR

2019-08-06Police Officer€800GDPRData Protection Authority of Mecklenburg-VorpommernGermanyNon-compliance with lawful basis for data processing
A police officer used a witnesse’s personal data to contact her.

A police officer used a witnesse’s personal data to contact her.

Articles: Art. 6 GDPR

2019-08-06Police Officer€800GDPRData Protection Authority of Mecklenburg-VorpommernGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

PreviousPage 3 of 7Next