Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

55 fines found

Total: $20.7M

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-09-08Warsaw University of Life Sciences€11KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2023-03-01Housing Cooperative€11KGDPRPolish National Personal Data Protection Office (UODO)PolandInsufficient fulfilment of data breach notification obligations
--

Articles: Art. 33 (1) GDPR, Art. 34 (1) GDPR

2021-12-09Warsaw University of Technology€10KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 24 (1) GDPR, Art. 25 (1) GDPR, Art. 32 (1), (2) GDPR

2022-11-30PIONIER (law firm)€10KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 (1), a) GDPR, Art. 6 (1) GDPR, Art. 9 GDPR

2019-10-18Polish Mayor€9KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-compliance with lawful basis for data processing
No data processing agreement has been concluded with the company whose servers c...

No data processing agreement has been concluded with the company whose servers contained the resources of the Public Information Bulletin (BIP) of the Municipal Office in Aleksandrów Kujawski. For this reason, a fine of 40.000 PLN (9400 EUR) was imposed on the mayor of the city.

Articles: Art. 28 GDPR

2019-10-18Polish Mayor€9KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-compliance with lawful basis for data processing
--

Articles: Art. 28 GDPR

2023-02-08Company€7KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 24 (1) GDPR, Art. 25 (1), (2) GDPR, Art. 32 (1), (2) GDPR

2022-08-30TIMSHEL Sp. z o.o.€7KGDPRPolish National Personal Data Protection Office (UODO)PolandInsufficient cooperation with supervisory authority
--

Articles: Art. 58 (1) e) GDPR

2023-01-19Szczecin-Centrum District Court€6KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 24 (1) GDPR, Art. 25 (1), (2) GDPR, Art. 32 (1), (2) GDPR

2021-01-05Śląski Uniwersytet Medyczny (Medical University of Silesia)€6KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 33 (1) GDPR, Art. 34 (1) GDPR

2021-04-27PNP S.A.€5KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-cooperation with Data Protection Authority
--

Articles: Art. 31 GDPR, Art. 58 (1) e) GDPR

2021-03-19Funeda Sp z o.o. €5KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-cooperation with Data Protection Authority
--

Articles: Art. 31 GDPR, Art. 58 (1) a), e) GDPR

2020-03-04School in Gdansk€5KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-compliance with lawful basis for data processing
Biometric fingerprint scanners were used in a school in Gdansk (Poland) to authe...

Biometric fingerprint scanners were used in a school in Gdansk (Poland) to authenticate students into the school’s payment processing system. While the parents have given written consent to the processing of this kind of data, the Polish National Personal Data Protection Office (UODO) argued that the data processing was nevertheless unlawful, as the consent was obtained involuntarily. It was argued that the school required the consent, otherwise, it would not have been able to process student’s payments at all, meaning parents had no choice other than to “consent”.

Articles: Art. 5 GDPR

2020-03-04School in Gdansk€5KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR

2020-03-09Vis Consulting Sp. Z o.o.€4KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 31 GDPR, Art. 58 GDPR

2022-06-06Esselmann Technika Pojazdowa Sp. z o.o. Sp. k.€4KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 33 GDPR

2020-07-10East Power Sp. z o.o.€3KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 31 GDPR, Art. 58 GDPR

2021-06-30Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra€3KGDPRPolish National Personal Data Protection Office (UODO)PolandInformation obligation non-compliance
--

Articles: Art. 33 (1) GDPR, Art. 34 (1) GDPR

2020-12-09Smart Cities Sp. z o.o.€3KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-cooperation with Data Protection Authority
--

Articles: Art. 31 GDPR, Art. 58 GDPR

2021-08-14President of the Zgierz District Court€2KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 25 (1) GDPR, Art. 32 (1) b), d), (2) GDPR

2022-07-27University Hospital of the Medical University of Warsaw€2KGDPRPolish National Personal Data Protection Office (UODO)PolandInsufficient fulfilment of data breach notification obligations
--

Articles: Art. 33 GDPR, Art. 34 GDPR

2022-05-31Stołeczny Ośrodek dla Osób Nietrzeźwych€2KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR

2019-11-01L. Sp z o.o.€2KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), f) GDPR

2022-11-02Mayor€2KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 25 (1) GDPR, Art. 32 (1), (2) GDPR

2022-08-31Unknown€1KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-cooperation with Data Protection Authority
--

Articles: Art. 31 GDPR, Art. 58 (1) a), e) GDPR

PreviousPage 2 of 3Next