Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

663 fines found

Total: $51.8M

DateCompanyFineRegulationAuthorityCountryTypeSummary
2021-01-21Alterna Operador Integral S.L.€50KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) b) GDPR

2020-10-26Conseguridad SL€50KGDPRSpanish Data Protection Authority (AEPD)SpainNo data protection officer appointed
--

Articles: Art. 37 GDPR

2019-06-24Vodafone ONO€48KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
A technical error allowed customers to view the personal data of other customers...

A technical error allowed customers to view the personal data of other customers on the company’s website’s customer area. The original fine of €60,000 was reduced to €48,000.

Articles: Art. 32 GDPR

2022-11-11Banco Bilbao Vizcaya Argentaria S.L.€48KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2019-05-06Telefónica SA€48KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR

2019-05-06Telefónica SA€48KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
A customer complained that their bank account was charged for two invoices for t...

A customer complained that their bank account was charged for two invoices for the services the customer has purchased but on the invoices, the personal details of a third party person were displayed. Initially, the fine was determined to be €60,000 but was reduced to €48,000.

Articles: Art. 5 (1) a) GDPR

2020-02-25HM Hospitales€48KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
An individual reported that at the time of their admission to the hospital they ...

An individual reported that at the time of their admission to the hospital they had to fill in a form that had a checkbox that indicated that if the checkbox is not ticked, the hospital can transfer the person’s private data to third parties. The data protection authority argued that this form was not in accordance with the GDPR because consent was to be obtained from the inactivity of the affected person.

Articles: Art. 5 GDPR, Art. 6 GDPR

2022-08-28NATURGY ENERGY GROUP, S.A.€48KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2019-06-24Vodafone ONO€48KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2020-02-28Vodafone ONO€48KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2020-02-25HM Hospitales€48KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-02-28Vodafone ONO€48KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
The company was fined due to several deficiencies in information security. Two c...

The company was fined due to several deficiencies in information security. Two clients of the company had received the same security access key, allowing to view each others’ personal details.

Articles: Art. 32 GDPR

2021-07-12Telefonica Moviles Espana, S.A.U.€45KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2020-07-31Vodafone España SAU€45KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-01-07Vodafone Espana€44KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
The company was fined because it sent a contract that included the name and addr...

The company was fined because it sent a contract that included the name and address and contact details of a client to a third party by accident.

Articles: Art. 5 (1) f) GDPR

2020-01-07Vodafone Espana€44KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR

2020-11-11Vodafone España, SAU€42KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2022-05-17Vodafone Espana, S.A.U.€42KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2022-05-24Alquiler Seguro SA€42KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDP

2020-11-16Vodafone España, SAU€42KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-03-03Vodafone España€42KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2020-02-14Vodafone España€42KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
An individual reported having had access to the personal data to third parties i...

An individual reported having had access to the personal data to third parties in their personal Vodafone profile.

Articles: Art. 32 GDPR

2020-03-03Vodafone España€42KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
A client’s personal data was accessed without authorization. The AEPD expl...

A client’s personal data was accessed without authorization. The AEPD explained that this happened due to lack of technical and organizational measures taken by the company to ensure information security.

Articles: Art. 32 GDPR

2022-08-02Banco Bilbao Vizcaya Argentaria S.L.€42KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2020-02-14Vodafone España€42KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

PreviousPage 6 of 27Next