Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
34 fines found
Total: $36.0M
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2021-06-07 | Region Varmland | €25K | GDPR | Data Protection Authority of Sweden | Sweden | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR |
| 2020-11-25 | Gnosjo Municipality | €20K | GDPR | Data Protection Authority of Swedenlop | Sweden | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 13 GDPR, Art. 35 GDPR, Art. 36 GDPR |
| 2020-04-29 | National Government Service Centre (NGSC) | €19K | GDPR | Data Protection Authority of Sweden | Sweden | Insufficient fulfilment of data breach notification obligations | --Articles: Art. 33 GDPR, Art. 34 GDPR |
| 2019-08-20 | Skellefteå school | €19K | GDPR | Data Protection Authority of Sweden | Sweden | Non-compliance with lawful basis for data processing | A school attempted to introduce the use of facial recognition software to facili...A school attempted to introduce the use of facial recognition software to facilitate the attendance process of students. The school was ultimately fined because the means used to monitor attendance were disproportionate to the goal itself. Moreover, students and their parents couldn’t freely withdraw consent from being monitored to validate attendance. Furthermore, one case of processing activity presented elevated risks since it involved children dependent on the high-school board. Ultimately, the school didn’t observe Art. 35 of the GDPR. Articles: Art. 5 (1) c) GDPR, Art. 9 GDPR, Art. 35 GDPR, Art. 36 GDPR |
| 2019-08-20 | Skellefteå school | €19K | GDPR | Data Protection Authority of Sweden | Sweden | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR, Art. 9 GDPR, Art. 35 GDPR, Art. 36 GDPR |
| 2023-01-17 | Dalarna Region | €18K | GDPR | Data Protection Authority of Sweden | Sweden | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) GDPR |
| 2023-04-26 | Skåne region | €18K | GDPR | Data Protection Authority of Sweden | Sweden | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) GDPR |
| 2020-05-12 | Örebro County Health and Medical Board | €11K | GDPR | Data Protection Authority of Sweden | Sweden | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-06-16 | Housing Association | €2K | GDPR | Data Protection Authority of Sweden | Sweden | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |