Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-09-03Bergen Municipality€276KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2023-04-12Aldi€253KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryUnknown
--

Articles: Unknown

2026-02-01NL Municipalities (x10)€250KGDPRNetherlands APNetherlandsother
Unlawful processing of religious data
2019-06-11Professional Football League (LaLiga)€250KGDPRSpanish Data Protection Authority (AEPD)SpainInformation obligation non-compliance
--

Articles: Art. 5 (1) a), Art. 7 (3) GDPR

2020-08-05Spartoo€250KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) GDPR, Art. 13 GDPR, Art. 14 GDPR

2022-01-01Unknown€250KGDPRData Protection Commissioner of MaltaMaltaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1), (2) GDPR

2022-02-02IAB Europe€250KGDPRBelgian Data Protection Authority (APD)BelgiumNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR, Art. 5 (2) GDPR, Art. 6 (1) GDPR, Art. 9 (1), (2) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 24 (1) GDPR, Art. 30 GDPR, Art. 31 GDPR, Art. 32 (1), (2) GDPR, Art. 37 GDPR

2019-06-11Professional Football League (LaLiga)€250KGDPRSpanish Data Protection Authority (AEPD)SpainInformation obligation non-compliance
A fine was issued to the National Football League (LaLiga) because it had failed...

A fine was issued to the National Football League (LaLiga) because it had failed to inform users of the implications contained within the app it offered. This app remotely accessed the users’ microphones once every minute to check pubs screening football matches. The AEPD thinks that the users were not sufficiently informed of this. Moreover, the users did not have the adequate possibility to withdraw their consent, once given.

Articles: Art. 5 (1) a), Art. 7 (3) GDPR

2022-09-13GIE INFOGREFFE€250KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information
--

Articles: Art. 5 (1) e) GDPR, Art. 32 GDPR

2026-02-01NL Municipalities (x10)€250KGDPRNetherlands APNetherlandsconsent
Unlawful processing of religious data by 10 Dutch municipalities.

Unlawful processing of religious data by 10 Dutch municipalities.

Articles: Art. 5, Art. 9

2020-12-03Östergötland Region€244KGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2020-12-03Västerbotten Region€244KGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2020-12-17ID Finance Poland Sp. z o.o.€235KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 25 (1) GDPR, Art. 32 (1) b), d), (2) GDPR

2022-12-09Viking Line Oy Abp€230KGDPRDeputy Data Protection OmbudsmanFinlandFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), d) GDPR, Art. 12 (3) GDPR, Art. 13 GDPR, Art. 15 (1) GDPR, Art. 25 (1) GDPR

2019-03-29Bisnode€220KGDPRPersonal Data Protection OfficePolandNon-compliance with the right of consent
--

Articles: Art.14 GDPR

2019-03-29Bisnode€220KGDPRPersonal Data Protection OfficePolandNon-compliance with the right of consent
The Company failed to observe Art.14 of the GDPR, which states that the data con...

The Company failed to observe Art.14 of the GDPR, which states that the data controller must inform the data subject of the processing of personal data. The DPA has stated that Bisnode has three months to notify a total of 6 million people of this.

Articles: Art.14 GDPR

2023-03-08Argon Medical Devices€220KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to notify DPA of a data breach
--

Articles: Art. 33 (1) GDPR

2019-03-26Private company€220KGDPRPolish National Personal Data Protection Office (UODO)PolandInformation obligation non-compliance
The private company was fined for having breached the information obligation in ...

The private company was fined for having breached the information obligation in the case of personal data of several entrepreneurs. The data was taken from public sources (Central Electronic Register and Information on Economic Activity) and used for commercial purposes. In accordance with Art. 14(1) – (3) of the GDPR, the company was obligated to inform all the individuals concerned about the data processing. However, the company informed only those individuals for whom it had email addresses. For the rest, the high operational costs made them ignore the information obligation.

Articles: Art. 14 GDPR

2019-03-26Private company€220KGDPRPolish National Personal Data Protection Office (UODO)PolandInformation obligation non-compliance
--

Articles: Art. 14 GDPR

2019-04-29Oslo Municipal Education Department€203KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to implement sufficient measures to ensure information security
The fine was issued on the following grounds: insufficient security measures est...

The fine was issued on the following grounds: insufficient security measures established on the app launched by an Oslo school. This app allowed students and parents to contact teachers in real-time. However, unauthorized access was detected, and unknown people gained access to personal data related to students and school employees.

Articles: Art. 32 GDPR

2019-06-03IDdesign A/S€201KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to comply with data processing principles
--

Articles: Art. 5 (1) e) GDPR, Art. 5 (2) GDPR

2019-06-03IDdesign A/S€201KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to comply with data processing principles
After an inspection in 2018 when irregularities were noticed, the company IDdesi...

After an inspection in 2018 when irregularities were noticed, the company IDdesign was fined. The company had overused the data of over 380.000 customers for a longer period of time than they were allowed to, as per the initial goals of the data processing. Moreover, the company had no clear deadlines regarding the deletion of personal data. The controller had also ignored the necessity of having a clear policy on the data deletion procedures.

Articles: Art. 5 (1) e) GDPR, Art. 5 (2) GDPR

2022-04-04Brussels Airport Zaventem€200KGDPRBelgian Data Protection Authority (APD)BelgiumNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR, Art. 6 (1) e) GDPR, Art. 9 (2) g) GDPR, Art. 12 GDPR, Art. 13 (1) c) GDPR, Art. 13 (2) e) GDPR, Art. 35 (1), (3), (7) b) GDPR

2019-10-07Telecommunication Service Provider€200KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to comply with data processing principles
Despite the clear refusal of telemarketing calls by the customers, the company p...

Despite the clear refusal of telemarketing calls by the customers, the company proceeded to ignore this because of technical errors.

Articles: Art. 5 (1) c) GDPR, Art. 25 GDPR

2022-02-01XFERA MOVILES, S.A.€200KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR

PreviousPage 10 of 82Next