Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2021-01-27Unknown€150KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-10-09Raiffeisen Bank SA€150KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2021-05-27Azienda Provinciale per i Servizi Sanitari di Trento€150KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1), f) GDPR, Art. 9 GDPR

2019-10-09Raiffeisen Bank SA€150KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
Raiffeisen Bank Romania did not observe the necessary security measures required...

Raiffeisen Bank Romania did not observe the necessary security measures required by the GDPR when it assessed the scores of individuals on the WhatsApp platform. The personal data was exchanged via WhatsApp.

Articles: Art. 32 GDPR

2022-04-28Tarento municipality€150KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 28 GDPR, Art. 35 GDPR

2023-01-19Dutch Social Insurance Institution (SVB)€150KGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1), (2) GDPR

2019-11-01Unknown€150KGDPRData State Inspectorate (DSI)LatviaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2019-11-01Unknown€150KGDPRData State Inspectorate (DSI)LatviaNon-compliance with lawful basis for data processing
No concrete details have been released at this point other than a fine of €150,0...

No concrete details have been released at this point other than a fine of €150,000 was imposed in November 2019. We will update this card once further information emerges.

Articles: Art. 6 GDPR

2019-12-19"Aegean Marine Petroleum Network Inc.€150KGDPRHellenic Data Protection Authority (HDPA)GreeceArt. 5 GDPR|Art. 6 GDPR|Art. 32 GDPR
http://www.dpa.gr/APDPXPortlets/htdocs/documentDisplay.jsp?docid=205,136,113,56,...

http://www.dpa.gr/APDPXPortlets/htdocs/documentDisplay.jsp?docid=205,136,113,56,60,108,243,88

Articles: "

2022-04-11BASER COMERCIALIZADORA DE REFERENCIA, S.A.€150KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 32 GDPR

2019-12-19Aegean Marine Petroleum Network Inc. €150KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 32 GDPR

2020-07-28Arp Hansel Hotel Group A/S€148KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) e) GDPR

2019-02-01Leave.EU & GoSkippy€140KGDPRInformation CommissionerUnited KingdomNon-compliance with the right of consent
Leave.EU subscriber emails contained marketing ads related to the GoSkippy servi...

Leave.EU subscriber emails contained marketing ads related to the GoSkippy services of the Eldon Insurance firm. The data subjects did not give their consent to this, hence the fine issued by the ICO.

Articles: Art.14 of the GDPR

2019-02-01Leave.EU & GoSkippy€140KGDPRInformation CommissionerUnited KingdomNon-compliance with the right of consent
--

Articles: Art.14 of the GDPR

2023-03-15Vodafone Espana, S.A.U.€136KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 32 GDPR

2021-08-05Insurance Company€135KGDPRNational Commission for Data Protection (CNPD)LuxembourgFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 32 (1) a), b) GDPR, Art. 33 (1), (5) GDPR

2020-05-03Telenor Norge AS€134KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2022-06-22Gyldendal A/S€134KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to comply with data processing principles
--

Articles: Art. 5 (1) e) GDPR

2022-07-13DKV Seguros y Reaseguros, S.A.E.€132KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR, Art. 33 GDPR

2019-06-27Unicredit Bank SA€130KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
The Company was issued a fine because it had failed to provide the necessary sec...

The Company was issued a fine because it had failed to provide the necessary security and organization measures in two cases. Firstly, it failed in the appropriate determination of the data processing means. Secondly, it failed in the appropriate implementation of necessary security safeguards, which led to the public disclosure of the personal data of over 337.042 people.

Articles: Art. 25 (1) GDPR, Art. 5 (1) c) GDPR

2019-06-27Unicredit Bank SA€130KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 25 (1) GDPR, Art. 5 (1) c) GDPR

2023-03-16CITYSCOOT€125KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR, Art. 28 (3) GDPR, Art. 82 Loi informatique et libertés

2022-03-08Energy company€124KGDPR Croatian Data Protection Authority (AZOP)Croatia Non-compliance with subjects' rights protection safeguards
--

Articles: Art. 15 (3) GDPR

2022-12-27Company€122KGDPRDeputy Data Protection OmbudsmanFinlandInsufficient fulfilment of information obligations
--

Articles: Art. 9 GDPR

2020-02-27Vodafone España€120KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
The company was not able to prove that an individual had given them consent to a...

The company was not able to prove that an individual had given them consent to access and process their personal data with the goal of opening a telephone contract. The AEPD further explained that the company unlawfully disclosed the affected person’s personal data to third party credit agencies.

Articles: Art. 5 GDPR

PreviousPage 12 of 82Next