Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2020-02-27 | Vodafone España | €120K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR |
| 2021-05-27 | Azienda Usl della Romagna | €120K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDPR, Art. 9 GDPR |
| 2022-12-15 | Eurosanita S.P.A. | €120K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 9 GDPR, Art. 32 GDPR |
| 2021-08-25 | Banco Bilbao Vizcaya Argentaria, S.A. | €120K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-04-29 | Oslo Municipal Education Department | €120K | GDPR | Norwegian Supervisory Authority (Datatilsynet) | Norway | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2021-01-04 | Unknown | €119K | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR, Art. 14 GDPR |
| 2022-01-19 | Santander Bank Polska S.A. | €117K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Insufficient fulfilment of data breach notification obligations | --Articles: Art. 34 (1) GDPR |
| 2022-03-10 | Tuckers Solicitors LLP | €115K | GDPR | Information Commissioner (ICO) | United Kingdom | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) f) GDPR |
| 2023-04-13 | Vodafone Espana, S.A.U. | €112K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2020-06-22 | Østfold HF Hospital | €112K | GDPR | Norwegian Supervisory Authority (Datatilsynet) | Norway | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2021-11-29 | UAB Prime Leasing | €110K | GDPR | Lithuanian Data Protection Authority (VDAI) | Lithuania | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) b), d) GDPR |
| 2021-12-09 | Limerick City and County Council | €110K | GDPR | Data Protection Authority of Ireland | Ireland | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 GDPR, Art. 12 GDPR, Art. 15 GDPR |
| 2021-09-29 | Danish Cancer Society | €107K | GDPR | Danish Data Protection Authority (Datatilsynet) | Denmark | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-12-03 | Rheinland-Pfalz Hospital | €105K | GDPR | Data Protection Authority of Rheinland-Pfalz | Germany | Non-compliance with lawful basis for data processing | The Data Protection Authority of Rheinland-Pfalz issued a fine of €105,000 after...The Data Protection Authority of Rheinland-Pfalz issued a fine of €105,000 after a hospital after a mixup of patients. As a consequence of this, wrong invoices were issues to the patients that released sensitive personal data. Articles: Art. 5 GDPR |
| 2019-12-03 | Rheinland-Pfalz Hospital | €105K | GDPR | Data Protection Authority of Rheinland-Pfalz | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-10-24 | Food company | €100K | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 GDPR, Art. 32 GDPR |
| 2020-12-01 | Apotheka e-apteek, Azeta.ee e-apteek, Südameapteegi e-apteek | €100K | GDPR | Estonian Data Protection Authority | Estonia | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-06-24 | EE | €100K | GDPR | Information Commissioner | United Kingdom | Non-compliance with the right of consent | --Articles: Art.14 GDPR |
| 2020-12-17 | Azienda Unita Sanitaria Locale Toscana Sud Est | €100K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) f) GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 28 GDPR, Art. 30 GDPR, Art. 32 GDPR, Art. 35 GDPR |
| 2019-06-24 | EE | €100K | GDPR | Information Commissioner | United Kingdom | Non-compliance with the right of consent | The Company sent marketing messages to over 2.5 million customers without their ...The Company sent marketing messages to over 2.5 million customers without their consent. The marketing message encouraged data subjects the “My EE” app to manage their accounts. Furthermore, the Company sent another batch of marketing messages to other customers afterward. Articles: Art.14 GDPR |
| 2020-12-01 | Azeeta.ee e-apteek | €100K | GDPR | Estonian Data Protection Authority | Estonia | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-12-01 | Südameapteegi e-apteek | €100K | GDPR | Estonian Data Protection Authority | Estonia | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-12-17 | Banca Transilvania SA | €100K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDPR, Art. 32 (1), (2) GDPR |
| 2022-04-04 | Brussels Airport Charleroi | €100K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a), b) GDPR, Art. 6 (1) c) GDPR, Art. 6 (3) GDPR, Art. 9 (2) i) GDPR, Art. 12 (1) GDPR, Art. 13 (1) c) GDPR, Art. 13 (2) e) GDPR, Art. 35 (1), (7) GDPR |
| 2022-12-01 | Lazio Region | €100K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 113 Codice della privacy, Art. 114 Codice della privacy |