Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2022-04-04Brussels Airport Charleroi€100KGDPRBelgian Data Protection Authority (APD)BelgiumNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), b) GDPR, Art. 6 (1) c) GDPR, Art. 6 (3) GDPR, Art. 9 (2) i) GDPR, Art. 12 (1) GDPR, Art. 13 (1) c) GDPR, Art. 13 (2) e) GDPR, Art. 35 (1), (7) GDPR

2019-06-24EE€100KGDPRInformation CommissionerUnited KingdomNon-compliance with the right of consent
--

Articles: Art.14 GDPR

2022-12-28Vodafone Espana, S.A.U.€100KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2019-10-24Food company€100KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 32 GDPR

2020-12-01Azeeta.ee e-apteek€100KGDPREstonian Data Protection AuthorityEstoniaNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2022-05-26Intesa Sanpaolo S.p.A.€100KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), f) GDPR, Art. 6 GDPR

2019-10-24Food company€100KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
Upon creation of an applicant portal where interested parties could apply their ...

Upon creation of an applicant portal where interested parties could apply their documents for a job, the food company failed to encrypt the applicant portal. The transmission of the data had no encryption and the data storage was completely unencrypted and offered no password-protected security systems. Moreover, the data was linked to Google, so anyone could find the applicants’ documents and retrieve them after a simple Google search.

Articles: Art. 5 GDPR, Art. 32 GDPR

2020-12-01Südameapteegi e-apteek€100KGDPREstonian Data Protection AuthorityEstoniaNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-05-22Posti Group Oyj€100KGDPRDeputy Data Protection OmbudsmanFinlandFailure to comply with processing principles
--

Articles: Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 15 GDPR

2023-03-16ORANGE ESPAGNE S.A.U.€100KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR

2021-11-24Norwegian State Pension Fund (SPK)€98KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c), e) GDPR, Art. 6 (1) GDPR, Art. 9 (2) GDPR

2020-12-16Unknown€97KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR, Art. 6 (1) GDPR, Art. 9 (1) GDPR, Art. 12 GDPR

2021-08-03Vodafone Espana, S.A.U.€96KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) GDPR, Art. 17 GDPR

2021-01-04Innovasjon Norge€96KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to comply with data processing principles
--

Articles: Art. 5 (1) GDPR, Art. 6 (1) GDPR

2023-01-05Premom (Easy Healthcare)$100KFTC Act Section 5FTCUnited Statesconsent
Fertility app shared health data with Google and AppsFlyer despite privacy promi...

Fertility app shared health data with Google and AppsFlyer despite privacy promises.

2019-05-23Organizer of SZIGET festival and VOLT festival€92KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryNon-compliance with lawful basis for data processing and information obligation non-compliance
--

Articles: Art. 6 GDPR, Art. 5 (1) b) GDPR, Art. 13 GDPR

2019-05-23Organizer of SZIGET festival and VOLT festival€92KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryNon-compliance with lawful basis for data processing and information obligation non-compliance
The subjects had not been informed about the data processing, and the data contr...

The subjects had not been informed about the data processing, and the data controllers had not complied with the principle of purpose limitation.

Articles: Art. 6 GDPR, Art. 5 (1) b) GDPR, Art. 13 GDPR

2022-06-09Tavistock & Portmann NHS Foundation Trust€91KGDPRInformation Commissioner (ICO)United KingdomFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2022-03-08Retail company€89KGDPRCroatian Data Protection Authority (AZOP)Croatia Failure to implement sufficient measures to ensure information security
--

Articles: Art 32 (1) b) and d) GDPR, Art 32 (2) GDPR, Art 32 (4) GDPR

2022-05-09Otavamedia Oy€85KGDPRDeputy Data Protection OmbudsmanFinlandFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR, Art. 12 (1), (2), (3), (4), (6) GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 25 GDPR

2023-04-04BANCO BILBAO VIZCAYA ARGENTARIA, S.A€84KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR, Art. 15 GDPR

2021-05-13Comune di Bolzano€84KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), c) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 13 GDPR, Art. 35 GDPR

2021-07-09Medicals Nordic I/S€81KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GPDR

2022-09-12Coin Dealer€81KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b) GDPR, Art. 6 (1) GDPR, Art. 7 (2) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR

2022-01-01Beauty salon€81KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryUnknown
--

Articles: Unknown

PreviousPage 14 of 82Next