Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2019-10-23 | Vodafone Espana | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) f) GDPR |
| 2020-02-03 | Xfera Moviles S.A. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | The Spanish Data Protection Authority revealed that Xfera Moviles S.A. has unlaw...The Spanish Data Protection Authority revealed that Xfera Moviles S.A. has unlawfully processed data that included bank details, customer address as well as name of various individuals. Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-09-22 | GLP Instalaciones 86, SL | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-10-16 | Xfera Moviles S.A. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-09-25 | Xfera Moviles S.A. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 1970-01-01 | Gestion De Cobros Yo Cobro SL | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | An online credit agency transferred an undue credit claim to a debt collecting a...An online credit agency transferred an undue credit claim to a debt collecting agency, providing the agency with the subject’s email address. However, the debt collecting agency sent emails to the company where the subject worked. This institutional email was accessible by all employees of that company. The online credit agency had not provided these emails. Articles: Art. 5 (1) f) GDPR |
| 2019-10-16 | Xfera Moviles S.A. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | The company had unlawfully processed the personal data despite the subject’s req...The company had unlawfully processed the personal data despite the subject’s request to stop doing so. Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-11-19 | Corporacion RTVE | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-09-17 | Vodafone España, SAU | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2021-12-02 | Irish Teacher Council | €60K | GDPR | Data Protection Authority of Ireland | Ireland | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) GDPR, Art. 32 (1) GDPR, Art. 33 GDPR |
| 2020-08-04 | Vodafone España, SAU | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2021-03-16 | Vodafone Espana | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR |
| 2021-07-27 | PRA Iberia S.L. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR, Art. 15 GDPR |
| 2021-12-16 | Banco Bilbao Vizcaya Argentaria S.A. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 GDPR |
| 2019-10-23 | Vodafone Espana | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | Invoicing details of a customer were sent to a third party customer during an in...Invoicing details of a customer were sent to a third party customer during an invoicing complaint. Articles: Art. 5 (1) f) GDPR |
| 2019-11-06 | Vodafone Espana | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | Vodafone sent customers invoicing details to a third party after a customer invo...Vodafone sent customers invoicing details to a third party after a customer invoicing complaint. The fine was originally determined to be €75,000 but later reduced to €60,000 after the quick cooperation of the company. Articles: Art. 6 GDPR |
| -- | ENDESA | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDPR |
| 2019-08-16 | Avon Cosmetics | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 GDPR |
| 2019-11-19 | Xfera Moviles S.A. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-11-19 | Xfera Moviles S.A. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | A private individual received an SMS from Xfera Móviles which was actually addre...A private individual received an SMS from Xfera Móviles which was actually addressed to a different person and which included personal details of that third party person. The information included personal details as well as login details to the Xfera Móviles website for the third party person. Articles: Art. 32 GDPR |
| 2019-11-21 | Viaqua Xestión SA | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 GDPR |
| 2020-03-04 | Vodafone España, S.A.U. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2021-02-11 | Roma Servizi per La Mobilita S.r.L. | €60K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-10-23 | Vodafone Espana, S.A.U. | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDPR |
| 2019-08-16 | Avon Cosmetics | €60K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | A client had complained that AVOND COSMETICS hadn’t observed the law when it pro...A client had complained that AVOND COSMETICS hadn’t observed the law when it processed his personal data erroneously. His identity wasn’t properly verified, which led to the erroneous matching of that client with a register of claims. As a result, the client wasn’t able to work with his bank. Moreover, a third-party utilized the client’s personal data unlawfully. Articles: Art. 6 GDPR |