Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,014 fines found

Total: $6.2B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2021-09-02Meta Platforms€225.0MGDPRData Protection Authority of IrelandIrelandNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a)

2021-09-02Meta Platforms€225.0MGDPRIreland DPCIrelandconsent
Lack of transparency about data sharing with Facebook.

Lack of transparency about data sharing with Facebook.

Articles: Art. 5(1)(a), Art. 12, Art. 13, Art. 14

2019-09-04Google$170.0MCOPPAFTCUnited Stateschildren
YouTube illegally collected personal information from children without parental ...

YouTube illegally collected personal information from children without parental consent, targeting ads to viewers of child-directed channels.

2025-09-01SHEIN€150.0MGDPRFrance CNILFranceconsent
Placing cookies without consent and non-functional opt-outs.

Placing cookies without consent and non-functional opt-outs.

Articles: Art. 5, Art. 6

2025-09-01SHEIN€150.0MGDPRFrance CNILFranceconsent
Placing cookies without consent and non-functional opt-outs.

Placing cookies without consent and non-functional opt-outs.

Articles: Art. 5, Art. 6

2025-09-01Google€125.0MGDPRFrance CNILFranceconsent
Cookie consent failures at account creation.

Cookie consent failures at account creation.

Articles: Art. 5, Art. 6

2025-09-01Google€125.0MGDPRFrance CNILFranceconsent
Cookie consent failures at account creation.

Cookie consent failures at account creation.

Articles: Art. 5, Art. 6

2021-12-31Google€90.0MGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 82 loi Informatique et Libertes

2021-12-31Google€60.0MGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 82 loi Informatique et Libertes

2021-12-31Meta Platforms€60.0MGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 82 loi Informatique et Libertes

2019-01-21Google€50.0MGDPRFrench Data Protection Authority (CNIL)FranceSeveral
--

Articles: Art. 13 GDPR, Art. 14 GDPR, Art. 6 GDPR, Art. 4 GDPR, Art. 5 GDPR

2019-01-21Google€50.0MGDPRFrench Data Protection Authority (CNIL)FranceSeveral
The French NGO “La Quadrature du Net” and the Austrian organization “None Of You...

The French NGO “La Quadrature du Net” and the Austrian organization “None Of Your Business” complained about the creation of a Google account related to the configuration of the Android system in a mobile phone. A fine of 50 million euros was issued because the following principles were not observed: the principle of transparency (Art. 5 GDPR), the sufficiency of information (Art.13 / 14 GDPR), and the presence of legal basis (Art. 6 GDPR).

Articles: Art. 13 GDPR, Art. 14 GDPR, Art. 6 GDPR, Art. 4 GDPR, Art. 5 GDPR

2024-02-01Blackbaud$49.5MFTC Act Section 5FTCUnited Statesdata_breach
Cloud software company settled with FTC and 49 state AGs after 2020 data breach.
2025-01-15Vodafone Germany€45.0MGDPRGermany BfDIGermanydata_breach
Vendor security failures and inadequate data controls.

Vendor security failures and inadequate data controls.

Articles: Art. 32

2025-01-01Vodafone Germany€45.0MGDPRGermany BfDIGermanydata_breach
Vendor security failures and inadequate data controls.

Vendor security failures and inadequate data controls.

Articles: Art. 32

2023-06-15Criteo€40.0MGDPRFrance CNILFranceconsent
Failed to verify consent before processing data for personalized advertising.

Failed to verify consent before processing data for personalized advertising.

Articles: Art. 7, Art. 15, Art. 17, Art. 26

2023-06-15Criteo€40.0MGDPRFrance CNILFranceconsent
Ad-tech company failed to verify consent before processing data for personalized...

Ad-tech company failed to verify consent before processing data for personalized advertising.

Articles: Art. 7, Art. 15, Art. 17, Art. 26

2020-10-01H&M Hennes & Mauritz Online Shop A.B. & Co. KG€32.3MGDPRData Protection Authority of HamburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2024-09-03Clearview AI€30.5MGDPRNetherlands APNetherlandsconsent
Built illegal facial recognition database with Dutch citizens photos.

Built illegal facial recognition database with Dutch citizens photos.

Articles: Art. 5, Art. 6, Art. 9, Art. 14, Art. 27

2023-05-31Amazon$30.8MCOPPAFTCUnited Stateschildren
Alexa retained children voice recordings indefinitely ($25M). Ring employees acc...

Alexa retained children voice recordings indefinitely ($25M). Ring employees accessed customer video feeds ($5.8M).

2020-02-01TIM - Telecom Provider€27.8MGDPRItalian Data Protection Authority (Garante)ItalyNon-cooperation with Data Protection Authority
A huge fine of €27,8 million was issued to the Italian telecom company TIM. The ...

A huge fine of €27,8 million was issued to the Italian telecom company TIM. The Italian Data Protection Authority (Garante) revealed that TIM was fined due to numerous unlawful data processing activities related to marketing and advertising, which included unsolicited promotional calls and prize competitions in which data subjects were entered without consent.One of the reasons for the large fine was the fact that the unlawful data processing activities involved several million individuals. One individual, for example, was called a total of 155 times in a month while TIM refused to add the affected individual on a no-call list even after several requests. The DPA determined that the company lacked control over the call centers and did not have adequate measures to add people to no-call lists.TIM also did not provide accurate and detailed enough privacy policies and data processing policies, and as such consumers were not efficiently informed about the data collected and processed. The company’s management of data breaches was also not efficient according to Garante.Besides the fine, Garante also imposed 20 corrective measures according to Art. 58(2) GDPR which prohibits TIM from processing marketing-related data of those individuals who have refused to receive promotional calls, individuals who asked to be blacklisted and individuals who are not clients of TIM.The company was also forbidden from using customer data collected from the “My Tim”, “Tim Personal” and “Tim Smart Kid” apps.

Articles: Art. 58(2) GDPR

2020-01-15TIM - Telecom Provider€27.8MGDPRItalian Data Protection Authority (Garante)ItalyNon-cooperation with Data Protection Authority
--

Articles: Art. 58(2) GDPR

2021-12-16Enel Energia S.p.A.€26.5MGDPRItalian Data Protection Authority (Garante)ItalyVarious offences
--

Articles: Art. 5 (1) a), d) GDPR, Art. 5 (2) GDPR, Art. 6 (1) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 21 GDPR, Art. 24 GDPR, Art. 25 (1) GDPR, Art. 30 GDPR, Art. 31 GDPR, Art. 130 (1), (2), (4) Codice della privacy

2020-10-16British Airways€22.0MGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2020-10-30Marriott International, Inc€20.4MGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

PreviousPage 2 of 81Next