Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-07-10Xfera Moviles S.A.€55KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 5 GDPR, Art. 32 GDPR

2022-12-15Azienda Universitaria Friuli Centrale€55KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 9 GDPR, Art. 14 GDPR, Art. 35 GDPR, Art. 2-sexies Codice della privacy

2020-10-23Deichmann KFT€55KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR, Art. 15 GDPR, Art. 18 (1) c) GDPR, Art. 25 GDPR

2020-12-11Umeå University€54KGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 (1), (2) GDPR

2021-01-04Vodafone Espana, S.A.U.€54KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) d), f) GDPR

2021-07-07Nordbornholms Byggeforretning Aps€54KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-09-08Midtjylland Region€54KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2022-01-19PIKA Sp. z o.o.€53KGDPRPolish National Personal Data Protection Office (UODO)Poland Non-compliance with subjects' rights protection safeguards
--

Articles: Art. 28 (3) c), f) GDPR, Art. 32 (1), (2) GDPR

2021-12-16Motor insurance center€52KGDPRDeputy Data Protection OmbudsmanFinlandNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), c) GDPR, Art. 25 (2) GDPR

2021-11-23Icelandic Ministry of Industry and Innovation€51KGDPRIcelandic Data Protection Authority ('Persónuvernd')IcelandNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 13 GDPR, Art. 25 GDPR, Art. 28 GDPR, Art. 32 GDPR

2019-01-01Meta Platforms€51KGDPRData Protection Authority of HamburgGermanyFailure to appoint a data protection officer
The German branch of Facebook was fined by €51,000 because it failed to appoint ...

The German branch of Facebook was fined by €51,000 because it failed to appoint a data protection officer. Facebook argued that it did in fact appoint a data protection officer in Ireland who acted as a data protection officer for all the local European Facebook branches. The Data Protection Authority of Hamburg, however, argued that Facebook did not notify the German authority about this appointment, and as such, the fine is valid. The reason the fine was relatively small was that Facebook did, after all, appoint a DPO but failed to notify German authorities. The fine was given to Facebook Germany GmbH, which is the local German branch of the company.The fine was issued sometimes in 2019 but was only made public by the Data Protection Authority of Hamburg in February 2020. The exact date of the fine was not revealed.

Articles: Art. 37 GDPR

2019-01-01Meta Platforms€51KGDPRData Protection Authority of HamburgGermanyFailure to appoint a data protection officer
--

Articles: Art. 37 GDPR

2021-01-21Alterna Operador Integral S.L.€50KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) b) GDPR

2019-03-01N26€50KGDPRData Protection Authority of BerlinGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2022-01-13Intellexa SA€50KGDPRHellenic Data Protection Authority (HDPA)GreeceNon-cooperation with Data Protection Authority
--

Articles: Art. 31 GDPR

2022-04-07Palumbo Superyacht Ancona s.r.l.€50KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), e) GDPR, Art. 13 GDPR, Art. 12 (3) GDPR, Art. 15 GDPR, Art. 157 Codice della privacy, Art. 166 (2) Codice della privacy

2020-02-03Vodafone España, S.A.U.€50KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR

2022-05-25Roularta Media Group€50KGDPRBelgian Data Protection Authority (APD)BelgiumFailure to comply with data processing principles
--

Articles: Art. 5 (1) e) GDPR, Art. 5 (2) GDPR, Art. 6 (1) a) GDPR, Art. 7 (1), (3) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 24 GDPR

2019-04-24Movimento 5 Stelle Party€50KGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-08-30Medical Company€50KGDPRAustrian Data Protection Authority (DSB)AustriaInformation obligation non-compliance
The company was fined because it had refused to comply with the obligation of ap...

The company was fined because it had refused to comply with the obligation of appointing a data protection officer.

Articles: Art. 13 GDPR, Art. 37 GDPR

--Unknown€50KGDPRData Protection Authority of BrandenburgGermanyNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 15 GDPR, Art. 28 GDPR

2022-05-26Azienda sanitaria uniersitaria Friuli Occidentale€50KGDPRItalian Data Protection Authority (Garante)ItalyUnknown
--

Articles: Unknown

2022-06-16SA Rossel & Cie€50KGDPRBelgian Data Protection Authority (APD)BelgiumNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) a) GDPR, Art. 7 (1) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR, Art. 14 GDPR

2020-02-03Vodafone España, S.A.U.€50KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
Vodafone España sent invoices of a client that contained personal data such as n...

Vodafone España sent invoices of a client that contained personal data such as name, ID card number, and address to their neighbor.

Articles: Art. 5 GDPR

2023-03-21SOCIEDAD ESPANOLA DE RADIODIFUSION, S.L.€50KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR

PreviousPage 20 of 82Next