Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2019-11-13 | Social Insurance Agency | €50K | GDPR | Slovak Data Protection Office | Slovakia | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2023-03-21 | SOCIEDAD ESPANOLA DE RADIODIFUSION, S.L. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR |
| 2021-01-27 | Azienda USL della Romagna | €50K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) a), d), f) GDPR, Art. 9 GDPR, Art. 32 (1) b) GDPR |
| 2020-04-28 | Proximus SA | €50K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Failure to implement sufficient measures to ensure information security | --Articles: Art. 31 GDPR, Art. 58 GDPR, Art. 37 GDPR |
| 2019-08-30 | Medical Company | €50K | GDPR | Austrian Data Protection Authority (DSB) | Austria | Information obligation non-compliance | --Articles: Art. 13 GDPR, Art. 37 GDPR |
| 2021-07-08 | Caixabank S.A. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) f) GDPR |
| 2021-01-27 | Azienda Ospedaliero Universitaria di Parma | €50K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GPDR, Art. 9 GDPR |
| 2019-10-31 | Menzis | €50K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with lawful basis for data processing | The marketing staff of the health insurance company Menzis had access to patient...The marketing staff of the health insurance company Menzis had access to patients’ data. Articles: Art. 5 GDPR |
| 2022-09-21 | Property development company | €50K | GDPR | Data Protection Authority of Baden-Wuerttemberg | Germany | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR, Art. 14 GDPR |
| 2019-03-01 | N26 | €50K | GDPR | Data Protection Authority of Berlin | Germany | Non-compliance with lawful basis for data processing | A bank had retained the personal data of former customers in order to create a b...A bank had retained the personal data of former customers in order to create a blacklist. Apparently, they wanted to prevent those customers from opening up new accounts at their bank because they were suspected of money laundering. While the bank wanted to hand-wave away this unlawful act by appealing to the German Banking Act, the Berlin Supervisory Authority found this to be illegal. Articles: Art. 6 GDPR |
| 2020-10-26 | Conseguridad SL | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | No data protection officer appointed | --Articles: Art. 37 GDPR |
| 2021-12-14 | IZA OBRAS Y PROMOCIONES, S.A. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2021-01-27 | Family Service / N.D.P.K. nv. | €50K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Multiple | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 13 GDPR, Art. 24 GDPR, Art. 25 GDPR, Art. 28 GDPR |
| -- | Unknown | €50K | GDPR | Data Protection Authority of Brandenburg | Germany | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 15 GDPR, Art. 28 GDPR |
| 2019-03-01 | N26 | €50K | GDPR | Data Protection Authority of Berlin | Germany | Non-compliance with lawful basis for data processing | --Articles: Art. 6 GDPR |
| 2023-03-21 | CONECTA5 TELECINCO, S.A.U. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art 5 (1) c) GDPR |
| 2020-10-09 | Centro de Investigación y Estudio para la Obesidad, SL | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2023-03-21 | EL DIARIO DE PRENSA DIGITAL SL. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR |
| 2023-03-21 | TITANIA COMPANIA EDITORIAL, S.L. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR |
| 2023-04-03 | 20 MINUTOS EDITORA, S.L. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2019-10-31 | Menzis | €50K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR |
| 2021-07-06 | Region Stockholm | €50K | GDPR | Data Protection Authority of Sweden | Sweden | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR, Art. 14 GDPR |
| 2020-08-28 | Bankia S.A. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) b) GDPR |
| 2019-11-13 | Social Insurance Agency | €50K | GDPR | Slovak Data Protection Office | Slovakia | " | https://www.etrend.sk/ekonomika/socialna-poistovna-porusila-gdpr-pokutu-50-tisic...https://www.etrend.sk/ekonomika/socialna-poistovna-porusila-gdpr-pokutu-50-tisic-eur-nechce-zaplatit.html Articles: "Art. 32 GDPR |
| 2021-01-21 | Alterna Operador Integral S.L. | €50K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) b) GDPR |