Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2021-07-12 | Telefonica Moviles Espana, S.A.U. | €45K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 GDPR |
| 2022-07-07 | Senseonics Inc. | €45K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), b), f) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 27 GDPR |
| 2020-07-31 | Vodafone España SAU | €45K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2021-02-11 | Istituti ospedalieri bergamaschi | €45K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) a), f) GDPR, Art. 9 GDPR, Art. 32 GDPR |
| 2020-01-07 | Vodafone Espana | €44K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | The company was fined because it sent a contract that included the name and addr...The company was fined because it sent a contract that included the name and address and contact details of a client to a third party by accident. Articles: Art. 5 (1) f) GDPR |
| 2020-01-07 | Vodafone Espana | €44K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR |
| 2020-02-14 | Vodafone España | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-03-03 | Vodafone España | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-11-11 | Vodafone España, SAU | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2022-05-24 | Alquiler Seguro SA | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDP |
| 2022-05-17 | Vodafone Espana, S.A.U. | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2020-02-14 | Vodafone España | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | An individual reported having had access to the personal data to third parties i...An individual reported having had access to the personal data to third parties in their personal Vodafone profile. Articles: Art. 32 GDPR |
| 2020-11-16 | Vodafone España, SAU | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2022-08-02 | Banco Bilbao Vizcaya Argentaria S.L. | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 GDPR |
| 2020-03-03 | Vodafone España | €42K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | A client’s personal data was accessed without authorization. The AEPD expl...A client’s personal data was accessed without authorization. The AEPD explained that this happened due to lack of technical and organizational measures taken by the company to ensure information security. Articles: Art. 32 GDPR |
| 2019-09-27 | Slovak Telekom | €40K | GDPR | Slovak Data Protection Office | Slovakia | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2023-02-20 | Vodafone | €40K | GDPR | Hellenic Data Protection Authority (HDPA) | Greece | Insufficient fulfilment of data breach notification obligations | --Articles: Art. 15 GDPR, Art. 33 GDPR |
| 2020-07-20 | Iberia Lae SA Operadora Unipersonal | €40K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-cooperation with Data Protection Authority | --Articles: Art. 58 GDPR |
| 2022-04-28 | Il Sole 24 Ore S.p.a. | €40K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 9 GDPR, Art. 12 GDPR |
| 2021-09-14 | Vodafone Espana, S.A.U. | €40K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2021-01-01 | Unknown | €40K | GDPR | Slovak Data Protection Office | Slovakia | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 5 (2) GDPR, Art. 28 GDPR |
| 2020-03-03 | Vodafone España | €40K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR |
| 2021-09-06 | AC Omonia | €40K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-06-30 | Tusla Child and Family Agency | €40K | GDPR | Data Protection Authority of Ireland | Ireland | Failure to implement sufficient measures to ensure information security | --Articles: Art. 33 GDPR |
| 2021-11-23 | Vodafone Espana, SAU | €40K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |