Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2023-03-23Bolzano Municipality€30KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 25 GDPR, Art. 32 GDPR, Art. 33 GDPR

2021-10-08Orange Espagne, SAU€30KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) a) GDPR

2020-01-23Azienda Ospedaliero Universitaria Integrata di Verona (Hospital)€30KGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2021-12-02Ica s.r.l.€30KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2022-07-19DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A.€30KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 5 (2) GDPR, Art. 6 GDPR, Art. 12 (2) GDPR

2020-03-18Telefonica€30KGDPRSpanish Data Protection Authority (AEPD)SpainNon-cooperation with Data Protection Authority
--

Articles: Art. 58 GDPR

2019-10-01Vueling Airlines€30KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
Vueling Airlines made it impossible for users to access their website without ac...

Vueling Airlines made it impossible for users to access their website without accepting the cookies. Therefore, one couldn’t browse the website unless they accepted the cookies. The AEPD sanctioned the company with 30.000 euros

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-01-14Azienda sanitaria provinciale di Enna€30KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 GDPR

2023-02-22DISPLAY CONNECTORS, S.L.€30KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR

2019-01-01Vodafone Espana, S.A.U.€30KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2020-01-23Sapienza Università di Roma€30KGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2019-11-14Telefónica SA€30KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR

2020-12-15Uppsalahem AB€30KGDPRData Protection Authority of SwedenSwedenFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 (1) f) GDPR

2021-07-05Mermaids€29KGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 (1), (2) GDPR

2022-01-26Uppsala regional board€29KGDPRData Protection Authority of SwedenSwedenNon-compliance with lawful basis for data processing
--

Articles: Art. 32 (1) GDPR

2021-06-18Magyar Telekom Nyrt.€28KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) d) GDPR, Art. 6 (1) GDPR, Art. 12 (2), (3), (4) GDPR, Art. 17 (1) GDPR, Art. 25 GDPR

2019-07-24Debt collection agency€28KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2019-07-24Debt collection agency€28KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
A private individual complained to the Data Protection Commission of Bulgaria (K...

A private individual complained to the Data Protection Commission of Bulgaria (KZLD) that a debt collection agency has information about her accounts and status of those accounts with the purpose of collecting tax owned by the complainant. The KZLD concluded that the agency had no legal basis to obtain and process the data.

Articles: Art. 6 GDPR

2019-09-03National Revenue Agency€28KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
The National Revenue Agency was fined with €28,100 because of the unlawful proce...

The National Revenue Agency was fined with €28,100 because of the unlawful processing of personal data of a private individual. The personal data of the individual was unlawfully collected and used in an enforcement case against them in order to recover a tax debt of €86,000. The National Revenue Agency also collected bank account data of the affected individual from the Bulgarian National Bank. The Bulgarian DPA argued that this data was collected unlawfully by the National Revenue Agency. This is one of the very rare cases where a DPA fines a government institution for the unlawful processing of personal data.

Articles: Art 6 (1) GDPR, Art 58 (2) e) GDPR, Art 83 (5) a) GDPR

2019-09-03National Revenue Agency€28KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
--

Articles: Art 6 (1) GDPR, Art 58 (2) e) GDPR, Art 83 (5) a) GDPR

2022-11-16Raiffeisen Bank SA€28KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 25 (1) GDPR, Art. 32 (1), (2), (4) GDPR

2020-07-02Odin Flissenter AS€28KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-06-19Aquateknikk AS€28KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-11-23YAY ehf.€27KGDPRIcelandic Data Protection Authority ('Persónuvernd')IcelandNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 28 GDPR, Art. 32 GDPR

2019-02-26Telecommunication service provider€27KGDPRBulgarian Commission for Personal Data Protection (KZLD)BulgariaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 5 (1) a) GDPR

PreviousPage 27 of 82Next