Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-03-03Vodafone España€24KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
The company sent two SMS messages to a person informing them about the rate chan...

The company sent two SMS messages to a person informing them about the rate change of a contract as well as the purchase of a mobile phone. The customer did not consent to the processing of their personal data and Vodafone sent the text messages without prior written consent from the customer.

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-08-31Surveyor General of Poland (‘GKK’) €23KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-07-15Office for geodesy and cartography€22KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR, Art. 58 GDPR

2020-12-10Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics)€22KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryMultiple
--

Articles: Art. 5 (1) a), b), c) GDPR, Art. 6 (1) GDPR, Art. 9 (2) GDPR, Art. 12 GDPR, Art. 13 GDPR

2019-10-19Vodafone Espana€21KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
Vodafone had processed personal data of the claimant (bank details, name, surnam...

Vodafone had processed personal data of the claimant (bank details, name, surname and national identification number) years after the contractual relationsid had ended. The fine of EUR 35.000 was reduced to EUR 21.000.Vodafone processed the personal details of a former client, details that included first name, last name and national ID number, several years after their contractual relationship had ended. The initial fine was set at €35,000 but it was reduced to €21,000 due to cooperation on behalf of Vodafone Espana.

Articles: Art. 6 (1) GDPR

2019-10-19Vodafone Espana€21KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2020-03-10Addiction Medicine Center€21KGDPRIcelandic Data Protection Authority ('Persónuvernd') IcelandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2020-03-10Addiction Medicine Center€21KGDPRIcelandic Data Protection Authority ('Persónuvernd')IcelandFailure to implement sufficient measures to ensure information security
A former employee of National Center of Addiction Medicine (‘SAA’) r...

A former employee of National Center of Addiction Medicine (‘SAA’) received boxes that contained personal belongings that he supposedly left there but personal data and health records of 252 former patients and documents with the names of around 3,000 individuals who once participated in an alcohol and drug abuse rehabilitation program.

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2020-08-04PrivatBo A.M.B.A€20KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 32 GDPR

2022-08-17Danish Immigration Agency€20KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2021-12-16Corradi s.r.l.€20KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 13 GDPR, Art. 157 Codice della privacy

2018-11-21Knuddels.de€20KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2021-12-16FCA Italy s.p.a.€20KGDPRItalian Data Protection Authority (Garante)Italy Non-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR

2022-05-13Synlab Med srl€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), c) GDPR, Art. 9 GDPR, Art. 2-ter Codice della privacy

2022-10-03PIRAEUS BANK S.A.€20KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 13 GDPR

2019-06-13Uniontrad Company€20KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
Complaints from the employees were received that they were unlawfully filmed in ...

Complaints from the employees were received that they were unlawfully filmed in the workspace. The company failed to observe the rules pertaining to the unlawful filming of employees all the time, and the necessity of providing information related to the data processing to the employees. The CNIL performed an audit in October 2018, and the company wasn’t observing the data protection laws. Therefore, fines were issued.

Articles: Art. 5 (1) c) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 32 GDPR

2020-02-03Iberia Lineas Aereas€20KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
The company continued to send emails to individuals even after the affected indi...

The company continued to send emails to individuals even after the affected individuals have requested to be removed from the company’s database or be added to a “no-contact” list.

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 21 GDPR

2022-05-12Bazar di Hu Xiaoyan€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 13 GDPR, Art. 114 Codice della privacy

2020-01-01Unknown€20KGDPRData Protection Commissioner of MaltaMaltaNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 13 GDPR, Art. 15 GDPR

2019-06-13Uniontrad Company€20KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 32 GDPR

2019-10-09Vreau Credit SRL€20KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR, Art. 33 GDPR

2020-11-06Xfera Moviles S.A.€20KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 31 GDPR

2019-10-09Vreau Credit SRL€20KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
The Company sent personal information through the WhatsApp platform to Raiffeise...

The Company sent personal information through the WhatsApp platform to Raiffeisen Bank in order to facilitate the assessment of personal scores. The results were returned on the same platform.

Articles: Art. 32 GDPR, Art. 33 GDPR

2022-01-01Telecommunications company€20KGDPRCroatian Data Protection Authority (AZOP)CroatiaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR, Art. 5 (1) d) GDPR

2022-11-10Sporitalia€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 9 GDPR, Art. 13 GDPR, Art. 30 (1) c) GDPR

PreviousPage 29 of 82Next