Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,014 fines found

Total: $6.2B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2022-02-10Clearview AI€20.0MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b), e) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 27 GDPR

2022-05-23Clearview AI€20.0MGDPRGreece HDPAGreececonsent
Unlawful processing of biometric data through facial recognition without consent...

Unlawful processing of biometric data through facial recognition without consent.

Articles: Art. 5, Art. 6, Art. 9

2022-07-13Clearview AI€20.0MGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 27 GDPR

2022-03-09Clearview AI€20.0MGDPRItaly GaranteItalyconsent
Facial recognition company unlawfully processed biometric data of people in Ital...

Facial recognition company unlawfully processed biometric data of people in Italy.

Articles: Art. 5, Art. 6, Art. 9, Art. 14, Art. 27

2022-10-17Clearview AI€20.0MGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 12 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 31 GDPR

2023-06-05Microsoft$20.0MCOPPAFTCUnited Stateschildren
Collected personal information from children creating Xbox accounts without noti...

Collected personal information from children creating Xbox accounts without notifying parents or obtaining consent.

2025-01-15HoganWillig/Genshin Impact (Cognosphere)$20.0MCOPPAFTCUnited Stateschildren
Genshin Impact developer settled FTC charges of collecting data from children wi...

Genshin Impact developer settled FTC charges of collecting data from children without consent.

2019-10-23Austrian Post€18.0MGDPRAustrian Data Protection Authority (DSB)AustriaNon-compliance with lawful basis for data processing
The Austrian Post had sold detailed personal profiles of approximately three mil...

The Austrian Post had sold detailed personal profiles of approximately three million Austrians to various companies and political parties. The profiles contained names, addresses, political predilections, and even intimate details.

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR

2022-03-15Meta Platforms€17.0MGDPR Data Protection Authority of IrelandIrelandFailure to comply with data processing principles
--

Articles: Art. 5 (2) GDPR, Art. 24 (1) GDPR

2020-07-13Wind Tre S.p.A.€16.7MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 12 GDPR. Art. 24 GDPR, Art. 25 GDPR

2024-02-22Avast$16.5MFTC Act Section 5FTCUnited Statesconsent
Antivirus company sold browsing data through subsidiary Jumpshot despite privacy...

Antivirus company sold browsing data through subsidiary Jumpshot despite privacy promises.

2019-10-30Deutsche Wohnen SE€14.5MGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to comply with data processing principles
The company collected data from multiple tenants without providing the option to...

The company collected data from multiple tenants without providing the option to remove that data once it was no longer required. This led to the company retaining personal data of tenants for years (salary statements, social security insurances, health insurances, tax insurances, bank statements). The Berlin Data Commissioner issued a fine of €14,500,000.

Articles: Art. 5 GDPR, Art. 25 GDPR

2023-04-04TikTok€14.5MGDPRInformation Commissioner (ICO)United KingdomFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 12 GDPR, Art. 13 GDPR

2020-11-12Vodafone Italia S.p.A€12.3MGDPRItalian Data Protection Authority (Garante)ItalyMultiple
--

Articles: Art. 5 (1), (2) GDPR, Art. 6 (1) GDPR, Art. 7 GDPR, Art. 15 (1) GDPR, Art. 16 GDPR, Art. 21 GDPR, Art. 24 GDPR, Art. 25 (1) GDPR, Art. 32 GDPR, Art. 33 GDPR

2021-01-08notebooksbilliger.de€10.4MGDPRData Protection Authority of NiedersachsenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2022-01-06Google€10.0MGDPRFrance CNILFranceconsent
Cookie consent mechanism did not allow users to refuse cookies as easily as acce...

Cookie consent mechanism did not allow users to refuse cookies as easily as accepting them.

Articles: Art. 82

2022-05-18Google€10.0MGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 17 GDPR

2019-12-091&1 Telecom GmbH€9.6MGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyFailure to implement sufficient measures to ensure information security
--

Articles: <a href="https://www.privacy-regulation.eu/en/32.htm">Art. 32 GDPR</a>

2019-12-091&1 Telecom GmbH€9.6MGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyFailure to implement sufficient measures to ensure information security
The telecom company 1&#038;1 Telecom GmbH was fined with €9,550,000 after it cam...

The telecom company 1&#038;1 Telecom GmbH was fined with €9,550,000 after it came to light that sensitive customer information could be obtained by phone by anyone by just telling a client&#8217;s name and date of birth. This could have permitted anyone to obtain the personal information of any customer in case they knew their name and date of birth. The BfDI considered that the company failed to implement the necessary technical measures to ensure the protection of personal data. The BfDI further revealed that the fine was intended to be much larger but was eventually decreased due to the cooperation of the company during the investigation.

Articles: Art. 32 GDPR

2021-09-28Austrian Post€9.5MGDPRAustrian Data Protection Authority (DSB)AustriaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2025-12-01Disney$10.0MCOPPAFTCUnited Stateschildren
Failed to manage YouTube channels used by children in compliance with COPPA.
2022-05-18Clearview AI€9.0MGDPRInformation Commissioner (ICO)United KingdomFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), e) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 16 GDPR, Art. 17 GDPR, Art. 21 GDPR, Art. 22 GDPR, Art. 35 GDPR

2019-12-11Eni Gas e Luce€8.5MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 17 GDPR, Art. 21 GDPR

2020-01-17Eni Gas e Luce€8.5MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
The Italian Data Protection Authority (Garante) imposed two fines of €11,5 milli...

The Italian Data Protection Authority (Garante) imposed two fines of €11,5 million total on Eni Gas and Luce because of the unlawful processing of personal data during an advertising campaign as well as for the activation of unsolicited contracts. This first fine of €8,5 million was issued for the unlawful processing of personal data in the context of a marketing campaign. The company made promotional calls without the consent of the contacted people and refused to acknowledge people&#8217;s wishes to be added onto a &#8220;do not contact&#8221; list. The company also did not provide an opt-out procedure for these unsolicited calls. The DPA also determined that the company lacked sufficient technical and organizational measures to protect users&#8217; personal data. Data was also processed longer than the allowed retention period. According to the DPA, some data was also collected from third party entities that did not have consent from the data subjects to disclose that data.

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 17 GDPR, Art. 21 GDPR

2022-01-14REWE International AG€8.0MGDPRAustrian Data Protection Authority (DSB)AustriaVarious offences
--

Articles: Art. 5 (1) c) GDPR, others

PreviousPage 3 of 81Next