Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2023-06-15Criteo€40.0MGDPRFrance CNILFranceconsent
Failed to verify consent before processing data for personalized advertising.

Failed to verify consent before processing data for personalized advertising.

Articles: Art. 7, Art. 15, Art. 17, Art. 26

2020-10-01H&M Hennes & Mauritz Online Shop A.B. & Co. KG€32.3MGDPRData Protection Authority of HamburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2024-09-03Clearview AI€30.5MGDPRNetherlands APNetherlandsconsent
Built illegal facial recognition database with Dutch citizens photos.

Built illegal facial recognition database with Dutch citizens photos.

Articles: Art. 5, Art. 6, Art. 9, Art. 14, Art. 27

2023-05-31Amazon$30.8MCOPPAFTCUnited Stateschildren
Alexa retained children voice recordings indefinitely ($25M). Ring employees acc...

Alexa retained children voice recordings indefinitely ($25M). Ring employees accessed customer video feeds ($5.8M).

2020-02-01TIM - Telecom Provider€27.8MGDPRItalian Data Protection Authority (Garante)ItalyNon-cooperation with Data Protection Authority
A huge fine of €27,8 million was issued to the Italian telecom company TIM. The ...

A huge fine of €27,8 million was issued to the Italian telecom company TIM. The Italian Data Protection Authority (Garante) revealed that TIM was fined due to numerous unlawful data processing activities related to marketing and advertising, which included unsolicited promotional calls and prize competitions in which data subjects were entered without consent.One of the reasons for the large fine was the fact that the unlawful data processing activities involved several million individuals. One individual, for example, was called a total of 155 times in a month while TIM refused to add the affected individual on a no-call list even after several requests. The DPA determined that the company lacked control over the call centers and did not have adequate measures to add people to no-call lists.TIM also did not provide accurate and detailed enough privacy policies and data processing policies, and as such consumers were not efficiently informed about the data collected and processed. The company’s management of data breaches was also not efficient according to Garante.Besides the fine, Garante also imposed 20 corrective measures according to Art. 58(2) GDPR which prohibits TIM from processing marketing-related data of those individuals who have refused to receive promotional calls, individuals who asked to be blacklisted and individuals who are not clients of TIM.The company was also forbidden from using customer data collected from the “My Tim”, “Tim Personal” and “Tim Smart Kid” apps.

Articles: Art. 58(2) GDPR

2020-01-15TIM - Telecom Provider€27.8MGDPRItalian Data Protection Authority (Garante)ItalyNon-cooperation with Data Protection Authority
--

Articles: Art. 58(2) GDPR

2021-12-16Enel Energia S.p.A.€26.5MGDPRItalian Data Protection Authority (Garante)ItalyVarious offences
--

Articles: Art. 5 (1) a), d) GDPR, Art. 5 (2) GDPR, Art. 6 (1) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 21 GDPR, Art. 24 GDPR, Art. 25 (1) GDPR, Art. 30 GDPR, Art. 31 GDPR, Art. 130 (1), (2), (4) Codice della privacy

2020-10-16British Airways€22.0MGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2020-10-30Marriott International, Inc€20.4MGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2022-02-10Clearview AI€20.0MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b), e) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 27 GDPR

2022-10-17Clearview AI€20.0MGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 12 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 31 GDPR

2022-05-23Clearview AI€20.0MGDPRGreece HDPAGreececonsent
Unlawful processing of biometric data through facial recognition without consent...

Unlawful processing of biometric data through facial recognition without consent.

Articles: Art. 5, Art. 6, Art. 9

2022-07-13Clearview AI€20.0MGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 27 GDPR

2022-03-09Clearview AI€20.0MGDPRItaly GaranteItalyconsent
Facial recognition company unlawfully processed biometric data of people in Ital...

Facial recognition company unlawfully processed biometric data of people in Italy.

Articles: Art. 5, Art. 6, Art. 9, Art. 14, Art. 27

2023-06-05Microsoft$20.0MCOPPAFTCUnited Stateschildren
Collected personal information from children creating Xbox accounts without noti...

Collected personal information from children creating Xbox accounts without notifying parents or obtaining consent.

2025-01-15HoganWillig/Genshin Impact (Cognosphere)$20.0MCOPPAFTCUnited Stateschildren
Genshin Impact developer settled FTC charges of collecting data from children wi...

Genshin Impact developer settled FTC charges of collecting data from children without consent.

2019-10-23Austrian Post€18.0MGDPRAustrian Data Protection Authority (DSB)AustriaNon-compliance with lawful basis for data processing
The Austrian Post had sold detailed personal profiles of approximately three mil...

The Austrian Post had sold detailed personal profiles of approximately three million Austrians to various companies and political parties. The profiles contained names, addresses, political predilections, and even intimate details.

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR

2022-03-15Meta Platforms€17.0MGDPR Data Protection Authority of IrelandIrelandFailure to comply with data processing principles
--

Articles: Art. 5 (2) GDPR, Art. 24 (1) GDPR

2020-07-13Wind Tre S.p.A.€16.7MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 12 GDPR. Art. 24 GDPR, Art. 25 GDPR

2024-02-22Avast$16.5MFTC Act Section 5FTCUnited Statesconsent
Antivirus company sold browsing data through subsidiary Jumpshot despite privacy...

Antivirus company sold browsing data through subsidiary Jumpshot despite privacy promises.

2019-10-30Deutsche Wohnen SE€14.5MGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to comply with data processing principles
The company collected data from multiple tenants without providing the option to...

The company collected data from multiple tenants without providing the option to remove that data once it was no longer required. This led to the company retaining personal data of tenants for years (salary statements, social security insurances, health insurances, tax insurances, bank statements). The Berlin Data Commissioner issued a fine of €14,500,000.

Articles: Art. 5 GDPR, Art. 25 GDPR

2023-04-04TikTok€14.5MGDPRInformation Commissioner (ICO)United KingdomFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 12 GDPR, Art. 13 GDPR

2020-11-12Vodafone Italia S.p.A€12.3MGDPRItalian Data Protection Authority (Garante)ItalyMultiple
--

Articles: Art. 5 (1), (2) GDPR, Art. 6 (1) GDPR, Art. 7 GDPR, Art. 15 (1) GDPR, Art. 16 GDPR, Art. 21 GDPR, Art. 24 GDPR, Art. 25 (1) GDPR, Art. 32 GDPR, Art. 33 GDPR

2021-01-08notebooksbilliger.de€10.4MGDPRData Protection Authority of NiedersachsenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2022-01-06Google€10.0MGDPRFrance CNILFranceconsent
Cookie consent mechanism did not allow users to refuse cookies as easily as acce...

Cookie consent mechanism did not allow users to refuse cookies as easily as accepting them.

Articles: Art. 82

PreviousPage 3 of 82Next