Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2019-10-09Vreau Credit SRL€20KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
The Company sent personal information through the WhatsApp platform to Raiffeise...

The Company sent personal information through the WhatsApp platform to Raiffeisen Bank in order to facilitate the assessment of personal scores. The results were returned on the same platform.

Articles: Art. 32 GDPR, Art. 33 GDPR

2022-11-10Sporitalia€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 9 GDPR, Art. 13 GDPR, Art. 30 (1) c) GDPR

2022-05-12Bazar di Hu Xiaoyan€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 13 GDPR, Art. 114 Codice della privacy

2022-10-03NATIONAL BANK OF GREECE S.A.€20KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 13 GDPR

2022-10-03EUROBANK ERGASIAS S.A.€20KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 13 GDPR

2018-11-21Knuddels.de€20KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
A hack revealed the personal data that included email addresses and passwords of...

A hack revealed the personal data that included email addresses and passwords of around 330,000 users.

Articles: Art. 32 GDPR

2019-10-18Wind Hellas Telecommunications€20KGDPRHellenic Data Protection Authority (HDPA)GreeceNon-compliance with subjects' rights protection safeguards
The company ignored objections voiced by the affected parties regarding advertis...

The company ignored objections voiced by the affected parties regarding advertising and marketing calls.

Articles: Art. 21 GDPR

2020-02-06RTI - Reti Televisive Italiane s.p.a.€20KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2019-10-18Wind Hellas Telecommunications€20KGDPRHellenic Data Protection Authority (HDPA)GreeceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 21 GDPR

2021-12-16FCA Italy s.p.a.€20KGDPRItalian Data Protection Authority (Garante)Italy Non-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR

2021-01-05Nestor SAS€20KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR, Art. 13 GDPR

2022-10-03ALFA BANK, S.A.€20KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 13 GDPR

2019-02-05Not available€20KGDPRPortuguese Data Protection Authority (CNPD)PortugalNon-compliance with lawful basis for data processing
Not available.

Not available.

Articles: Art. 15 GDPR

2021-11-30DAVISER SERVICIOS, S.L.€20KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR

2020-11-23Burgo Group, S.p.A€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 13 GDPR

2020-11-26Concentrix Cvg Italy s.r.l.€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), c) GDPR, Art. 6 (1) b), c) GDPR, Art. 9 (1) b) GDPR

2019-01-01https://datenschutz-hamburg.de/assets/pdf/28._Taetigkeitsbericht_Datenschutz_2019_HmbBfDI.pdf€20KGDPRData Protection Authority of HamburgGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 33 GDPR, Art. 34 GDPR

2019-11-29SC CNTAR TAROM SA€20KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
A fine of €20,000 was issued to the Romanian national airline Tarom because it f...

A fine of €20,000 was issued to the Romanian national airline Tarom because it failed to implement the necessary technical measures to ensure the security of personal information. As a consequence of these inadequate measures, a Tarom employee was able to access the flight booking application without authorization and see the personal data of 22 passengers, after which the employee took a photo of the list and made it public online.

Articles: Art. 32 GDPR

2020-10-29Gaypa s.r.l.€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 12 GDPR, Art. 13 GDPR

2022-04-28Nos s.r.l.s.€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 13 GDPR, Art. 14 GDPR

2020-02-03Iberia Lineas Aereas€20KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 21 GDPR

2019-04-08Private individual€20KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR

2019-04-12SC CNTAR TAROM SA€20KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-04-08Private individual€20KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
Video surveillance was used to monitor employees.

Video surveillance was used to monitor employees.

Articles: Art. 5 (1) c) GDPR

2022-04-07Made in Italy s.r.l.s.€20KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 7 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR, Art. 130 (3) Codice della privacy, Art. 157 Codice della privacy, Art. 166 (2) Codice della privacy

PreviousPage 30 of 82Next