Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2019-04-08Private individual€20KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
Video surveillance was used to monitor employees.

Video surveillance was used to monitor employees.

Articles: Art. 5 (1) c) GDPR

2022-04-28Nos s.r.l.s.€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 13 GDPR, Art. 14 GDPR

2021-12-13Elektro & Automasjon Systemer AS€20KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to comply with data processing principles
--

Articles: Art. 6 (1) f) GDPR

2022-08-05Cosmopol Security S.p.A.€20KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 (3) GDPR, Art. 15 GDPR

2022-06-16Deutsche Bank S.p.A.€20KGDPRItalian Data Protection Authority (Garante)ItalyNon-cooperation with Data Protection Authority
--

Articles: Art. 12 (3) GDPR, Art. 15 GDPR

2019-02-05Not available€20KGDPRPortuguese Data Protection Authority (CNPD)PortugalNon-compliance with lawful basis for data processing
--

Articles: Art. 15 GDPR

2022-08-25Recover AS€20KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) e) GDPR

2021-06-07Master Distancia S.A.€20KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) GDPR

2018-12-01Unknown€20KGDPRData Protection Authority of HamburgGermanyInformation obligation non-compliance
--

Articles: Art. 83 (4) a) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR

2022-10-03PIRAEUS BANK S.A.€20KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 13 GDPR

2022-08-19Medical Laboratory€20KGDPRBelgian Data Protection Authority (APD)BelgiumFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 32 GDPR, Art. 35 (1), (3) GDPR

2020-11-23Burgo Group, S.p.A€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 13 GDPR

2020-10-29Gaypa s.r.l.€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 12 GDPR, Art. 13 GDPR

2022-12-01Amazon Italia Logistica s.r.l.€20KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR, Art. 15 GDPR

2022-11-21ING BANK NV Amsterdam Sucursala București €20KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1), (2) GDPR

2018-12-01Unknown€20KGDPRData Protection Authority of HamburgGermanyInformation obligation non-compliance
A data breach was not notified in time and the affected subjects were not made a...

A data breach was not notified in time and the affected subjects were not made aware.

Articles: Art. 83 (4) a) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR

2019-01-01https://datenschutz-hamburg.de/assets/pdf/28._Taetigkeitsbericht_Datenschutz_2019_HmbBfDI.pdf€20KGDPRData Protection Authority of HamburgGermanyFailure to implement sufficient measures to ensure information security
HVV GmbH had not reported a data breach to the data protection authority in due ...

HVV GmbH had not reported a data breach to the data protection authority in due time. This data breach was related to the security gap in the Customer E-Service, in that that clients with an HVV card who logged in the CES could access the data of other customers by changing the URL to match their data profile.

Articles: Art. 33 GDPR, Art. 34 GDPR

2022-09-06MUXERS CONCEPT, S.L.€20KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2022-05-12Bazar di Hu Xiaoyan€20KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 13 GDPR, Art. 114 Codice della privacy

2020-10-26Università Campus Bio-medico di Roma (Polyclinic)€20KGDPRItalian Data Protection Authority (Garante)Italy--
--

Articles: Art. 5 (2) a), f) GDPR, Art. 9 GDPR

2021-06-07Radiotelevision del principado de Asturias€20KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR, Art. 12 GDPR

2020-11-25Gnosjo Municipality€20KGDPRData Protection Authority of SwedenlopSwedenFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 13 GDPR, Art. 35 GDPR, Art. 36 GDPR

2020-01-01Unknown€19KGDPRCzech Data Protection Authority (UOOU)Czech RepublicMultiple
--

Articles: Art. 5 (1) a) GDPR, Art. 6 (1) GDPR, Art. 12 (2), (3), Art. 15 GDPR, Art. 16 GDPR, Art. 17 GDPR, Art. 18 GDPR, Art. 19 GDPR, Art. 20 GDPR, Art. 21 GDPR, Art. 22 GDPR

2021-01-05Unknown€19KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to notify DPA of a data breach
--

Articles: Art. 34 (1), (2) GDPR, Art. 58 (2) e) GDPR

2020-12-04Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.€19KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to notify DPA of a data breach
--

Articles: Art. 33 (1) GDPR, Art. 34 (1) GDPR

PreviousPage 31 of 82Next