Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2023-02-28GRUP NORCONSULTING, S.L.€15KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 15 GDPR, Art. 17 GDPR

2020-08-04Mapei S.p.A€15KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 17 GDPR

2021-06-03PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ€15KGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b) GDPR, Art. 5 (2) GDPR

2022-05-16Arbeidstilsynet€15KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) e) GDPR

2022-01-13Azienda sanitaria unica regionale Marche€14KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR, Art. 35 GDPR

2020-03-10Gladsaxe Municipality€14KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
A computer that belonged to the administration of the municipality was stolen. T...

A computer that belonged to the administration of the municipality was stolen. The computer was not encrypted and it included the personal identification numbers of 20,620 residents.

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2019-12-10Hora Credit IFN SA€14KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-compliance with lawful basis for data processing
Three fined were issued on Hora Credit IFN SA because personal data of an indivi...

Three fined were issued on Hora Credit IFN SA because personal data of an individual was transmitted through email to a third party. The following investigation revealed that the company processed personal data without any means to validate the accuracy and authenticity of the data collected and processed. The operator also did not employ enough technical and organizational measures to protect the collected personal data. The case was made worse by the fact that the company did not notify the ANSPDCP after the data breach was discovered, as required by the law. The three fined issued were of €3,000, €10,000 and €1,000 for all the three issues of non-compliance discovered by the ANSPDCP.

Articles: Art. 5 GDPR, Art. 25 GDPR, Art. 32 GDPR, Art. 33 GDPR

2020-03-10Gladsaxe Municipality€14KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2019-12-10Hora Credit IFN SA€14KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 25 GDPR, Art. 32 GDPR, Art. 33 GDPR

2019-01-01Doctor€14KGDPRCypriot Data Protection CommissionerCyprusNon-compliance with lawful basis for data processing
The data controller could not provide access to personal information to a patien...

The data controller could not provide access to personal information to a patient because the dossier could not be identified. The patient complained to the Commissioner about this, and the hospital was fined 5.000 Euros.

Articles: Art. 5 GDPR, Art. 6 GDPR

2019-01-01Doctor€14KGDPRCypriot Data Protection CommissionerCyprusNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-09-25Odin Flissenter AS€14KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-10-27Car Importer€14KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1), (2) GDPR, Art. 6 (1) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR

2022-03-02Company€14KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryFailure to comply with data processing principles
--

Articles: Art. 5 (2) GDPR, Art. 6 (1) GDPR, Art. 12 (2) GDPR, Art. 17 (1) b) GDPR

2021-12-16Municipality of Frederiksberg€13KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2021-02-12IDdesign A / S (update)€13KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to comply with data processing principles
--

Articles: Art. 5 (1) e) GDPR, Art. 5 (2) GDPR

2022-05-12Civilstyrelsen€13KGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR, Art. 33 GDPR

2023-04-04Company€13KGDPRHungarian National Authority for Data Protection and the Freedom of InformationHungaryInsufficient fulfilment of data subjects rights
--

Articles: Art. 12 GDPR, Art. 13 GDPR

2021-10-13Unknown€13KGDPRNational Commission for Data Protection (CNPD)LuxembourgInsufficient involvement of data protection officer
--

Articles: Art. 38 (1) GDPR, Art. 39 (1) b) GDPR

2020-06-25Department of Home Affairs€13KGDPRInformation Commissioner of Isle of ManIsle of ManFailure to comply with processing principles
--

Articles: Art. 12 GDPR, Art. 15 GDPR

2019-04-25Sports association€13KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2019-04-25Sports association€13KGDPRPolish National Personal Data Protection Office (UODO)PolandNon-compliance with lawful basis for data processing
The sports association published personal data related to judges who had receive...

The sports association published personal data related to judges who had received judicial licenses online. Moreover, the exact addresses and PESEL numbers of these judges became public. As the sports association acted outside the law, fines were in order. However, there were mitigating circumstances in that the sports association immediately noticed its mistakes and attempted to remove the data from the public domain. Still, these attempts were ineffective, and a penalty was issued. The 585 judges had suffered no damage because of this, so the penalty was adjusted by the president of the Office of Competition and Consumer Protection.

Articles: Art. 6 GDPR

2023-05-04Political party€13KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2020-05-22Unknown Company€13KGDPRDeputy Data Protection OmbudsmanFinlandFailure to comply with data processing principles
--

Articles: Art. 5 GPDR, Art. 6 GDPR

2021-01-01Energy Supplier€13KGDPRData Protection Authority of SaxonyGermanyUnknown
--

Articles: Unknown

PreviousPage 34 of 82Next