Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-05-22Unknown Company€13KGDPRDeputy Data Protection OmbudsmanFinlandFailure to comply with data processing principles
--

Articles: Art. 5 GPDR, Art. 6 GDPR

2021-01-01Energy Supplier€13KGDPRData Protection Authority of SaxonyGermanyUnknown
--

Articles: Unknown

2022-07-06Głównego Geodetę Kraju€12KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 33 (1) GDPR, Art. 34 (1) GDPR

1970-01-01Restaurant€12KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
The restaurant wanted to sanction an employee using images taken by another empl...

The restaurant wanted to sanction an employee using images taken by another employee in the restaurant, to be used as evidence.

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR

2020-10-23Recambios Villalegre S.L.€12KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 GDPR, Art. 13 GDPR

--ALBERTO FORTE COMPSITE, S.L.€12KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 35 GDPR

2021-02-04Orthodontic Clinic€12KGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) GDPR

2022-10-20Comune di Salento€12KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b), e) GDPR, Art. 6 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 30 GDPR

2022-10-14SEAN SERIOS S.L.€12KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2021-12-08Unknown€12KGDPRBelgian Data Protection Authority (APD)BelgiumNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 (3) GDPR, Art. 14 (1), (2), (3) GDPR, Art. 15 GDPR, Art. 17 (1) c) GDPR, Art. 21 (2) GDPR

2022-05-22Comune di Napoli Corpo di Polizia Municipale€12KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 88 GDPR, Art. 113 Codice della privacy

2019-01-21Madrileña Red de Gas€12KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

--Restaurant€12KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR

2019-01-21Madrileña Red de Gas€12KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
The gas company did not have the necessary technical measures in place to verify...

The gas company did not have the necessary technical measures in place to verify the identity of the subjects’ data. It was alleged by a third party that the company emailed their information to a third party in regards to a request.

Articles: Art. 32 GDPR

2020-07-10Vodafone Espana, SAU€12KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 5 GDPR

2021-10-18HIV Scotland€12KGDPRInformation Commissioner (ICO)United KingdomNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR, Art. 32 (1), (2) GDPR

2019-09-03Commercial representative of telecommunication service provider€12KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2019-09-03Commercial representative of telecommunication service provider€12KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
A fine of €11,760 was issued on the commercial representative of a national tele...

A fine of €11,760 was issued on the commercial representative of a national telecommunications provider due to the unlawful processing of the personal data of a client. The commercial representative unlawfully processed the data of a client with the goal of closing a contract for mobile telephoning services.

Articles: Art. 6 (1) GDPR

2020-05-12Örebro County Health and Medical Board€11KGDPRData Protection Authority of SwedenSwedenFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-09-08Warsaw University of Life Sciences€11KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2023-03-01Housing Cooperative€11KGDPRPolish National Personal Data Protection Office (UODO)PolandInsufficient fulfilment of data breach notification obligations
--

Articles: Art. 33 (1) GDPR, Art. 34 (1) GDPR

2021-09-29Territorial Administration of the Government of Genoa€11KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), c) GDPR, Art. 6 (1) c), e) Art. 6 (2) GDPR, Art. 6 (3) b) GDPR GDPR, Art. 2-ter (1), (3) Codice della privacy

2019-11-25Fan Courier Express SRL€11KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-11-25Fan Courier Express SRL€11KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
Fan Courier Express SRL, which is a national courier service, was given an €11,0...

Fan Courier Express SRL, which is a national courier service, was given an €11,000 fine because it failed to take appropriate technical and organizational measures to prevent the loss of personal data (name, bank card number, CVV code, cardholder’s address, personal identification number, serial and identity card number, bank account number, authorized credit limit) of over 1100 private individuals.

Articles: Art. 32 GDPR

2019-07-31Private individual (football coach)€11KGDPRAustrian Data Protection Authority (DSB)AustriaNon-compliance with lawful basis for data processing
A soccer coach was fined for having covertly filmed female players while they we...

A soccer coach was fined for having covertly filmed female players while they were taking showers. This had taken place for many years.

Articles: Art. 6 GDPR

PreviousPage 35 of 82Next