Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2021-09-02 | Rhodes Municipal Transport Company | €8K | GDPR | Hellenic Data Protection Authority (HDPA) | Greece | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 5 (1) c) GDPR, Art. 12 (3) GDPR, Art. 15 GDPR |
| 2022-10-24 | ADSL HOUSE, S.L. | €8K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 48 (1) b) LGT, Art. 21 GDPR, Art. 23 (4) LOPDGDD |
| 2020-09-22 | Iweb Internet Learning, S.L. | €8K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 7 GDPR, Art. 12 GDPR, Art. 13 GDPR |
| 2021-06-11 | Unknown | €8K | GDPR | National Commission for Data Protection (CNPD) | Luxembourg | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR, Art. 13 GDPR |
| 2022-04-01 | Company | €8K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a) GDPR, Art. 6 (1) f) GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 18 GDPR, Art. 21 GDPR, Art. 28 GDPR |
| 2022-01-13 | Azienda Sanitaria Locale Frosinone | €8K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a) GDPR, Art. 12 GDPR, Art. 13 GDPR |
| 2021-06-16 | PVV Overijssel | €8K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Failure to implement sufficient measures to ensure information security | --Articles: Art. 33 GDPR |
| 2022-01-01 | DW Dynamic Works LIMITED | €8K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-06-23 | Miraclia | €8K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-10-24 | Military Hospital | €7K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Information obligation non-compliance | --Articles: Art. 32 GDPR, Art. 33 GDPR |
| 2019-10-28 | Military Hospital | €7K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Information obligation non-compliance | A military hospital did not meet the reporting deadline imposed for data breache...A military hospital did not meet the reporting deadline imposed for data breaches. The data protection authority further increased the fine due to the lack of technical and organizational measured to prevent the loss of personal data. Articles: Art. 32 GDPR, Art. 33 GDPR |
| 2022-01-01 | Police officer | €7K | GDPR | Data Protection Authority of Hessen | Germany | Unknown | --Articles: Unknown |
| 2020-12-07 | Perfomeclic | €7K | GDPR | French Data Protection Authority (CNIL) | France | Failure to comply with data processing principles | --Articles: Art. 5 (1) c), e) GDPR, Art. 14 GDPR, Art. 21 GDPR, Art. 28 GDPR, Art. L34-5 CPCE |
| 2021-01-07 | Gveik AS | €7K | GDPR | Norwegian Supervisory Authority (Datatilsynet) | Norway | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2023-02-08 | Company | €7K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 24 (1) GDPR, Art. 25 (1), (2) GDPR, Art. 32 (1), (2) GDPR |
| 2021-06-11 | Unknown | €7K | GDPR | National Commission for Data Protection (CNPD) | Luxembourg | Failure to comply with data processing principles | --Articles: Art. 5 (1) c), e) GDPR, Art. 13 GDPR, Art. 32 (1) GDPR |
| 2020-08-05 | Acc Consulting Varsinais-Suomi | €7K | GDPR | Deputy Data Protection Ombudsman | Finland | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-01-01 | Unknown | €7K | GDPR | Data Protection Authority of Bavaria | Germany | Non-cooperation with Data Protection Authority | --Articles: Art. 58 (1) f) GDPR |
| 2022-06-20 | Asociația de Proprietari Aviației Park | €7K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), c), e) GDPR, Art. 5 (2) GDPR, Art. 6 GDPR |
| 2020-03-10 | Hørsholm Municipality | €7K | GDPR | Danish Data Protection Authority (Datatilsynet) | Denmark | Failure to implement sufficient measures to ensure information security | A work computer belonging to a city government employee was stolen. The computer...A work computer belonging to a city government employee was stolen. The computer contained personal data of around 1,600 city government employees as well as sensitive information such as social security numbers. Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR |
| 2022-12-19 | ΜΑΡΙΑ ΠΕΔΙΩΤΗ ΚΑΙ ΣΙΑ Ο.Ε. | €7K | GDPR | Hellenic Data Protection Authority (HDPA) | Greece | Insufficient fulfilment of data subjects rights | --Articles: Art. 12 GDPR, Art. 15 GDPR, Art. 31 GDPR |
| 2023-01-26 | Azienda Ospedaliera Bianchi Melacrino Morelli | €7K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 9 GDPR, Art. 32 GDPR, Art. 75 Codice della privacy |
| 2022-08-09 | CDI Transport Intern și Internațional SRL | €7K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 12 (1) GDPR, Art. 58 (1) a), e) GDPR |
| 2022-05-22 | Azienda Socio Sanitaria Territoriale Dei Sette Laghi | €7K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 9 GDPR, Art. 32 GDPR |
| 2023-01-16 | Πολίτης newspaper | €7K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR, Art. 6 (1) f) GDPR |