Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2022-01-01DW Dynamic Works LIMITED€5KGDPRCypriot Data Protection CommissionerCyprusFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2020-02-03Queseria Artesenal Ameco S.L.€5KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
The company was fined because it processed personal data without the consent of ...

The company was fined because it processed personal data without the consent of the affected parties.

Articles: Art. 5 GDPR, Art. 6 GDPR

2019-12-13Entirely Shipping & Trading S.R.L.€5KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-compliance with lawful basis for data processing
A second fine was issued to the company for the unlawful processing of employee ...

A second fine was issued to the company for the unlawful processing of employee biometric data (fingerprints). The processing of biometric data allegedly was necessary to give employees access to certain rooms. The national DPA argued that this was too excessive.

Articles: Art. 5 (1) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 9 GDPR

2019-12-13Entirely Shipping & Trading S.R.L.€5KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-compliance with lawful basis for data processing
The company installed video surveillance in order to monitor employee activity. ...

The company installed video surveillance in order to monitor employee activity. The problem arose from the fact that some cameras were installed in the locker rooms where the staff kept their spare clothes and regularly used to get dressed and undressed.

Articles: Art. 5 (1) GDPR, Art. 6 GDPR, Art. 7 GDPR

2020-12-02Asociación de Víctimas por Arbitrariedades Judiciales, (JAVA)€5KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) GDPR

2020-07-02Xfera Moviles S.A.€5KGDPRSpanish Data Protection Authority (AEPD)SpainNon-cooperation with Data Protection Authority
--

Articles: Art. 31 GDPR, Art. 58 GDPR

2019-12-10Shop Macoyn, S.L.€5KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to implement sufficient measures to ensure information security
The company sent advertising emails to multiple recipients where every one of th...

The company sent advertising emails to multiple recipients where every one of the recipients was able to see the email address of all other recipients. This was because the sender sent all the email addresses as CC instead of BCC.

Articles: Art. 32 GDPR

2019-12-03Linea Directa Aseguradora€5KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
An insurance company sent advertising emails to clients without the necessary co...

An insurance company sent advertising emails to clients without the necessary consent.

Articles: Art. 6 GDPR

2019-11-28City councilor€5KGDPRBelgian Data Protection Authority (APD)BelgiumNon-compliance with lawful basis for data processing
Two Belgian politicians, a city councilor and a mayor have been fined €5,000 eac...

Two Belgian politicians, a city councilor and a mayor have been fined €5,000 each for sending out campaign emails to recipients who have not consented to receive such emails.

Articles: Art. 6 GDPR

2019-11-28Mayor€5KGDPRBelgian Data Protection Authority (APD)BelgiumNon-compliance with lawful basis for data processing
Two Belgian politicians, a city councilor and a mayor have been fined €5,000 eac...

Two Belgian politicians, a city councilor and a mayor have been fined €5,000 each for sending out campaign emails to recipients who have not consented to receive such emails.

Articles: Art. 6 GDPR

2021-07-08Pediatrician€5KGDPRHellenic Data Protection Authority (HDPA)GreeceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 (1) GDPR, Art. 15 (1) GDPR

2022-01-01Cypriot Ministry of Defense€5KGDPRCypriot Data Protection CommissionerCyprusInsufficient data processing agreement
--

Articles: Art. 24 GDPR, Art. 32 GDPR

1970-01-01Vodafone Espana€5KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with processing principles
Vodafone mistakenly charged a customer whose information it disclosed to BADEXCU...

Vodafone mistakenly charged a customer whose information it disclosed to BADEXCUG, a solvency registry. SETSTI, the Spanish telecommunications and information agency demanded that Vodafone reimburse the client. The AEPD decided that Vodafone had acted erroneously and that it had breached the principle of accuracy.

Articles: Art. 5 (1) d) GDPR

2019-01-23Small shipping company€5KGDPRData Protection AuthorityGermanyhttps://dataprivacy.foxrothschild.com/2019/01/articles/european-union/hessian-dpa-fines-shipping-company-for-missing-data-processing-agreement/
The data controller company lacked a data processing agreement with the Spanish ...

The data controller company lacked a data processing agreement with the Spanish service provider.

Articles: Art. 28 of the GDPR

2022-01-01Trucking company€5KGDPRData Protection Commission of Bulgaria (KZLD)BulgariaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2021-08-09Club Gimnasia Ritmica San Antonio€5KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 GDPR

2022-12-15Comune di Borgia€5KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 (2), (4) GDPR, Art. 37 (7) GDPR

2021-10-04Caldereria Y Soldadura De Estructuras Metalicas, SL€5KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2019-03-01State Hospital€5KGDPRCypriot Data Protection CommissionerCyprusNon-compliance with subjects' rights protection safeguards
The data controller could not provide access to personal information to a patien...

The data controller could not provide access to personal information to a patient because the dossier could not be identified. The patient complained to the Commissioner about this, and the hospital was fined 5.000 Euros.

Articles: Art. 15 GDPR

2018-12-17Kolibri Image Regina und Dirk Maass GbR€5KGDPRData Protection Authority of HamburgGermanyFailure to collect sufficient data processing consent
This fine was apparently withdrawn. The case concerned the Kolibri Image who lod...

This fine was apparently withdrawn. The case concerned the Kolibri Image who lodged a complaint that a service provider did not want to sign a processing agreement. Afterward, the Kolibri Image was fined because it didn’t have any processing agreement with the service provider. However, the company argued that the service provider was not a processor, and therefore the fine was unreasonable and unwarranted.

Articles: Art. 28 (3) GDPR

2023-01-26Misterbianco municipality€5KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 2-ter Codice della privacy

2019-02-18Lands Authority€5KGDPRData Protection Commissioner of MaltaMaltaFailure to implement sufficient measures to ensure information security
The Lands Authority had a data breach where 10 GB worth of personal data was pub...

The Lands Authority had a data breach where 10 GB worth of personal data was publicly accessible on the internet. The data contained sensitive information about data subjects. The Data Protection Commissioner might issue a fine of 25.000 Euros for each of the violations (data breaches).

Articles: Art. 5 GDPR, Art. 32 GDPR

2020-01-30Comune di Colledara€5KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-02-11Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da Pietrelcina€5KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), f) GDPR, Art. 9 GDPR

2023-02-08Medijobs Platform SRL€5KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b), (2) GDPR

PreviousPage 48 of 82Next