Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2022-01-01 | DW Dynamic Works LIMITED | €5K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-02-03 | Queseria Artesenal Ameco S.L. | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | The company was fined because it processed personal data without the consent of ...The company was fined because it processed personal data without the consent of the affected parties. Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-12-13 | Entirely Shipping & Trading S.R.L. | €5K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with lawful basis for data processing | A second fine was issued to the company for the unlawful processing of employee ...A second fine was issued to the company for the unlawful processing of employee biometric data (fingerprints). The processing of biometric data allegedly was necessary to give employees access to certain rooms. The national DPA argued that this was too excessive. Articles: Art. 5 (1) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 9 GDPR |
| 2019-12-13 | Entirely Shipping & Trading S.R.L. | €5K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with lawful basis for data processing | The company installed video surveillance in order to monitor employee activity. ...The company installed video surveillance in order to monitor employee activity. The problem arose from the fact that some cameras were installed in the locker rooms where the staff kept their spare clothes and regularly used to get dressed and undressed. Articles: Art. 5 (1) GDPR, Art. 6 GDPR, Art. 7 GDPR |
| 2020-12-02 | Asociación de Víctimas por Arbitrariedades Judiciales, (JAVA) | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR |
| 2020-07-02 | Xfera Moviles S.A. | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-cooperation with Data Protection Authority | --Articles: Art. 31 GDPR, Art. 58 GDPR |
| 2019-12-10 | Shop Macoyn, S.L. | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | The company sent advertising emails to multiple recipients where every one of th...The company sent advertising emails to multiple recipients where every one of the recipients was able to see the email address of all other recipients. This was because the sender sent all the email addresses as CC instead of BCC. Articles: Art. 32 GDPR |
| 2019-12-03 | Linea Directa Aseguradora | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | An insurance company sent advertising emails to clients without the necessary co...An insurance company sent advertising emails to clients without the necessary consent. Articles: Art. 6 GDPR |
| 2019-11-28 | City councilor | €5K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Non-compliance with lawful basis for data processing | Two Belgian politicians, a city councilor and a mayor have been fined €5,000 eac...Two Belgian politicians, a city councilor and a mayor have been fined €5,000 each for sending out campaign emails to recipients who have not consented to receive such emails. Articles: Art. 6 GDPR |
| 2019-11-28 | Mayor | €5K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Non-compliance with lawful basis for data processing | Two Belgian politicians, a city councilor and a mayor have been fined €5,000 eac...Two Belgian politicians, a city councilor and a mayor have been fined €5,000 each for sending out campaign emails to recipients who have not consented to receive such emails. Articles: Art. 6 GDPR |
| 2021-07-08 | Pediatrician | €5K | GDPR | Hellenic Data Protection Authority (HDPA) | Greece | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 12 (1) GDPR, Art. 15 (1) GDPR |
| 2022-01-01 | Cypriot Ministry of Defense | €5K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Insufficient data processing agreement | --Articles: Art. 24 GDPR, Art. 32 GDPR |
| 1970-01-01 | Vodafone Espana | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with processing principles | Vodafone mistakenly charged a customer whose information it disclosed to BADEXCU...Vodafone mistakenly charged a customer whose information it disclosed to BADEXCUG, a solvency registry. SETSTI, the Spanish telecommunications and information agency demanded that Vodafone reimburse the client. The AEPD decided that Vodafone had acted erroneously and that it had breached the principle of accuracy. Articles: Art. 5 (1) d) GDPR |
| 2019-01-23 | Small shipping company | €5K | GDPR | Data Protection Authority | Germany | https://dataprivacy.foxrothschild.com/2019/01/articles/european-union/hessian-dpa-fines-shipping-company-for-missing-data-processing-agreement/ | The data controller company lacked a data processing agreement with the Spanish ...The data controller company lacked a data processing agreement with the Spanish service provider. Articles: Art. 28 of the GDPR |
| 2022-01-01 | Trucking company | €5K | GDPR | Data Protection Commission of Bulgaria (KZLD) | Bulgaria | Non-compliance with lawful basis for data processing | --Articles: Art. 6 GDPR |
| 2021-08-09 | Club Gimnasia Ritmica San Antonio | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 GDPR |
| 2022-12-15 | Comune di Borgia | €5K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 (2), (4) GDPR, Art. 37 (7) GDPR |
| 2021-10-04 | Caldereria Y Soldadura De Estructuras Metalicas, SL | €5K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 GDPR |
| 2019-03-01 | State Hospital | €5K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Non-compliance with subjects' rights protection safeguards | The data controller could not provide access to personal information to a patien...The data controller could not provide access to personal information to a patient because the dossier could not be identified. The patient complained to the Commissioner about this, and the hospital was fined 5.000 Euros. Articles: Art. 15 GDPR |
| 2018-12-17 | Kolibri Image Regina und Dirk Maass GbR | €5K | GDPR | Data Protection Authority of Hamburg | Germany | Failure to collect sufficient data processing consent | This fine was apparently withdrawn. The case concerned the Kolibri Image who lod...This fine was apparently withdrawn. The case concerned the Kolibri Image who lodged a complaint that a service provider did not want to sign a processing agreement. Afterward, the Kolibri Image was fined because it didn’t have any processing agreement with the service provider. However, the company argued that the service provider was not a processor, and therefore the fine was unreasonable and unwarranted. Articles: Art. 28 (3) GDPR |
| 2023-01-26 | Misterbianco municipality | €5K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 2-ter Codice della privacy |
| 2019-02-18 | Lands Authority | €5K | GDPR | Data Protection Commissioner of Malta | Malta | Failure to implement sufficient measures to ensure information security | The Lands Authority had a data breach where 10 GB worth of personal data was pub...The Lands Authority had a data breach where 10 GB worth of personal data was publicly accessible on the internet. The data contained sensitive information about data subjects. The Data Protection Commissioner might issue a fine of 25.000 Euros for each of the violations (data breaches). Articles: Art. 5 GDPR, Art. 32 GDPR |
| 2020-01-30 | Comune di Colledara | €5K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2021-02-11 | Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da Pietrelcina | €5K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a), f) GDPR, Art. 9 GDPR |
| 2023-02-08 | Medijobs Platform SRL | €5K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) b), (2) GDPR |