Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,014 fines found

Total: $6.2B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2022-01-27OTE Group€3.2MGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to implement sufficient measures to ensure information
--

Articles: Art. 32 GDPR

2020-01-17Eni Gas e Luce€3.0MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
The Italian Data Protection Authority (Garante) imposed two fines of €11,5 milli...

The Italian Data Protection Authority (Garante) imposed two fines of €11,5 million total on Eni Gas and Luce because of the unlawful processing of personal data during an advertising campaign as well as for the activation of unsolicited contracts. This second fine of €3 million was issued for the opening of unsolicited contracts for the provision of electricity and gas. A large number of individuals have reported that they have only learned of the new contracts after they received a termination letter from their old provider. Some complaints even reported false data as well as forged signatures.

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-10-21Caixabank Payments & Consumer EFC, EP, S.A.U.€3.0MGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) GDPR

2019-12-11Eni Gas e Luce€3.0MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-12-03Capio St. Goran AB€2.9MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2021-05-13Iren Mercato S.p.A.€2.9MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1), (2) GDPR, Art. 6 (1) GDPR, Art. 7 (1) GDPR

2021-11-25Dutch Minister of Finance€2.8MGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 (1) e) GDPR, Art. 8 Wbp

2019-08-28National Revenue Agency€2.6MGDPRData Protection Commission of Bulgaria (KZLD)BulgariaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-08-28National Revenue Agency€2.6MGDPRData Protection Commission of Bulgaria (KZLD)BulgariaFailure to implement sufficient measures to ensure information security
Because of the inappropriate handling of personal data, more than 6 million indi...

Because of the inappropriate handling of personal data, more than 6 million individuals had their data hacked. This informational leak was a direct cause of the company’s security laxity.

Articles: Art. 32 GDPR

2021-06-10Foodinho s.r.l.€2.6MGDPRItalian Data Protection Authority (Garante)ItalyMultiple types of violations
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 13 GDPR, Art. 22 (3) GDPR, Art. 25 GDPR, Art. 30 (1) a), b), c), f), g) GDPR, Art. 32 GDPR, Art. 35 GDPR, Art. 37 (7) GDPR

2021-07-26Mercadona S.A.€2.5MGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 25 (1) GDPR, Art. 35 GDPR

2021-07-22Deliveroo Italy s.r.l.€2.5MGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 13 GDPR, Art. 22 (3) GDPR, Art. 25 GDPR, Art. 30 (1) c), f), g) GDPR, Art. 32 GDPR, Art. 35 GDPR, Art. 37 (7) GDPR

2023-05-04B2 Kapital d.o.o.€2.3MGDPRCroatian Data Protection Authority (AZOP)CroatiaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR, Art. 13 (1) GDPR, Art. 28 (3) GDPR, Art. 32 (1) b), d) GDPR, Art. 32 (2) GDPR

2020-11-18Carrefour France€2.3MGDPRFrench Data Protection Authority (CNIL)FranceMultiple
--

Articles: Art. 5 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR, Art. 32 GDPR, Art. 33 GDPR

2024-05-15Airbnb Ireland€2.1MGDPRIreland DPCIrelandconsent
Excessive collection and processing of ID document data.

Excessive collection and processing of ID document data.

Articles: Art. 6

2021-08-02Unser O-Bonus Club GmbH€2.0MGDPRAustrian Data Protection Authority (DSB)AustriaFailure to comply with data processing principles
--

Articles: Art. 6 GDPR, Art. 7 GDPR, Art. 12 GDPR

2022-10-06Alpha Exploration€2.0MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), e), f) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 12 (1) GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 27 (4) GDPR, Art. 28 GDPR, Art. 32 GDPR, Art. 35 GDPR

2022-02-11Amazon Road Transport Spain S.L.€2.0MGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) GDPR, Art. 10 GDPR, Art. 10 LOPDGDD

2022-03-03BREBAU GmbH€1.9MGDPRData Protection Authority of BremenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 (1) GDPR, Art. 6 (1) GDPR, Art. 9 GDPR

2021-07-20SGAM AG2R LA MONDIALE€1.8MGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) e) GDPR, Art. 13 GDPR, Art .14 GDPR

2021-06-21Storstockholms Lokaltrafik€1.6MGDPRData Protection Authority of SwedenSwedenNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), c) GDPR, Art. 6 (1) f) GDPR, Art. 13 GDPR

2022-10-04Easylife Ltd.€1.5MGDPR Information Commissioner (ICO)United KingdomFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 13 (1) c) GDPR, Regulation 21 PECR

2022-04-15DEDALUS BIOLOGIE€1.5MGDPR French Data Protection Authority (CNIL)France Non-compliance with subjects' rights protection safeguards
--

Articles: Art. 28 GDPR, Art. 29 GDPR, Art. 32 GDPR

2020-12-03Aleris Sjukvård AB€1.5MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2020-11-13Ticketmaster UK Limited€1.4MGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

PreviousPage 5 of 81Next