Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2020-03-16 | Private person | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-10-29 | Borgo Fonte Scura s.r.l. | €4K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR |
| 2022-07-19 | Bookstore employee | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1), f) GDPR, Art. 32 GDPR |
| 2020-03-06 | Liceo Scientifico Nobel di Torre del Greco | €4K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | The school unlawfully published health data of over 2,000 teachers on its websit...The school unlawfully published health data of over 2,000 teachers on its website. Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-03-06 | Spanish Data Protection Authority (AEPD) | €4K | GDPR | Private person | Spain | Non-compliance with lawful basis for data processing | A private person unlawfully used CCTV cameras. The AEPD revealed that the CCTC c...A private person unlawfully used CCTV cameras. The AEPD revealed that the CCTC camera system used by the individual for home protection also filmed part of a public space. Articles: Art. 5 GDPR |
| 2023-02-27 | Attorney | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 6 GDPR |
| 2022-07-07 | E Software Concept SRL | €4K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to implement sufficient measures to ensure information | --Articles: Art. 32 (1) b), (2) GDPR, Art. 58 (1) a), e) GDPR |
| 2022-03-22 | English School Cyprus | €4K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2021-12-17 | T. Stene Transport AS | €4K | GDPR | Norwegian Supervisory Authority (Datatilsynet) | Norway | Unknown | --Articles: Unknown |
| 2020-01-01 | Television Broadcaster | €4K | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to comply with data processing principles | --Articles: Art. 12 (1) GDPR |
| 2022-01-01 | PRINTAFORM Ltd. | €4K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Failure to implement sufficient measures to ensure information security | --Articles: Art. 28 (3) GDPR, Art. 32 (1) GDPR |
| 2020-07-02 | Saunier-Tec Mantenimientos de Calor y Frio, SL. | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to implement sufficient measures to ensure information security | --Articles: Art. 33 GDPR |
| 2022-07-15 | ECOZONO Y CULTURA, S.L. | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2020-02-28 | AEMA Hispánica | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDPR |
| 2022-12-02 | Federation of Sports for People with Intellectual Disabilities of Castilla la Mancha-FECAM | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 9 (2) a) GDPR, Art. 13 GDPR |
| 2020-01-14 | Zhang Bordeta 2006, S.L. | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-04-15 | AMADOR RECREATIVOS, S.L | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2019-04-15 | AMADOR RECREATIVOS, S.L | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | The games lounge was fined because it improperly used and processed surveillance...The games lounge was fined because it improperly used and processed surveillance footage data. Articles: Art. 5 (1) c) GDPR |
| 2022-11-11 | XASTRE DO PETO, S.L. | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR, Art. 13 GDPR, Art. 21 GDPR |
| 2020-01-14 | Zhang Bordeta 2006, S.L. | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | The store was fined because it installed video surveillance that also took image...The store was fined because it installed video surveillance that also took images of the sidewalk in front of it and invaded pedestrians’ privacy. Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2022-12-05 | Retailer | €4K | GDPR | Croatian Data Protection Authority (AZOP) | Croatia | Insufficient fulfilment of information obligations | --Articles: Art. 27 (1) Croatian act on the Implementation of the GDPR |
| 2022-02-10 | Azienda socio sanitaria territoriale Melegnano e della Martesana | €4K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 9 GDPR |
| 2022-01-01 | Universal Life Insurance Public Co Ltd. | €4K | GDPR | Cypriot Data Protection Commissioner | Cyprus | Insufficient data processing agreement | --Articles: Art. 24 (1) GDPR, Art. 28 (1) GDPR |
| 2022-12-02 | CASA 7 PERSONAL SHOPPER, S.L. | €4K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR |
| 2022-06-06 | Esselmann Technika Pojazdowa Sp. z o.o. Sp. k. | €4K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Failure to implement sufficient measures to ensure information security | --Articles: Art. 33 GDPR |