Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-07-10East Power Sp. z o.o.€3KGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to implement sufficient measures to ensure information security
--

Articles: Art. 31 GDPR, Art. 58 GDPR

2022-01-01Company€3KGDPRCzech Data Protection Authority (UOOU)Czech RepublicUnknown
--

Articles: Unknown

2020-12-11Cosmetic Medical Limited€3KGDPRInformation Commissioner of Isle of ManIsle of ManNon-cooperation with Data Protection Authority
--

Articles: Art. 31 GDPR

2023-02-03Epic Ltd.€3KGDPRCypriot Data Protection CommissionerCyprusNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR, Art. 24 (1), (2) GDPR, Art. 32 (1) GDPR

2018-12-18Not disclosed€3KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryFailure to implement sufficient measures to ensure information security
The data subject was not given access to CCTV recordings and was not informed th...

The data subject was not given access to CCTV recordings and was not informed that he could complain to the supervisory authority about the data controller’s refusal to retain the recordings.

Articles: Art. 12 (4) GDPR, Art. 15 GDPR, Art. 18 (1) c) GDPR, Art. 13 GDPR

2019-02-28Kecskemét Mayor's Office€3KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR

2018-12-18Not disclosed€3KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryFailure to implement sufficient measures to ensure information security
--

Articles: Art. 12 (4) GDPR, Art. 15 GDPR, Art. 18 (1) c) GDPR, Art. 13 GDPR

2019-03-04Not disclosed€3KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryNon-compliance with subjects' rights protection safeguards
The financial institution refused the data erasure request of a customer, arguin...

The financial institution refused the data erasure request of a customer, arguing that it was in the institution’s best interests to retain the phone number, given that the customer had debts. However, the NAIH argued that the creditor could communicate with the debtor by post, and the phone number was unnecessary. The financial institution had broken the data minimization and purpose limitation principles. A fine was issued equal to 0.025% of the institution’s annual net revenue.

Articles: Art. 5 (1) b) GDPR, Art. 5 (1) c) GDPR, Art. 13 (3) GDPR, Art. 17 (1) GDPR, Art. 6 (4) GDRP

2020-03-06Retailer€3KGDPRSpanish Data Protection Authority (AEPD)SpainInformation obligation non-compliance
--

Articles: Art. 13 GDPR, Art. 14 GDPR

2019-03-04Not disclosed€3KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 5 (1) b) GDPR, Art. 5 (1) c) GDPR, Art. 13 (3) GDPR, Art. 17 (1) GDPR, Art. 6 (4) GDRP

2019-02-28Kecskemét Mayor's Office€3KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryNon-compliance with lawful basis for data processing
The fine was issued after the Mayor’s Office unlawfully disclosed personal infor...

The fine was issued after the Mayor’s Office unlawfully disclosed personal information related to a whistleblower. The individual complained to the NAIH about his employer. Afterward, the company requested information about the complaint, and the Mayor’s Office “accidentally” released the name of the complainant. The individual was fired as a result.

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR

2022-12-06Retailer€3KGDPRCroatian Data Protection Authority (AZOP)CroatiaInsufficient fulfilment of information obligations
--

Articles: Art. 27 (2) Croatian Act on the Implementation of the GDPR

1970-01-01UniCredit Bank€3KGDPRCzech Data Protection Authority (UOOU)Czech RepublicNon-compliance with lawful basis for data processing
UniCredit Bank opened a bank account for a person who has not requested any acco...

UniCredit Bank opened a bank account for a person who has not requested any account to be opened. The bank allegedly had his personal data at their disposal because the affected person was responsible for closing a bank account operated by his employer. The bank was requested to prove that it had consent from the data subject to process his personal data but was unable to provide this proof.

Articles: Art. 6 GDPR

--UniCredit Bank€3KGDPRCzech Data Protection Authority (UOOU)Czech RepublicNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2019-05-13Not known€3KGDPRCzech Data Protection Authority (UOOU)Czech RepublicNot known
Not available.

Not available.

Articles: Art. 5 (1) a) GDPR, Art. 5 (1) b) GDPR, Art. 32 (1) GDPR

2019-05-13Not known€3KGDPRCzech Data Protection Authority (UOOU)Czech RepublicNot known
--

Articles: Art. 5 (1) a) GDPR, Art. 5 (1) b) GDPR, Art. 32 (1) GDPR

2023-03-14Tinmar Energy SA€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b) GDPR, Art. 32 (2) GDPR

2020-02-11Vodafone Romania€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2022-06-30Company€3KGDPR National Commission for Data Protection (CNPD)LuxembourgFailure to comply with data processing principles
--

Articles: Art. 5 (1) e) GDPR, Art. 13 GDPR

2020-12-30ING Bank€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a)-d) GDPR, Art. 6 (1) GDPR

2020-03-25Enel Energie€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to implement sufficient measures to ensure information security
Enel Energie sent a client an email that contained the personal information of a...

Enel Energie sent a client an email that contained the personal information of another client, failing to employ the necessary organizational and technical measures.

Articles: Art. 32 GDPR

2020-11-10Miguel Ibáñez Bezanilla, S.L.€3KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 13 GDPR, Art. 32 GDPR

2020-09-30Venu Sanz Chef, S.L.€3KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2020-10-01Megareduceri TV S.R.L.€3KGDPRRomanian National Supervisory Authority for Personal Data Processing (ANSPDCP)RomaniaFailure to comply with Data Processing Authority's orders
--

Articles: Art. 31 GDPR, Art. 58 GDPR

2022-06-03Lodeju, S.L.€3KGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR, Art. 13 GDPR

PreviousPage 52 of 82Next