Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2022-06-15 | S.C. Wine Point S.R.L. | €3K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) b) GDPR |
| 2022-06-28 | FLY FUT, S.L. | €3K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2020-01-09 | Vodafone Espana | €3K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-cooperation with Data Protection Authority | The company did not provide information to the AEPD in relation to an investigat...The company did not provide information to the AEPD in relation to an investigation. Articles: Art. 58 GDPR |
| 2021-05-26 | Vodafone Espana, S.A.U. | €3K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-cooperation with Data Protection Authority | --Articles: Art. 58 (1) GDPR |
| 2022-10-06 | Associazione Rescue Drones Network ODV | €3K | GDPR | Italian Data Protection Authority (Garante) | Italy | Insufficient fulfilment of data subjects rights | --Articles: Art. 12 GDPR, Art. 15 (3) GDPR |
| 2020-02-11 | Vodafone Romania | €3K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to comply with data processing principles | Vodafone Romania employed weak and insufficient security measures, which led to ...Vodafone Romania employed weak and insufficient security measures, which led to an event of erroneous data processing. When an individual issued a complaint, the company incorrectly processed the client’s data and sent it to a wrong e-mail address. Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR |
| 2023-01-25 | CASAL DE L’ESPLUGA DE FRANCOLI | €3K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2022-05-22 | Zito Auto di Gianfranco Zito | €3K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), c) GDPR, Art. 114 Codice della privacy |
| 2022-12-01 | Store Owner (Woolen) | €3K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 13 GDPR, Art. 114 Codice della privacy |
| 2020-12-02 | Comercio Online Levante, S.L. | €3K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR |
| 2021-11-14 | Vodafone România SA | €3K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) b) GDPR, Art. 32 (2) GDPR, Art. 3 (1) Law No. 506/2004, Art. 3 (3) a), b) Law No. 506/2004 |
| 2020-03-26 | bank | €3K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-10-15 | Unknown Company | €3K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 13 GDPR, Art. 24 GDPR, Art. 25 GDPR |
| 2019-06-03 | Claim management company | €3K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-06-26 | Financial Enterprise | €3K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 21 GDPR |
| 2019-06-26 | Unknown | €3K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-12-09 | Smart Cities Sp. z o.o. | €3K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Non-cooperation with Data Protection Authority | --Articles: Art. 31 GDPR, Art. 58 GDPR |
| 2022-01-27 | EU Disinfolab | €3K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a), c), f) GDPR, Art. 6 (1) GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 14 GDPR, Art. 30 GDPR, Art. 32 GDPR, Art. 35 GDPR |
| 2021-04-08 | Unknown | €3K | GDPR | National Commission for Data Protection (CNPD) | Luxembourg | Failure to comply with data processing principles | --Articles: Art 5 (1) e) GDPR, Art. 13 GDPR |
| 2021-04-20 | Website operator | €3K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information | Hungary | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (2) GDPR, Art. 24 GDPR |
| 2020-01-01 | Mall.tv | €3K | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2022-01-01 | Covid-19 Test Center | €3K | GDPR | Data Protection Authority of Hamburg | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) GDPR |
| 2022-01-01 | Credit institution | €3K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information | Hungary | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR, Art. 5 (2) GDPR |
| 2022-12-08 | Jewelry manufacturer | €3K | GDPR | Croatian Data Protection Authority (AZOP) | Croatia | Insufficient fulfilment of information obligations | --Articles: Art. 27 (2) Croatian Act on the Implementation of the GDPR |
| 2022-12-08 | Retailer | €3K | GDPR | Croatian Data Protection Authority (AZOP) | Croatia | Insufficient fulfilment of information obligations | --Articles: Art. 27 (2) Croatian Act on the Implementation of the GDPR |