Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2021-07-27 | PODEMOS Political Party | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR, Art. 13 GDPR |
| 2020-12-03 | Dr Marín Cirugia Plástica, S.L.P. | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 GDPR |
| 2023-03-06 | Finopro IFN SA | €2K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) b), c) GDPR, Art. 32 (2) GDPR |
| 2018-12-20 | Private individual | €2K | GDPR | Austrian Data Protection Authority (DSB) | Austria | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a) GDPR, Art. 5 (1) c) GDPR, Art. 6 (1) GDPR, Art. 13 GDPR |
| 2021-08-14 | President of the Zgierz District Court | €2K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) f) GDPR, Art. 25 (1) GDPR, Art. 32 (1) b), d), (2) GDPR |
| 2018-12-20 | Private individual | €2K | GDPR | Austrian Data Protection Authority (DSB) | Austria | Non-compliance with lawful basis for data processing | A person was fined for having unlawfully filmed public areas using a private CCT...A person was fined for having unlawfully filmed public areas using a private CCTV system. The system filmed parking lots, sidewalks, a garden area of a nearby property, and it also filmed the neighbors going in and out of their homes. The video surveillance was found to be unreasonable given the initial purpose of the CCTV system itself. Because it filmed private areas of life without the express consent of the people involved, the subject was fined. Articles: Art. 5 (1) a) GDPR, Art. 5 (1) c) GDPR, Art. 6 (1) GDPR, Art. 13 GDPR |
| 2022-07-27 | University Hospital of the Medical University of Warsaw | €2K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Insufficient fulfilment of data breach notification obligations | --Articles: Art. 33 GDPR, Art. 34 GDPR |
| 2022-12-13 | Company | €2K | GDPR | National Commission for Data Protection (CNPD) | Luxembourg | Non-compliance with lawful basis for data processing | --Articles: Art. 12 (1) GDPR, Art. 13 GDPR |
| 2022-05-31 | Stołeczny Ośrodek dla Osób Nietrzeźwych | €2K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR |
| 2021-07-27 | Vasco Andaluza de Inversiones S.L. | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR |
| 2021-07-27 | Body Tonic Shop S.L. | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR |
| 2022-07-28 | Auto Hi-Fi System S.n.c. | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), c) GDPR, Art. 13 GDPR |
| 2022-11-02 | Rapido Finance, S.L. | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR |
| 2022-04-29 | Santa Ninfa Municipality | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), c) GDPR, Art. 6 (1) c), e) Art. 6 (2) GDPR, Art. 6 (3) b) GDPR GDPR, Art. 2-ter (1), (3) Codice della privacy |
| 2021-09-29 | Physician | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a) GDPR, Art. 9 GDPR |
| 2021-10-28 | OTTO s.r.l. | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 GDPR |
| 2021-05-27 | Private individual | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2022-09-19 | Banca Comercială Română SA | €2K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to implement sufficient measures to ensure information | --Articles: Art. 25 (1) GDPR, Art. 32 (1) b), d), e) GDPR |
| 2022-09-21 | Istituto Comprensivo – IC Cosenza III “V. Negroni” | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 2-ter Codice della privacy, Art. 2-septies (8) Codice della privacy |
| 2022-07-21 | Global Service s.r.l. | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR |
| 2022-12-28 | Homeowners Association | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR, Art. 15 GDPR |
| 2020-11-18 | Anmavas 61, S.L. | €2K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-cooperation with Data Protection Authority | --Articles: Art. 58 GDPR |
| 2022-03-10 | Operatorul Briza Land S.R.L. | €2K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 15 GDPR |
| 2022-02-10 | Comune di Guidizzolo | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), c) GDPR, Art. 6 GDPR, Art. 2-ter Codice della privacy |
| 2022-05-12 | Singh Market | €2K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR |