Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,014 fines found

Total: $6.2B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2022-10-20Douglas Italia S.p.a.€1.4MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) b), e) GDPR, Art. 5 (2) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 12 (1) GDPR, Art. 13 (2) a) GDPR, Art. 24 GDPR, Art. 25 (1) GDPR

2023-02-01GoodRx$1.5MHealth Breach Notification RuleFTCUnited Statesconsent
First FTC enforcement under Health Breach Notification Rule. Shared health data ...

First FTC enforcement under Health Breach Notification Rule. Shared health data with advertisers.

2022-04-05Danske Bank€1.3MGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to comply with data processing principles
--

Articles: Art. 5 (2) GDPR

2021-12-21Lisbon City Council€1.3MGDPRPortuguese Data Protection Authority (CNPD)PortugalNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 6 GDPR, Art. 9 (1) a) GDPR, Art. 13 (1), (2) GDPR, Art. 35 (3) GDPR

2020-06-30Allgemeine Ortskrankenkasse€1.2MGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 32 GDPR

2021-06-07MedHelp AB€1.2MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) a), f) GDPR, Art. 6 GDPR, Art. 9 (1) GDPR, Art. 13 GDPR, Art. 32 GDPR

2020-12-03Aleris Sjukvård AB€1.2MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2022-07-26Volkswagen€1.1MGDPRData Protection Authority of SaxonyGermanynsufficient fulfilment of information obligations
--

Articles: Art. 13 GDPR, Art. 28 GDPR, Art. 30 GDPR, Art. 35 GDPR

2022-06-23TotalEnergies Electricite et Gaz France€1.0MGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 14 GDPR, Art. 15 GDPR, Art. 21 GDPR

2022-11-24Areti spa€1.0MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) d), e) GDPR, Art. 5 (2) GDPR, Art. 12 GDPR, Art. 15 GDPR, Art. 24 GDPR

2022-01-19Fortum Marketing and Sales Polska S.A.€1.0MGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art 24 (1) GDPR, Art. 25 (1) GDPR, Art. 28 (1) GDPR, Art. 32 (1), (2) GDPR

2021-11-12WS WiSpear Systems Ltd€925KGDPRCypriot Data Protection CommissionerCyprusNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR

2023-02-06Sats ASA€900KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), e) GDPR, Art. 6 (1) GDPR, Art. 12 (1), (3) GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 17 GDPR

2020-11-111&1 Telecom GmbH€900KGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2021-09-24Vattenfal Europe Sales GmbH€900KGDPRData Protection Authority of HamburgGermanyInsufficient data processing agreement
--

Articles: Art. 12 GDPR, Art. 13 GDPR

2022-07-28Hannoversche Volksbank€900KGDPRData Protection Authority of SaxonyGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR

2022-02-01TELEFONICA MOVILES ESPANA, S.A.U.€900KGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR

2019-10-31UWV - Insurance provider€900KGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to implement sufficient measures to ensure information security
The Dutch employee insurance service provider – “Uitvoeringsinstituu...

The Dutch employee insurance service provider – “Uitvoeringsinstituut Werknemersverzekeringen – UWV did not use multi-factor authentication for accessing the employer web portal. Health and safety services, as well as employers, were able to view and collect data from employees, data to which normally they should not have had access to.

Articles: Art. 32 GDPR

2019-10-31UWV - Insurance provider€900KGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2020-07-06Bureau Krediet Registration€830KGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsNon-compliance with lawful basis for data processing
--

Articles: Art. 12 GDPR, Art. 15 GDPR

2020-11-18Carrefour Banque€800KGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 GDPR

2020-07-13Iliad Italia S.p.A.€800KGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 25 GDPR

2022-11-10Discord Inc.€800KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) e) GDPR, Art. 13 GDPR, Art. 25 (2) GDPR, Art. 32 GDPR, Art. 35 GDPR

2021-07-22Roma Capitale€800KGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 25 GDPR, Art. 28 GDPR, Art. 32 GDPR

2021-04-09TikTok€750KGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsInformation obligation non-compliance
--

Articles: Art. 12 GDPR

PreviousPage 6 of 81Next