Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2020-12-16 | Next Time Media Ügynökség Kft. | €1K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Hungary | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) GDPR |
| 2022-03-29 | Workshop | €1K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information | Hungary | Failure to comply with data processing principles | --Articles: Art. 5 (1) b), c), GDPR, Art. 6 (1) f) GDPR, Art. 13 (1), (2) GDPR |
| 2022-01-01 | Website operator | €1K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information | Hungary | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 12 (2), (3) GDPR, Art. 31 GDPR |
| 2021-01-20 | Private individual | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR |
| 2022-09-23 | URBANO DIVERTIA, S.L. | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDPR |
| 2021-06-14 | Inmopiso Zaragoza S.L. | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 13 GDPR |
| 2023-02-21 | Private individual | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR, Art. 13 GDPR |
| 2022-05-09 | CONTIMAG INVEST, S.L. | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 GDPR |
| 2021-12-16 | Private Individual | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Information obligation non-compliance | --Articles: Art. 13 GDPR |
| 2022-08-28 | DIGITECNIA SOLUTIONS, S.L. | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2022-01-21 | Property Owner Community | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2022-02-23 | FRUTAS Y VERDURAS LOS CAMPEONES, S.L. | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 GDPR |
| 2022-01-27 | Researcher | €1K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a), c), f) GDPR, Art. 6 (1) GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 14 GDPR, Art. 32 GDPR |
| 2020-11-27 | Private individual | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR |
| 2022-04-23 | MOVALIA TRASLADOS, S.L.U. | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR, Art. 13 GDPR |
| 2022-09-25 | Health insurance provider | €1K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information | Hungary | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 5 (2) GDPR, Art. 12 (3), (4) GDPR, Art. 31 GDPR |
| 2023-05-05 | FUNDACIO PRIVADA UNIVERSITARIA EADA | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2020-06-03 | Entrepreneur running a non-public nursery and pre-school | €1K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Failure to comply with Data Processing Authority's orders | --Articles: Art. 31 GDPR, Art. 58 GDPR |
| 2019-02-04 | Car renting company | €1K | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to implement sufficient measures to ensure information security | The company sold a card that was constantly tracked through GPS. The owner found...The company sold a card that was constantly tracked through GPS. The owner found this out and reported it since the company had no information related to this GPS tracking. The Czech Data Protection Authority decreed that this was a violation of Art. 5 (1) of the GDPR, and issued a fine. Articles: Art. 5 (1) a) GDPR |
| 2019-02-04 | Credit brokerage | €1K | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to implement sufficient measures to ensure information security | The company did not process the data using the appropriate security measures req...The company did not process the data using the appropriate security measures required to prevent unlawful alteration or destruction of the data. Articles: Art. 32 GDPR |
| 2019-02-04 | Car renting company | €1K | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) a) GDPR |
| 2019-02-04 | Credit brokerage | €1K | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-09-03 | Private enforcement agent | €1K | GDPR | Data Protection Commission of Bulgaria (KZLD) | Bulgaria | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 12 (4) GDPR, Art. 15 GDPR |
| 2019-09-03 | Private enforcement agent | €1K | GDPR | Data Protection Commission of Bulgaria (KZLD) | Bulgaria | Non-compliance with subjects' rights protection safeguards | A private enforcement agent was fined for the unlawful processing of personal da...A private enforcement agent was fined for the unlawful processing of personal data of an individual. The agent had conducted video surveillance on the individual and refused to grant access to the collected data. The affected individual submitted an application to access their personal data but the enforcement agent rejected this request and refused to motivate this decision. Articles: Art. 12 (4) GDPR, Art. 15 GDPR |
| 2019-09-03 | Telecom company | €1K | GDPR | Data Protection Commission of Bulgaria (KZLD) | Bulgaria | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR, Art. 25 (1) GDPR |