Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2022-11-24 | STS Di Prisinzano s.r.l. | €1K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR |
| 2022-11-24 | Private individual | €1K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 32 GDPR, Art. 2-septies (8) Codice della privacy |
| 2023-01-31 | Dent Estet Clinic SA | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to notify DPA of a data breach | --Articles: Art. 33 GDPR |
| 2022-11-09 | SC Das Sense Society SRL | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-cooperation with Data Protection Authority | --Articles: Art. 58 (1) GDPR |
| 2021-11-15 | Private individual | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2022-02-07 | Café Operator | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2022-02-01 | SC Grupex 2000 SRL | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to comply with data processing principles | --Articles: Art. 6 GDPR, Art. 9 GDPR |
| 2022-01-13 | A.S.L. Napoli 1 Centro | €1K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 2-ter Codice della privacy |
| 2021-12-16 | Universita Telematica Internazionale Uninettuno | €1K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) c) GDPR |
| 2022-08-29 | Alpha Bank Romania SA | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 29 GDPR, Art. 32 (1) b) GDPR, Art. 32 (2), (4) GDPR |
| 2022-08-16 | Farpa s.r.l. | €1K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR, Art. 88 GDPR, Art. 114 Codice della privacy |
| 2022-04-18 | IKEA România S.R.L. | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 12 (3) GDPR |
| 2022-02-02 | Café Operator | €1K | GDPR | National Commission for Data Protection (CNPD) | Luxembourg | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR, Art. 13 GDPR |
| 2022-06-20 | SC Interactions Marketing SRL | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) b) GDPR |
| 2022-02-21 | Store owner | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 GDPR |
| 2022-02-22 | Civil law firm “Sabou, Burz & Cuc” | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) a), b), c), f) GDPR, Art. 5 (2) GDPR, Art. 6 GDPR |
| 2023-01-31 | Dentist | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) a) GDPR, Art. 9 (2) a) GDPR |
| 2022-01-13 | Villa Masi Residenza per anziani | €1K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 GDPR |
| 2022-12-20 | Private Individual | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 5 (1) c) GDPR |
| 2020-10-29 | American College of Greece | €1K | GDPR | Hellenic Data Protection Authority (HDPA) | Greece | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 12 (3), (4) GDPR |
| 2021-07-01 | Unknown | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Failure to comply with data processing principles | --Articles: Art. 6 (1) GDPR |
| 2021-10-04 | Store owner | €1K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Information obligation non-compliance | --Articles: Art. 13 GDPR |
| 2023-02-01 | Tensa Art Design SA | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Insufficient fulfilment of data subjects rights | --Articles: Art. 21 (3) GDPR |
| 2023-01-18 | Dante Internațional SA | €1K | GDPR | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Romania | Information obligation non-compliance | --Articles: Art. 17 GDPR |
| 1970-01-01 | Individual entrepreneur | €980 | GDPR | Czech Data Protection Authority (UOOU) | Czech Republic | Failure to implement sufficient measures to ensure information security | An online game operator was exposed to a DDoS attack that led to the malfunction...An online game operator was exposed to a DDoS attack that led to the malfunctioning of the game serves. The attackers blackmailed the operator into paying money for the attacks to stop. As part of the “deal”, the attackers offered the operator to create and implement a better firewall protection system that would prevent any future attacks from other parties. The operator agreed to this “deal”. The game operator then implemented the new code which indeed proved to be better than the old one used but – let’s be honest, unsurprisingly – also included a backdoor that allowed the attacker to steal all the data that was on the server which included player details and personal information. The attacker uploaded this information on their website after that. Articles: Art. 32 GDPR |