Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2021-01-01Political organization€0GDPR Data Protection Authority of SaarlandGermanyUnknown
--

Articles: Unknown

2021-01-01Physician€0GDPRData Protection Authority of BrandenburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 9 GDPR

2021-01-01Private individual€0GDPRAustrian Data Protection Authority (DSB)AustriaFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), c) GDPR

2021-01-01Clinic€0GDPRData Protection Authority of BerlinGermanyUnknown
--

Articles: Unknown

2021-01-01Police department€0GDPRData Protection Authority of SaxonyGermanyUnknown
--

Articles: Unknown

2021-01-01Unknown€0GDPRData Protection Authority of BerlinGermanyUnknown
--

Articles: Unknown

2019-07-08British Airways€0GDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
The ICO notified the British Airways of its intention to issue a fine worth 183....

The ICO notified the British Airways of its intention to issue a fine worth 183.39 million pounds because of an alleged infringement of Art. 31 of the GDPR. The reason for this is related to an incident which the company reported in September 2018, when the British Airways website had diverted the users’ traffic to a dangerous website. The hackers in charge of this website had stolen the personal data of more than 500.000 customers. The company had poor security mechanisms to prevent such cyber-attacks from happening.<strong>Notice:</strong> British Airways is facing a fine of €204,600,000, but this is not yet final. As such, it’s not included in our statistics dashboard.

Articles: Art. 32 GDPR

2021-01-01Medicalclinic€0GDPRData Protection Authority of BerlinGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-01-01Real estate agent€0GDPRData Protection Authority of BrandenburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR, Art. 12 GDPR

2021-01-01Unknown€0GDPRData Protection Authority of BrandenburgGermanyUnknown
--

Articles: Unknown

2022-01-01Aid organization€0GDPRData Protection Authority of BrandenburgGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 28 (3) GDPR, Art. 32 GDPR

2022-01-01Restaurant operator€0GDPRData Protection Authority of BrandenburgGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2019-07-09Marriott International, Inc€0GDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
While the trial hasn’t ended yet, the ICO intends to fine the company. This is i...

While the trial hasn’t ended yet, the ICO intends to fine the company. This is in accordance with Art. 32 of the GDPR, which the company allegedly infringed in a cyber-incident in November 2018. The incident involved the public exposal of personal records belonging to over 339 million people, out of which 31 million were residents of the European Economic Area. This vulnerability is believed to have been present in the Starwood hotels group, which Marriott International acquired. Due to the inappropriate and insufficient attention paid to the security of the systems, the ICO believes a fine is in order.<strong>Notice:</strong> Marriott is facing a fine of €110,390,200, but this is not yet final. As such, it’s not included in our statistics dashboard.

Articles: Art. 32 GDPR

--Hamburger Volksbank eG€0GDPRData Protection Authority of HamburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 21 GDPR

2021-01-01Private individual€0GDPRData Protection Authority of SaxonyGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

2021-02-22Security company €0GDPRCroatian Data Protection Authority (AZOP)CroatiaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1) b), d) GDPR, Art. 32 (2), (4) GDPR

2022-01-01Operator of a swimming pool€0GDPRData Protection Authority of BrandenburgGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) c) GDPR

2021-01-01Company€0GDPRData Protection Authority of NiedersachsenGermanyFailure to implement sufficient measures to ensure information
--

Articles: Art. 25 GDPR, Art. 32 GDPR

2022-01-01Bank€0GDPRData Protection Authority of BrandenburgGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 28 (3) GDPR, Art. 32 GDPR

2019-10-01Deutsche Wohnen SE€0GDPRData Protection Authority of BerlinGermanyFailure to comply with data processing principles
Further fines of between €6,000 and €17,000 were issues to the company due to th...

Further fines of between €6,000 and €17,000 were issues to the company due to the faulty storage of personal data. See the separate entry about Deutsche Wohnen SE.

Articles: Art. 5 GDPR, Art. 25 GDPR

2021-10-06Meta Platforms€0GDPRData Protection Authority of IrelandIrelandNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR, Art. 12 (1) GDPR, Art. 13 (1) c) GDPR

1970-01-01Unknown€0GDPRSlovak Data Protection OfficeSlovakiaFailure to implement sufficient measures to ensure information security
Personal data in the form of documents were thrown to the garbage dump, which is...

Personal data in the form of documents were thrown to the garbage dump, which is an improper method of disposing of such documents.

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

1970-01-01Unknown€0GDPRSlovak Data Protection OfficeSlovakiaNon-compliance with subjects' rights protection safeguards
The data controller did not comply with the data subject’s request to access per...

The data controller did not comply with the data subject’s request to access personal data related to audio recordings.

Articles: Art. 15 GDPR

2019-07-10Driver and Vehicle Licensing Agency (DVLA)€0GDPRInformation CommissionerUnited KingdomNon-compliance (Data Breach)
The Company shared personal driver details with other third-parties, including p...

The Company shared personal driver details with other third-parties, including parking firms.

Articles: Unknown

2021-01-01Unknown€0GDPRData Protection Authority of SaxonyGermanyFailure to implement sufficient measures to ensure information
--

Articles: Art. 32 GDPR

PreviousPage 79 of 82Next