Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2021-11-25 | Cabinet Office | €585K | GDPR | Information Commissioner (ICO) | United Kingdom | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR |
| 2022-02-24 | Dutch Foreign Ministry | €565K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 13 (1) e) GDPR, Art. 32 (1) GDPR |
| 2022-10-31 | TECHPUMP SOLUTIONS, S.L. | €525K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Several | --Articles: Art. 5 (1) a), b), e) GDPR, Art. 6 (1) GDPR, Art. 8 GDPR, Art. 12 (1), (2) GDPR, Art. 13 GDPR, Art. 25 GDPR, Art. 30 (1) GDPR, Art. 22 (2) LSSI |
| 2020-12-20 | Locatefamily.com | €525K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Failure to comply with data processing principles | --Articles: Art. 27 GDPR |
| 2022-01-14 | DPG Media Magazines B.V. | €525K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 12 (2) GDPR |
| 2022-09-20 | Unknown company | €525K | GDPR | Data Protection Authority of Berlin | Germany | Non-cooperation with Data Protection Authority | --Articles: Art. 38 (6) GDPR |
| 2020-03-03 | Royal Dutch Tennis Assoc. | €525K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2020-03-03 | Royal Dutch Tennis Assoc. | €525K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with lawful basis for data processing | The Royal Dutch Tennis Association (“KNLTB”) was fined a total of €5...The Royal Dutch Tennis Association (“KNLTB”) was fined a total of €525,000 for selling the personal data of more than 350,000 of its members to sponsors. The sponsors have then contacted some of these individuals by email and telephone for marketing purposes. Personal data sold included the name, gender, and address of various individuals. No consent was obtained from the affected individuals beforehand. The Royal Dutch Tennis Association (“KNLTB”) argued that it had a legitimate interest to sell this data, and as such did not commit a GDPR breach. The Dutch Data Protection Authority, however, rejected this and ruled that KNLTB had no legal basis to sell the personal data of its members to third parties. Articles: Art. 5 GDPR, Art. 6 GDPR |
| 2019-08-28 | DSK Bank | €511K | GDPR | Data Protection Commission of Bulgaria (KZLD) | Bulgaria | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-08-28 | DSK Bank | €511K | GDPR | Data Protection Commission of Bulgaria (KZLD) | Bulgaria | Failure to implement sufficient measures to ensure information security | Data leakage due to the inappropriate security and organizational measures of th...Data leakage due to the inappropriate security and organizational measures of the company. Information related to more than 23.000 credits records belonging to more than 33.000 customers were made public. The data included names, ID numbers, biometric data, addresses, and copies of identity cards. Articles: Art. 32 GDPR |
| 2021-06-14 | Brico Prive | €500K | GDPR | French Data Protection Authority (CNIL) | France | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) e) GDPR, Art. 13 GDPR, Art. 17 GDPR, Art. 32 GDPR, Art. 82 Loi informatique et libertés, Art. L. 34-5 CPCE |
| 2019-11-21 | Futura Internationale | €500K | GDPR | French Data Protection Authority (CNIL) | France | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 21 GDPR |
| 2020-12-17 | Roma Capitale (Rome Municipality) | €500K | GDPR | Italian Data Protection Authority (Garante) | Italy | Multiple | --Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 28 (2), (3) GDPR, Art. 32 GDPR |
| 2019-11-21 | Futura Internationale | €500K | GDPR | French Data Protection Authority (CNIL) | France | Non-compliance with subjects' rights protection safeguards | Futura Internationale was fined because after several individuals have complaine...Futura Internationale was fined because after several individuals have complained that they were cold-called by the company even after they have expressly requested not to be called again. The reason why the fine was so high relative to similar cases and fines was that the CNIL determined that the company had received a large number of letters requesting to be taken off from the call lists but decided to ignore them. More so, Futura Internationale was found to store excessive information about customers and their health data. The company did also not inform their customers about the processing of their personal data and that all telephone conversations were recorded. Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 21 GDPR |
| 2022-05-04 | Bulgarian Post EAD | €500K | GDPR | Data Protection Commission of Bulgaria (KZLD) | Bulgaria | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 (1) b), c), d) GDPR, Art. 32 (2) GDPR |
| 2022-11-10 | Vodafone Italia S.p.A. | €500K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 12 (1) GDPR, Art. 13 GDPR, Art. 130 (1), (2), (3) Codice della privacy |
| 2021-09-27 | Ferde AS | €496K | GDPR | Norwegian Supervisory Authority (Datatilsynet) | Norway | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 28 (3) GDPR, Art. 32 (2) GDPR, Art. 44 GDPR |
| 2022-04-05 | Bank of Ireland | €463K | GDPR | Data Protection Authority of Ireland | Ireland | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR, Art. 33 GDPR, Art. 34 GDPR |
| 2022-03-15 | CafePress | $500K | FTC Act Section 5 | FTC | United States | data_breach | Failed to secure consumer data, leading to breach affecting millions. CEO ordere...Failed to secure consumer data, leading to breach affecting millions. CEO ordered to implement security program. |
| 2023-01-23 | Centric Health Ltd. | €460K | GDPR | Data Protection Authority of Ireland | Ireland | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR |
| 2019-06-18 | Hague Hospital | €460K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2019-06-18 | Hague Hospital | €460K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Failure to implement sufficient measures to ensure information security | After a serious investigation, the DDPA surmised that the Hague Hospital failed ...After a serious investigation, the DDPA surmised that the Hague Hospital failed to provide the appropriate security measures for possession of patient records. This investigation had started following several events when multiple staff hospital members had checked the personal data of a Dutch person. Measures were taken, and the hospital was warned – it would have to update its security measures by the 2nd of October 2019 or it would incur e penalty of 100.000 EUR every two weeks. Articles: Art. 32 GDPR |
| 2020-12-15 | €450K | GDPR | Data Protection Authority of Ireland | Ireland | Failure to notify DPA of a data breach | --Articles: Art. 33 (1), (5) GDPR | |
| 2021-05-31 | UWV (Dutch Employee insurance service provider) | €450K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-12-14 | Virgin Mobile Polska | €443K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f), (2) GDPR, Art. 25 (1) GDPR, Art. 32 (1) b), d), (2) GDPR |