Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2023-02-17Suomen Asiakastieto Oy€440KGDPRDeputy Data Protection OmbudsmanFinlandNon-cooperation with Data Protection Authority
--

Articles: Art. 58 (2) GDPR

2021-10-18Østre Toten municipality€412KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2021-07-26Monsanto Corporation€400KGDPRFrench Data Protection Authority (CNIL)FranceInformation obligation non-compliance
--

Articles: Art. 14 GDPR, Art. 28 GDPR

2018-07-17Hospital€400KGDPRPortuguese Data Protection Authority (CNPD)PortugalFailure to implement sufficient measures to ensure information security
The hospital was found to create fake doctor profiles for the personnel to unlaw...

The hospital was found to create fake doctor profiles for the personnel to unlawfully access patient data. The management system found 985 registered doctors when the hospital only had 296 doctors.

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2021-07-22Atac s.p.a.€400KGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 30 GDPR, Art. 32 GDPR

2018-07-17Hospital€400KGDPRPortuguese Data Protection Authority (CNPD)PortugalFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2021-11-12Transavia€400KGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 (1), (2) GDPR

2019-05-28SERGIC€400KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
The company was fined because of two reasons – the complete lack of security mea...

The company was fined because of two reasons – the complete lack of security measures, and excessive data storage. Regarding the former reason, personal data, including health cards, IDs, divorce judgments, and account statements were available online with no authentication procedure. Moreover, the company breached the data storage deadline it had in place and kept clients’ data for more than it should have.

Articles: Art. 32 GDPR

2021-11-04Régie autonome des transports parisiens€400KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) c) GDPR, Art. 5 (1) e) GDPR, Art. 5 (2) GDPR, Art. 32 GDPR

2019-05-28SERGIC€400KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2020-11-24City of Stockholm€394KGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 32 GDPR

2020-12-03Karolinska University Hospital of Solna€390KGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2021-02-11Roma Capitale€350KGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 28 GDPR, Art. 32 GDPR

2020-12-03Sahlgrenska University Hospital€341KGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2019-12-17Doorstep Dispensaree€320KGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-12-20Doorstep Dispensaree€320KGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
The company had stored some 500,000 documents containing names, addresses, dates...

The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back of the building and failed to protect these documents from the elements, resulting in water damage to the documents.The company stored around 500,000 documents that contained the names, addresses, birth fates, and NHS identification numbers as well as medical information and prescriptions in unsealed containers at the back of a building. As a result of this, the documents were exposed to the elements which resulted in water damage and potentially to the loss of some data.

Articles: Art. 32 GDPR

2023-01-01Ediscom S.p.a.€300KGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b), c) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 14 GDPR, Art. 25 GDPR, Art. 130 Codice della privacy

2022-12-08FREE SAS€300KGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 12 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 32 GDPR, Art. 33 GDPR

2021-12-28FREE MOBILE€300KGDPRFrench Data Protection Authority (CNIL)FranceFailure to implement sufficient measures to ensure information security
--

Articles: Art. 12 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. 25 GDPR, Art. 32 GDPR

2021-03-10VfB Stuttgart 1893 AG€300KGDPRData Protection Authority of Baden-WuerttembergGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (2) GDPR

2019-12-02Unknown€294KGDPRData Protection Authority of NiedersachsenGermanyFailure to comply with data processing principles
A company was fined with €294,000 because of the “unnecessarily long&#8221...

A company was fined with €294,000 because of the “unnecessarily long” storage and retention of personal data in the selection of personnel. During the selection process, even health data was requested, which was excessive according to the DPA.

Articles: Art. 5 GDPR

2019-12-02Unknown€294KGDPRData Protection Authority of NiedersachsenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 GDPR

2020-06-12Digi Távközlési Szolgáltató Kft.€288KGDPRHungarian National Authority for Data Protection and the Freedom of Information (NAIH)HungaryFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) b), (e) GDPR, Art. 32 (1), (2) GDPR

2022-07-21Telecommunications company€285KGDPRCroatian Data Protection Authority (AZOP)CroatiaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 25 (1) GDPR, Art. 32 (1) b) GDPR, Art. 32 (2) GDPR

2020-09-03Bergen Municipality€276KGDPRNorwegian Supervisory Authority (Datatilsynet)NorwayFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

PreviousPage 9 of 82Next