Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2023-05-04B2 Kapital d.o.o.€2.3MGDPRCroatian Data Protection Authority (AZOP)CroatiaNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR, Art. 13 (1) GDPR, Art. 28 (3) GDPR, Art. 32 (1) b), d) GDPR, Art. 32 (2) GDPR

2020-11-18Carrefour France€2.3MGDPRFrench Data Protection Authority (CNIL)FranceMultiple
--

Articles: Art. 5 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 17 GDPR, Art. 21 GDPR, Art. 32 GDPR, Art. 33 GDPR

2024-05-15Airbnb Ireland€2.1MGDPRIreland DPCIrelandconsent
Excessive collection and processing of ID document data.

Excessive collection and processing of ID document data.

Articles: Art. 6

2022-10-06Alpha Exploration€2.0MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), e), f) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 12 (1) GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 27 (4) GDPR, Art. 28 GDPR, Art. 32 GDPR, Art. 35 GDPR

2022-02-11Amazon Road Transport Spain S.L.€2.0MGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) GDPR, Art. 10 GDPR, Art. 10 LOPDGDD

2021-08-02Unser O-Bonus Club GmbH€2.0MGDPRAustrian Data Protection Authority (DSB)AustriaFailure to comply with data processing principles
--

Articles: Art. 6 GDPR, Art. 7 GDPR, Art. 12 GDPR

2022-03-03BREBAU GmbH€1.9MGDPRData Protection Authority of BremenGermanyFailure to comply with data processing principles
--

Articles: Art. 5 (1) GDPR, Art. 6 (1) GDPR, Art. 9 GDPR

2021-07-20SGAM AG2R LA MONDIALE€1.8MGDPRFrench Data Protection Authority (CNIL)FranceFailure to comply with data processing principles
--

Articles: Art. 5 (1) e) GDPR, Art. 13 GDPR, Art .14 GDPR

2021-06-21Storstockholms Lokaltrafik€1.6MGDPRData Protection Authority of SwedenSwedenNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), c) GDPR, Art. 6 (1) f) GDPR, Art. 13 GDPR

2022-10-04Easylife Ltd.€1.5MGDPR Information Commissioner (ICO)United KingdomFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 13 (1) c) GDPR, Regulation 21 PECR

2022-04-15DEDALUS BIOLOGIE€1.5MGDPR French Data Protection Authority (CNIL)France Non-compliance with subjects' rights protection safeguards
--

Articles: Art. 28 GDPR, Art. 29 GDPR, Art. 32 GDPR

2020-12-03Aleris Sjukvård AB€1.5MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2020-11-13Ticketmaster UK Limited€1.4MGDPRInformation Commissioner (ICO)United KingdomFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 32 GDPR

2022-10-20Douglas Italia S.p.a.€1.4MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) b), e) GDPR, Art. 5 (2) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 12 (1) GDPR, Art. 13 (2) a) GDPR, Art. 24 GDPR, Art. 25 (1) GDPR

2023-02-01GoodRx$1.5MHealth Breach Notification RuleFTCUnited Statesconsent
First FTC enforcement under Health Breach Notification Rule. Shared health data ...

First FTC enforcement under Health Breach Notification Rule. Shared health data with advertisers.

2022-04-05Danske Bank€1.3MGDPRDanish Data Protection Authority (Datatilsynet)DenmarkFailure to comply with data processing principles
--

Articles: Art. 5 (2) GDPR

2021-12-21Lisbon City Council€1.3MGDPRPortuguese Data Protection Authority (CNPD)PortugalNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 6 GDPR, Art. 9 (1) a) GDPR, Art. 13 (1), (2) GDPR, Art. 35 (3) GDPR

2020-06-30Allgemeine Ortskrankenkasse€1.2MGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 32 GDPR

2021-06-07MedHelp AB€1.2MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) a), f) GDPR, Art. 6 GDPR, Art. 9 (1) GDPR, Art. 13 GDPR, Art. 32 GDPR

2020-12-03Aleris Sjukvård AB€1.2MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2022-07-26Volkswagen€1.1MGDPRData Protection Authority of SaxonyGermanynsufficient fulfilment of information obligations
--

Articles: Art. 13 GDPR, Art. 28 GDPR, Art. 30 GDPR, Art. 35 GDPR

2022-06-23TotalEnergies Electricite et Gaz France€1.0MGDPRFrench Data Protection Authority (CNIL)FranceNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 14 GDPR, Art. 15 GDPR, Art. 21 GDPR

2022-01-19Fortum Marketing and Sales Polska S.A.€1.0MGDPRPolish National Personal Data Protection Office (UODO)PolandFailure to comply with data processing principles
--

Articles: Art. 5 (1) f) GDPR, Art 24 (1) GDPR, Art. 25 (1) GDPR, Art. 28 (1) GDPR, Art. 32 (1), (2) GDPR

2022-11-24Areti spa€1.0MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) d), e) GDPR, Art. 5 (2) GDPR, Art. 12 GDPR, Art. 15 GDPR, Art. 24 GDPR

2021-11-12WS WiSpear Systems Ltd€925KGDPRCypriot Data Protection CommissionerCyprusNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) a) GDPR

PreviousPage 6 of 82Next