Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
2,028 fines found
Total: $8.1B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2023-02-06 | Sats ASA | €900K | GDPR | Norwegian Supervisory Authority (Datatilsynet) | Norway | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), e) GDPR, Art. 6 (1) GDPR, Art. 12 (1), (3) GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 17 GDPR |
| 2022-07-28 | Hannoversche Volksbank | €900K | GDPR | Data Protection Authority of Saxony | Germany | Non-compliance with lawful basis for data processing | --Articles: Art. 6 (1) GDPR |
| 2019-10-31 | UWV - Insurance provider | €900K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2020-11-11 | 1&1 Telecom GmbH | €900K | GDPR | The Federal Commissioner for Data Protection and Freedom of Information (BfDI) | Germany | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2022-02-01 | TELEFONICA MOVILES ESPANA, S.A.U. | €900K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDPR |
| 2019-10-31 | UWV - Insurance provider | €900K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Failure to implement sufficient measures to ensure information security | The Dutch employee insurance service provider – “Uitvoeringsinstituu...The Dutch employee insurance service provider – “Uitvoeringsinstituut Werknemersverzekeringen – UWV did not use multi-factor authentication for accessing the employer web portal. Health and safety services, as well as employers, were able to view and collect data from employees, data to which normally they should not have had access to. Articles: Art. 32 GDPR |
| 2021-09-24 | Vattenfal Europe Sales GmbH | €900K | GDPR | Data Protection Authority of Hamburg | Germany | Insufficient data processing agreement | --Articles: Art. 12 GDPR, Art. 13 GDPR |
| 2020-07-06 | Bureau Krediet Registration | €830K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with lawful basis for data processing | --Articles: Art. 12 GDPR, Art. 15 GDPR |
| 2020-07-13 | Iliad Italia S.p.A. | €800K | GDPR | Italian Data Protection Authority (Garante) | Italy | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 25 GDPR |
| 2022-11-10 | Discord Inc. | €800K | GDPR | French Data Protection Authority (CNIL) | France | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 (1) e) GDPR, Art. 13 GDPR, Art. 25 (2) GDPR, Art. 32 GDPR, Art. 35 GDPR |
| 2021-07-22 | Roma Capitale | €800K | GDPR | Italian Data Protection Authority (Garante) | Italy | Failure to implement sufficient measures to ensure information security | --Articles: Art. 5 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 25 GDPR, Art. 28 GDPR, Art. 32 GDPR |
| 2020-11-18 | Carrefour Banque | €800K | GDPR | French Data Protection Authority (CNIL) | France | Failure to comply with data processing principles | --Articles: Art. 5 GDPR |
| 2023-02-27 | Bank of Ireland 365 | €750K | GDPR | Data Protection Authority of Ireland | Ireland | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 32 (1) GDPR |
| 2021-04-09 | TikTok | €750K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Information obligation non-compliance | --Articles: Art. 12 GDPR |
| 2022-12-13 | Alektum Oy | €750K | GDPR | Deputy Data Protection Ombudsman | Finland | Insufficient fulfilment of data subjects rights | --Articles: Art. 12 (3) GDPR, Art. 15 (1), (3) GDPR |
| 2020-04-30 | Unknown organization | €725K | GDPR | Dutch Supervisory Authority for Data Protection (AP) | Netherlands | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 9 GDPR |
| 2022-03-28 | Klarna Bank AB | €720K | GDPR | Data Protection Authority of Sweden | Sweden | Failure to comply with data processing principles | --Articles: Art. 5 (1) a) GDPR, Art. 5 (2) GDPR, Art. 12 (1) GDPR, Art. 13 (2) f) GDPR, Art. 14 (2) g) GDPR |
| 2022-02-01 | Orange Espagne, S.A.U. | €700K | GDPR | Spanish Data Protection Authority (AEPD) | Spain | Non-compliance with lawful basis for data processing | --Articles: Art. 5 (1) f) GDP |
| 2019-09-10 | Morele.net | €645K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Failure to implement sufficient measures to ensure information security | Morele.net was sanctioned with a fine of PLN 2.8 million because it hadn’t ensur...Morele.net was sanctioned with a fine of PLN 2.8 million because it hadn’t ensured the proper security standards of customers’ data. As a consequence, more than 2.2 million people had their personal data accessed illegally. Articles: Art. 32 GDPR |
| 2019-09-10 | Morele.net | €645K | GDPR | Polish National Personal Data Protection Office (UODO) | Poland | Failure to implement sufficient measures to ensure information security | --Articles: Art. 32 GDPR |
| 2022-02-08 | Budapest Bank Zrt. | €634K | GDPR | Hungarian National Authority for Data Protection and the Freedom of Information | Hungary | Failure to comply with data processing principles | --Articles: Art. 5 (1) a), b) GDPR, Art. 6 (1), (4) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 21 (1), (2) GDPR, Art. 24 (1) GDPR, Art. 25 (1), (2) GDPR |
| 2021-12-07 | Psykoterapiakeskus Vastaamo | €608K | GDPR | Deputy Data Protection Ombudsman | Finland | Failure to comply with data processing principles | --Articles: Art. 5 (1) f) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR |
| 2022-08-19 | ACCOR SA | €600K | GDPR | French Data Protection Authority (CNIL) | France | Failure to implement sufficient measures to ensure information | --Articles: Art. 12 GDPR, Art. 13 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. 32 GDPR, L. 34-5 CPCE |
| 2022-11-24 | ÉLECTRICITÉ DE FRANCE | €600K | GDPR | French Data Protection Authority (CNIL) | France | Non-compliance with subjects' rights protection safeguards | --Articles: Art. 7 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 14 GDPR, Art. 15 GDPR, Art. 21 GDPR, Art. L. 34-5 CPCE |
| 2020-07-14 | Google Belgium SA | €600K | GDPR | Belgian Data Protection Authority (APD) | Belgium | Non-compliance with lawful basis for data processing | --Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 17 (1) a) GDPR, Art. 12 GDPR |