Search Privacy Fines
Browse and filter privacy enforcement fines worldwide.
698 fines found
Total: $7.9B
| Date | Company | Fine | Regulation | Authority | Country | Type | Summary |
|---|---|---|---|---|---|---|---|
| 2020-10-16 | British Airways | £20.0M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | British Airways (BA) fined £20m for failing to protect the personal and financia...British Airways (BA) fined £20m for failing to protect the personal and financial details of more than 400,000 of its customers. |
| 2020-10-30 | Marriott International Inc | £18.4M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | Marriott International Inc fined £18.4million for failing to keep millions of cu...Marriott International Inc fined £18.4million for failing to keep millions of customers’ personal data secure. Marriott estimates that 339 million guest records worldwide were affected following a cyber-attack in 2014 on Starwood Hotels and Resorts Worldwide Inc. The attack, from an unknown source, remained undetected until September 2018, by which time the company had been acquired by Marriott. |
| 2022-10-17 | SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE | €20.0M | GDPR | France CNIL | France | other | Défaut de base légale; Non respect du droit d'accès Non respect du droit à l'eff...Défaut de base légale; Non respect du droit d'accès Non respect du droit à l'effacement Défaut de coopération avec la CNIL |
| 2022-03-15 | 12 Facebook personal data breaches | €17.0M | GDPR | Ireland DPC | Ireland | other | The DPC has adopted a decision, imposing a fine of €17 million on Meta Platforms...The DPC has adopted a decision, imposing a fine of €17 million on Meta Platforms Ireland Limited (formerly Facebook Ireland Limited) (“Meta Platforms”). The decision followed an inquiry by… Articles: Art. 5, Art. 24, Art. 32 |
| 2025-10-15 | Capita plc and aptia Pension Solutions Ltd | £14.0M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | -- |
| 2026-01-08 | OPÉRATEUR DE TÉLÉPHONIE FIXE | €15.0M | GDPR | France CNIL | France | other | Défaut de sécurité des données; Obligation de communiquer une violation de donné...Défaut de sécurité des données; Obligation de communiquer une violation de données aux personnes concernées |
| 2024-11-01 | OpenAI | €15.0M | GDPR | Italy Garante | Italy | other | ChatGPT processing without legal basis |
| 2023-04-04 | TikTok Information Technologies UK Limited and TikTok Inc (TikTok) | £12.7M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | The Information Commissioner’s Office (ICO) has issued a £12,700,000 fine to Tik...The Information Commissioner’s Office (ICO) has issued a £12,700,000 fine to TikTok Information Technologies UK Limited and TikTok Inc (TikTok) for a number of breaches of data protection law, including failing to use children’s personal data lawfully. |
| 2023-12-29 | SOCIETE PROPOSANT DES SERVICES DE TELECOMUNICATION | €10.0M | French ePrivacy rules (cookies) | France CNIL | France | consent | Information des personnes et transparence Consentement des personnes (cookies) |
| 2022-05-18 | Clearview AI Inc. | £7.6M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | ICO fines facial recognition database company Clearview AI Inc £7.5m and orders ...ICO fines facial recognition database company Clearview AI Inc £7.5m and orders UK data to be deleted |
| 2022-12-29 | SOCIETE CREANT ET COMMERCIALISANT DES PRODUITS ELECTRONIQUES GRAND PUBLIC, DES ORDINATEURS PERSONNELS ET DES LOGICIELS | €8.0M | French ePrivacy rules (cookies) | France CNIL | France | consent | Consentement des personnes (cookies et traceurs) |
| 2025-01-01 | Poczta Polska | €6.3M | GDPR | Poland UODO | Poland | other | Illegal processing of 30M citizens' data |
| 2026-01-22 | ÉTABLISSEMENT PUBLIC ADMINISTRATIF | €5.0M | GDPR | France CNIL | France | other | Défaut de sécurité des données |
| 2025-01-01 | Replika (Luka Inc.) | €5.0M | GDPR | Italy Garante | Italy | other | AI chatbot GDPR violations |
| 2026-05-01 | IQVIA Operations FR | €5.0M | GDPR | France CNIL | France | other | Health data warehouse safeguard failures |
| 2022-12-29 | SOCIETES EXPLOITANT UNE GAMME DE PLATEFORMES DE DISTRIBUTION DE CONTENUS | €5.0M | French ePrivacy rules (cookies) | France CNIL | France | consent | Consentement des personnes (cookies et traceurs) |
| 2022-10-19 | Interserve Group Limited | £4.4M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | Between 18 March 2019 and 1 December 2020 Interserve Limited (“Interserve”) fail...Between 18 March 2019 and 1 December 2020 Interserve Limited (“Interserve”) failed to process personal data in a manner that ensured appropriate security of the personal data using appropriate technical and organisational measures as required by Article 5(1)(f) and Article 32 GDPR. This rendered Interserve vulnerable to a cyber-attack which took place in the period 30 March 2020 to 2 May 2020 and affected the personal data of up to 113,000 employees of Interserve. |
| 2025-01-01 | ING Bank Śląski | €4.4M | GDPR | Poland UODO | Poland | other | Unlawful scanning of customer ID documents |
| 2025-01-01 | McDonald's Polska | €4.0M | GDPR | Poland UODO | Poland | other | Employee, customer data processing violations |
| 2025-12-30 | SOCIETE DU SECTEUR TERTIAIRE | €3.5M | French ePrivacy rules (cookies) | France CNIL | France | consent | Obligation de traiter les données de façon licite; Information des personnes; Ob...Obligation de traiter les données de façon licite; Information des personnes; Obligation de réaliser une analyse d'impact; Défaut de sécurité des données; Consentement des personnes (cookies) |
| 2025-03-26 | Advanced Computer Software Group Limited | £3.1M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | The Information Commissioner’s Office (ICO) has fined Advanced Computer Software...The Information Commissioner’s Office (ICO) has fined Advanced Computer Software Group Ltd (Advanced) £3.07m for security failings that put the personal information of 79,404 people at risk.? Advanced provides IT and software services to organisations, including the NHS and other healthcare providers, and processes people’s personal information on behalf of these organisations.? The fine relates to a ransomware incident in August 2022. Hackers accessed certain systems of Advanced’s health and care subsidiary via a customer account that did not have multi-factor authentication (MFA). The cyber attack was widely reported at the time, with reports of disruption to critical services such as NHS 111, and other healthcare staff unable to access patient records. |
| 2025-06-05 | 23andMe | £2.3M | UK GDPR / DPA 2018 | UK ICO | United Kingdom | other | -- |
| 2022-12-29 | SOCIETE DE DEVELOPPEMENT DE JEUX MOBILES | €3.0M | French ePrivacy rules (cookies) | France CNIL | France | consent | Consentement des personnes (cookies et traceurs) |
| 2020-11-18 | GRANDE DISTRIBUTION | €2.3M | French ePrivacy rules (cookies) | France CNIL | France | consent | Manquement relatif à la conservation des données ; manquement relatif à l'exerci...Manquement relatif à la conservation des données ; manquement relatif à l'exercice des droits ; manquement relatif à l'information des personnes ; manquements relatifs aux droit d'accès, droit d'effacement, droit d'opposition ; manquement relatif à l'obligation d'assurer la sécurité et la confidentialité des données ; manquement relatif aux cookies |
| 2026-06-30 | Amazon | $2.3M | Other | FTC | US | other | Amazon will pay $2.25 million in civil penalties to settle Federal Trade Commiss...Amazon will pay $2.25 million in civil penalties to settle Federal Trade Commission allegations that the online retail giant knowingly violated the Fair Credit Reporting Act (FCRA) by refusing to provide transaction records to consumers whose personal information was used by identity thieves to commit fraud. The complaint , filed by the Department of Justice upon notification and referral from the FTC, alleged that in numerous instances, Amazon.com Inc. failed to comply with Section 609(e) of the FCRA, which requires companies to, within 30 days of a consumer’s request, provide victims of identity theft with application and business transaction records about fraudulent transactions made in their names. According to the complaint, Amazon had no written policy to respond to Section 609(e) requests until early 2025, after it learned of the FTC’s investigation, despite prior outreach from FTC staff advising the company to review its compliance with Section 609(e). “Amazon often put identit |