Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

698 fines found

Total: $7.9B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-10-16British Airways£20.0MUK GDPR / DPA 2018UK ICOUnited Kingdomother
British Airways (BA) fined £20m for failing to protect the personal and financia...

British Airways (BA) fined £20m for failing to protect the personal and financial details of more than 400,000 of its customers.

2020-10-30Marriott International Inc£18.4MUK GDPR / DPA 2018UK ICOUnited Kingdomother
Marriott International Inc fined £18.4million for failing to keep millions of cu...

Marriott International Inc fined £18.4million for failing to keep millions of customers’ personal data secure. Marriott estimates that 339 million guest records worldwide were affected following a cyber-attack in 2014 on Starwood Hotels and Resorts Worldwide Inc. The attack, from an unknown source, remained undetected until September 2018, by which time the company had been acquired by Marriott.

2022-10-17SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE€20.0MGDPRFrance CNILFranceother
Défaut de base légale; Non respect du droit d'accès Non respect du droit à l'eff...

Défaut de base légale; Non respect du droit d'accès Non respect du droit à l'effacement Défaut de coopération avec la CNIL

2022-03-1512 Facebook personal data breaches€17.0MGDPRIreland DPCIrelandother
The DPC has adopted a decision, imposing a fine of €17 million on Meta Platforms...

The DPC has adopted a decision, imposing a fine of €17 million on Meta Platforms Ireland Limited (formerly Facebook Ireland Limited) (“Meta Platforms”). The decision followed an inquiry by…

Articles: Art. 5, Art. 24, Art. 32

2025-10-15Capita plc and aptia Pension Solutions Ltd£14.0MUK GDPR / DPA 2018UK ICOUnited Kingdomother
--
2026-01-08OPÉRATEUR DE TÉLÉPHONIE FIXE€15.0MGDPRFrance CNILFranceother
Défaut de sécurité des données; Obligation de communiquer une violation de donné...

Défaut de sécurité des données; Obligation de communiquer une violation de données aux personnes concernées

2024-11-01OpenAI€15.0MGDPRItaly GaranteItalyother
ChatGPT processing without legal basis
2023-04-04TikTok Information Technologies UK Limited and TikTok Inc (TikTok)£12.7MUK GDPR / DPA 2018UK ICOUnited Kingdomother
The Information Commissioner’s Office (ICO) has issued a £12,700,000 fine to Tik...

The Information Commissioner’s Office (ICO) has issued a £12,700,000 fine to TikTok Information Technologies UK Limited and TikTok Inc (TikTok) for a number of breaches of data protection law, including failing to use children’s personal data lawfully.

2023-12-29SOCIETE PROPOSANT DES SERVICES DE TELECOMUNICATION€10.0MFrench ePrivacy rules (cookies)France CNILFranceconsent
Information des personnes et transparence Consentement des personnes (cookies)
2022-05-18Clearview AI Inc.£7.6MUK GDPR / DPA 2018UK ICOUnited Kingdomother
ICO fines facial recognition database company Clearview AI Inc £7.5m and orders ...

ICO fines facial recognition database company Clearview AI Inc £7.5m and orders UK data to be deleted

2022-12-29SOCIETE CREANT ET COMMERCIALISANT DES PRODUITS ELECTRONIQUES GRAND PUBLIC, DES ORDINATEURS PERSONNELS ET DES LOGICIELS€8.0MFrench ePrivacy rules (cookies)France CNILFranceconsent
Consentement des personnes (cookies et traceurs)
2025-01-01Poczta Polska€6.3MGDPRPoland UODOPolandother
Illegal processing of 30M citizens' data
2026-01-22ÉTABLISSEMENT PUBLIC ADMINISTRATIF€5.0MGDPRFrance CNILFranceother
Défaut de sécurité des données
2025-01-01Replika (Luka Inc.)€5.0MGDPRItaly GaranteItalyother
AI chatbot GDPR violations
2026-05-01IQVIA Operations FR€5.0MGDPRFrance CNILFranceother
Health data warehouse safeguard failures
2022-12-29SOCIETES EXPLOITANT UNE GAMME DE PLATEFORMES DE DISTRIBUTION DE CONTENUS€5.0MFrench ePrivacy rules (cookies)France CNILFranceconsent
Consentement des personnes (cookies et traceurs)
2022-10-19Interserve Group Limited£4.4MUK GDPR / DPA 2018UK ICOUnited Kingdomother
Between 18 March 2019 and 1 December 2020 Interserve Limited (“Interserve”) fail...

Between 18 March 2019 and 1 December 2020 Interserve Limited (“Interserve”) failed to process personal data in a manner that ensured appropriate security of the personal data using appropriate technical and organisational measures as required by Article 5(1)(f) and Article 32 GDPR. This rendered Interserve vulnerable to a cyber-attack which took place in the period 30 March 2020 to 2 May 2020 and affected the personal data of up to 113,000 employees of Interserve.

2025-01-01ING Bank Śląski€4.4MGDPRPoland UODOPolandother
Unlawful scanning of customer ID documents
2025-01-01McDonald's Polska€4.0MGDPRPoland UODOPolandother
Employee, customer data processing violations
2025-12-30SOCIETE DU SECTEUR TERTIAIRE€3.5MFrench ePrivacy rules (cookies)France CNILFranceconsent
Obligation de traiter les données de façon licite; Information des personnes; Ob...

Obligation de traiter les données de façon licite; Information des personnes; Obligation de réaliser une analyse d'impact; Défaut de sécurité des données; Consentement des personnes (cookies)

2025-03-26Advanced Computer Software Group Limited£3.1MUK GDPR / DPA 2018UK ICOUnited Kingdomother
The Information Commissioner’s Office (ICO) has fined Advanced Computer Software...

The Information Commissioner’s Office (ICO) has fined Advanced Computer Software Group Ltd (Advanced) £3.07m for security failings that put the personal information of 79,404 people at risk.? Advanced provides IT and software services to organisations, including the NHS and other healthcare providers, and processes people’s personal information on behalf of these organisations.? The fine relates to a ransomware incident in August 2022. Hackers accessed certain systems of Advanced’s health and care subsidiary via a customer account that did not have multi-factor authentication (MFA). The cyber attack was widely reported at the time, with reports of disruption to critical services such as NHS 111, and other healthcare staff unable to access patient records.

2025-06-0523andMe£2.3MUK GDPR / DPA 2018UK ICOUnited Kingdomother
--
2022-12-29SOCIETE DE DEVELOPPEMENT DE JEUX MOBILES€3.0MFrench ePrivacy rules (cookies)France CNILFranceconsent
Consentement des personnes (cookies et traceurs)
2020-11-18GRANDE DISTRIBUTION€2.3MFrench ePrivacy rules (cookies)France CNILFranceconsent
Manquement relatif à la conservation des données ; manquement relatif à l'exerci...

Manquement relatif à la conservation des données ; manquement relatif à l'exercice des droits ; manquement relatif à l'information des personnes ; manquements relatifs aux droit d'accès, droit d'effacement, droit d'opposition ; manquement relatif à l'obligation d'assurer la sécurité et la confidentialité des données ; manquement relatif aux cookies

2026-06-30Amazon$2.3MOtherFTCUSother
Amazon will pay $2.25 million in civil penalties to settle Federal Trade Commiss...

Amazon will pay $2.25 million in civil penalties to settle Federal Trade Commission allegations that the online retail giant knowingly violated the Fair Credit Reporting Act (FCRA) by refusing to provide transaction records to consumers whose personal information was used by identity thieves to commit fraud. The complaint , filed by the Department of Justice upon notification and referral from the FTC, alleged that in numerous instances, Amazon.com Inc. failed to comply with Section 609(e) of the FCRA, which requires companies to, within 30 days of a consumer’s request, provide victims of identity theft with application and business transaction records about fraudulent transactions made in their names. According to the complaint, Amazon had no written policy to respond to Section 609(e) requests until early 2025, after it learned of the FTC’s investigation, despite prior outreach from FTC staff advising the company to review its compliance with Section 609(e). “Amazon often put identit

PreviousPage 2 of 28Next