Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

698 fines found

Total: $7.9B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2026-07-09RentGrow$2.3MOtherFTCUSother
RentGrow, a provider of consumer reports for tenant screening, will be required ...

RentGrow, a provider of consumer reports for tenant screening, will be required to pay $2.25 million to settle Federal Trade Commission allegations that the company violated the Fair Credit Reporting Act (FCRA), including by failing to use reasonable procedures to ensure the accuracy of its reports, and the FTC Act. The FCRA requires consumer reporting agencies (CRAs) to maintain reasonable procedures to assure the maximum possible accuracy of the information they include in background screening reports, disclose the sources of information used to compile a background screening report when a consumer requests it and take certain steps when a consumer disputes the completeness or accuracy of information in their background screening report. A complaint , filed by the Department of Justice upon notification and referral from the FTC, alleged that Massachusetts-based RentGrow Inc. is a CRA since it compiles information it obtains from a variety of sources into background screening reports

2021-07-20ASSURANCE€1.8MGDPRFrance CNILFranceother
Durée de conservation Défaut d'information des personnes
2025-12-22SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES€1.7MGDPRFrance CNILFranceother
Défaut de sécurité des données
2025-11-27SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERE€1.5MFrench ePrivacy rules (cookies)France CNILFranceconsent
Consentement des personnes (cookies)
2022-04-15SOCIETE D'EDITION DE LOGICIELS APPLICATIFS€1.5MGDPRFrance CNILFranceother
Obligation d’encadrer les relations entre le responsable de traitement et le sou...

Obligation d’encadrer les relations entre le responsable de traitement et le sous-traitant Obligation pour le sous-traitant de ne traiter les données que sur instruction du responsable de traitement Défaut de sécurité des données

2020-11-13Ticketmaster UK Limited£1.3MUK GDPR / DPA 2018UK ICOUnited Kingdomother
The ICO found that the company failed to put appropriate security measures in pl...

The ICO found that the company failed to put appropriate security measures in place to prevent a cyber-attack on a chat-bot installed on its online payment page. The data breach, which included names, payment card numbers, expiry dates and CVV numbers, potentially affected 9.4million of Ticketmaster’s customers across Europe including 1.5million in the UK

2025-06-23City of Dublin Education and Training Board€1.4MGDPRIreland DPCIrelandother
This decision arises from an own-volition inquiry that the DPC commenced in July...

This decision arises from an own-volition inquiry that the DPC commenced in July 2019. The inquiry related to a personal data breach notified by City of Dublin Education and Training Board …

Articles: Art. 5, Art. 32, Art. 33, Art. 34

2022-10-04Easylife Limited£1.4MUK GDPR / DPA 2018UK ICOUnited Kingdomother
Easylife Limited has contravened Article 5(1)(a) of the GDPR in that there were ...

Easylife Limited has contravened Article 5(1)(a) of the GDPR in that there were serious deficiencies in the way it has collected, processed, and used the personal and special category data of 145,400 individuals.

2026-05-01South Staffs Water£1.0MGDPRUK ICOUnited Kingdomdata_breach
Personal data breach response failure
2025-12-11SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT D'OUTILS MARKETING€1.0MGDPRFrance CNILFranceother
Conservation injustifiée de données par un sous-traitant; Traitement de données ...

Conservation injustifiée de données par un sous-traitant; Traitement de données par un sous-traitant non autorisé par le responsable de traitement; Registre des activités de traitement

2024-11-22Maynooth University€1.0MGDPRIreland DPCIrelandother
This decision arises from an own-volition inquiry that the DPC commenced in July...

This decision arises from an own-volition inquiry that the DPC commenced in July 2019. The inquiry related a personal data breach notified by Maynooth University in November 2018. The…

Articles: Art. 5, Art. 32, Art. 33

2022-06-23SOCIETE FOURNITURE ET PRODUCTION D'ELECTRICITE ET DE GAZ€1.0MGDPRFrance CNILFranceother
Non respect de l'art L 34-5 CPCE - prospection commerciale Défaut d'information ...

Non respect de l'art L 34-5 CPCE - prospection commerciale Défaut d'information Modalités d'exercice des droits Non respect du droit d'accès Non respect du droit d'opposition

2025-05-15SOCIETE AYANT UNE ACTIVITE DE MARKETING ET DE CONCEPTION DE SITES WEB€900KGDPRFrance CNILFranceother
Consentement des personnes (prospection commerciale par voie électronique - L. 3...

Consentement des personnes (prospection commerciale par voie électronique - L. 34-5 CPCE); Preuve du consentement des personnes (art 7 RGPD); Défaut de base légale art 6-1 RGDP

2024-09-26Police Service of Northern Ireland£750KUK GDPR / DPA 2018UK ICOUnited Kingdomother
The Police Service of Northern Ireland has been fined £750,000 for infringing Ar...

The Police Service of Northern Ireland has been fined £750,000 for infringing Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024.

2020-11-18BANQUE€800KFrench ePrivacy rules (cookies)France CNILFranceconsent
Manquement relatif à l'obligation de traiter des données de manière loyale ; man...

Manquement relatif à l'obligation de traiter des données de manière loyale ; manquement relatif à l'information des personnes ; manquement relatif aux cookies

2025-11-20SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRE€750KFrench ePrivacy rules (cookies)France CNILFranceconsent
Consentement des personnes (cookies); Information des personnes (cookies)
2026-08-27Cox Media Group$880KFTC Act Section 5FTCUSconsent
The Federal Trade Commission finalized orders requiring Cox Media Group (CMG) an...

The Federal Trade Commission finalized orders requiring Cox Media Group (CMG) and two other firms to pay a total of $930,000 to settle allegations they deceived customers by falsely claiming to offer an AI-powered service that could target localized ads based on conversations captured from consumers’ smart devices and that consumers had opted into such targeting. In three separate complaints first announced in May , the FTC alleged that Georgia-based media and marketing company CMG Media Corporation, which does business as Cox Media Group , and two marketing firms it worked with, New Hampshire-based MindSift LLC and Wisconsin-based 1010 Digital Works LLC , deceived customers by claiming they used a special algorithm to listen in on and detect pertinent conversations from smart devices in order to target ads to consumers within a specific geographic region. Contrary to these companies’ claims, however, the marketing service wasn’t based on voice data, and consumers hadn’t opted into thi

2024-08-28SOCIETE SPECIALISEE DANS LA REALISATION D'ETUDES STATISTIQUES EN MATIERE DE DONNEES DE SANTE€800KGDPRFrance CNILFranceother
Absence de demande d'autorisation auprès de la CNIL (entrepôts de données de san...

Absence de demande d'autorisation auprès de la CNIL (entrepôts de données de santé)

2024-09-05SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINS€800KGDPRFrance CNILFranceother
Absence de demande d'autorisation auprès de la CNIL (entrepôts de données de san...

Absence de demande d'autorisation auprès de la CNIL (entrepôts de données de santé) Obligation de traiter les données de façon licite

2024-10-10SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIE€750KGDPRFrance CNILFranceother
Défaut de sécurité des données Durée de conservation
2023-02-27Bank of Ireland 365€750KGDPRIreland DPCIrelandother
The inquiry was commenced after BOI notified the DPC of a series of 10 data brea...

The inquiry was commenced after BOI notified the DPC of a series of 10 data breaches relating to the BOI365 banking app. The data breach notifications concerned individuals gaining…

Articles: Art. 5, Art. 32

2022-11-10SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEE€800KGDPRFrance CNILFranceother
Durée de conservation Obligation de transparence Défaut d'information Non respec...

Durée de conservation Obligation de transparence Défaut d'information Non respect du droit d'opposition Protection des données par défaut Obligation de réaliser une analyse d'impact Défaut de sécurité des données

2018-09-19Equifax Limited£500KUK GDPR / DPA 2018UK ICOUnited Kingdomother
Credit reference agency Equifax fined for security breach
2018-10-24Facebook Ireland Ltd / Facebook Inc£500KUK GDPR / DPA 2018UK ICOUnited Kingdomother
Data Controller(s) fined for serious breaches of the first and seventh data prot...

Data Controller(s) fined for serious breaches of the first and seventh data protection principles in respect of the processing of the personal data of ‘UK Users’.

2025-07-03SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE DE MOBILIER, DECORATION ET D'EQUIPEMENTS DOMESTIQUES€600KFrench ePrivacy rules (cookies)France CNILFranceconsent
Durée de conservation; Information des personnes; Information et consentement (c...

Durée de conservation; Information des personnes; Information et consentement (cookies); Consentement des personnes (prospection commerciale par voie électronique - L. 34-5 CPCE)

PreviousPage 3 of 28Next