Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

698 fines found

Total: $7.9B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2020-01-09Currys Group Limited (previously DSG Retail Ltd)£500KUK GDPR / DPA 2018UK ICOUnited Kingdomother
The Information Commissioner’s Office (ICO) has fined DSG Retail Limited (DSG) £...

The Information Commissioner’s Office (ICO) has fined DSG Retail Limited (DSG) £500,000 after a ‘point of sale’ computer system was compromised as a result of a cyber-attack, affecting at least 14 million people.

2020-03-04Cathay Pacific£500KUK GDPR / DPA 2018UK ICOUnited Kingdomother
Cathay Pacific Airways Limited £500,000 for failing to protect the security of i...

Cathay Pacific Airways Limited £500,000 for failing to protect the security of its customers’ personal data. Between October 2014 and May 2018 Cathay Pacific’s computer systems lacked appropriate security measures which led to customers’ personal details being exposed.

2020-03-02CRDNN Limited£500KPECRUK ICOUnited Kingdommarketing
CRDNN Limited fined with the maximum £500,000 fine for making more than 193 mill...

CRDNN Limited fined with the maximum £500,000 fine for making more than 193 million automated nuisance calls.

2023-10-12SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTES€600KGDPRFrance CNILFranceother
Consentement des personnes (prospection commerciale) Information des personnes e...

Consentement des personnes (prospection commerciale) Information des personnes et transparence Non respect du droit d'accès Encadrement des relations entre le responsable de traitement et le sous-traitant Obligation de documenter une violation de données

2022-08-03SOCIETE SPECIALISEE DANS LE SECTEUR DE L'HOTELLERIE€600KGDPRFrance CNILFranceother
Non respect de l'art L 34-5 CPCE - prospection commerciale Défaut d'information ...

Non respect de l'art L 34-5 CPCE - prospection commerciale Défaut d'information Non respect du droit d'accès Non respect du droit d'opposition Défaut de sécurité des données

2017-05-10Keurboom Communications Ltd£400KPECRUK ICOUnited Kingdommarketing
A company behind 99.5 million nuisance calls has been fined a record £400,000 by...

A company behind 99.5 million nuisance calls has been fined a record £400,000 by the Information Commissioner’s Office (ICO).

2016-09-30TalkTalk Telecom Group PLC£400KUK GDPR / DPA 2018UK ICOUnited Kingdomother
SQL injection attack
2018-01-08The Carphone Warehouse Ltd£400KUK GDPR / DPA 2018UK ICOUnited Kingdomother
Carphone Warehouse fined £400,000 after serious failures placed customer and emp...

Carphone Warehouse fined £400,000 after serious failures placed customer and employee data at risk.

2018-11-26Uber£385KUK GDPR / DPA 2018UK ICOUnited Kingdomother
Uber fined for failing to protect customers’ personal information during a cybe...

Uber fined for failing to protect customers’ personal information during a cyber attack.

2025-06-09Department of Social Protection€550KGDPRIreland DPCIrelandother
The Data Protection Commission (DPC) has completed an inquiry into the Departmen...

The Data Protection Commission (DPC) has completed an inquiry into the Department of Social Protection’s (DSP) processing of biometric facial templates and the use of associated facial…

Articles: Art. 5, Art. 6, Art. 9, Art. 35

2021-06-14SOCIÉTÉ ÉDITANT UN SITE DE VENTES PRIVÉES DEDIÉ AU BRICOLAGE, AU JARDINAGE ET À L'AMÉNAGEMENT DE LA MAISON€500KGDPRFrance CNILFranceother
Durées de conservation Défaut d'information des personnes Non-respect des demand...

Durées de conservation Défaut d'information des personnes Non-respect des demandes d'effacement des données Défaut de sécurité des données Consentement pour la prospection commerciale

2025-11-27SOCIETE DE VENTE A DISTANCE€500KFrench ePrivacy rules (cookies)France CNILFranceconsent
Consentement des personnes (cookies); Information des personnes (cookies)
2022-11-24SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICES€600KGDPRFrance CNILFranceother
Non respect de l'art L 34-5 CPCE - prospection commerciale Défaut d'information ...

Non respect de l'art L 34-5 CPCE - prospection commerciale Défaut d'information Obligation de transparence Non respect du droit d'opposition Non respect du droit d'accès Défaut de sécurité des données

2024-04-04COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATION€525KGDPRFrance CNILFranceother
Consentement des personnes (prospection commerciale par voie électronique - L. 3...

Consentement des personnes (prospection commerciale par voie électronique - L. 34-5 CPCE) Défaut de base légale Information des personnes (art. 14) et transparence

2019-11-21SOCIETE D'INSTALLATION D'EQUIPEMENTS D'ISOLATION€500KGDPRFrance CNILFranceother
Non adéquation, non pertinence et caractère excessif des données, défaut d'infor...

Non adéquation, non pertinence et caractère excessif des données, défaut d'information des personnes, non-respect du droit d'opposition, non coopération avec l'autorité de contrôle, transfert non encadré de données hors de l'UE

2018-01-12Miss-sold Products UK Ltd£350KPECRUK ICOUnited Kingdommarketing
Miss-Sold Products UK Ltd fined £350,000 after they failed to ensure that market...

Miss-Sold Products UK Ltd fined £350,000 after they failed to ensure that marketing calls sent to individuals who had consented to receive marketing.

2016-02-24Prodial Ltd£350KPECRUK ICOUnited Kingdommarketing
Automated calls being made relating to PPI claims
2017-09-08Your Money Rights Ltd.£350KPECRUK ICOUnited Kingdommarketing
Your Money Rights Ltd. Made unsolicited automated marketing calls without consen...

Your Money Rights Ltd. Made unsolicited automated marketing calls without consent of recipients

2020-12-09Twitter International Company€450KGDPRIreland DPCIrelandother
This Inquiry, which was commenced by the Data Protection Commission (‘the Commis...

This Inquiry, which was commenced by the Data Protection Commission (‘the Commission) on 22 January 2019, examined whether Twitter International Company (‘TIC’) had complied with its…

Articles: Art. 33, Art. S 110, Art. S 111

2022-03-14Bank of Ireland Group plc€463KGDPRIreland DPCIrelandother
This inquiry was commenced in respect of 22 personal data breach notifications t...

This inquiry was commenced in respect of 22 personal data breach notifications that Bank of Ireland Group plc (“BOI”) made to the Data Protection Commission (“DPC”) between 9 November 2018…

Articles: Art. 32, Art. 33, Art. 34

2012-05-28Brighton & Sussex University Hospitals NHS Trust£325KUK GDPR / DPA 2018UK ICOUnited Kingdomother
Insecure disposal of hard drives containing personal data
2018-05-14Crown Prosecution Service£325KUK GDPR / DPA 2018UK ICOUnited Kingdomother
Breach of Principle 7 of the DPA involving highly sensitive personal data where ...

Breach of Principle 7 of the DPA involving highly sensitive personal data where a number of data subjects were involved.

2023-02-23Centric Health Ltd€460KGDPRIreland DPCIrelandother
The DPC commenced the Inquiry following a ransomware attack affecting patient da...

The DPC commenced the Inquiry following a ransomware attack affecting patient data held on Centric’s patient administration system which was notified to the DPC on 5 December 2019. As a…

Articles: Art. 3, Art. 32

2012-11-26Christopher Niebel£300KPECRUK ICOUnited Kingdommarketing
Sending unsolicited direct marketing texts to mobile subscribers who had not con...

Sending unsolicited direct marketing texts to mobile subscribers who had not consented to receive them

2021-07-26SOCIÉTÉ SPECIALISÉE DANS LES BIOTECHNOLOGIES AGRICOLES€400KGDPRFrance CNILFranceother
Défaut d'information des personnes Obligation d’encadrer les relations avec un s...

Défaut d'information des personnes Obligation d’encadrer les relations avec un sous-traitant

PreviousPage 4 of 28Next