Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

2,028 fines found

Total: $8.1B

DateCompanyFineRegulationAuthorityCountryTypeSummary
2023-06-13Spotify€5.0MGDPRSweden IMYSwedenconsent
Failed to properly fulfill data access requests under right of access.

Failed to properly fulfill data access requests under right of access.

Articles: Art. 15

2020-03-11Google€5.0MGDPRData Protection Authority of SwedenSwedenFailure to comply with data processing principles
--

Articles: Art. 5 GDPR, Art. 6 GDPR, Art. 17 GDPR

2020-12-11Banco Bilbao Vizcaya Argentaria, S.A.€5.0MGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 GDPR, Art. 13 GDPR

2025-01-01Replika (Luka Inc.)€5.0MGDPRItaly GaranteItalyother
AI chatbot GDPR violations
2025-03-01Replika (Luka Inc.)€5.0MGDPRItaly GaranteItalyconsent
AI chatbot GDPR violations.

AI chatbot GDPR violations.

Articles: Art. 5, Art. 6

2023-06-13Spotify€5.0MGDPRSweden IMYSwedenconsent
Failed to properly fulfill data access requests.

Failed to properly fulfill data access requests.

Articles: Art. 15

--Edison Energia S.p.A.€4.9MGDPRItalian Data Protection Authority (Garante)ItalyFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 5 (2) GDPR, Art. 6 GDPR, Art. 7 GDPR, Art. 12 (1), (2), (3) GDPR, Art. 21 (2) GDPR, Art. 24 (1), (2) GDPR, Art. 25 (1) GDPR

2025-01-01ING Bank Śląski€4.4MGDPRPoland UODOPolandother
Unlawful scanning of customer ID documents
2022-11-02Portuguese National Statistical Institute€4.3MGDPRPortuguese Data Protection Authority (CNPD)PortugalFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 9 (1) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 28 (1), (6), (7) GDPR, Art. 35 (1), (2), (3) b) GDPR, Art. 44 GDPR, Art. 46 (2) GDPR

2025-01-01McDonald's Polska€4.0MGDPRPoland UODOPolandother
Employee and customer data processing violations
2022-02-01Vodafone Espana, S.A.U.€3.9MGDPRSpanish Data Protection Authority (AEPD)SpainNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR

2022-04-07Dutch Tax and Customs Administration€3.7MGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to comply with data processing principles
--

Articles: Art. 5 (1) a), b), d), e) GDPR, Art. 6 (1) GDPR, Art. 32 (1) GDPR, Art. 35 (2) GDPR

2021-09-16Sky Italia S.r.l.€3.3MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1), (2) GDPR, Art. 6 (1) GDPR, Art. 7 GDPR, Art. 12 (2) GDPR, Art. 14 GDPR, Art. 21 GDPR, Art. 28 GDPR, Art. 29 GDPR

2022-01-27OTE Group€3.2MGDPRHellenic Data Protection Authority (HDPA)GreeceFailure to implement sufficient measures to ensure information
--

Articles: Art. 32 GDPR

2020-01-17Eni Gas e Luce€3.0MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
The Italian Data Protection Authority (Garante) imposed two fines of €11,5 milli...

The Italian Data Protection Authority (Garante) imposed two fines of €11,5 million total on Eni Gas and Luce because of the unlawful processing of personal data during an advertising campaign as well as for the activation of unsolicited contracts. This second fine of €3 million was issued for the opening of unsolicited contracts for the provision of electricity and gas. A large number of individuals have reported that they have only learned of the new contracts after they received a termination letter from their old provider. Some complaints even reported false data as well as forged signatures.

Articles: Art. 5 GDPR, Art. 6 GDPR

2019-12-11Eni Gas e Luce€3.0MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 GDPR, Art. 6 GDPR

2021-10-21Caixabank Payments & Consumer EFC, EP, S.A.U.€3.0MGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 6 (1) GDPR

2020-12-03Capio St. Goran AB€2.9MGDPRData Protection Authority of SwedenSwedenFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 32 (1) GDPR, Art. 32 (2) GDPR

2021-05-13Iren Mercato S.p.A.€2.9MGDPRItalian Data Protection Authority (Garante)ItalyNon-compliance with lawful basis for data processing
--

Articles: Art. 5 (1), (2) GDPR, Art. 6 (1) GDPR, Art. 7 (1) GDPR

2021-11-25Dutch Minister of Finance€2.8MGDPRDutch Supervisory Authority for Data Protection (AP)NetherlandsFailure to comply with data processing principles
--

Articles: Art. 5 (1) a) GDPR, Art. 6 (1) e) GDPR, Art. 8 Wbp

2019-08-28National Revenue Agency€2.6MGDPRData Protection Commission of Bulgaria (KZLD)BulgariaFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-08-28National Revenue Agency€2.6MGDPRData Protection Commission of Bulgaria (KZLD)BulgariaFailure to implement sufficient measures to ensure information security
Because of the inappropriate handling of personal data, more than 6 million indi...

Because of the inappropriate handling of personal data, more than 6 million individuals had their data hacked. This informational leak was a direct cause of the company’s security laxity.

Articles: Art. 32 GDPR

2021-06-10Foodinho s.r.l.€2.6MGDPRItalian Data Protection Authority (Garante)ItalyMultiple types of violations
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 13 GDPR, Art. 22 (3) GDPR, Art. 25 GDPR, Art. 30 (1) a), b), c), f), g) GDPR, Art. 32 GDPR, Art. 35 GDPR, Art. 37 (7) GDPR

2021-07-26Mercadona S.A.€2.5MGDPRSpanish Data Protection Authority (AEPD)SpainFailure to comply with data processing principles
--

Articles: Art. 5 (1) c) GDPR, Art. 6 GDPR, Art. 9 GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 25 (1) GDPR, Art. 35 GDPR

2021-07-22Deliveroo Italy s.r.l.€2.5MGDPRItalian Data Protection Authority (Garante)ItalyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 (1) a), c), e) GDPR, Art. 13 GDPR, Art. 22 (3) GDPR, Art. 25 GDPR, Art. 30 (1) c), f), g) GDPR, Art. 32 GDPR, Art. 35 GDPR, Art. 37 (7) GDPR

PreviousPage 5 of 82Next