Back to Feed

Tag

Privacy Fines

DPA enforcement actions and penalties

50 items tagged #privacy-fines

Articles

7-Eleven confirms data breach claimed by the ShinyHunters gang

7-Eleven confirms cyberattack by ShinyHunters gang that stole 600K+ records from Salesforce systems.

NAIH (Hungary) - NAIH-3344-1/2026

Hungarian DPA fines university HUF 1.5M for excessive data processing in dormitory admissions.

AP (The Netherlands) - Decision of 11 December 2023 imposing administrative fine on Uber

Dutch DPA fines Uber €10M for lacking transparency and failing data subject rights access.

AP (The Netherlands) - 2025-005323

Dutch DPA finds Yango app unlawfully transferred EEA user data to Russia without proper safeguards

AEPD (Spain) - EXP202408867

Spain's AEPD fined sports retailer €120K for data breach affecting 300K+ people

AP (The Netherlands) - 2025-005323

Netherlands DPA finds GDPR violations in data transfers to Russia via inadequate safeguards

AP (The Netherlands) - 2025-005323

Netherlands DPA fines Yandex €100M for unlawful data transfers to Russia without adequate safeguards.

AP (The Netherlands) - 2025-005323

Dutch DPA fines Yango €100M for unlawful data transfers to Russia without safeguards.

GM agrees to $12.75M California settlement over sale of drivers’ data

GM settles $12.75M California CCPA violation over illegal sale of drivers' location and behavior data.

AEPD (Spain) - EXP202408867

AEPD fines Spanish sports retailer €120K for data breach affecting 300K+ customers

‼️🇫🇷 Leroy Merlin France allegedly leaked exposing 367,462 loyalty program records A threat ac...

Threat actor claims to be selling 367,462 Leroy Merlin France loyalty program records.

‼️🇫🇷 NRJ Mobile allegedly leaked exposing 266K customer records from the French MVNO A threat...

NRJ Mobile data breach exposes 266K customer records from French MVNO.

‼️🇫🇷 https://t.co/czppXO8djQ, a French government health-related platform, has allegedly been b...

French government health platform breached; 233,837 records leaked with taunt to authorities.

French prosecutors link 15-year-old to gov mega-breach

French prosecutors charge 15-year-old with stealing 18M records from national secure documents agency ANTS.

AEPD (Spain) - EXP202404507

Spanish DPA fines bank €400K for CCTV access via shared credentials violating GDPR Article 32.

Garante per la protezione dei dati personali (Italy) - 10241537

Italian DPA fines Poste Italiane and PostePay €12.5M for unlawful malware detection data collection.

CE - 482872

French court upholds €40M GDPR fine against Criteo for cookie consent violations.

CNIL (France) - SAN-2025-014

CNIL fines Mobius Solutions €1M for data retention, unauthorized processing, and record-keeping failures.

Garante per la protezione dei dati personali (Italy) - 10241537

Italian DPA fines Poste Italiane and PostePay €12.5M for unlawful malware detection data processing.

AEPD (Spain) - EXP202406208

Spain's AEPD fined EVO Banco €240K for API vulnerability causing 1.27M data breach.

CNIL (France) - SAN-2025-011

CNIL fines American Express Carte France €1.5M for cookie consent violations.

AEPD (Spain) - EXP202406208

Spain's AEPD fines EVO Banco €240K for API vulnerability exposing 1.27M customers' data.

Garante per la protezione dei dati personali (Italy) - 9870014

Italian DPA fines Ediscom €300K for GDPR violations in marketing data collection.

Garante per la protezione dei dati personali (Italy) - 10241537

Italian DPA fines Poste Italiane and PostePay €12.5M for GDPR violations in device data collection.

AEPD (Spain) - EXP202404507

Spanish DPA fines bank €400K for CCTV system shared credentials violating GDPR Article 32.

Arkansas State Crime Lab Database Breached: Threat Actor kittykatkrew Leaks Court Calendars and Law Enforcement Personnel Directory

Threat actor kittykatkrew breaches Arkansas State Crime Lab, leaks court calendars and law enforcement personnel

CNIL (France) - SAN-2026-002

CNIL fines Free €15M for insufficient VPN security and incomplete breach notifications.

Garante per la protezione dei dati personali (Italy) - 10233328

Italian DPA fines employer €50K for GDPR violations in employee email handling and metadata storage.

Garante per la protezione dei dati personali (Italy) - 10229191

Italian DPA fines airline €190,000 for unlawful digital forensics on former board member.

UODO (Poland) - DKN.5112.33.2022

Polish DPA fines company €1.39M for unlawfully collecting ID card and passport scans.

UODO (Poland) - DKN.5112.33.2022

Polish DPA fines company €1.39M for unlawfully collecting ID card and passport images.

ANSPDCP (Romania) - 07.11.2025

Romanian DPA fined Klass Wagen SRL €7,000 for failing to deactivate former employee accounts, enabling data breach.

BL - 24-154313ASD-BORG/02

Norway's Borgarting Court upholds €5M GDPR fine against Grindr for invalid consent and undisclosed data sharing.

Chartered Institute of Bankers of Nigeria (CIBN) Database Breached: 250GB Including Member PII, Source Code, and ID Documents Leaked

Threat actor Rabid leaks 250GB CIBN database with member PII, ID documents, and source code.

Garante per la protezione dei dati personali (Italy) - 10238270

Italy's DPA fines energy corporation Eni €96K for unlawfully publishing lawsuit plaintiffs' personal data.

British Scattered Spider hacker pleads guilty to crypto theft charges

British Scattered Spider leader Tyler Buchanan pleads guilty to $8M crypto theft via SMS phishing.

Garante per la protezione dei dati personali (Italy) - 10238270

Italian DPA fines Eni €96,000 for unlawfully publishing personal data of climate lawsuit claimants.

UODO (Poland) - DKN.5112.33.2022

Poland's UODO fines company €1.39M for unlawfully collecting ID card and passport scans.

‼️🇧🇪🇳🇱 A dataset allegedly containing 400,000 customer records from https://t.co/aYoDX9MCrG,...

400,000 customer records from major Belgian-Dutch marketplace leaked on cybercrime forum.

🚨 Nobu Restaurants Data Breach Exposes SSNs and Government IDs On November 5th, 2025, Akira ran...

Akira ransomware claims breach of Nobu Restaurants, stealing 71GB of SSNs, IDs, and financial records.

Garante per la protezione dei dati personali (Italy) - 10229191

Italian DPA finds airline company violated GDPR by conducting forensic investigation on board chairman's email without

AEPD (Spain) - EXP202406208

Spanish DPA fines Bankinter €240K for API vulnerability breach affecting 1.27M customers.

AEPD (Spain) - EXP202406208

Spain's AEPD fined EVO Banco €240K for data breach affecting 1.27M individuals via API vulnerability.

AEPD (Spain) - EXP202309453

Spain's AEPD fines AXA €200K for failing to prevent former employee account takeover.

AEPD (Spain) - EXP202309453

Spain's AEPD fines AXA €200K for insufficient security allowing former employee account access.

AEPD (Spain) - EXP202411411

Spain's AEPD fines transport company €200K for mandatory employee monitoring apps violating GDPR data minimization and

AEPD (Spain) - EXP202411411

Spain's AEPD fines transport company €200K for mandating employee tracking apps on personal phones.

Researchers Say Fiverr Left User Files Open to Google Search

Fiverr exposed thousands of user files including tax records and IDs via misconfigured Cloudinary storage indexed by

DVI (Latvia) - SIA “ZZ Dats”

Latvia's DPA fined SIA "ZZ Dats" €300,000 for Article 32 GDPR violations after major data breach affecting

CA Luxembourg - 52757C

Luxembourg court annuls €746M Amazon GDPR fine, orders reassessment of fault and proportionality.