1

GDPR fines 2019 – much ado about nothing?

The latest update on the GDPR fines is enlisted below and it shows that privacy is not dead.

 

PWC BS

Fine: € 150 000

Reason: inappropriate legal basis (consent) and violation of the principle of accountability

DPA: HDPA (GR)

Data Subjects: employees

 

Marriott International

Fine: £ 99 200 396

Reason: data breach

DPA: ICO (UK)

Data Subjects: customers (399 M)

 

British Airways

Fine: £ 183 390 000

Reason: data breach

DPA: ICO (UK)

Data Subjects: customers (500 K)

 

Taxa 4×35

Fine: € 160 000

Reason: failure to delete customers’ data

DPA: Danish DPA (DK)

Data Subjects: customers (9 M)

 

Municipality of Bergen

Fine: € 170 000

Reason: inadequate data security

DPA: Norwegian DPA (NO)

Data Subjects: users (35 K)

 

Google

Fine: € 50 000 000

Reason: lack of transparency, inadequate information, lack of valid consent regarding the ads personalization

DPA: CNIL (FR)

Data Subjects: users

 

Uniontrad Compan

Fine: € 20 000

Reason: the video surveillance systems it set up to monitor its employees

DPA: CNIL (FR)

Data Subjects: employees

 

EE Limited

Fine: € 100 000

Reason: direct marketing messages to its customer without consent

DPA: ICO (UK)

Data Subjects: customers (2,5 M)

 

Facebook

Fine: € 1 000 000

Reason: Cambridge Analytica (€ 1 M)

DPA: Garante (IT)

Data Subjects: users

 

Facebook

Fine: € 2 000 000

Reason: breaching the country`s law on internet transparency

DPA: Federal Office of Justice (DE)

Data Subjects: users

 

Österreichische Post AG (ÖPAG)

Fine: € 18 000 000

Reason: processing personal data on the alleged political affinity of affected data subjects

DPA: The Austrian data protection authority (DPA)

Data Subjects: users

Related Posts

card__image

New information security regulation for financial institutions – DORA

On January 17, 2025, the Digital Operational Resilience Act (Regulation (EU) 2022/2554) or DORA (Digital Operational Resilience Act) entered into force. The DORA focuses on information and communications technology (ICT) risk management by introducing strict rules for ICT risk management, incident reporting, operational resilience testing, and third-party ICT risk oversight.   Prior to the adoption […]

card__image

Secure by Design: From Concept to Cybersecurity Imperative in 2025

In a rapidly evolving digital landscape, the Secure by Design (SbD) philosophy is proving strategically essential and measurably effective. A report from Secure Code Warrior, analyzing data from 600 enterprise customers over nine years, found that large organizations that train developers in secure-by-design practices can reduce software vulnerabilities by over 50%. Companies with more than […]

card__image

Zero-Day Vulnerabilities: Unseen Threats and Their Impact

The ultimate guide to zero-day vulnerabilities and their effects in 2025 starts with a clear truth: zero-day vulnerabilities rank among the most severe dangers in the modern digital landscape.   A zero-day vulnerability  — flaws exploited before patches are available. This makes them incredibly challenging to detect and counter, leaving businesses exposed to substantial operational […]

Leave a Reply

Your email address will not be published. Required fields are marked *