1

GDPR fines 2019 – much ado about nothing?

Disculpa, pero esta entrada está disponible sólo en en, ru y ua.

The latest update on the GDPR fines is enlisted below and it shows that privacy is not dead.

 

PWC BS

Fine: € 150 000

Reason: inappropriate legal basis (consent) and violation of the principle of accountability

DPA: HDPA (GR)

Data Subjects: employees

 

Marriott International

Fine: £ 99 200 396

Reason: data breach

DPA: ICO (UK)

Data Subjects: customers (399 M)

 

British Airways

Fine: £ 183 390 000

Reason: data breach

DPA: ICO (UK)

Data Subjects: customers (500 K)

 

Taxa 4×35

Fine: € 160 000

Reason: failure to delete customers’ data

DPA: Danish DPA (DK)

Data Subjects: customers (9 M)

 

Municipality of Bergen

Fine: € 170 000

Reason: inadequate data security

DPA: Norwegian DPA (NO)

Data Subjects: users (35 K)

 

Google

Fine: € 50 000 000

Reason: lack of transparency, inadequate information, lack of valid consent regarding the ads personalization

DPA: CNIL (FR)

Data Subjects: users

 

Uniontrad Compan

Fine: € 20 000

Reason: the video surveillance systems it set up to monitor its employees

DPA: CNIL (FR)

Data Subjects: employees

 

EE Limited

Fine: € 100 000

Reason: direct marketing messages to its customer without consent

DPA: ICO (UK)

Data Subjects: customers (2,5 M)

 

Facebook

Fine: € 1 000 000

Reason: Cambridge Analytica (€ 1 M)

DPA: Garante (IT)

Data Subjects: users

 

Facebook

Fine: € 2 000 000

Reason: breaching the country`s law on internet transparency

DPA: Federal Office of Justice (DE)

Data Subjects: users

 

Österreichische Post AG (ÖPAG)

Fine: € 18 000 000

Reason: processing personal data on the alleged political affinity of affected data subjects

DPA: The Austrian data protection authority (DPA)

Data Subjects: users

Related Posts

card__image

New information security regulation for financial institutions – DORA

Disculpa, pero esta entrada está disponible sólo en en, ru y ua. On January 17, 2025, the Digital Operational Resilience Act (Regulation (EU) 2022/2554) or DORA (Digital Operational Resilience Act) entered into force. The DORA focuses on information and communications technology (ICT) risk management by introducing strict rules for ICT risk management, incident reporting, operational […]

card__image

Secure by Design: From Concept to Cybersecurity Imperative in 2025

Disculpa, pero esta entrada está disponible sólo en en y ua. In a rapidly evolving digital landscape, the Secure by Design (SbD) philosophy is proving strategically essential and measurably effective. A report from Secure Code Warrior, analyzing data from 600 enterprise customers over nine years, found that large organizations that train developers in secure-by-design practices […]

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *