Privacy Fines Database
Real enforcement actions from 26 jurisdictions worldwide. Understand the cost of non-compliance with GDPR, CCPA, and other privacy regulations.
€7.1B+
Total GDPR Fines
132+
Fines Tracked
26
Jurisdictions
~1M
Breach Notifications Since 2018
Sanctioned organizations by size
54%
SMEs & Startups
< €50M revenue
26%
Large Enterprises
€50M–€1B revenue
12%
Public Sector
Gov, health, education
8%
Tech Giants
> €1B revenue
Source: DLA Piper GDPR Survey 2026 (443 breach notifications/day, ~1M cumulative since 2018), CMS Enforcement Tracker (2,800+ GDPR fines, €7.1B cumulative). Most fines target small & mid-size companies.
GDPR Fine Simulator — Estimate Your Penalty Risk
Estimate the potential fine your organization could face based on regulation, violation type, company size, and aggravating factors. Based on real DPA enforcement patterns.
€20M or 4% for serious violations (Art 83(5)). €10M or 2% for lesser violations (Art 83(4)).
Processing personal data without valid legal basis (GDPR Art 6). The most common and most heavily fined violation.
Longer violations attract higher penalties.
Estimated Fine Range
High Risk€1.1M
Most likely estimate
Factors Applied
Disclaimer: This simulator provides rough estimates based on publicly available penalty frameworks and real DPA enforcement patterns. Actual fines depend on many factors including DPA discretion, remediation efforts, company cooperation, and precedent. This is not legal advice. See real fine examples →
Don't risk a fine — scan your website now
Free Privacy Scan →Europe
16 jurisdictionsIEIreland
Data Protection Commission (DPC)
| Company | Amount | Year |
|---|---|---|
TikTok Unlawful data transfers to China Failed to ensure adequate protection for EU user data transferred to China and lacked transparency about data processing practices. | €530M | 2025 |
Meta (Facebook) Unlawful EU-US data transfers Transferred EU user data to the US without adequate safeguards post-Schrems II ruling. Largest GDPR fine ever issued. | €1.2B | 2023 |
Meta (Instagram) Children's data processing Made children's accounts public by default and exposed phone numbers and email addresses of minors aged 13–17. | €405M | 2023 |
Unlawful advertising data processing Processed personal data for behavioral advertising without a valid legal basis, violating consent and legitimate interest principles. | €310M | 2024 |
Meta (Facebook) Data breach — 29M accounts A 2018 data breach exposed personal data of 29 million accounts due to insufficient technical and organizational security measures. | €251M | 2024 |
Transparency failures Failed to provide clear and transparent information to users about how their personal data was being shared with Meta companies. | €225M | 2021 |
TikTok Children's privacy violations Default public settings for children's accounts and enabled direct messaging to minors without adequate age verification. | €345M | 2023 |
FRFrance
CNIL (Commission Nationale de l'Informatique et des Libertés)
| Company | Amount | Year |
|---|---|---|
Google LLC Cookie consent violations Google.fr and YouTube.com made it difficult for users to refuse cookies — "Accept All" was one click but refusing required multiple steps. | €150M | 2022 |
Microsoft Ireland Advertising cookies without consent Bing deposited advertising cookies on users' devices without prior consent and lacked a clear rejection mechanism. | €60M | 2022 |
Criteo Tracking without valid consent Ad-tech company tracked users across millions of websites without obtaining valid, prior consent as required by the ePrivacy Directive. | €40M | 2024 |
Amazon France Cookie deposit without consent Deposited advertising cookies on users' computers without prior consent or adequate information about cookie purposes. | €35M | 2020 |
Google LLC Cookie deposit without consent Placed advertising cookies on google.fr without adequate prior information or consent, violating the French Data Protection Act. | €100M | 2020 |
Clearview AI Biometric data collection without basis Scraped billions of facial images from the internet without any legal basis, creating a biometric database without individuals' knowledge or consent. | €20M | 2022 |
SAF Logistics (transport SME) Employee surveillance via GPS Small logistics company tracked delivery drivers via GPS in real-time without proper consent or data protection impact assessment. | €200K | 2023 |
DS Automobiles (car dealership) Marketing emails without consent Car dealership sent promotional emails to prospects who never consented and failed to honor unsubscribe requests within the legal deadline. | €100K | 2024 |
Real estate agency (unnamed) Excessive data collection from tenants Small agency demanded bank statements, tax returns and ID copies beyond what is legally permitted for tenant applications. | €75K | 2023 |
DEGermany
16 State DPAs + BfDI (Federal)
| Company | Amount | Year |
|---|---|---|
Vodafone GmbH General data processing violations Non-compliance with general data processing principles under GDPR, including insufficient measures for lawful processing of customer data. | €45M | 2025 |
H&M Employee surveillance Systematically surveilled employees at its Nuremberg service center by recording detailed private information about health, religion, and family during return-to-work meetings. | €35.3M | 2020 |
Deutsche Wohnen Excessive data retention Real estate company stored tenant personal data indefinitely without any data retention policy, keeping old financial records, personal IDs, and employment contracts. | €14.5M | 2024 |
1&1 Telecom Insufficient authentication Customer service agents could access customer accounts using only a name and date of birth — no additional identity verification was required. | €9.55M | 2019 |
Delivery service (Hamburg) Employee health data processing Small food delivery company collected employees' health data (sick notes with diagnosis details) and stored them in an insecure shared folder. | €16K | 2024 |
Dental practice (Bavaria) Patient records without encryption Dental clinic stored unencrypted patient health records on a server accessible from the open internet, exposing sensitive medical data. | €10K | 2023 |
Fitness studio (Berlin) CCTV in changing rooms Gym installed surveillance cameras covering changing room entrances without proper signage, consent, or a legitimate purpose under GDPR. | €8.5K | 2024 |
NLNetherlands
Autoriteit Persoonsgegevens (AP)
| Company | Amount | Year |
|---|---|---|
Uber Improper EU-US data transfers Transferred EU driver personal data to the US headquarters without adequate safeguards (Standard Contractual Clauses or DPF). | €290M | 2024 |
Clearview AI Unlawful facial recognition database Built a facial recognition database by scraping billions of images from the internet without consent, legal basis, or transparency. | €30.5M | 2024 |
Netflix Inadequate privacy notices Failed to adequately inform customers about what personal data was collected and how it was used between 2018 and 2020. | €4.75M | 2024 |
Uber Transparency on data transfers Insufficient transparency about third-country data transfers and data retention periods communicated to drivers. | €10M | 2025 |
Dentist practice (Amsterdam) Unencrypted patient data sharing Dental practice emailed unencrypted patient health records and X-rays to third-party labs using regular email without any security measures. | €12K | 2024 |
Webshop (Utrecht) No cookie consent mechanism Small online retailer loaded Google Analytics and Facebook Pixel tracking cookies before obtaining any user consent, with no cookie banner at all. | €7.5K | 2023 |
LULuxembourg
CNPD (Commission Nationale pour la Protection des Données)
| Company | Amount | Year |
|---|---|---|
Amazon Europe Advertising targeting without consent Amazon's behavioral advertising system processed personal data for targeted ads without obtaining valid consent from users. Legal challenge lost in 2025. | €746M | 2021 |
Amazon Europe Data subject access rights failures Failed to adequately respond to customer data access requests within the required timeframe under GDPR Article 15. | €2.25M | 2022 |
Satispay Europe Marketing without consent Fintech company sent promotional communications to users who had not given valid consent for direct marketing purposes. | €180K | 2024 |
ITItaly
Garante per la protezione dei dati personali
| Company | Amount | Year |
|---|---|---|
OpenAI AI training without legal basis Processed personal data to train ChatGPT without a valid legal basis and failed to report a data breach within the 72-hour notification window. | €15M | 2024 |
Clearview AI Biometric data processing Operated an unlawful biometric surveillance system by scraping facial images of Italian residents without consent or legal basis. | €20M | 2022 |
Enel Energia Unsolicited telemarketing Made millions of unsolicited telemarketing calls using data obtained from unauthorized lists, contacting people on the do-not-call registry. | €26.5M | 2021 |
TIM (Telecom Italia) Aggressive telemarketing Systematic telemarketing violations including making calls without consent, ignoring opt-out requests, and mishandling personal data across call centers. | €27.8M | 2020 |
Bar Gioia (café) Illegal CCTV installation Small bar installed surveillance cameras without required information signs and filmed public sidewalk areas without any legal basis. | €600 | 2023 |
Macelleria La Costata (butcher) Excessive video surveillance Butcher shop installed cameras covering public areas and staff workstations without a data protection impact assessment or employee consent. | €1.5K | 2023 |
Medical practice (Rome) Patient emails without BCC Doctor sent a group email to 45 patients about test results using CC instead of BCC, exposing all patients' email addresses and health conditions. | €7K | 2024 |
Hotel (Florence) Passport data retention Small hotel kept photocopies of guests' passports for years instead of the mandatory 24-hour retention period, storing them in an unlocked cabinet. | €15K | 2023 |
ESSpain
AEPD (Agencia Española de Protección de Datos)
| Company | Amount | Year |
|---|---|---|
CaixaBank Unlawful customer data processing Processed customer data for marketing purposes without valid consent and failed to adequately document processing activities. | €6.2M | 2021 |
Vodafone España Unsolicited communications Sent marketing communications to users who had opted out and processed personal data for telemarketing without adequate consent mechanisms. | €8.15M | 2021 |
La Liga (football) Surveillance via mobile app Used the official La Liga app to activate microphones and GPS on users' phones to detect unauthorized broadcasts of football matches. | €250K | 2021 |
EDP Energía Lack of consent for processing Processed customer personal data for marketing and profiling without obtaining proper consent, affecting a large customer base. | €1.5M | 2023 |
Dental clinic (Madrid) Video surveillance in examination rooms Small dental practice installed CCTV in the doctor's office, recording patients during examinations without consent or legitimate interest. | €1.2K | 2024 |
Restaurant owner (Valencia) Unlawful CCTV recording Restaurant installed cameras filming public streets and neighbouring properties without proper signage or a valid legal basis. | €2K | 2023 |
Gym (Barcelona) Biometric access without consent Fitness center used fingerprint scanners for member access without obtaining explicit consent for biometric data processing. | €5K | 2024 |
Online shop (Seville) Missing privacy policy Small e-commerce website collected customer data (names, addresses, payments) without any privacy policy or data processing information. | €3K | 2023 |
Real estate agency (Málaga) Sharing tenant data without basis Agency shared personal data of tenants with third-party service providers without consent or a data processing agreement. | €10K | 2024 |
SESweden
IMY (Integritetsskyddsmyndigheten)
| Company | Amount | Year |
|---|---|---|
Apoteket AB (pharmacy) Meta Pixel data leak Transferred sensitive health-related personal data to Meta via the Meta Pixel advertising tracker installed on their e-commerce website. | €3.5M | 2024 |
Spotify AB Right of access violation Failed to provide users with sufficiently clear information about how their personal data was processed in response to access requests. | €3.5M | 2024 |
Apohem AB (pharmacy) Meta Pixel health data transfer Pharmacy chain transferred sensitive customer health data to Meta through advertising pixel, revealing purchases of medical products. | €800K | 2024 |
Capio St. Görans Hospital Unauthorized record access Hospital staff accessed patient records without medical justification. Inadequate access controls allowed employees to view any patient data. | €30K | 2023 |
GRGreece
HDPA (Hellenic Data Protection Authority)
| Company | Amount | Year |
|---|---|---|
Hellenic Post (ELTA) Data breach — dark web exposure Inadequate technical and organizational security measures led to a data breach that exposed customer personal data on the dark web. | €2.9M | 2024 |
Ministry of Interior + MEP Unsolicited political communication Personal data leaked and used for unsolicited political messages in election campaigns without citizen consent. | €440K | 2024 |
Ministry of Migration AI surveillance without safeguards Deployed AI-powered surveillance in refugee camps without proper data protection impact assessments or data retention policies. | €175K | 2024 |
FIFinland
Data Protection Ombudsman
| Company | Amount | Year |
|---|---|---|
Posti (postal service) Unlawful automatic mailbox creation Automatically created electronic mailboxes for citizens without consent, processing personal data unlawfully. | €2.4M | 2024 |
Verkkokauppa.com No data retention limits Failed to define data retention periods and forced customers to create mandatory accounts for online purchases — went beyond what is necessary. | €856K | 2024 |
Taksi Helsinki Excessive data collection Collected and stored excessive personal data from taxi passengers beyond what was necessary for the service provided. | €72K | 2021 |
Psykoterapiakeskus Vastaamo Massive therapy data breach Private psychotherapy records of 33,000+ patients were stolen and leaked online due to catastrophically poor security. CEO was criminally charged. | Criminal prosecution | 2023 |
Private school (Helsinki) Student data without legal basis Private school processed detailed behavioral notes on students and shared them with external psychologists without parental consent. | €5K | 2024 |
BEBelgium
APD (Autorité de protection des données)
| Company | Amount | Year |
|---|---|---|
Unnamed hospital Cybersecurity failure — 300K records Insufficient cybersecurity protections led to a cyberattack that compromised the personal data of 300,000 patients. | €200K | 2024 |
RTL Belgium Non-compliant cookie banner Cookie banner lacked a "Reject All" button and used misleading design with color contrasts steering users toward acceptance. | €40K/day | 2024 |
Freedelity Consent and data minimization failures Violated consent mechanisms, data minimization principles, and retained customer data excessively beyond the purpose of collection. | €5K/day | 2025 |
Construction firm (Liège) Unauthorized employee monitoring Small construction company installed keystroke loggers on employee computers to monitor productivity without informing workers or having a legal basis. | €3K | 2024 |
PLPoland
UODO (Urząd Ochrony Danych Osobowych)
| Company | Amount | Year |
|---|---|---|
Santander Bank Polska Failure to notify data breach Lost bank documents containing personal data and failed to notify affected individuals about the data breach as required. | €335K | 2024 |
Polish bank (unnamed) Failure to inform breach victims Did not inform individuals whose data was compromised in a breach, violating the GDPR notification obligation. | €928K | 2024 |
Toyota Bank Polska DPO independence issues Data Protection Officer was not positioned to operate independently and the bank failed to adequately document its profiling activities. | €132K | 2024 |
DKDenmark
Datatilsynet
| Company | Amount | Year |
|---|---|---|
Netcompany Group Digital mail service security failures Security vulnerabilities in a digital mail service exposed personal data of citizens, referred to police for prosecution. | €2.2M | 2024 |
OiSTER Telecom Data breach — 247K customers Data breach affected 246,748 customers' personal data. Reported to police with a recommended fine of DKK 750,000. | €100K | 2025 |
DSB (Danish State Railways) Employee data processing Unlawfully processed employee personal data and failed to maintain adequate records of processing activities. | €134K | 2022 |
IDdesign A/S Data retention violations Retained personal data of 385,000 former customers for years beyond what was necessary, with no deletion procedures in place. | €200K | 2021 |
NONorway
Datatilsynet
| Company | Amount | Year |
|---|---|---|
Telenor ASA Organizational GDPR failures Issues with Records of Processing Activities (RoPA) and failure to ensure Data Protection Officer (DPO) independence as required. | €380K | 2025 |
Grindr LLC Sharing sensitive data without consent Shared users' GPS location, device identifiers, and sexual orientation data with advertising partners without valid legal consent. | €6.3M | 2021 |
Municipality of Bergen Student data breach Personal data of 35,000 students and employees was exposed due to a security flaw in the school administration system. | €170K | 2020 |
Stortinget (Parliament) Cyberattack security failures The Norwegian Parliament suffered a cyberattack exploiting vulnerabilities in Microsoft Exchange, exposing email accounts of elected officials. | €68K | 2021 |
ATAustria
DSB (Datenschutzbehörde)
| Company | Amount | Year |
|---|---|---|
Austrian Post Failure to fulfill data subject rights Created profiles on political preferences of Austrian citizens and sold this data to political parties without adequate consent. | €9.5M | 2021 |
Media company (unnamed) Failure to cooperate with DPA Refused to cooperate with the data protection authority during an investigation, obstructing regulatory enforcement. | €15.2K | 2024 |
REWE Group (supermarket) Customer profiling without consent Loyalty card program processed customer behavior data for profiling purposes without valid consent under GDPR. | €8M | 2023 |
Jö Bonus Club Tracking purchase behavior Loyalty program tracked detailed purchase behavior of 4 million Austrians and used it for targeted advertising without adequate consent. | €2M | 2023 |
Physiotherapy practice (Vienna) Unsecured patient records Small physiotherapy clinic stored patient treatment records on a shared computer without password protection, accessible to all staff and visitors. | €11K | 2024 |
PTPortugal
CNPD (Comissão Nacional de Proteção de Dados)
| Company | Amount | Year |
|---|---|---|
Instituto Nacional de Estatística Unlawful international data transfers Census data was transferred to the US via Cloudflare without adequate safeguards and no data protection impact assessment was conducted. | €4.3M | 2022 |
Hospital do Barreiro Unauthorized access to patient records Hospital allowed non-medical staff to access patient records through falsified doctor profiles. 985 active profiles for only 296 doctors. | €400K | 2019 |
Câmara Municipal de Lisboa Sharing activist data with embassies The Lisbon city council shared personal data of protest organizers with foreign embassies, endangering activists from authoritarian countries. | €1.25M | 2022 |
United Kingdom
1 jurisdictionsGBUnited Kingdom
ICO (Information Commissioner's Office)
| Company | Amount | Year |
|---|---|---|
Capita Group Cybersecurity failure — 6.6M records Failed to secure personal data of 6.6 million individuals including sensitive information after a cyber-attack. Originally proposed at £45M, reduced via early settlement. | £14M | 2025 |
British Airways Data breach — 400K customers Hackers skimmed payment card data from 400,000 customers through the BA website due to poor security measures. | £20M | 2020 |
Marriott International Data breach — 339M records Failure to keep personal data secure led to a breach affecting approximately 339 million guest records globally. | £18.4M | 2020 |
Advanced Computer Software Ransomware attack — NHS disruption Inadequate cybersecurity allowed a ransomware attack that compromised 79,404 individuals' data and disrupted NHS 111 healthcare services. | £3.07M | 2025 |
23andMe Security failure — 155K UK users Failed to implement appropriate security measures, leading to a credential-stuffing attack that exposed genetic data of 155,592 UK users. | £2.31M | 2025 |
Police Service of NI Accidental data leak — 9,483 officers Accidentally published a spreadsheet containing the personal details of all 9,483 serving officers and staff. | £750K | 2024 |
Law firm (London) Client data sent to wrong recipient Small solicitors firm accidentally emailed sensitive case files including medical and financial records to the wrong person due to autocomplete error. | £10K | 2024 |
Recruitment agency (Manchester) CV database without security Staffing agency stored CVs containing personal data of 5,000+ candidates in an unencrypted, publicly accessible cloud folder. | £7.5K | 2023 |
Americas
3 jurisdictionsUSUSA (California)
CPPA + California Attorney General
| Company | Amount | Year |
|---|---|---|
Zoom Privacy and security failures Misleading security claims, sharing data with Facebook, and security vulnerabilities that enabled "Zoombombing" incidents. | $85M | 2021 |
Disney Opt-out non-compliance Failed to honor consumer opt-out requests for data sharing on its streaming platform. Part of a broader 2024 enforcement sweep on streaming services. | $2.75M | 2025 |
Healthline Media Sensitive health data leakage Allowed third-party trackers to collect sensitive user health data without consent and failed to provide a functional opt-out mechanism. | $1.55M | 2025 |
Tractor Supply Co. HR data privacy violations First CCPA fine targeting HR data. Failed to provide privacy rights information to job applicants and had a broken opt-out mechanism. | $1.35M | 2025 |
American Honda Excessive verification for rights requests Required excessive personal information for consumer verification and shared data with ad tech companies without appropriate contractual safeguards. | $632K | 2025 |
DoorDash Customer data sharing without notice Shared customer personal data with third-party marketing companies without informing consumers or providing an opt-out option. | $375K | 2023 |
Todd Snyder Inc. Misconfigured privacy portal Privacy portal was misconfigured, delaying opt-out requests. Additionally demanded excessive personal information from consumers making privacy requests. | $345K | 2025 |
BRBrazil
ANPD (Autoridade Nacional de Proteção de Dados)
| Company | Amount | Year |
|---|---|---|
Telecom operator (unnamed) Customer data processing without basis Processed customer personal data for commercial purposes without a valid legal basis, affecting millions of subscribers. | R$6.6M | 2024 |
Telekall Infoservice First-ever LGPD fine Microenterprise processed personal data for WhatsApp marketing campaigns without a valid legal basis — the very first LGPD enforcement action. | R$14.4K | 2023 |
Instituto Nacional do Seguro Social (INSS) Social security data breach Personal data of social security beneficiaries was accessed by unauthorized third parties and used for predatory loan marketing. | R$3.3M | 2024 |
Bytedance (TikTok Brazil) Children's data processing Collected and processed personal data of children under 13 without parental consent and inadequate age verification mechanisms. | R$1.7M | 2024 |
CACanada
OPC (Office of the Privacy Commissioner)
| Company | Amount | Year |
|---|---|---|
Clearview AI Unlawful facial recognition Scraped images of Canadians from the internet for facial recognition without consent. Ordered to cease operations and delete all Canadian data. | Order to delete data | 2021 |
Equifax Data breach — 19K Canadians The 2017 data breach exposed personal data of 19,000 Canadians. Investigation found inadequate security safeguards and poor data governance. | Compliance agreement | 2019 |
Tim Hortons Excessive location tracking The Tim Hortons app tracked users' location data every few minutes even when the app was closed, far exceeding what was necessary. | Compliance agreement | 2022 |
Home Depot Sharing data without consent Shared customer email addresses with Meta for targeted advertising when customers provided receipts, without obtaining meaningful consent. | Compliance agreement | 2023 |
Aylo (Pornhub/MindGeek) Non-consensual content Investigation into inadequate verification systems that failed to prevent non-consensual intimate images from being uploaded and distributed. | Under investigation | 2024 |
Asia-Pacific
5 jurisdictionsAUAustralia
OAIC (Office of the Australian Information Commissioner)
| Company | Amount | Year |
|---|---|---|
Clearview AI Facial recognition without consent Scraped Australian residents' facial images from social media without knowledge or consent to build a biometric surveillance database. | Cease operations order | 2021 |
Australian Information Commissioner v HealthEngine Misleading health data practices Shared patient personal information with insurance brokers, lawyers, and advertisers without proper consent or disclosure. | A$1.38M | 2023 |
Medibank Massive data breach — 9.7M records A 2022 ransomware attack exposed highly sensitive health data of 9.7 million current and former customers due to inadequate cybersecurity. | Ongoing litigation | 2023 |
Optus (SingTel) Data breach — 10M customers A cyberattack exposed personal data of 10 million customers including passport and driver's license numbers due to an exposed API endpoint. | A$12M settlement | 2023 |
Latitude Financial Data breach — 14M records Hackers stole 14 million customer records including driver's license numbers, passport numbers, and financial data from systems dating back to 2005. | Under investigation | 2023 |
SGSingapore
PDPC (Personal Data Protection Commission)
| Company | Amount | Year |
|---|---|---|
SingHealth Data breach — 1.5M patients Singapore's worst data breach. Hackers accessed personal data of 1.5 million patients including PM Lee Hsien Loong's prescription data. | S$250K | 2019 |
IHiS (IT vendor) Inadequate cybersecurity for SingHealth As the IT service provider for SingHealth, failed to implement adequate security measures and delayed response to the cyber-attack. | S$750K | 2019 |
Consumers Association of Singapore Security arrangement failures Failed to implement reasonable security arrangements and adequate policies to protect personal data under its care. | S$20K | 2024 |
KRSouth Korea
PIPC (Personal Information Protection Commission)
| Company | Amount | Year |
|---|---|---|
Meta (Facebook Korea) Sharing sensitive data without consent Collected and shared sensitive information about 980,000 Korean users (political views, sexual orientation, religion) with advertisers without consent. | ₩6.5B (~€4.5M) | 2022 |
Google Korea Location data consent violations Collected location data from Android users without proper consent and made it difficult for users to opt out of location tracking. | ₩69.2B (~€48M) | 2022 |
Business On Communication SQL injection data breach Data breach resulting from SQL injection attacks due to insufficient security safeguards. Failed to send timely breach notifications. | ₩139.7M (~€95K) | 2025 |
JPJapan
PPC (Personal Information Protection Commission)
| Company | Amount | Year |
|---|---|---|
LINE Corporation Cross-border data handling failures Allowed subsidiary in China to access Japanese user data including messages and payment info without proper user notification. | Administrative guidance | 2021 |
NTT Docomo / dpoint Inadequate third-party data controls Failed to maintain adequate oversight of third-party contractors who had access to customer personal information. | Administrative guidance | 2023 |
Toyota Motor Corporation Cloud misconfiguration data exposure Location and vehicle ID data of 2.15 million customers was publicly accessible for over a decade due to a cloud environment misconfiguration. | Administrative guidance | 2023 |
NTT Communications Unauthorized access — 17K records Data breach affected 17,000 corporate customer records after attackers gained unauthorized access to internal systems through compromised VPN credentials. | Administrative guidance | 2024 |
INIndia
Data Protection Board of India (DPBI)
| Company | Amount | Year |
|---|---|---|
(Enforcement starting 2027) New regulatory framework DPDP Rules notified Nov 2025. Penalties range from ₹50 Crore to ₹250 Crore per violation. Full compliance deadline: May 2027. | Framework active | 2025 |
BigBasket (Tata Digital) Data breach — 20M users Personal data of 20 million users including emails, phone numbers, and hashed passwords was found on sale on the dark web. | IT Act action | 2021 |
Air India Data breach — 4.5M passengers Flight booking data of 4.5 million passengers leaked including passport details, credit card info, and ticket information. | IT Act action | 2021 |
Domino's India Data breach — 180M orders Personal data from 180 million pizza orders leaked online including names, phone numbers, addresses, and email IDs. | IT Act action | 2021 |
Middle East
1 jurisdictionsTRTurkey
KVKK Board
| Company | Amount | Year |
|---|---|---|
Privacy policy update violations Forced users to accept new privacy policy sharing data with Meta companies. Found to violate transparency and informed consent requirements. | ₺1.95M | 2021 |
Meta (Facebook) Data breach notification failure Failed to notify Turkish authorities about a data breach in a timely manner and inadequate security measures to prevent unauthorized access. | ₺1.65M | 2020 |
Google LLC Cookie policy violations Failed to obtain valid consent for cookies and did not provide adequate information about data processing purposes on Google services used in Turkey. | ₺1.96M | 2023 |
Yemeksepeti (Delivery Hero) Data breach — 21.5M users Online food delivery platform suffered a massive data breach exposing personal data of 21.5 million users including addresses and phone numbers. | ₺1.9M | 2021 |
TikTok Children's data processing Insufficient age verification and parental consent mechanisms for Turkish users under 13, violating KVKK requirements for sensitive data. | ₺1.75M | 2022 |
Most Common Violation Types
Insufficient Legal Basis
34%Processing personal data without valid consent or legitimate interest
Typical range: €50K – €1.2B
Unlawful Data Transfers
20%Transferring personal data to third countries without adequate safeguards
Typical range: €100K – €1.2B
Insufficient Security
18%Inadequate technical and organizational measures leading to data breaches
Typical range: €10K – £14M
Data Subject Rights
15%Failure to fulfill access, deletion, or portability requests
Typical range: €5K – €20M
Cookie Consent Violations
8%Loading trackers before consent or lacking "reject all" options
Typical range: €10K – €150M
Transparency Failures
5%Insufficient privacy notices or unclear data processing information
Typical range: €5K – €225M
Regulation Overview
| Regulation | Scope | Max Penalty |
|---|---|---|
| GDPR | 27 EU member states + EEA | €20M or 4% of global turnover |
| UK GDPR | United Kingdom | £17.5M or 4% of global turnover |
| CCPA / CPRA | California, USA | $7,988 per intentional violation |
| LGPD | Brazil | 2% of revenue, capped at R$50M |
| PIPEDA | Canada | C$100K per violation (CPPA: C$25M proposed) |
| PDPA | Singapore | S$1M or 10% of local turnover |
| PIPA | South Korea | 3–10% of total sales |
| APPI | Japan | ¥100M (admin fines under review) |
| Privacy Act | Australia | A$50M, 3x benefit, or 30% of turnover |
| DPDP | India | ₹250 Crore (~€28M) |
| KVKK | Turkey | ₺1.9M per violation |
Don't become the next headline
Scan your website for privacy issues, security vulnerabilities, and compliance gaps — all in under 60 seconds.
Start Free Audit