government social media healthcare service provider fine education law enforcement finance dark web retail web phama telecoms charity insurance travel app manufacturing operating system legal tech gaming publishing transport utilities
story hacked malware unauthorised access ransomware vulnerability accidental disclosure phishing unsecured database poor security insider threat unsecured server hacked email lost device identity theft website hacked ddos stolen documents Trojans financial inside job RDP spear phishing breached skimming
cyber attack breach notification privacy security flaw legislation poor operations user credentials physical security customer data third party Cryptocurrency enforcement email hacked insecure storage court action encryption fraud VPN passwords zero day spyware 3rd parties state hacking employee data remote working

DPC seeking penalty of up to €36m against Facebook
Singapore commision fine decision £10,000
Ransomware attacks on US schools and colleges cost 945bn
SEC Sanctions Public Company for Misleading Disclosures About Data Breach - Privacy & Information Security Law Blog
UPMC Settles Employee Data Breach Lawsuit for $2.65 Million
France's data protection authority, the Commission nationale de l’informatique et des libertés, announced a 1.75 million euro fine against multinational insurer AG2R La Mondiale for violating data retention provisions under the EU General Data Protection Regulation
The Information Commissioner’s Office (ICO) has fined transgender charity Mermaids £25,000 for failing to keep the personal data of its users secure.
Norwegian DPA: Moss Municipal Council fined | European Data Protection Board
First American Financial Pays Farcical $500K Fine – Krebs on Security
Cedaredge company fined for not securing customer data | Western Colorado | gjsentinel.com
Sanctions against 6 business operators including the Personal Information Commission and Microsoft
The Secret IRS Files Trove of NeverBeforeSeen Records Reveal How the Wealthiest Avoid Income Tax ProPublica
Medhelp will pay 12 million after the 1177 leak
Fin(d)ing Locatefamily.com: Dutch DPA imposes €525,000 fine for not having a GDPR representative
(Peachstate Pays $25,000 to Settle Potential HIPAA violation
City pays $350,000 after suing “hackers” for opening Dropbox link it sent them | Ars Technica
Dutch privacy watchdog fines Booking.com €475K – POLITICO
Restaurant fined 2000 Euros for breaching Art. 5 (1) c) GDPR - Non-compliance with general data processing principles
Hamburger Volksbank eG fined Unknown Euros for breaching Art. 21 GDPR - Insufficient fulfilment of data subjects rights
Hamburger Verkehrsverbund GmbH (HVV GmbH) fined 20,000 Euros for breaching Art. 33 GDPR, Art. 34 GDPR - Insufficient fulfilment of data breach notification obligations
Facebook Germany GmbH fined 51,000 Euros for breaching Art. 37 GDPR - Lack of appointment of data protection officer
Unknown fined 294,000 Euros for breaching Art. 5 GDPR - Non-compliance with general data processing principles
AMADOR RECREATIVOS, S.L fined 3,600 Euros for breaching Art. 5 (1) c) GDPR - Non-compliance with general data processing principles
Employer fined 9,000 Euros for breaching Art. 5 (1) c) GDPR - Non-compliance with general data processing principles
Employer fined 20,000 Euros for breaching Art. 5 (1) c) GDPR - Non-compliance with general data processing principles
Vodafone España, S.A.U. fined 40,000 Euros for breaching Art. 6 GDPR - Insufficient legal basis for data processing
Vodafone España, S.A.U. fined 30,000 Euros for breaching Art. 5 (1) f) GDPR, Art. 32 GDPR - Insufficient technical and organisational measures to ensure information security
TELEFONICA MOVILES ESPAÑA, S.A.U. fined 48,000 Euros for breaching Art. 5 (1) a) GDPR - Non-compliance with general data processing principles
VODAFONE ONO, S.A.U. fined 48,000 Euros for breaching Art. 32 GDPR - Insufficient technical and organisational measures to ensure information security
VODAFONE ONO, S.A.U. fined 36,000 Euros for breaching Art. 5 (1) f) GDPR - Non-compliance with general data processing principles
Vodafone España, S.A.U. fined 21,000 Euros for breaching Art. 6 (1) GDPR - Insufficient legal basis for data processing
Doctor fined 14,000 Euros for breaching Art. 5 GDPR, Art. 6 GDPR - Insufficient legal basis for data processing
Newspaper fined 10,000 Euros for breaching Art. 6 GDPR - Insufficient legal basis for data processing
State Hospital fined 5,000 Euros for breaching Art. 15 GDPR - Insufficient fulfilment of data subjects rights
Asesoría Alpi-Clúa S.L. fined 3,000 Euros for breaching Art. 5 (1) f) GDPR, Art. 32 (1) GDPR - Non-compliance with general data processing principles
Vodafone España, S.A.U. fined 60,000 Euros for breaching Art. 6 (1) GDPR - Insufficient legal basis for data processing
Hackers hacked into the system of three Prague polyclinics, e-mails and ordering system do not work
Heredad de Urueña S.A. fined 2000 Euros for breaching Art. 13 GDPR - Insufficient fulfilment of information obligations
Cultural association fined 3,000 Euros for breaching Art. 6 (1) a) GDPR - Insufficient legal basis for data processing
School fined 1,000 Euros for breaching Art. 5 (1) c) GDPR, Art. 6 (1) GDPR, Art. 8 GDPR - Insufficient legal basis for data processing