4 ms·
GDPR Enforcement Tracker – list of GDPR fines
- nsjames 3y agoInteresting to see the correlation between size of a company and their fine. ORANGE spain for instance got a 200,000 EUR fine, but some local physician only got 1,500.
- Denote6737 3y agoWhat surprised me was the UK MoD. 400,000
- g_p 3y agoThat sounds like a fine that was the maximum under the pre-GDPR regime, rather than the GDPR-era penalty regime. If the offence took place before the new rules were in force, the old penalties apply, even if the case takes some time to be resolved.
- cccbbbaaa 3y agoThe violation happened in 2021. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2023/12/ico-fines-ministry-of-defence-for-afghan-evacuation-data-breach/ https://ico.org.uk/about-the-ico/media-centre/news-and-blogs... I'm actually surprised the ICO can fine the UK government. This can't happen in France, for instance.
- Someone 3y agoDetails at https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2023/12/ico-fines-ministry-of-defence-for-afghan-evacuation-data-breach/ https://ico.org.uk/about-the-ico/media-centre/news-and-blogs... That was an error with potentially very grave consequences, but it seems the MoD handled it well once they were aware of it (“Soon after the data breach, the MoD contacted the people affected asking them to delete the email, change their email address, and inform the ARAP team of their new contact details via a secure form. The MoD also conducted an internal investigation, made a statement in Parliament about the data breach, and updated the ARAP’s email policies and processes, including implementing a ‘second pair of eyes’ policy for the ARAP team when sending emails to multiple external recipients”) I don’t think a larger fine would have made them do better, so why make it higher?
- yau8edq12i 3y agoWere you expecting something different?
- nsjames 3y agoI had no expectations tbh. Was a pleasant surprise.
- izacus 3y agoThe US law firms and compliance consultants were scaremongering a lot around these fines (after all, they got paid for consulting there and making sure this is as scary as possible).
- hnbad 3y agoTo be fair, in the US regulations seem to be thought of as something enforced against smaller companies while larger companies can afford expensive lawyers to sidestep them. The difference is that EU privacy law can't easily be sidestepped because it specifically targets these large companies. OTOH this might just be a case of "temporarily inconvenienced billionaire" logic or the same fear mongering as "if we raise minimum wage you won't be able to afford rent".
- t-writescode 3y agoA review of what the GDPR is and what an expected fine is according to the law itself, this is exactly what you would expect to see. Its maximum penalty is related to the company's annual, worldwide revenue. From https://gdpr.eu/fines/ https://gdpr.eu/fines/: > The more serious infringements go against the very principles of the right to privacy and the right to be forgotten that are at the heart of the GDPR. These types of infringements could result in a fine of up to €20 million, or 4% of the firm’s worldwide annual revenue from the preceding financial year, whichever amount is higher. (emphasis theirs, well, bold not italics, but yeah.)
- input_sh 3y agoKey words: "up to". Meta/Facebook/WhatsApp was fined about 2.4 billion (6 out of top 10 fines), but still nowhere near close to the maximum (which would be about 54 billion).
- arlcode 3y agoThat tracks with European regulatory enforcement practices. Everytime a new EU regulation is discussed on HN people are up in arms about the "maximum fines" and some replace the "maximum" with "mandatory". Fines need to be reasonable and proportional and that is not optional if they should survive a court case. The big fines are tool used to bring global conglomerates into compliance.
- nsjames 3y agoYeah that makes a lot of sense, I guess I had just never thought of it that way.
- agilob 3y ago> Warning: fopen(https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r71bDfpaH7LSqdu-2XTTnk8k/export?gid=511705091&format=csv https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r...): Failed to open stream: Connection refused in /mnt/web308/b1/30/54257730/htdocs/enforcementtracker/index.php on line 1493 Fatal error: Uncaught TypeError: fgetcsv(): Argument #1 ($stream) must be of type resource, bool given in /mnt/web308/b1/30/54257730/htdocs/enforcementtracker/index.php:1496 Stack trace: #0 /mnt/web308/b1/30/54257730/htdocs/enforcementtracker/index.php(1496): fgetcsv(false) #1 {main} thrown in /mnt/web308/b1/30/54257730/htdocs/enforcementtracker/index.php on line 1496 Just open the file yourself https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r71bDfpaH7LSqdu-2XTTnk8k/export?gid=511705091&format=csv https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r...
- Retr0id 3y agoWeb preview: https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r71bDfpaH7LSqdu-2XTTnk8k/preview#gid=511705091 https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r... Full-fat google docs view: https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r71bDfpaH7LSqdu-2XTTnk8k/view#gid=511705091 https://docs.google.com/spreadsheets/d/1s2eNqf5xpVX8j6LfnL6r...
- raybb 3y agoInteresting to see some individuals and seemingly individual police officers fined. I know it was theoretically possible but I wonder what the stories are there.
- klaustopher 3y agoAt least for Germany there are cases, where police officers have leaked information about people that they have access to through their systems. Especially leaking data about political opponents to certain groups.
- hnbad 3y agoI don't know which case you're thinking of but generally the trend seems to be police officers leaking data about (perceived) left-wing activists to far-right groups. There is a known far-right extremism problem in the German police force and military, e.g. the founder of GSG9 (think German SWAT) and a brigadier general and former commander of the KSK (think German SOCOM/SEAL) published a book with a far-right publishing house, which was the first in a series of incidents that led to the KSK being reformed in 2020 to (hopefully) address the systemic far-right extremism problem. There have been credible claims of ties of far-right terrorist groups like Combat 18 and NSU 2.0 to the police. E.g. in one of the biggest news stories there was a find of not only a disturbing cache of weapons and body bags but also "kill lists" found to be sourced from police computers. There are obvious ideological reasons why police officers are more likely to be supportive of far-right extremism than, say, far-left extremism. That isn't to say police officers are generally far-right but maintaining the status quo, opposing disturbances of the public order and enforcing the letter of the law fit better with conservatism than progressivism and social justice movements, let alone radical leftism.
- Etherlord87 3y agoHere's one story: a doctor interviewed by polish TV station "TVN" complained on patients not getting receipts for painkiller meds for 2 days. To which the Polish Minister of Health Adam Niedzielski responded on twitter [1] saying the doctor lied, because he prescribed himself a psychotropic/painkiller drug a day prior. € 23000 [1] http://web.archive.org/web/20230805142446/https://twitter.com/a_niedzielski/status/1687472741127987200 http://web.archive.org/web/20230805142446/https://twitter.co...
- bryanrasmussen 3y agohas anyone checked increase of fines over time? My theory is that fines should start getting bigger the longer companies keep infringing.
- madsbuch 3y agoThey do have a statistics page: https://www.enforcementtracker.com/?insights https://www.enforcementtracker.com/?insights This does not entirely answer your question, but it has some indication: 1. They started fining around 2019. 2. Large fines, over EUR 1mil, started around 2021. From this I would not say that the fines get bigger, they just start to fine when they have been infringing for long enough.
- fransje26 3y agoPositively surprised to see that fines are being enforced for non-compliers, with some of the fines being significant. I still encounter sites that are not complying with GDPR, but maybe things will improve after all.
- GJim 3y ago> Positively surprised to see that fines are being enforced for non-compliers Why? I'm curious what it was you expected to happen?
- fransje26 3y agoI expected that they might have went behind a few high-profile cases, for the show, and an entire group of smaller non-compliers would simply continue their business as usual. I often wondered if flagging smaller websites not respecting the GDPR to the relevant watchdogs would have any effect at all, or that it was just a waste of time because small-fish complaints would go straight to the bin. I stand corrected, and will not hesitate to do so going forward.
- deleted 3y ago[deleted]
- maxehmookau 3y agoDisappointing in the UK that two fines have been given to charities and NHS trusts trying to help trans people. Seems an ugly front in the culture war.
- 4ugSWklu 3y agoWhy is that disappointing? Are charities and NHS trusts that help trans people above the law?
- maxehmookau 3y agoNo, of course not. I'm just curious why such a large proportion (14%) of GDPR fines in the UK have been handed to trans-friendly organisations. Sure, in isolation, they are obviously justified. But why such a focus?
- hnbad 3y agoI don't think it's meaningful to talk about "a large proportion" with this few data points. They're serious privacy violations because of the nature of the data that was exposed. We're also only talking about two organizations, both of which did have legitimate privacy violation incidents. You're drawing conclusions based on statistically meaningless sample sizes.
- Symbiote 3y ago> This penalty has been issued because of contraventions by Mermaids of Articles 5(1)(f) and 32(1) and (2) of the GDPR in that during the period of 25 May 2018 to 14 June 2019 Mermaids failed to implement an appropriate level of organisational and technical security to its internal email systems, which resulted in documents or emails containing personal data, including in some cases relating to children and / or including in some cases special category data, being searchable and viewable online by third parties through internet search engine results. A fine for this seems reasonable. Data on sexuality and medical history is protected beyond the normal level for personal data.
- Macha 3y ago
- sylware 3y agogoogle doc? REALLY?
- deleted 3y ago[deleted]