government social media healthcare service provider fine education law enforcement finance dark web web retail phama app insurance telecoms security charity travel manufacturing operating system legal tech gaming publishing transport
story hacked malware unauthorised access ransomware vulnerability accidental disclosure phishing unsecured database poor security insider threat unsecured server hacked email lost device website hacked identity theft ddos stolen documents hacking financial Trojans inside job RDP spear phishing breached
cyber attack breach notification privacy security flaw legislation poor operations user credentials physical security customer data third party Cryptocurrency enforcement email hacked insecure storage court action encryption fraud VPN passwords zero day spyware 3rd parties state hacking employee data remote working

Martin County tax collector still silent amid cyberattack | WPEC
DPC seeking penalty of up to €36m against Facebook
Singapore commision fine decision £10,000
Ransomware attacks on US schools and colleges cost 945bn
SEC Sanctions Public Company for Misleading Disclosures About Data Breach - Privacy & Information Security Law Blog
UPMC Settles Employee Data Breach Lawsuit for $2.65 Million
France's data protection authority, the Commission nationale de l’informatique et des libertés, announced a 1.75 million euro fine against multinational insurer AG2R La Mondiale for violating data retention provisions under the EU General Data Protection Regulation
Norwegian DPA: Moss Municipal Council fined | European Data Protection Board
First American Financial Pays Farcical $500K Fine – Krebs on Security
Cedaredge company fined for not securing customer data | Western Colorado | gjsentinel.com
Sanctions against 6 business operators including the Personal Information Commission and Microsoft
The Secret IRS Files Trove of NeverBeforeSeen Records Reveal How the Wealthiest Avoid Income Tax ProPublica
Medhelp will pay 12 million after the 1177 leak
Fin(d)ing Locatefamily.com: Dutch DPA imposes €525,000 fine for not having a GDPR representative
(Peachstate Pays $25,000 to Settle Potential HIPAA violation
City pays $350,000 after suing “hackers” for opening Dropbox link it sent them | Ars Technica
Dutch privacy watchdog fines Booking.com €475K – POLITICO
Unknown fined 294,000 Euros for breaching Art. 5 GDPR - Non-compliance with general data processing principles
Employer fined 20,000 Euros for breaching Art. 5 (1) c) GDPR - Non-compliance with general data processing principles
TELEFONICA MOVILES ESPAÑA, S.A.U. fined 48,000 Euros for breaching Art. 5 (1) a) GDPR - Non-compliance with general data processing principles
Vodafone España, S.A.U. fined 21,000 Euros for breaching Art. 6 (1) GDPR - Insufficient legal basis for data processing
State Hospital fined 5,000 Euros for breaching Art. 15 GDPR - Insufficient fulfilment of data subjects rights
Asesoría Alpi-Clúa S.L. fined 3,000 Euros for breaching Art. 5 (1) f) GDPR, Art. 32 (1) GDPR - Non-compliance with general data processing principles
Vodafone España, S.A.U. fined 60,000 Euros for breaching Art. 6 (1) GDPR - Insufficient legal basis for data processing
Hackers hacked into the system of three Prague polyclinics, e-mails and ordering system do not work
Heredad de Urueña S.A. fined 2000 Euros for breaching Art. 13 GDPR - Insufficient fulfilment of information obligations
Cultural association fined 3,000 Euros for breaching Art. 6 (1) a) GDPR - Insufficient legal basis for data processing
School fined 1,000 Euros for breaching Art. 5 (1) c) GDPR, Art. 6 (1) GDPR, Art. 8 GDPR - Insufficient legal basis for data processing
Certime S.A. fined 5,000 Euros for breaching Art. 5 (1) b) GDPR - Non-compliance with general data processing principles
Google facing $5bn lawsuit over Chrome's not-so-incognito mode | TechRadar
NBQ Technology, S.A.U. fined 12,000 Euros for breaching Art. 6 (1) GDPR - Insufficient legal basis for data processing
Private Person fined 1,500 Euros for breaching Art. 5 (1) c) GDPR - Non-compliance with general data processing principles
Vodafone España, S.A.U. fined 8,150,000 Euros for breaching Art. 28 GDPR, Art. 24 GDPR, Art. 44 GDPR, Art. 21 LSSI, Art. 48 (1) b) LGT, Art. 21 GDPR, Art. 23 LOPDGDD - Insufficient fulfilment of data subjects rights
Epsilon agrees to pay $150m fine to DoJ for selling data to fraudsters | News | GRC World Forums
Xfera Moviles S.A. fined 90,000 Euros for breaching Art. 5 (1) f) GDPR, Art. 17 GDPR, Art. 32 GDPR - Insufficient technical and organisational measures to ensure information security
Equifax Iberica S.L. fined 50,000 Euros for breaching Art. 6 (1) f) GDPR - Insufficient legal basis for data processing
Filigrana Comunicación S.L.U. fined 8,000 Euros for breaching Art. 6 (1) GDPR, Art. 13 GPDR, Art. 14 GDPR - Insufficient fulfilment of information obligations
Hospital Campogrande DE fined 10,000 Euros for breaching Art. 5 (1) f) GDPR - Non-compliance with general data processing principles
VfB Stuttgart 1893 AG fined 300,000 Euros for breaching Art. 5 (2) GDPR - Non-compliance with general data processing principles
Homeowners Association fined 15,000 Euros for breaching Art. 5 (1) f) GDPR - Non-compliance with general data processing principles