<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fines Archives - Measured Collective</title>
	<atom:link href="https://measuredcollective.com/category/fines/feed/" rel="self" type="application/rss+xml" />
	<link>https://measuredcollective.com/category/fines/</link>
	<description></description>
	<lastBuildDate>Mon, 06 Jul 2026 06:14:47 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://measuredcollective.com/wp-content/uploads/2023/05/cropped-mc-icon-1-120x120.png</url>
	<title>Fines Archives - Measured Collective</title>
	<link>https://measuredcollective.com/category/fines/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects</title>
		<link>https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 06 Jul 2026 06:14:47 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14983</guid>

					<description><![CDATA[<p>A B2B platform holds years of customer booking data collected for one operational purpose. A product team wants to mine it for a new analytics pilot. No breach, no hacker. Just reuse. In May 2026, Spain&#8217;s data protection authority closed a cross-border GDPR case against Amadeus with a €14.4 million fine, reduced from €18 million ... </p>
<p class="read-more-container"><a title="AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects" class="read-more button" href="https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/#more-14983" aria-label="Read more about AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/aepd-fines-amadeus-e14-4m-over-traveller-profiling-what-the-booking-data-case-means-for-reuse-projects/">AEPD fines Amadeus €14.4M over traveller profiling: what the booking-data case means for reuse projects</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>California sues 23andMe: why genetic-data security failures become a board issue</title>
		<link>https://measuredcollective.com/california-sues-23andme-why-genetic-data-security-failures-become-a-board-issue/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 08 Jun 2026 06:44:31 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14921</guid>

					<description><![CDATA[<p>California says 23andMe failed to protect genetic data and misled consumers after the 2023 breach. Here is why the lawsuit matters for boards, privacy teams, and managers.</p>
<p>The post <a href="https://measuredcollective.com/california-sues-23andme-why-genetic-data-security-failures-become-a-board-issue/">California sues 23andMe: why genetic-data security failures become a board issue</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Disney CCPA settlement: why cross-device opt-outs must work account-wide</title>
		<link>https://measuredcollective.com/disney-ccpa-settlement-why-cross-device-opt-outs-must-work-account-wide/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 25 May 2026 06:15:14 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14888</guid>

					<description><![CDATA[<p>California&#8217;s 11 February 2026 settlement with Disney is one of the clearest CCPA warnings yet for teams that run the same customer account across multiple apps, devices, and ad-tech integrations. The point is bigger than streaming. It is about whether one opt-out request actually stops sale or sharing everywhere your systems say it should. If ... </p>
<p class="read-more-container"><a title="Disney CCPA settlement: why cross-device opt-outs must work account-wide" class="read-more button" href="https://measuredcollective.com/disney-ccpa-settlement-why-cross-device-opt-outs-must-work-account-wide/#more-14888" aria-label="Read more about Disney CCPA settlement: why cross-device opt-outs must work account-wide">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/disney-ccpa-settlement-why-cross-device-opt-outs-must-work-account-wide/">Disney CCPA settlement: why cross-device opt-outs must work account-wide</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO secures £355,880.10 confiscation order against Rizwan Manjra — why insider misuse controls still matter</title>
		<link>https://measuredcollective.com/ico-confiscation-order-rizwan-manjra-insider-misuse-controls/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sat, 23 May 2026 07:22:19 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14881</guid>

					<description><![CDATA[<p>On 21 May 2026, the ICO said it had secured a £355,880.10 confiscation order against former motor-insurance worker Rizwan Manjra. This was not a corporate fine. It was a proceeds-of-crime order after an employee had already admitted unlawfully accessing personal information for financial gain. The compliance lesson is still squarely for organisations: insider misuse stays ... </p>
<p class="read-more-container"><a title="ICO secures £355,880.10 confiscation order against Rizwan Manjra — why insider misuse controls still matter" class="read-more button" href="https://measuredcollective.com/ico-confiscation-order-rizwan-manjra-insider-misuse-controls/#more-14881" aria-label="Read more about ICO secures £355,880.10 confiscation order against Rizwan Manjra — why insider misuse controls still matter">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-confiscation-order-rizwan-manjra-insider-misuse-controls/">ICO secures £355,880.10 confiscation order against Rizwan Manjra — why insider misuse controls still matter</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>General Motors CCPA settlement: why data minimization is now an enforcement risk</title>
		<link>https://measuredcollective.com/general-motors-ccpa-settlement-why-data-minimization-is-now-an-enforcement-risk/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 18 May 2026 06:14:00 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14868</guid>

					<description><![CDATA[<p>California’s settlement with General Motors shows how CCPA data minimisation is now an enforcement risk. Here’s what the case says about retention, purpose limits, sensitive data, and the checks managers should run now.</p>
<p>The post <a href="https://measuredcollective.com/general-motors-ccpa-settlement-why-data-minimization-is-now-an-enforcement-risk/">General Motors CCPA settlement: why data minimization is now an enforcement risk</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO fines South Staffordshire PLC &#038; South Staffordshire Water £963,900 after phishing-led breach exposed 633,887 people’s data</title>
		<link>https://measuredcollective.com/ico-fines-south-staffordshire-963900-phishing-breach-critical-infrastructure/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Wed, 13 May 2026 08:39:20 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14831</guid>

					<description><![CDATA[<p>The ICO fined South Staffordshire £963,900 after a phishing-led cyber attack exposed 633,887 people’s data. What failed, and what managers should review now.</p>
<p>The post <a href="https://measuredcollective.com/ico-fines-south-staffordshire-963900-phishing-breach-critical-infrastructure/">ICO fines South Staffordshire PLC &amp; South Staffordshire Water £963,900 after phishing-led breach exposed 633,887 people’s data</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Reddit Fined £14.47m by ICO for Children&#8217;s Privacy Failures — 2026</title>
		<link>https://measuredcollective.com/reddit-ico-fine-childrens-privacy-failures-2026/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 08:49:23 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<category><![CDATA[Fines]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/?p=14794</guid>

					<description><![CDATA[<p>Reddit fined £14.47m by ICO for children's privacy failures under GDPR and DPA 2018. What this means for your organisation.</p>
<p>The post <a href="https://measuredcollective.com/reddit-ico-fine-childrens-privacy-failures-2026/">Reddit Fined £14.47m by ICO for Children&#8217;s Privacy Failures — 2026</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Advanced Computer Software Group Fined £3m by ICO for NHS Ransomware Data Breach — 2025</title>
		<link>https://measuredcollective.com/advanced-computer-software-group-fined-3m-by-ico-for-nhs-ransomware-data-breach-2025/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sun, 26 Apr 2026 06:41:22 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/advanced-computer-software-group-fined-3m-by-ico-for-nhs-ransomware-data-breach-2025/</guid>

					<description><![CDATA[<p>The ICO fined Advanced Computer Software Group £3m for the 2022 NHS ransomware data breach. Learn what this means for your data security compliance.</p>
<p>The post <a href="https://measuredcollective.com/advanced-computer-software-group-fined-3m-by-ico-for-nhs-ransomware-data-breach-2025/">Advanced Computer Software Group Fined £3m by ICO for NHS Ransomware Data Breach — 2025</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Reddit Fined £14.47m by ICO for Children&#8217;s Privacy Failures — 2026</title>
		<link>https://measuredcollective.com/reddit-fined-14-47m-by-ico-for-childrens-privacy-failures-2026/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Sat, 04 Apr 2026 04:39:40 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/reddit-fined-14-47m-by-ico-for-childrens-privacy-failures-2026/</guid>

					<description><![CDATA[<p>Reddit fined £14.47m by ICO for children's privacy failures under GDPR and DPA 2018. What this means for your organisation.</p>
<p>The post <a href="https://measuredcollective.com/reddit-fined-14-47m-by-ico-for-childrens-privacy-failures-2026/">Reddit Fined £14.47m by ICO for Children&#8217;s Privacy Failures — 2026</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Age Verification Is No Longer Optional: How Regulators Are Raising the Bar</title>
		<link>https://measuredcollective.com/age-verification-is-no-longer-optional-how-regulators-are-raising-the-bar/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Wed, 11 Mar 2026 06:44:45 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Guides]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/age-verification-is-no-longer-optional-how-regulators-are-raising-the-bar/</guid>

					<description><![CDATA[<p>In early 2026, regulators on both sides of the Atlantic fined platforms, blocked laws, and rewrote policy — all focused on one question: are you doing enough to verify whether your users are children? Three enforcement actions in February and March 2026 make the direction of travel unmistakable. Self-declaration tick boxes are no longer a ... </p>
<p class="read-more-container"><a title="Age Verification Is No Longer Optional: How Regulators Are Raising the Bar" class="read-more button" href="https://measuredcollective.com/age-verification-is-no-longer-optional-how-regulators-are-raising-the-bar/#more-14740" aria-label="Read more about Age Verification Is No Longer Optional: How Regulators Are Raising the Bar">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/age-verification-is-no-longer-optional-how-regulators-are-raising-the-bar/">Age Verification Is No Longer Optional: How Regulators Are Raising the Bar</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO&#8217;s Public Sector Approach: Why the Post Office Received a Reprimand Instead of a £1m Fine</title>
		<link>https://measuredcollective.com/icos-public-sector-approach-why-the-post-office-received-a-reprimand-instead-of-a-1m-fine/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Wed, 31 Dec 2025 12:34:02 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/icos-public-sector-approach-why-the-post-office-received-a-reprimand-instead-of-a-1m-fine/</guid>

					<description><![CDATA[<p>In December 2025, the ICO concluded its investigation into a data breach that exposed personal information belonging to 502 victims of the Post Office Horizon scandal. After considering a fine of up to £1.094 million, the regulator instead issued a reprimand under its &#8220;public sector approach&#8221; policy. The decision has drawn sharp criticism from privacy ... </p>
<p class="read-more-container"><a title="ICO&#8217;s Public Sector Approach: Why the Post Office Received a Reprimand Instead of a £1m Fine" class="read-more button" href="https://measuredcollective.com/icos-public-sector-approach-why-the-post-office-received-a-reprimand-instead-of-a-1m-fine/#more-13897" aria-label="Read more about ICO&#8217;s Public Sector Approach: Why the Post Office Received a Reprimand Instead of a £1m Fine">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/icos-public-sector-approach-why-the-post-office-received-a-reprimand-instead-of-a-1m-fine/">ICO&#8217;s Public Sector Approach: Why the Post Office Received a Reprimand Instead of a £1m Fine</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>The EU&#8217;s First DSA Fine: What X&#8217;s €120m Penalty Means for Digital Platform Compliance</title>
		<link>https://measuredcollective.com/the-eus-first-dsa-fine-what-xs-e120m-penalty-means-for-digital-platform-compliance/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Wed, 31 Dec 2025 12:33:59 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<guid isPermaLink="false">https://measuredcollective.com/the-eus-first-dsa-fine-what-xs-e120m-penalty-means-for-digital-platform-compliance/</guid>

					<description><![CDATA[<p>On 5 December 2025, the European Commission issued its first-ever fine under the Digital Services Act (DSA). X, formerly Twitter, was fined €120 million for three specific violations of the EU&#8217;s platform regulation rulebook. This decision matters beyond X. It shows how the Commission interprets its enforcement powers and what it expects from large platforms ... </p>
<p class="read-more-container"><a title="The EU&#8217;s First DSA Fine: What X&#8217;s €120m Penalty Means for Digital Platform Compliance" class="read-more button" href="https://measuredcollective.com/the-eus-first-dsa-fine-what-xs-e120m-penalty-means-for-digital-platform-compliance/#more-13896" aria-label="Read more about The EU&#8217;s First DSA Fine: What X&#8217;s €120m Penalty Means for Digital Platform Compliance">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/the-eus-first-dsa-fine-what-xs-e120m-penalty-means-for-digital-platform-compliance/">The EU&#8217;s First DSA Fine: What X&#8217;s €120m Penalty Means for Digital Platform Compliance</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>ICO fines Care Home Director for Deleting Data: The Warning Every Manager Should Read</title>
		<link>https://measuredcollective.com/ico-fines-care-home-director-for-deleting-data-the-warning-every-director-should-read/</link>
		
		<dc:creator><![CDATA[Scott Dooley]]></dc:creator>
		<pubDate>Mon, 08 Sep 2025 12:53:28 +0000</pubDate>
				<category><![CDATA[DPA]]></category>
		<category><![CDATA[Fines]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://wpstaging.measuredcollective.com/?p=13036</guid>

					<description><![CDATA[<p>On 3 September 2025, Jason Blake, 56, director of Bridlington Lodge Care Home in Yorkshire, was ordered to pay £1,100 in fines and £5,440 in costs after being found guilty of failing to respond to a data subject access request (DSAR). The case is a rare criminal prosecution for DSAR non-compliance. The Facts In April ... </p>
<p class="read-more-container"><a title="ICO fines Care Home Director for Deleting Data: The Warning Every Manager Should Read" class="read-more button" href="https://measuredcollective.com/ico-fines-care-home-director-for-deleting-data-the-warning-every-director-should-read/#more-13036" aria-label="Read more about ICO fines Care Home Director for Deleting Data: The Warning Every Manager Should Read">Read more</a></p>
<p>The post <a href="https://measuredcollective.com/ico-fines-care-home-director-for-deleting-data-the-warning-every-director-should-read/">ICO fines Care Home Director for Deleting Data: The Warning Every Manager Should Read</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Canal+ fined €600k for GDPR breaches including failure to report data breach</title>
		<link>https://measuredcollective.com/canal-fined-e600k-for-gdpr-breaches-including-failure-to-report-data-breach/</link>
		
		<dc:creator><![CDATA[Harry Mulhern]]></dc:creator>
		<pubDate>Mon, 06 Nov 2023 03:59:19 +0000</pubDate>
				<category><![CDATA[Fines]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://wpstaging.measuredcollective.com/?p=11983</guid>

					<description><![CDATA[<p>French broadcasting company Groupe Canal+ was recently fined €600,000 by the French data protection authority (CNIL) for multiple violations of the EU’s General Data Protection Regulation (GDPR).</p>
<p>The post <a href="https://measuredcollective.com/canal-fined-e600k-for-gdpr-breaches-including-failure-to-report-data-breach/">Canal+ fined €600k for GDPR breaches including failure to report data breach</a> appeared first on <a href="https://measuredcollective.com">Measured Collective</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
