AI Compliance Penalty Database
Track every major AI and data privacy enforcement action worldwide. Learn from others' mistakes before regulators come knocking.
Fined for using member data for behavioral analysis and targeted advertising without proper consent.
Uber
Fined for transferring EU driver data to US without adequate safeguards after Schrems II ruling.
Workday
Class action lawsuit alleging AI hiring tools discriminate against Black and older applicants. Case ongoing.
OpenAI
Investigation into ChatGPT data collection practices. Temporary ban lifted after compliance measures implemented.
TikTok
Fined for failing to protect children's privacy and making accounts public by default for users aged 13-17.
iTutorGroup
First enforcement action under NYC LL144. Fined for using AI hiring tool that discriminated against older applicants.
Meta (Facebook)
Record GDPR fine for transferring EU user data to US servers without adequate protection. Largest GDPR penalty ever issued.
Microsoft
Fined for dropping advertising cookies on Bing without user consent.
Clearview AI
Fined for illegally collecting and using biometric data of French citizens through facial recognition technology.
Clearview AI
Fined for collecting facial images of UK residents without consent and failing to have a lawful basis for processing.
Fined for making it difficult for users to refuse cookies on YouTube, violating consent requirements.
Fined for lack of transparency about how user data is shared with Facebook.
Amazon
Fined for processing personal data in violation of GDPR, particularly regarding targeted advertising practices.
Marriott International
Fined for data breach affecting 339 million guest records worldwide, including 7 million UK residents.
British Airways
Fined for data breach affecting 400,000+ customers. Original fine of £183M reduced due to COVID-19 impact.
H&M
Fined for extensive surveillance of employees, including recording personal details about health, family, and religion.
Don't Become the Next Case Study
The average AI compliance fine is over €200M. Our assessments help you identify and fix compliance gaps before regulators find them.
Understanding AI Compliance Penalties
Key Regulations
- GDPR (EU) - Up to €20M or 4% of global revenue
- NYC Local Law 144 - $500-$1,500 per violation per day
- Colorado AI Act - $20,000 per violation (effective Feb 2026)
- EU AI Act - Up to €35M or 7% of global revenue
- UK GDPR - Up to £17.5M or 4% of global revenue
Common Violations
- AI Bias in Hiring - Discriminatory algorithms in recruitment
- Data Transfers - Moving data without adequate safeguards
- Lack of Transparency - Not disclosing AI decision-making
- Missing Consent - Processing data without proper consent
- Inadequate Security - Data breaches from poor protection