Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Nov 2020LSS-boendeGnosjö kommun - Socialutskottet was fined by IMY for unlawful video surveillance in an LSS residence. The authority found processing of personal and sensitive data without a legal basis and no data protection impact assessment.SEIMYGDPR€19,600
26 Nov 2020Reti Televisive Italiane S.p.a.Reti Televisive Italiane S.p.a. was fined EUR 10,000 by the Garante for broadcasting a segment on “Le Iene” that included footage of an individual recorded without consent. The person was identifiable, which constituted a breach of data protection rules.ITGaranteGDPR€10,000
26 Nov 2020Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks.ITGaranteGDPR€20,000
26 Nov 2020Ministero dell’InternoThe Ministry of the Interior was fined by the Garante for the unauthorized dissemination of video and images related to a police incident. The authority found a breach of GDPR rules governing the processing of personal data.ITGaranteGDPR€60,000
26 Nov 2020Charly Mike s.r.l.Charly Mike s.r.l. was fined by the Garante EUR 3,000 for improper use of a video surveillance system at Hotel Olimpo. The system was used for continuous monitoring and remote viewing of employees, in breach of data protection rules.ITGaranteGDPR€3,000
27 Nov 2020CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR.ESAEPDGDPR€5,000
02 Dec 2020Sahlgrenska Universitets­sjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€340,000
02 Dec 2020Region ÖstergötlandRegion Östergötland was fined by IMY for failing to perform a needs and risk analysis before granting access rights in its journal system. The authority found that this breached several GDPR provisions.SEIMYGDPR€243,000
02 Dec 2020Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€389,000
02 Dec 2020Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements.SEIMYGDPR€1,167,000
02 Dec 2020Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€243,000
02 Dec 2020Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems.SEIMYGDPR€2,917,000
02 Dec 2020Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements.SEIMYGDPR€1,458,000
03 Dec 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 75,000 EUR for failing to properly verify the identity of individuals requesting changes in line ownership. This failure resulted in unauthorized access and processing of personal data.ESAEPDGDPR€75,000
03 Dec 2020Dane anonimowe (W. Polska Sp. z o.o. z siedzibą w G.)UODO imposed a fine of PLN 1,968,524 on W. Polska Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing subscribers’ personal data in IT systems.PLUODOGDPR€440,000
04 Dec 2020BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website.ESAEPDePrivacy€8,000
04 Dec 2020BEINNOVA.ESBEINNOVA.ES was fined by the AEPD EUR 2,000 for sending unsolicited marketing emails without the recipient's consent. This conduct breached Article 21 of the LSSI on electronic commercial communications.ESAEPDePrivacy€2,000
09 Dec 2020Dane anonimowe (Z. Sp. z o.o. z siedzibą w U. przy ul.)The President of the Personal Data Protection Office (UODO) imposed a fine of PLN 12,838.2 on Z. Sp. z o.o. The sanction was issued for failing to cooperate with the authority and for not providing access to personal data and other information necessary for the performance of its duties.PLUODOGDPR€2,902
09 Dec 2020Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization.HUNAIHGDPR€2,240
09 Dec 2020Guldborgsund KommuneGuldborgsund Kommune was fined 50,000 DKK by Datatilsynet for a data breach. Sensitive information was mistakenly sent to an unauthorized recipient, causing significant consequences for the affected individuals.DKDatatilsynetGDPR€6,718