Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2021Dña. B.B.B.The entity was fined for publishing personal images and contact numbers on a dating website without proper consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€2,000
01 Jan 2021RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€5,000
01 Jan 2021ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD for sending advertising emails without the recipients’ consent. It also failed to comply with a request to delete personal data from its databases.ESAEPDePrivacy€5,000
01 Jan 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 100,000 EUR by the AEPD for requiring customers to submit photographs of both sides of their ID cards as a condition for package delivery. The authority found that this practice breached data protection principles.ESAEPDGDPR€100,000
01 Jan 2021ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings.ESAEPDGDPR€70,000
01 Jan 2021CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose.ESAEPDGDPR€4,000
01 Jan 2021Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR.PTComissão Nacional de Proteção de DadosGDPR€1,250,000
01 Jan 2021ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules.ESAEPDGDPR€5,000
04 Jan 2021MACASVER S.L.MACASVER S.L. was fined €8,000 by the AEPD for incorrectly identifying the driver of a vehicle involved in a traffic violation. The authority found a breach of the GDPR data accuracy principle.ESAEPDGDPR€8,000
04 Jan 2021Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing.NODatatilsynetGDPR€95,750
05 Jan 2021Dane anonimowe (M. Sp. z o.o. z siedzibą w Z. przy)The President of UODO imposed an administrative fine of PLN 21,397 on M. Sp. z o.o. The company failed to cooperate with the authority and did not provide information needed to assess a complaint concerning personal data processing.PLUODOGDPR€4,705
05 Jan 2021Dane anonimowe (Panią M. Z. prowadzącą działalność gospodarczą pod firmą K.)The President of UODO imposed a fine of PLN 85,588 on an individual conducting business under the name K. The authority found that an order contained in an administrative decision on personal data protection had not been complied with.PLUODOGDPR€18,822
05 Jan 2021DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach.PLUODOGDPR€5,498
08 Jan 2021C.C.C.C.C.C. was fined EUR 2,000 by the AEPD. The authority found that the company failed to provide a written contract and did not inform the complainant about the processing of personal data, in breach of Article 13 GDPR.ESAEPDGDPR€2,000
11 Jan 2021RIPOBRUNA 2007, S.L.RIPOBRUNA 2007, S.L. was fined by the AEPD 2,000 EUR for installing surveillance cameras directed toward public spaces without justified cause. The authority found this processing to be contrary to data protection principles.ESAEPDGDPR€2,000
11 Jan 2021Dane anonimowe (M. S.A. z siedzibą w Z. przy ul.)The President of UODO imposed an administrative fine of PLN 136,437 on M. S.A. The penalty was issued because the company did not report a personal data breach to the supervisory authority without undue delay.PLUODOGDPR€30,123
12 Jan 2021ASOCIACIÓN CULTURAL ***ASOCIACIÓN.1The association was fined for sharing images of a minor in WeChat groups without parental consent. The authority found a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
14 Jan 2021Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32.ITGaranteGDPR€8,000
14 Jan 2021Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles.NODatatilsynetGDPR€38,796
14 Jan 2021IDFINANCE SPAIN, S.L.IDFINANCE SPAIN, S.L. was fined by the AEPD EUR 5,000 after an incident in which a user could access another customer's personal data and loan information through a faulty email link. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€5,000