Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Jan 2021Poliambulatorio Talenti S.r.l.Poliambulatorio Talenti S.r.l. was fined €2,000 by the Italian supervisory authority, Garante. The case concerned the improper handling of a data access request, which constitutes a breach of GDPR Article 5.ITGaranteGDPR€2,000
14 Jan 2021Azienda Ospedaliera San Pio di BeneventoAzienda Ospedaliera San Pio di Benevento was fined by the Garante 10,000 EUR for publishing employees’ personal data on its intranet without a proper legal basis. The case concerned unauthorized disclosure of personal data within the organization’s internal environment.ITGaranteGDPR€10,000
14 Jan 2021SIA "Lursoft IT"A fine of EUR 65,000 was imposed. The decision is final and has entered into force.LVDVIGDPR€65,000
14 Jan 2021Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
14 Jan 2021Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements.ITGaranteGDPR€18,000
14 Jan 2021Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined by the Garante €30,000 for unlawfully processing employees’ biometric data to monitor attendance. The conduct breached GDPR requirements on lawful processing and data minimisation.ITGaranteGDPR€30,000
14 Jan 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 200,000 for continuing to send emails to a complainant despite earlier sanctions for similar conduct. The authority treated this as a recurring breach of GDPR Article 6.1, indicating processing without a valid legal basis.ESAEPDGDPR€200,000
15 Jan 2021VODAFONE ESPAÑA, S.A.U.The Spanish data protection authority imposed a total fine of EUR 8,150,000 on VODAFONE ESPAÑA, S.A.U. The sanction covers breaches of GDPR Articles 28 and 44, as well as additional violations of LSSICE and tax-related rules.ESAgencia Española de Protección de DatosGDPR€8,150,000
18 Jan 2021INDUSTRIAS METÁLICAS ANRO, S.L.INDUSTRIAS METÁLICAS ANRO, S.L. was fined by the AEPD for failing to comply with cookie policy requirements on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
18 Jan 2021MEJORFRESCO TIENDA ONLINE, S.L.MEJORFRESCO TIENDA ONLINE, S.L. was fined by the AEPD EUR 2,000 for sending advertising emails without the recipient's consent. The case concerned Article 21 of the LSSI and reflects unlawful direct marketing practices.ESAEPDePrivacy€2,000
19 Jan 2021EQUIFAX IBERICA, S.L.EQUIFAX IBERICA, S.L. was fined by the AEPD 50,000 EUR for including personal data in a credit file without a valid debt and without proper notice. The authority found this breached data processing principles.ESAEPDGDPR€50,000
20 Jan 2021XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 40,000 by the AEPD for failing to respond to a data access request. The case concerns non-compliance with GDPR obligations relating to data subject rights.ESAEPDGDPR€40,000
20 Jan 2021BICLAMEDIA, S.L.BICLAMEDIA, S.L. was fined 1,500 EUR by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€1,500
25 Jan 2021PATIO ANCESTRAL, S.L.PATIO ANCESTRAL, S.L. was fined by the AEPD in the amount of EUR 5,000 for sending a letter containing personal data to the complainant's workplace. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
26 Jan 2021Grindr LLCThe Norwegian DPA intends to fine Grindr 100 million NOK for sharing user data with third parties without valid consent. The conduct was assessed as a breach of GDPR consent requirements.NODatatilsynetGDPR€9,627,000
26 Jan 2021VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 100,000 EUR for unlawfully registering a prepaid phone line under the complainant’s ID and accessing credit information without a legitimate interest. The company also failed to properly comply with requests for access to and deletion of personal data.ESAEPDGDPR€100,000
27 Jan 2021Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting.ITGaranteGDPR€10,000
27 Jan 2021Azienda ospedaliera regionale “San Carlo” di PotenzaAzienda ospedaliera regionale “San Carlo” di Potenza was fined EUR 70,000 by the Garante for violations related to the processing of personal data. The case concerned the handling of sensitive health data.ITGaranteGDPR€70,000
27 Jan 2021Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance.ITGaranteGDPR€10,000
27 Jan 2021Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty.ITGaranteGDPR€10,000