Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jan 2021Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles.ITGaranteGDPR€4,000
27 Jan 2021Comune di Cesano BosconeThe Municipality of Cesano Boscone was fined EUR 2,000 by the Garante for publishing personal data related to a disciplinary sanction on its website. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
27 Jan 2021Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
27 Jan 2021Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules.ITGaranteGDPR€20,000
27 Jan 2021Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€50,000
27 Jan 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 100,000 EUR for making a commercial call to a number registered on the Robinson list. The authority found that this breached data protection and direct marketing opt-out requirements.ESAEPDGDPR€100,000
27 Jan 2021STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards.ESAEPDGDPR€4,000
27 Jan 2021De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations.BEAPDGDPR€50,000
28 Jan 2021TRES-F-NETWORK, S.A.UTRES-F-NETWORK, S.A.U was fined by the AEPD 4,000 EUR for sending commercial SMS messages without the recipient's consent and without an existing commercial relationship. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€4,000
30 Jan 2021DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements.ESAEPDePrivacy€3,000
03 Feb 2021Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion.NODatatilsynetGDPR€19,316
03 Feb 2021ASESORÍA MUNIZ SOLÁN, S.L.ASESORÍA MUNIZ SOLÁN, S.L. was fined by the AEPD 2,000 EUR for breaching confidentiality after sending a debt certificate relating to a third party instead of the correct document. The authority also noted inadequate security measures under GDPR Article 32.ESAEPDGDPR€2,000
03 Feb 2021NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD 40,000 EUR for processing personal data without a legal basis. The case was linked to a denied financial operation following an identity theft incident.ESAEPDGDPR€40,000
03 Feb 2021MERCADONA S.A.MERCADONA S.A. was fined EUR 170,000 by the AEPD for failing to respond to a data access request within the required timeframe and for deleting security camera footage. The authority found that these actions breached GDPR obligations, including Articles 12 and 6.ESAEPDGDPR€170,000
05 Feb 2021NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€1,000
10 Feb 2021Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act.SEIMYePrivacy€248,000
10 Feb 2021CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules.ESAEPDGDPR€2,000
11 Feb 2021Istituto Superiore Statale "Pitagora"Istituto Superiore Statale "Pitagora" was fined by the Garante 5,000 EUR for unlawful processing of personal data. The authority found failures to ensure data minimization and transparency toward data subjects.ITGaranteGDPR€5,000
11 Feb 2021Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR.NLAPGDPR€440,000
11 Feb 2021Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data.ITGaranteGDPR€45,000