Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Mar 2021Mediacom s.r.l.Mediacom s.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The authority found that this conduct breached GDPR rules on the processing of personal data for marketing purposes.ITGaranteGDPR€15,000
11 Mar 2021Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data.ITGaranteGDPR€10,000
11 Mar 2021COMUNIDAD DE PROPIETARIOS B.B.B.COMUNIDAD DE PROPIETARIOS B.B.B. was fined by the AEPD in the amount of 2,000 EUR for irregularities in its video surveillance system. The authority found that the cameras captured public spaces, which breached the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€2,000
11 Mar 2021Azienda Ospedaliera San Giovanni AddolorataAzienda Ospedaliera San Giovanni Addolorata was fined EUR 20,000 by the Garante for inadequate data protection measures concerning patient health data. The authority found breaches of GDPR Articles 5 and 32.ITGaranteGDPR€20,000
11 Mar 2021Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing.ITGaranteGDPR€5,000
11 Mar 2021Planet Group spaPlanet Group spa was fined EUR 80,000 by the Garante. The authority found that the company made unsolicited promotional calls without a proper legal basis, breaching GDPR rules on data processing and privacy by design.ITGaranteGDPR€80,000
11 Mar 2021dott. Gregorio GrecoDott. Gregorio Greco was fined 6,400 EUR by the Garante for failing to provide information to data subjects and for processing patients' health-related personal data without consent. The case concerns patient data and breaches of transparency and lawful basis requirements.ITGaranteGDPR€6,400
12 Mar 2021PRODUCCIONES ROCKNROCK, S.L.PRODUCCIONES ROCKNROCK, S.L. was fined EUR 2,000 by the AEPD for failing to provide information or obtain consent for cookies on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
15 Mar 2021Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached.BEAPDGDPR€2,000
16 Mar 2021SIA "“fit People”A fine of EUR 5,836 was imposed. The decision has entered into force.LVDVIGDPR€5,836
17 Mar 2021BODY TONIC SHOP, S.L.BODY TONIC SHOP, S.L. was fined by the AEPD EUR 2,000 for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
17 Mar 2021VASCO ANDALUZA DE INVERSIONES, S.L.VASCO ANDALUZA DE INVERSIONES, S.L. was fined by the AEPD 2,000 EUR for unlawfully sharing personal data with third parties without informing the data subject. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
17 Mar 2021GERCO FIT, S.L.GERCO FIT, S.L. was fined by the AEPD in the amount of 2,000 EUR for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
17 Mar 2021SOLRAM T Y R S.L.SOLRAM T Y R S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to delete personal data from its databases. The authority found a breach of Article 17 GDPR after the company continued sending unsolicited commercial messages via WhatsApp.ESAEPDGDPR€3,000
18 Mar 2021Vodafone España, S.A.U.The AEPD imposed a 50,000 EUR fine on Vodafone España, S.A.U. for unauthorized processing of personal data. The case involved fraudulent contracting of mobile services in the complainant's name.ESAEPDGDPR€50,000
19 Mar 2021Dane anonimowe (T. Spółka z o.o.)The President of UODO imposed an administrative fine of PLN 22,739.5 on T. Sp. z o.o. The sanction was issued for failing to cooperate with the supervisory authority and for not providing information necessary to examine a complaint.PLUODOGDPR€4,922
22 Mar 2021Tájékoztatási kötelezettség elmulasztása, hozzáférési jog és adatkezelés korlátozásához való jogThe controller did not inform the data subject within the required timeframe about actions taken on their requests. It also delayed access to the requested footage and failed to block the camera recording, resulting in a data protection fine.HUNAIHGDPR€1,365
22 Mar 2021Engedményezés utáni követeléskezeléssel kapcsolatos adatkezelés jogalapja, érintetti kérelem teljesítéseThe supervisory authority found a GDPR breach in the processing of personal data for debt collection after assignment of a claim. The controller did not establish a proper legal basis, failed to provide clear information about that basis, and did not properly handle data subject requests.HUNAIHGDPR€13,650
23 Mar 2021Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules.CZUOOUePrivacy€382
23 Mar 2021KUTXABANK, S.A.KUTXABANK, S.A. was fined EUR 100,000 by the AEPD for failing to properly handle a data deletion request. The issue affected the complainant’s ability to open a new account.ESAEPDGDPR€100,000