Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Mar 2021ABANCA CORPORACIÓN BANCARIA, S.A.ABANCA CORPORACIÓN BANCARIA, S.A. was fined EUR 5,000 by the AEPD for using cookies on its website without providing the required information to users or obtaining their consent. The case concerns failures to meet legal notice and consent requirements.ESAEPDePrivacy€5,000
23 Mar 2021Irish Credit Bureau DACThe Irish Data Protection Commission (DPC) fined Irish Credit Bureau DAC EUR 90,000 in inquiry IN-19-7-2. The fine has been collected.IEDPCGDPR€90,000
24 Mar 2021ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A. was fined EUR 30,000 by the AEPD. The authority found that after a policy was canceled, the company continued processing personal data without a lawful basis, in breach of Article 6 GDPR.ESAEPDGDPR€30,000
24 Mar 2021IBERDROLA CLIENTES, SAUIberdrola Clientes, SAU was fined EUR 70,000 by the AEPD for changing the contracted power in a supply agreement without the consent of the contract holder. The authority found that this conduct breached data protection rules.ESAEPDGDPR€70,000
24 Mar 2021Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards.NODatatilsynetGDPR€4,923
24 Mar 2021Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals.HUNAIHGDPR€27,400
25 Mar 2021Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules.ITGaranteGDPR€50,000
25 Mar 2021Comune di MonteiasiComune di Monteiasi was fined by the Garante €4,000 for breaching the data minimization principle. The municipality published personal data on its website, including names and IBANs, that were not necessary for transparency purposes.ITGaranteGDPR€4,000
25 Mar 2021Kamerák üzemeltetése idősek otthonábanThe authority imposed a fine for using video surveillance for unlawful purposes. It also found that the data subjects were not adequately informed and that there was no proper legal basis for processing.HUNAIHGDPR€1,370
25 Mar 2021Dragefossen ASDragefossen AS was fined 150,000 NOK by Datatilsynet for unlawfully live streaming surveillance footage from a camera in Rognan sentrum on the internet. The authority found no legal basis for the processing, which breached GDPR Articles 6 and 5.NODatatilsynetGDPR€14,756
25 Mar 2021Fastweb S.p.A.Fastweb S.p.A. was sanctioned by the Garante for making unauthorized promotional calls and sending messages without proper consent. The authority also found insufficient measures to ensure data processing security and GDPR compliance.ITGaranteGDPR€4,501,000
25 Mar 2021Unione dei Comuni Valli del Reno, Lavino e SamoggiaUnione dei Comuni Valli del Reno, Lavino e Samoggia was fined by the Garante EUR 13,000 for improperly publishing personal data on the web. The authority found a breach of GDPR principles on lawfulness and data processing.ITGaranteGDPR€13,000
25 Mar 2021TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data.ITGaranteGDPR€7,000
25 Mar 2021OneDirect S.r.l.OneDirect S.r.l. was fined EUR 30,000 by the Garante. The authority found that the company sent unsolicited promotional emails despite objections and failed to respond to data subject requests.ITGaranteGDPR€30,000
25 Mar 2021Convitto Nazionale Statale "Giordano Bruno"Convitto Nazionale Statale "Giordano Bruno" was fined by the Garante for breaching data protection principles. The authority found that personal data had been made available online for an extended period, contrary to the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€1,000
25 Mar 2021Comune di CastellanzaComune di Castellanza was fined by the Garante EUR 4,000 for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. Personal data remained accessible online for an extended period.ITGaranteGDPR€4,000
25 Mar 2021GEDI News Network S.p.a.GEDI News Network S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned failure to comply with a request to delete personal data from an article about a 1998 legal case, which remained prejudicial because the outcome was not updated.ITGaranteGDPR€20,000
26 Mar 2021CAIXABANK S.A.CAIXABANK S.A. was fined EUR 60,000 by the AEPD for processing personal data without consent. The case concerned a current account contract signed on behalf of the complainant without proper authorization.ESAEPDGDPR€60,000
30 Mar 2021TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for using a customer's phone number without consent. This led to numerous unsolicited calls, despite prior claims that security measures had been implemented.ESAEPDGDPR€75,000
30 Mar 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for failing to delete personal data after phone contracts ended. This led to continued SMS notifications with zero-balance invoices being sent to former customers.ESAEPDGDPR€150,000