Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Apr 2021Clear Channel Italia S.p.A.Clear Channel Italia S.p.A. was fined by the Garante EUR 75,000 for conducting intrusive checks on employees’ devices without a proper legal basis. The authority found breaches of data minimization and proportionality principles.ITGaranteGDPR€75,000
15 Apr 2021INPSThe Italian Data Protection Authority fined INPS €12,000 for failing to provide a data subject with access to their personal data and for unlawfully communicating personal data to third parties. The authority found breaches of lawfulness, fairness, and transparency.ITGaranteGDPR€12,000
15 Apr 2021HAZTEOIR.ORGThe association HazteOir.Org was fined EUR 5,000 by the AEPD for including images and names of individuals in a pamphlet without their consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
15 Apr 2021Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly.ITGaranteGDPR€5,000
15 Apr 2021Società triveneta di chirurgiaSocietà triveneta di chirurgia was fined EUR 2,000 by the Garante for processing personal data without meeting the requirements of lawfulness, fairness, and transparency. The authority also found a breach of the data minimization principle.ITGaranteGDPR€2,000
15 Apr 2021Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
15 Apr 2021Tiberia Assicurazioni s.a.s.Tiberia Assicurazioni s.a.s. was fined by the Garante 1,500 EUR for sending an insurance contract proposal by email without the recipient's consent. The authority found this to be a breach of GDPR Article 6.ITGaranteGDPR€1,500
15 Apr 2021Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules.ITGaranteGDPR€2,000
16 Apr 2021CREATOR ENERGY, S.L.CREATOR ENERGY, S.L. was fined by the AEPD 6,000 EUR for using personal data without consent to contract gas, electricity, and maintenance services. The authority found this conduct breached Article 6(1)(b) GDPR.ESAEPDGDPR€6,000
19 Apr 2021BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection.HUNAIHGDPR€13,900
19 Apr 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD. The authority found that the company failed to comply with a data subject's right to erasure and sent commercial communications without the recipient's explicit consent.ESAEPDePrivacy€15,000
20 Apr 2021RIUSA II, S.ARIUSA II, S.A was fined by the AEPD 5,000 EUR for not providing users with the option to reject or configure cookies on its website. The authority treated this as a breach of data protection rules.ESAEPDePrivacy€5,000
20 Apr 2021Elszámoltathatóság elvének megsértéseThe entity was fined by the NAIH for breaching the accountability principle and failing to implement appropriate technical and organizational measures to ensure GDPR compliance. The violations concerned data processing activities related to its websites.HUNAIHGDPR€2,770
20 Apr 2021EB CREATIVE LABEB CREATIVE LAB was fined by the AEPD EUR 5,000 for failing to provide information or obtain consent for cookies on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
20 Apr 2021B.B.B.The entity was fined for not providing an adequate privacy policy on its website. This constituted a breach of Article 13 of the GDPR, which requires proper information to be provided to data subjects.ESAEPDGDPR€2,000
21 Apr 2021Fondazione Policlinico Tor Vergata di RomaFondazione Policlinico Tor Vergata di Roma was fined by the Garante 15,000 EUR for breaches of data processing principles. The case concerned compliance with lawfulness, fairness, transparency, and security measures.ITGaranteGDPR€15,000
21 Apr 2021Ministero dell’Istruzione, dell’Università e della Ricerca, Ufficio Scolastico Regionale per la Toscana, Ufficio VIII Ambito territoriale della provincia di LivornoThe Italian Ministry of Education was fined 3,000 EUR by the Garante. The case concerned personal data of teachers remaining accessible online in breach of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
21 Apr 2021Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5.ITGaranteGDPR€20,000
21 Apr 2021Azienda provinciale per i servizi sanitari di TrentoAzienda provinciale per i servizi sanitari di Trento was fined by the Garante EUR 40,000 for violations related to the processing of health data. The authority found omissions in implementing technical and organizational measures for access to the health dossier.ITGaranteGDPR€40,000
21 Apr 2021Società Eurosanità s.p.a.Società Eurosanità s.p.a. was fined by the Garante in the amount of 5,000 EUR for a breach involving the processing of health data. The authority found violations of GDPR Articles 5 and 9, indicating improper handling of special category personal data.ITGaranteGDPR€5,000