Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Apr 2021ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights.FITSVGDPR€70,000
22 Apr 2021DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider.PLUODOGDPR€249,000
22 Apr 2021Magyar ÁllamkincstárThe Hungarian National Authority for Data Protection and Freedom of Information (NAIH) fined Magyar Államkincstár HUF 1,000,000. The authority found a breach of GDPR lawfulness and data minimization principles because personal data were transferred without a proper legal basis.HUNAIHGDPR€2,750
23 Apr 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without proper consent. The case involved a call to a customer about a service package that the customer had not authorized.ESAEPDGDPR€70,000
23 Apr 2021Vodafone España, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 70,000 for failing to adequately prevent identity theft. As a result, unauthorized phone line contracts were entered into using a customer's personal data.ESAEPDGDPR€70,000
23 Apr 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's mobile line ownership without consent. The company also charged the customer's account amounts related to a third party's phone line.ESAEPDGDPR€50,000
23 Apr 2021FRIGORIFICA BOTANA, S.L.FRIGORIFICA BOTANA, S.L. was fined by the AEPD EUR 4,000 for disproportionate audio/video recording in a meeting room without a justified cause or proper notice. The authority found this breached data protection principles.ESAEPDGDPR€4,000
23 Apr 2021VODAFONE SERVICIOS, S.L.U.Vodafone Servicios, S.L.U. was fined by the AEPD 50,000 EUR for failing to verify a customer's identity. The lapse enabled identity fraud and the unauthorized creation of an account.ESAEPDGDPR€50,000
23 Apr 2021B.B.B.The entity was fined for operating a video surveillance system at the workplace without informing employees through the required informational signage. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€1,000
23 Apr 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD EUR 70,000 for allowing unauthorized access to a customer's personal data. The data was then used to fraudulently contract mobile lines without the customer's consent.ESAEPDGDPR€70,000
23 Apr 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's tariff without consent. The case involved identity impersonation and improper processing of personal data under the GDPR.ESAEPDGDPR€50,000
23 Apr 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 70,000 by the AEPD after a third party gained unauthorized access to a customer account. The incident led to changes in personal data and services without the customer’s consent.ESAEPDGDPR€70,000
27 Apr 2021Diszpécseri munkakört betöltő munkavállalóval folytatott telefonhívás rögzítéseThe decision concerned the unlawful recording and use of phone calls without a proper legal basis and without adequate transparency. The authority found breaches of GDPR accountability, lawful processing, and transparency principles.HUNAIHGDPR€1,380
27 Apr 2021Dane anonimowe (K. Spółkę Akcyjną z siedzibą w N. przy ul.)The President of UODO imposed an administrative fine of PLN 22,739 on the company. The sanction resulted from failure to cooperate with the supervisory authority and from not providing information necessary to resolve the case.PLUODOGDPR€4,982
27 Apr 2021XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 3,000 for sending commercial emails without the recipient’s consent. The authority found a breach of Article 21 of the LSSI, despite the recipient’s attempts to unsubscribe.ESAEPDePrivacy€3,000
27 Apr 2021B.B.B.B.B.B. was fined 500 EUR by the AEPD for installing a surveillance camera. The camera captured common areas and a neighbor's parking space, which breached data protection rules.ESAEPDGDPR€500
29 Apr 2021Comune di PutifigariComune di Putifigari was fined EUR 3,000 by the Garante for publishing special-category personal data online. The disclosed information could reveal individuals' health status, which breached GDPR requirements on data protection and privacy.ITGaranteGDPR€3,000
29 Apr 2021Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data.ITGaranteGDPR€30,000
29 Apr 2021Azienda Ospedaliero Universitaria PisanaAzienda Ospedaliero Universitaria Pisana was fined by the Garante EUR 4,000 for breaches of the principles of lawfulness, fairness, transparency, integrity, and confidentiality in data processing. The case concerned improper handling of personal data under GDPR requirements.ITGaranteGDPR€4,000
29 Apr 2021Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations.ITGaranteGDPR€5,000