Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2021LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD €1,000 for sending commercial emails to an individual whose email address was included in the Robinson List. The conduct breached Spanish data protection rules governing unsolicited marketing communications.ESAEPDePrivacy€1,000
29 Apr 2021Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements.ITGaranteGDPR€45,000
29 Apr 2021Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period.ITGaranteGDPR€4,000
29 Apr 2021Comune di Santa NinfaComune di Santa Ninfa was fined by the Garante 2,000 EUR for publishing a complainant’s personal data online. The publication also included detailed references to enforcement proceedings, which breached GDPR requirements.ITGaranteGDPR€2,000
29 Apr 2021Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards.ITGaranteGDPR€6,000
29 Apr 2021CRIQUET PUBLICIDAD, S.L.CRIQUET PUBLICIDAD, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The recipient’s address was registered on the Robinson List, which constitutes a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
29 Apr 2021Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6.NLAPGDPR€600,000
29 Apr 2021FederpolFederpol was fined 5,000 EUR by the Garante for improperly sharing members’ personal information with other associates. The authority found that this breached data protection rules and required a valid legal basis and appropriate safeguards.ITGaranteGDPR€5,000
04 May 2021CLUB GIMNASIA RÍTMICA SAN ANTONIOThe club was fined by the AEPD for publishing images of minors on social media without proper consent. The authority found a breach of GDPR Article 6 on lawful processing.ESAEPDGDPR€5,000
05 May 2021Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data.NODatatilsynetGDPR€2,503,000
05 May 2021Munkavállalói e-mail fiókok és munkaeszközök használatával és azok ellenőrzésével összefüggő adatkezelésThe controller did not provide the data subject with adequate prior information about the processing of work email and computer usage. The authority found this to breach the principles of fairness and accountability in data processing.HUNAIHGDPR€5,560
05 May 2021Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification.HUNAIHGDPR€5,560
06 May 2021Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA.NODatatilsynetGDPR€497,000
06 May 2021YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions.BEAPDGDPR€50,000
07 May 2021B.B.B.The entity was fined for improperly directing surveillance cameras toward public transit areas and the complainant's home entrance. This conduct breached data protection rules.ESAEPDGDPR€1,500
10 May 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for processing personal data without proper consent, in breach of Article 6(1) GDPR. The penalty was set at EUR 70,000, with reductions available for early payment and acknowledgment of responsibility.ESAEPDGDPR€70,000
11 May 2021Érintetti jog és tájékoztatási kötelezettség megsértéseThe case concerned unlawful processing of personal data in connection with debt collection. The entity failed to respond to data subject requests and unlawfully transferred personal data.HUNAIHGDPR€1,395
11 May 2021Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident.NLAPGDPR€7,500
11 May 2021Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days.NODatatilsynetGDPR€124,000
12 May 2021A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications.GRHDPAGDPR€5,000