Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 May 2021Anonymisé (CNPD decision-17-fr-2021)The CNPD found that the company breached GDPR principles by failing to comply with data minimization and retention limits in its video surveillance practices. A fine of EUR 1,900 was imposed.LUCNPDGDPR€1,900
12 May 2021Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved.NLAPGDPR€525,000
12 May 2021xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure.HRAZOPGDPR€30,553
12 May 2021E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use.ESAEPDGDPR€3,100,000
12 May 2021Anonymisé (CNPD decision-14-fr-2021)The company was fined by the CNPD in the amount of 2,600 EUR for breaching GDPR requirements on data minimization, data retention, and information obligations. The case concerned non-compliant personal data processing and a failure to provide the required information to data subjects.LUCNPDGDPR€2,600
12 May 2021KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued.GRHDPAGDPR€5,000
12 May 2021Anonymisé (CNPD decision-16-fr-2021)The company was fined for failing to comply with the data minimization principle and for not providing adequate information to data subjects under GDPR Articles 5(1)(c) and 13. The CNPD decision indicates deficiencies in the company’s processing practices and privacy disclosures.LUCNPDGDPR€1,000
12 May 2021Anonymisé (CNPD decision-15-fr-2021)The CNPD imposed a EUR 2,900 fine for breaching the data minimization principle in connection with video surveillance. The camera’s field of view covered areas that were not necessary for the processing purpose, contrary to Article 5(1)(c) GDPR.LUCNPDGDPR€2,900
13 May 2021Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles.ITGaranteGDPR€84,000
13 May 2021Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€2,000
13 May 2021Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data.ITGaranteGDPR€100,000
13 May 2021Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity.ITGaranteGDPR€20,000
13 May 2021ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection.ITGaranteGDPR€20,000
13 May 2021Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register.ITGaranteGDPR€2,856,000
13 May 2021Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects.ITGaranteGDPR€80,000
14 May 2021persoană fizicăA natural person was fined EUR 200 by ANSPDCP for violating GDPR requirements. The case concerned breaches related to the processing of personal data.ROANSPDCPGDPR€200
14 May 2021SIA "SS"DVI imposed a fine of EUR 100,000 on SIA "SS". According to the record, the sanction was later annulled.LVDVIGDPR€100,000
17 May 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules.ESAEPDGDPR€5,000
17 May 2021Vodafone Servicios, S.L.U.The AEPD fined Vodafone Servicios, S.L.U. 50,000 EUR for processing personal data without proper consent. The breach led to unauthorized charges on a customer's bank account.ESAEPDGDPR€50,000
17 May 2021VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 80,000 EUR for processing personal data without proper consent. The case involved linking phone lines to incorrect data and enrolling a customer in services without authorization.ESAEPDGDPR€80,000