Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 May 2021TELEFÓNICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD for using personal data to contract a service without the data subject’s consent and for listing the complainant in credit information files for a debt that was not recognized. The case concerns processing without a valid legal basis and improper reporting of alleged debt.ESAEPDGDPR€75,000
19 May 2021CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing.NLAPGDPR€15,000
19 May 2021Asociație de Proprietari din municipiul IașiThe association was fined EUR 500 by ANSPDCP for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR.ROANSPDCPGDPR€500
19 May 2021TNT EXPRESS WORLDWIDE SPAIN, S.L.TNT Express Worldwide Spain, S.L. was fined by the AEPD €10,000 for incorrectly linking a personal delivery service to a corporate account. This resulted in the unauthorized sharing of personal data with the complainant’s employer.ESAEPDGDPR€10,000
20 May 2021B.B.B.The entity did not provide the complainant with information about data processing or the ability to exercise rights after receiving a CV via WhatsApp in response to a job offer. AEPD imposed a fine of EUR 2,000 for breaching transparency obligations.ESAEPDGDPR€2,000
21 May 2021COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€2,000
26 May 2021VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending SMS messages about an alleged debt for services not contracted by the complainant. The case involved incorrect processing of personal data and the use of inaccurate contact details.ESAEPDGDPR€50,000
27 May 2021Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches.ITGaranteGDPR€120,000
27 May 2021Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante 10,000 EUR for unlawfully communicating a customer's financial data related to a Postepay card to an unauthorized third party. The case concerns a breach of personal data protection and financial confidentiality requirements.ITGaranteGDPR€10,000
27 May 2021Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9.ITGaranteGDPR€10,000
27 May 2021Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules.ITGaranteGDPR€4,000
27 May 2021Tempocasa S.p.A.Tempocasa S.p.A. was fined €120,000 by the Italian Garante. The authority found that the company made unsolicited promotional calls without the required consent, breaching GDPR rules on data processing and consent.ITGaranteGDPR€120,000
27 May 2021Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information.ITGaranteGDPR€200,000
31 May 2021AUTOMECANICA JÉREZ, S.L.AUTOMECANICA JÉREZ, S.L. was fined EUR 4,000 by the AEPD. The authority found that the company sent a mass email without masking personal data and sent commercial emails and SMS messages without consent.ESAEPDePrivacy€4,000
31 May 2021Anonymizováno (ÚOOÚ UOOU-03580/20-23)The entity was fined for continuing to process personal data for marketing purposes despite the data subject's objection and request for erasure. The authority found this to be a breach of GDPR Article 21.CZUOOUGDPR€79
01 Jun 2021RADIO POPULAR S.A.RADIO POPULAR S.A. was fined EUR 2,000 by the AEPD for not providing users with the option to reject cookies on its website. The authority found this practice non-compliant with data protection rules and consent requirements.ESAEPDePrivacy€2,000
02 Jun 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for improper handling of personal data. A complaint revealed discrepancies in the data linked to a customer's identity, and the penalty was reduced due to early payment.ESAEPDGDPR€50,000
02 Jun 2021TENTEA ENERGY, S.L.TENTEA ENERGY, S.L. was fined by the AEPD EUR 5,000 for using personal data and a signature without consent in connection with energy service contracts. The authority also found a refusal to provide access to personal data in relation to a cancellation request.ESAEPDGDPR€5,000
04 Jun 2021FINCAS MIGUEL GARCÍA, S.LFINCAS MIGUEL GARCÍA, S.L was fined 2,000 EUR by the AEPD for failing to provide the complainant with its privacy policy before collecting personal data. The authority found this to be a breach of the information duty under Article 13 GDPR.ESAEPDGDPR€2,000
04 Jun 2021INTERSUMI S.C.INTERSUMI S.C. was fined EUR 2,000 by the AEPD for not having an adequate privacy policy on its website. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€2,000