Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jun 2021FLY FUT, S.L.FLY FUT, S.L. was fined by the AEPD in the amount of 3,000 EUR for recording a minor during football matches without prior consent. The case concerns a breach of data protection rules and the requirement to obtain consent before processing a child’s image.ESAEPDGDPR€3,000
07 Jun 2021Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000.SEIMYGDPR€64,643
07 Jun 2021CLUB NÁUTICO EL ESTACIOThe entity published personal data on its website without access restrictions. This breached confidentiality and data security principles.ESAEPDGDPR€3,000
07 Jun 2021EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. was fined EUR 1,000 by the AEPD for improperly sharing an employee’s personal data with the company committee. The authority found a breach of data protection rules.ESAEPDGDPR€1,000
07 Jun 2021Regionstyrelsen Region VärmlandRegionstyrelsen Region Värmland was fined by IMY 250,000 SEK for failing to inform patients calling the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found this to be a breach of GDPR transparency requirements.SEIMYGDPR€24,863
07 Jun 2021Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations.SEIMYGDPR€49,725
07 Jun 2021MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing.SEIMYGDPR€1,193,000
07 Jun 2021Regionstyrelsen Region SörmlandRegionstyrelsen Region Sörmland was fined by IMY 250,000 SEK for failing to inform callers to the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found a breach of GDPR transparency requirements.SEIMYGDPR€24,863
08 Jun 2021BAR DA VINCI (SHUANGFENG ZHOU)BAR DA VINCI (SHUANGFENG ZHOU) was fined 500 EUR by the AEPD for operating a surveillance system without proper signage. The authority also found that the system captured excessive footage of public areas, constituting a GDPR breach.ESAEPDGDPR€500
08 Jun 2021DKN.5131.10.2020StatusnieprawomocnaTytuThe President of UODO imposed a fine of PLN 100,000 for failing to notify data breaches within the required deadline. The case concerns the obligation to report personal data breaches to the supervisory authority on time.PLUODOGDPR€22,372
08 Jun 2021IMAGINA FRAN SPORT, S.L.IMAGINA FRAN SPORT, S.L. was fined 2,000 EUR by the AEPD for not having an updated privacy policy on its website. The authority found a breach of the information obligations under GDPR Article 13.ESAEPDGDPR€2,000
09 Jun 2021Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures.SEIMYGDPR€34,794
09 Jun 2021S.C.The operator was fined by ANSPDCP for failing to provide requested information to the supervisory authority. This constituted a breach of GDPR requirements.ROANSPDCPGDPR€2,000
09 Jun 2021INMOPISO ZARAGOZA, S.L.INMOPISO ZARAGOZA, S.L. was fined EUR 2,000 by the AEPD for failing to provide data protection information to a customer who made a deposit for a property purchase. The case concerns a breach of the transparency and information duty owed to the data subject.ESAEPDGDPR€2,000
10 Jun 2021MARIA & DESPOINA KOUSATHANA O.E.The company was fined by the HDPA 5,000 EUR for operating a video surveillance system without proper notification and for unlawful camera use in kitchen areas. The authority also found that data subjects were not informed about the processing of their personal data.GRHDPAGDPR€5,000
10 Jun 2021dott. MariniThe Garante imposed a EUR 20,000 fine on dott. Marini for unlawfully collecting information about patients' HIV status. The authority found a breach of the principles of necessity and proportionality in personal data processing.ITGaranteGDPR€20,000
10 Jun 2021orthodontiepraktijkThe entity failed to implement appropriate technical and organizational measures to secure personal data, which constitutes a breach of Article 32 GDPR. Sensitive data on the website was not transmitted over encrypted connections, increasing the risk of disclosure.NLAPGDPR€12,000
10 Jun 2021Ministero dell’InternoThe Italian Data Protection Authority fined Ministero dell’Interno EUR 75,000 for posting videos on social media that breached data protection rules. The footage related to a criminal case was shared by the police and contained violent content, which was found inconsistent with data protection principles.ITGaranteGDPR€75,000
10 Jun 2021aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data.ITGaranteGDPR€20,000
10 Jun 2021Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention.ITGaranteGDPR€2,600,000