Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Jul 2021Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis.DKDatatilsynetGDPR€13,448
07 Jul 2021Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers.NLAPGDPR€450,000
07 Jul 2021Anonymizováno (ÚOOÚ UOOU-04873/20-24)The entity was fined for unlawfully publishing personal data on YouTube. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency.CZUOOUGDPR€117
08 Jul 2021Consiglio Regionale della Valle d’AostaConsiglio Regionale della Valle d’Aosta was fined EUR 1,000 by the Garante for failing to remove personal data from its website after a request. The authority found this to be a breach of data protection rights.ITGaranteGDPR€1,000
08 Jul 2021Azienda ospedaliero-universitaria SeneseAzienda ospedaliero-universitaria Senese was fined by the Garante 25,000 EUR for violations related to data breaches involving health data and patient information. The case concerned the handling of sensitive data and required assessment of compliance with data protection obligations.ITGaranteGDPR€25,000
08 Jul 2021Regione PugliaThe Garante fined Regione Puglia EUR 30,000 for the unlawful dissemination of personal health data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€30,000
09 Jul 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for failing to implement adequate security measures. The deficiency led to unauthorized bank transfers from a customer's account after a SIM card incident.ESAEPDGDPR€50,000
09 Jul 2021Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls.DKDatatilsynetGDPR€53,788
12 Jul 2021A.A.A.The entity was fined for processing personal data through a video surveillance system without appropriate security measures and without the required informational signage. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,000
12 Jul 2021B.B.B.B.B.B. was fined by the AEPD EUR 1,200 for operating a video surveillance system without proper signage. The case involved a breach of GDPR Article 13, and a new camera was installed despite prior warnings without correcting the deficiencies.ESAEPDGDPR€1,200
13 Jul 2021Dane anonimowe (Prezesa Sądu Rejonowego w M. za naruszenie art. 5 ust. 1 lit. f), art. 25 ust. 1, art. 32 ust. 1 lit. b) i d) oraz art. 32 ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 10,000 on the President of the District Court for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing data using portable external storage devices.PLUODOGDPR€2,189
14 Jul 2021LABORATORIOS GONZÁLEZ, S.L.LABORATORIOS GONZÁLEZ, S.L. was fined by the AEPD 20,000 EUR for sharing an employee’s COVID-19 antibody test result with the employee’s superior without consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€20,000
14 Jul 2021Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules.GRHDPAGDPR€2,000
15 Jul 2021Anonymisé (CNPD decision-27-fr-2021)The company did not meet GDPR requirements to inform individuals about data processing, especially in relation to video surveillance and employee notices. CNPD treated this as a breach of the information obligations owed to data subjects.LUCNPDGDPR€3,500
16 Jul 2021Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen.DKDatatilsynetGDPR€67,220
22 Jul 2021Atac s.p.a.Atac s.p.a. was fined by the Garante 400,000 EUR for processing personal data without a specific legal basis and without adequate security measures. The case concerned users of paid parking services in Rome.ITGaranteGDPR€400,000
22 Jul 2021Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules.ITGaranteGDPR€10,000
22 Jul 2021Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk.ITGaranteGDPR€35,000
22 Jul 2021Regione LombardiaRegione Lombardia was fined by the Garante 200,000 EUR for publishing personal data on its website that could reveal individuals' economic and social hardship. The authority found that this breached GDPR transparency and data protection requirements.ITGaranteGDPR€200,000
22 Jul 2021Flowbird s.r.l.Flowbird s.r.l. was fined EUR 30,000 by the Garante for processing personal data through parking meters in Rome without a legal basis. The authority also found that the company failed to maintain a record of processing activities.ITGaranteGDPR€30,000