Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Jul 2021Regione CalabriaThe Garante imposed a 10,000 EUR fine on Regione Calabria for publishing personal data on its website. The conduct breached GDPR rules on lawful processing and protection of personal data.ITGaranteGDPR€10,000
22 Jul 2021Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects.ITGaranteGDPR€800,000
22 Jul 2021Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities.ITGaranteGDPR€4,000
22 Jul 2021TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form.NLAPGDPR€750,000
25 Jul 2021CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity.ESAEPDGDPR€5,000
25 Jul 2021CYNGASA, S.L.CYNGASA, S.L. was fined by the AEPD EUR 5,000 for transferring an employee’s personal data to another company without consent. The authority found this conduct to be a breach of Article 6 of the GDPR.ESAEPDGDPR€5,000
27 Jul 2021BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for failing to implement adequate security measures to verify the identity of customers accessing sensitive information through an automated phone system. The authority found a breach of data integrity and confidentiality principles.ESAEPDGDPR€200,000
30 Jul 2021Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual for violating GDPR requirements. The case was handled by the Romanian supervisory authority ANSPDCP.ROANSPDCPGDPR€100
30 Jul 2021Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual by ANSPDCP for violating GDPR requirements. The case concerned a confirmed breach of personal data protection obligations.ROANSPDCPGDPR€100
30 Jul 2021Mederos Moviten, S.L.Mederos Moviten, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. Several unauthorized contracts were created using the complainant’s personal information, indicating unlawful use of personal data.ESAEPDGDPR€15,000
02 Aug 2021FUENSANTA S.L.FUENSANTA S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to provide access to information under Article 58.1 of the GDPR. The case concerned non-compliance with information access obligations toward the supervisory authority.ESAEPDGDPR€3,000
04 Aug 2021Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39.LUCNPDGDPR€17,700
04 Aug 2021Anonymisé (CNPD decision-30-fr-2021)The public establishment failed to communicate the DPO’s contact details to the supervisory authority and did not provide the DPO with the resources needed to perform the role effectively. CNPD found breaches of GDPR Articles 37(7), 38(2), and 39(1)(b) and imposed a fine of 6,600 EUR.LUCNPDGDPR€6,600
05 Aug 2021Anonymisé (CNPD decision-31-fr-2021)The company sent emails containing sensitive medical data to incorrect recipients. The authority also found a breach of data protection duties due to improper documentation of the incidents.LUCNPDGDPR€275,000
05 Aug 2021Anonymisiert (DSB 2021-0.518.795)An individual was fined for unlawfully processing and disclosing health-related personal data of a kindergarten teacher. The violation consisted of sending an email with sensitive information to her employer.ATDSBGDPR€600
05 Aug 2021COMUNIDAD DE VECINOS ***COMUNIDAD.1The community of neighbors was fined EUR 1,000 by the AEPD for failing to provide adequate information about video surveillance. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€1,000
05 Aug 2021HUBSIDE IBÉRICA S.L.HUBSIDE IBÉRICA S.L. was fined by the AEPD for charging a customer for services that were not contracted. Personal and bank account data were collected during a purchase, and the penalty was reduced due to early payment.ESAEPDGDPR€5,000
07 Aug 2021SPORTIUM APUESTAS DIGITAL S.A.U.SPORTIUM APUESTAS DIGITAL S.A.U. was fined by the AEPD 5,000 EUR for sending marketing emails after a data deletion request and for having non-compliant cookie policies on its website. The case indicates failures in data protection and user consent controls.ESAEPDePrivacy€5,000
09 Aug 2021ACONCAGUA JUEGOS S.A.ACONCAGUA JUEGOS S.A. was fined by the AEPD 10,000 EUR for failing to appoint a Data Protection Officer. The authority also found that the company did not address a data subject’s erasure request within the legal deadline.ESAEPDGDPR€10,000
12 Aug 2021NATURAL LOGISTICS, S.L.NATURAL LOGISTICS, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient's objection. This breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€3,000