Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Sept 2021LODEJU, S.L.LODEJU, S.L. was fined EUR 3,000 by the AEPD for excessive video surveillance of public space without proper signage. The authority found a breach of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
10 Sept 2021LA OFICINA BAR XXXXThe entity installed two surveillance cameras aimed at public areas without justification. This breached data protection principles.ESAEPDGDPR€1,500
16 Sept 2021Farpa s.r.l.Farpa s.r.l. was fined by the Garante 1,000 EUR for failing to provide proper information to data subjects, including workers, about the processing of personal data through a video surveillance system. The authority found that the information duty toward affected individuals was not met adequately.ITGaranteGDPR€1,000
16 Sept 2021Barilla G. e R. fratelli S.p.A.Barilla G. e R. fratelli S.p.A. was fined by the Garante EUR 75,000 for violations linked to the use of a video surveillance system at its operational site. The system did not comply with data protection requirements.ITGaranteGDPR€75,000
16 Sept 2021Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality.ITGaranteGDPR€20,000
16 Sept 2021La Prima S.r.l.La Prima S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The authority found that this conduct breached GDPR requirements.ITGaranteGDPR€5,000
16 Sept 2021Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information.ITGaranteGDPR€5,000
16 Sept 2021Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data.ITGaranteGDPR€5,000
16 Sept 2021Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€5,000
16 Sept 2021Azienda sanitaria provinciale di CosenzaAzienda sanitaria provinciale di Cosenza was fined by the Garante for unlawfully publishing health data on its institutional website. The case involved breaches of data protection principles and required security measures for sensitive data.ITGaranteGDPR€18,000
16 Sept 2021Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA.ITGaranteGDPR€150,000
16 Sept 2021Ordine Provinciale di Roma dei Medici Chirurghi e degli OdontoiatriOrdine Provinciale di Roma dei Medici Chirurghi e degli Odontoiatri was fined by the Garante €5,000 for failing to adequately respond to a data subject’s request for access to personal data. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
16 Sept 2021Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals.ITGaranteGDPR€2,000
16 Sept 2021Favrskov KommuneFavrskov Kommune was fined 75,000 DKK for failing to implement appropriate security measures, including encryption, to protect sensitive personal data on a stolen laptop. The authority found a breach of GDPR Article 32.DKDatatilsynetGDPR€10,086
16 Sept 2021Accademia di Belle Arti di RomaAccademia di Belle Arti di Roma was fined EUR 5,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data in a disciplinary procedure and the dissemination of sensitive information.ITGaranteGDPR€5,000
17 Sept 2021Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR.CYCyDPCGDPR€10,000
23 Sept 2021TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 1,000,000 for failing to adequately prevent unauthorized SIM card duplication. The breach enabled access to confidential information and caused financial losses for customers.ESAEPDGDPR€1,000,000
24 Sept 2021B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,500
27 Sept 2021Сиела Норма АДThe CPDP found that Сиела Норма АД violated the GDPR by inaccurately processing personal data. The error led to an individual being misidentified as a liquidator of companies, and a fine of 5,000 BGN was imposed.BGCPDPGDPR€2,557
27 Sept 2021B.B.B.The entity was fined by the AEPD for operating a video surveillance system without proper informational signage. The system also captured footage beyond the intended purpose, including public transit areas.ESAEPDGDPR€1,500