Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Dec 2021Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject.ITGaranteGDPR€30,000
16 Dec 2021Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling.ITGaranteGDPR€26,513,000
16 Dec 2021Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach.ITGaranteGDPR€10,000
16 Dec 2021Sindicato Intersectorial Trabajadores/as Provincia de AlicanteThe labor union was fined by the AEPD for breaching data protection rules. The case concerned the publication of committee meeting minutes containing signatures on a union notice board and in a WhatsApp group.ESAEPDGDPR€2,000
16 Dec 2021ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data.ITGaranteGDPR€10,000
16 Dec 2021LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles.FITSVGDPR€52,000
16 Dec 2021Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€1,000
16 Dec 20211000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR.ITGaranteGDPR€1,000
17 Dec 2021Kormánytisztviselő jogviszonyának megszűnésével összefüggésben egészségügyi adat kezelése, és erre irányuló hozzáférés megtagadásaThe authority found that the controller unlawfully denied access to personal data and failed to provide complete information about data processed in connection with the termination of employment. This breached GDPR Articles 12, 14, and 15.HUNAIHGDPR€1,632
20 Dec 2021B.B.B.A video recording showing an individual being assaulted was shared via WhatsApp without that person's consent. The AEPD found a breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
20 Dec 2021INSEKT FOOD S.L.INSEKT FOOD S.L. was fined by the AEPD EUR 4,000 for sharing an individual's personal data in WhatsApp group chats without consent. The authority found that the processing lacked a lawful basis under Article 6 of the GDPR.ESAEPDGDPR€4,000
22 Dec 2021wyżej wymienionąA financial penalty was imposed on an individual conducting business activity for failing to ensure that the President of the Personal Data Protection Office had access to personal data and information necessary to perform his duties. The case concerned obstruction of the supervisory authority’s powers.PLUODOGDPR€982
22 Dec 2021SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights.HUNAIHGDPR€1,355
23 Dec 2021wyżej wymienionąAn administrative fine was imposed on an individual conducting business activity. The violation consisted of failing to provide the President of the Personal Data Protection Office with access to personal data and information necessary to perform his duties.PLUODOGDPR€983
23 Dec 2021Federación Estatal de Servicios, Movilidad y Consumo de la UGT (FESMC-UGT)FESMC-UGT was fined 2,000 EUR by the AEPD for sending emails to employees’ corporate addresses without proper authorization. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,000
31 Dec 2021Dane anonimowe (S. Spółka z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 18,192 on the company. The sanction resulted from failing to provide access to personal data and other information necessary for the authority to perform its duties.PLUODOGDPR€3,957
01 Jan 2022B.B.B.B.B.B. was fined 1,000 EUR by the AEPD. The authority found that the company shared individuals’ personal data in a WhatsApp group without consent, in breach of data protection rules.ESAEPDGDPR€1,000
01 Jan 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company impersonated another energy provider and used personal data without consent.ESAEPDGDPR€10,000
01 Jan 2022BOOKSY INTERNATIONAL SPOLKA, S.L.BOOKSY INTERNATIONAL SPOLKA, S.L. was fined by the AEPD €500 for sending unsolicited commercial SMS messages. The recipient was registered on the Robinson List, which constituted a breach of Article 21 of the LSSI.ESAEPDePrivacy€500
01 Jan 2022CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification.ESAEPDGDPR€25,000