Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Oct 2021Telefónica de España, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD EUR 15,000 for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The authority noted that the messages were sent despite the recipient's objection.ESAEPDePrivacy€15,000
06 Oct 2021Anonymisé (CNPD decision-35-fr-2021)The company was fined by the CNPD in the amount of 5,300 EUR for breaching GDPR requirements. The authority found that it failed to provide adequate information to data subjects and did not comply with the data minimization principle.LUCNPDGDPR€5,300
04 Oct 2021AD735 DATA MEDIA ADVERTISING S.L.The entity was fined by the AEPD for breaching data protection rules. It continued sending commercial emails despite repeated requests from the complainant to delete their data.ESAEPDePrivacy€6,000
04 Oct 2021LA ÚLTIMA HORA NOTICIAS, S.L.LA ÚLTIMA HORA NOTICIAS, S.L. was fined by the AEPD EUR 2,000 for installing cookies on users’ devices without prior consent. The authority also found that the website did not provide adequate information about the cookies used.ESAEPDePrivacy€2,000
04 Oct 2021ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 50,000 EUR for breaching GDPR data accuracy principles. The case involved identity theft and false documentation in a request to transfer an electricity contract.ESAEPDGDPR€50,000
04 Oct 2021SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
29 Sept 2021dott.ssa Manuela MazzoliThe Garante imposed a fine of 2,000 EUR on dott.ssa Manuela Mazzoli for breaches of data protection rules. The case concerned the processing of personal data in the healthcare sector, including the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
29 Sept 2021Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing.ITGaranteGDPR€10,000
29 Sept 2021Kræftens BekæmpelseKræftens Bekæmpelse was fined by Datatilsynet 75,000 DKK for inadequate protection of sensitive health data. The incident affected at least 1,448 individuals and resulted from missing security measures that allowed unauthorized access to personal data.DKDatatilsynetGDPR€10,086
29 Sept 2021GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules.ITGaranteGDPR€30,000
29 Sept 2021K-city srlK-city srl was fined by the Italian Garante in the amount of 5,000 EUR for breaching data protection principles. The case concerned the management of a paid parking service for the Municipality of Formia, where compliance with lawfulness, fairness, and transparency was not ensured.ITGaranteGDPR€5,000
29 Sept 2021Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data.ITGaranteGDPR€11,000
29 Sept 2021Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor.ITGaranteGDPR€30,000
27 Sept 2021Сиела Норма АДThe CPDP found that Сиела Норма АД violated the GDPR by inaccurately processing personal data. The error led to an individual being misidentified as a liquidator of companies, and a fine of 5,000 BGN was imposed.BGCPDPGDPR€2,557
27 Sept 2021B.B.B.The entity was fined by the AEPD for operating a video surveillance system without proper informational signage. The system also captured footage beyond the intended purpose, including public transit areas.ESAEPDGDPR€1,500
24 Sept 2021B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,500
23 Sept 2021TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 1,000,000 for failing to adequately prevent unauthorized SIM card duplication. The breach enabled access to confidential information and caused financial losses for customers.ESAEPDGDPR€1,000,000
17 Sept 2021Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR.CYCyDPCGDPR€10,000
16 Sept 2021Farpa s.r.l.Farpa s.r.l. was fined by the Garante 1,000 EUR for failing to provide proper information to data subjects, including workers, about the processing of personal data through a video surveillance system. The authority found that the information duty toward affected individuals was not met adequately.ITGaranteGDPR€1,000
16 Sept 2021Barilla G. e R. fratelli S.p.A.Barilla G. e R. fratelli S.p.A. was fined by the Garante EUR 75,000 for violations linked to the use of a video surveillance system at its operational site. The system did not comply with data protection requirements.ITGaranteGDPR€75,000