Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jun 2021S.C.The operator was fined by ANSPDCP for failing to provide requested information to the supervisory authority. This constituted a breach of GDPR requirements.ROANSPDCPGDPR€2,000
09 Jun 2021INMOPISO ZARAGOZA, S.L.INMOPISO ZARAGOZA, S.L. was fined EUR 2,000 by the AEPD for failing to provide data protection information to a customer who made a deposit for a property purchase. The case concerns a breach of the transparency and information duty owed to the data subject.ESAEPDGDPR€2,000
08 Jun 2021BAR DA VINCI (SHUANGFENG ZHOU)BAR DA VINCI (SHUANGFENG ZHOU) was fined 500 EUR by the AEPD for operating a surveillance system without proper signage. The authority also found that the system captured excessive footage of public areas, constituting a GDPR breach.ESAEPDGDPR€500
08 Jun 2021DKN.5131.10.2020StatusnieprawomocnaTytuThe President of UODO imposed a fine of PLN 100,000 for failing to notify data breaches within the required deadline. The case concerns the obligation to report personal data breaches to the supervisory authority on time.PLUODOGDPR€22,372
08 Jun 2021IMAGINA FRAN SPORT, S.L.IMAGINA FRAN SPORT, S.L. was fined 2,000 EUR by the AEPD for not having an updated privacy policy on its website. The authority found a breach of the information obligations under GDPR Article 13.ESAEPDGDPR€2,000
07 Jun 2021Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000.SEIMYGDPR€64,643
07 Jun 2021CLUB NÁUTICO EL ESTACIOThe entity published personal data on its website without access restrictions. This breached confidentiality and data security principles.ESAEPDGDPR€3,000
07 Jun 2021EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. was fined EUR 1,000 by the AEPD for improperly sharing an employee’s personal data with the company committee. The authority found a breach of data protection rules.ESAEPDGDPR€1,000
07 Jun 2021Regionstyrelsen Region VärmlandRegionstyrelsen Region Värmland was fined by IMY 250,000 SEK for failing to inform patients calling the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found this to be a breach of GDPR transparency requirements.SEIMYGDPR€24,863
07 Jun 2021Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations.SEIMYGDPR€49,725
07 Jun 2021MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing.SEIMYGDPR€1,193,000
07 Jun 2021Regionstyrelsen Region SörmlandRegionstyrelsen Region Sörmland was fined by IMY 250,000 SEK for failing to inform callers to the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found a breach of GDPR transparency requirements.SEIMYGDPR€24,863
06 Jun 2021FLY FUT, S.L.FLY FUT, S.L. was fined by the AEPD in the amount of 3,000 EUR for recording a minor during football matches without prior consent. The case concerns a breach of data protection rules and the requirement to obtain consent before processing a child’s image.ESAEPDGDPR€3,000
04 Jun 2021FINCAS MIGUEL GARCÍA, S.LFINCAS MIGUEL GARCÍA, S.L was fined 2,000 EUR by the AEPD for failing to provide the complainant with its privacy policy before collecting personal data. The authority found this to be a breach of the information duty under Article 13 GDPR.ESAEPDGDPR€2,000
04 Jun 2021INTERSUMI S.C.INTERSUMI S.C. was fined EUR 2,000 by the AEPD for not having an adequate privacy policy on its website. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€2,000
02 Jun 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for improper handling of personal data. A complaint revealed discrepancies in the data linked to a customer's identity, and the penalty was reduced due to early payment.ESAEPDGDPR€50,000
02 Jun 2021TENTEA ENERGY, S.L.TENTEA ENERGY, S.L. was fined by the AEPD EUR 5,000 for using personal data and a signature without consent in connection with energy service contracts. The authority also found a refusal to provide access to personal data in relation to a cancellation request.ESAEPDGDPR€5,000
01 Jun 2021RADIO POPULAR S.A.RADIO POPULAR S.A. was fined EUR 2,000 by the AEPD for not providing users with the option to reject cookies on its website. The authority found this practice non-compliant with data protection rules and consent requirements.ESAEPDePrivacy€2,000
31 May 2021AUTOMECANICA JÉREZ, S.L.AUTOMECANICA JÉREZ, S.L. was fined EUR 4,000 by the AEPD. The authority found that the company sent a mass email without masking personal data and sent commercial emails and SMS messages without consent.ESAEPDePrivacy€4,000
31 May 2021Anonymizováno (ÚOOÚ UOOU-03580/20-23)The entity was fined for continuing to process personal data for marketing purposes despite the data subject's objection and request for erasure. The authority found this to be a breach of GDPR Article 21.CZUOOUGDPR€79