Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Jan 2012Porto 2000 società cooperativa a r. l.Porto 2000 società cooperativa a r. l. was fined EUR 30,000 by the Garante. The authority found that the company had not appointed data processing officers and had failed to implement minimum security measures for the video surveillance system at the Ancona tourist port.ITGaranteGDPR€30,000
02 Feb 2012Casa di cura Villa Giustina s.r.l.Casa di cura Villa Giustina s.r.l. was fined 40,000 EUR by the Garante. The authority found that the company failed to submit the required notification for personal data processing activities under the Italian Data Protection Code.ITGaranteGDPR€40,000
09 Feb 2012Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements.ITGaranteGDPR€100,000
16 Feb 2012Amiat s.p.a.Amiat s.p.a. was fined EUR 30,000 by the Garante for failing to designate Allsystems s.p.a. as a data processor and for not providing the necessary instructions. The authority found that the company did not adopt the minimum security measures required for data processing.ITGaranteGDPR€30,000
22 Feb 2012J & J CONSULTINGJ & J CONSULTING was fined by the AEPD €1,800 for sending unsolicited commercial emails. The conduct continued despite unsubscribe requests, which breached Article 21 of the LSSI.ESAEPDePrivacy€1,800
05 Mar 2012GRANDES ALMACENES FNAC ESPAÑA S.A.The AEPD fined GRANDES ALMACENES FNAC ESPAÑA S.A. 36,000 EUR for sending unsolicited marketing emails to a customer who had opted out. The conduct breached the LSSI rules on electronic communications and recipient consent.ESAEPDePrivacy€36,000
05 Mar 2012NAUTALIA VIAJES, S.L.NAUTALIA VIAJES, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited commercial messages without prior consent from recipients. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€1,200
07 Mar 2012INSTITUTO TECNOLOGICO AUTESEL SLINSTITUTO TECNOLOGICO AUTESEL SL was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€600
08 Mar 2012Comune di Marano PrincipatoThe Municipality of Marano Principato was fined by the Garante for processing personal data without appointing data processors and for failing to adopt minimum security measures. The authority found a breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€10,000
15 Mar 2012Ammiro Partners s.r.l.Ammiro Partners s.r.l. was fined for violations related to the processing of personal data. The authority cited failure to comply with a prior injunction and failure to respond to requests from the Garante.ITGaranteGDPR€250,000
20 Mar 2012GAS NATURAL S.U.R. SDG S.A.GAS NATURAL S.U.R. SDG S.A. was fined EUR 1,800 by the AEPD for continuing to send commercial emails to a complainant after they had requested that such communications stop. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,800
21 Mar 2012GROUPON SPAIN SLGROUPON SPAIN SL was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The messages were sent despite the recipient's requests to unsubscribe, which breached Article 21 of the LSSI.ESAEPDePrivacy€30,001
21 Mar 2012Solar Energy Group s.p.aSolar Energy Group s.p.a was fined by the Garante 32,000 EUR for processing personal data collected through online forms without providing the required information or obtaining consent. The authority found breaches of Articles 13 and 23 of the Italian Privacy Code.ITGaranteGDPR€32,000
05 Apr 2012XY s.r.l.XY s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial communications by email despite the recipient's repeated objections. The case indicates a breach of data protection rules governing electronic marketing and respect for opt-out requests.ITGaranteGDPR€10,400
12 Apr 2012Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law.ITGaranteGDPR€120,000
11 May 2012PLEGADOS IRUÑA S.L.PLEGADOS IRUÑA S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€600
16 May 2012CONFORAMA ESPAÑA S.A.CONFORAMA ESPAÑA S.A. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited advertising SMS messages to customers. The conduct breached Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
18 May 2012INATED S.L.INATED S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial communications by email. This conduct breached Article 21.1 of the LSSI, which prohibits such messages without prior recipient consent.ESAEPDePrivacy€600
22 May 2012Municipal Water and Sewerage Company of RhodesThe Municipal Water and Sewerage Company of Rhodes was fined 5,000 EUR by the HDPA. The authority found that the company failed to satisfy the complainant’s data access rights and did not respond within the mandatory 15-day period.GRHDPAGDPR€5,000
30 May 2012ESCUELA HIPICA OLIMPIA, S.L.ESCUELA HIPICA OLIMPIA, S.L. was fined by the AEPD EUR 1,200 for sending commercial emails after the individual requested deletion of personal data and cessation of advertising communications. The case concerns failure to respect the recipient’s opt-out and data erasure request.ESAEPDePrivacy€1,200