Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 May 2021YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions.BEAPDGDPR€50,000
05 May 2021Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data.NODatatilsynetGDPR€2,503,000
05 May 2021Munkavállalói e-mail fiókok és munkaeszközök használatával és azok ellenőrzésével összefüggő adatkezelésThe controller did not provide the data subject with adequate prior information about the processing of work email and computer usage. The authority found this to breach the principles of fairness and accountability in data processing.HUNAIHGDPR€5,560
05 May 2021Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification.HUNAIHGDPR€5,560
04 May 2021CLUB GIMNASIA RÍTMICA SAN ANTONIOThe club was fined by the AEPD for publishing images of minors on social media without proper consent. The authority found a breach of GDPR Article 6 on lawful processing.ESAEPDGDPR€5,000
29 Apr 2021Comune di PutifigariComune di Putifigari was fined EUR 3,000 by the Garante for publishing special-category personal data online. The disclosed information could reveal individuals' health status, which breached GDPR requirements on data protection and privacy.ITGaranteGDPR€3,000
29 Apr 2021Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data.ITGaranteGDPR€30,000
29 Apr 2021Azienda Ospedaliero Universitaria PisanaAzienda Ospedaliero Universitaria Pisana was fined by the Garante EUR 4,000 for breaches of the principles of lawfulness, fairness, transparency, integrity, and confidentiality in data processing. The case concerned improper handling of personal data under GDPR requirements.ITGaranteGDPR€4,000
29 Apr 2021Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations.ITGaranteGDPR€5,000
29 Apr 2021LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD €1,000 for sending commercial emails to an individual whose email address was included in the Robinson List. The conduct breached Spanish data protection rules governing unsolicited marketing communications.ESAEPDePrivacy€1,000
29 Apr 2021Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements.ITGaranteGDPR€45,000
29 Apr 2021Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period.ITGaranteGDPR€4,000
29 Apr 2021Comune di Santa NinfaComune di Santa Ninfa was fined by the Garante 2,000 EUR for publishing a complainant’s personal data online. The publication also included detailed references to enforcement proceedings, which breached GDPR requirements.ITGaranteGDPR€2,000
29 Apr 2021Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards.ITGaranteGDPR€6,000
29 Apr 2021CRIQUET PUBLICIDAD, S.L.CRIQUET PUBLICIDAD, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The recipient’s address was registered on the Robinson List, which constitutes a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
29 Apr 2021Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6.NLAPGDPR€600,000
29 Apr 2021FederpolFederpol was fined 5,000 EUR by the Garante for improperly sharing members’ personal information with other associates. The authority found that this breached data protection rules and required a valid legal basis and appropriate safeguards.ITGaranteGDPR€5,000
27 Apr 2021Diszpécseri munkakört betöltő munkavállalóval folytatott telefonhívás rögzítéseThe decision concerned the unlawful recording and use of phone calls without a proper legal basis and without adequate transparency. The authority found breaches of GDPR accountability, lawful processing, and transparency principles.HUNAIHGDPR€1,380
27 Apr 2021Dane anonimowe (K. Spółkę Akcyjną z siedzibą w N. przy ul.)The President of UODO imposed an administrative fine of PLN 22,739 on the company. The sanction resulted from failure to cooperate with the supervisory authority and from not providing information necessary to resolve the case.PLUODOGDPR€4,982
27 Apr 2021XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 3,000 for sending commercial emails without the recipient’s consent. The authority found a breach of Article 21 of the LSSI, despite the recipient’s attempts to unsubscribe.ESAEPDePrivacy€3,000