Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Mar 2021VASCO ANDALUZA DE INVERSIONES, S.L.VASCO ANDALUZA DE INVERSIONES, S.L. was fined by the AEPD 2,000 EUR for unlawfully sharing personal data with third parties without informing the data subject. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
17 Mar 2021GERCO FIT, S.L.GERCO FIT, S.L. was fined by the AEPD in the amount of 2,000 EUR for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
17 Mar 2021SOLRAM T Y R S.L.SOLRAM T Y R S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to delete personal data from its databases. The authority found a breach of Article 17 GDPR after the company continued sending unsolicited commercial messages via WhatsApp.ESAEPDGDPR€3,000
16 Mar 2021SIA "“fit People”A fine of EUR 5,836 was imposed. The decision has entered into force.LVDVIGDPR€5,836
15 Mar 2021Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached.BEAPDGDPR€2,000
12 Mar 2021PRODUCCIONES ROCKNROCK, S.L.PRODUCCIONES ROCKNROCK, S.L. was fined EUR 2,000 by the AEPD for failing to provide information or obtain consent for cookies on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
11 Mar 2021Mediacom s.r.l.Mediacom s.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The authority found that this conduct breached GDPR rules on the processing of personal data for marketing purposes.ITGaranteGDPR€15,000
11 Mar 2021Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data.ITGaranteGDPR€10,000
11 Mar 2021COMUNIDAD DE PROPIETARIOS B.B.B.COMUNIDAD DE PROPIETARIOS B.B.B. was fined by the AEPD in the amount of 2,000 EUR for irregularities in its video surveillance system. The authority found that the cameras captured public spaces, which breached the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€2,000
11 Mar 2021Azienda Ospedaliera San Giovanni AddolorataAzienda Ospedaliera San Giovanni Addolorata was fined EUR 20,000 by the Garante for inadequate data protection measures concerning patient health data. The authority found breaches of GDPR Articles 5 and 32.ITGaranteGDPR€20,000
11 Mar 2021Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing.ITGaranteGDPR€5,000
11 Mar 2021Planet Group spaPlanet Group spa was fined EUR 80,000 by the Garante. The authority found that the company made unsolicited promotional calls without a proper legal basis, breaching GDPR rules on data processing and privacy by design.ITGaranteGDPR€80,000
11 Mar 2021dott. Gregorio GrecoDott. Gregorio Greco was fined 6,400 EUR by the Garante for failing to provide information to data subjects and for processing patients' health-related personal data without consent. The case concerns patient data and breaches of transparency and lawful basis requirements.ITGaranteGDPR€6,400
10 Mar 2021B.B.B.The entity was fined by the AEPD in the amount of 4,000 EUR for installing a video surveillance system aimed at public areas. The authority also found that images were captured without justified cause and retained longer than permitted by law.ESAEPDGDPR€4,000
09 Mar 2021NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD €20,000 for processing personal data without a legal basis. The case was related to identity theft in a microcredit contract.ESAEPDGDPR€20,000
09 Mar 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 100,000 by the AEPD for failing to permanently delete personal data after a request. As a result, the complainant continued to receive SMS messages.ESAEPDGDPR€100,000
05 Mar 2021APARTAMENTOS PLAYA DE COVACHOS, S.L.The company was fined by the AEPD in the amount of 1,000 EUR for operating video surveillance without the required information for recorded individuals. It did not identify the data controller, explain how rights could be exercised, or state the purpose of the surveillance, which breaches Article 13 GDPR.ESAEPDGDPR€1,000
04 Mar 2021VODAFONE ESPAÑA, S.A.U.Vodafone España was fined for processing personal data without a legal basis. The company linked a prepaid phone line to an individual without consent and shared the data with law enforcement.ESAEPDGDPR€100,000
04 Mar 2021Anonymizováno (ÚOOÚ UOOU-02022/20-24)The entity was fined for unauthorized publication of personal data of thirty individuals on a website. The authority found a breach of the basic principles of personal data processing under GDPR.CZUOOUGDPR€5,724
04 Mar 2021CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.CEDICO, a diagnostic imaging center, was fined EUR 30,000 by the AEPD. The authority found that the company unlawfully shared a patient's MRI report with a mutual insurance company, breaching data protection principles.ESAEPDGDPR€30,000