Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Mar 2021ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles.ESAEPDGDPR€4,000
03 Mar 2021COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD EUR 2,000 for installing a surveillance camera system without the required authorization. The cameras recorded private areas, which breached privacy rules.ESAEPDGDPR€2,000
02 Mar 2021Anonymisert (Datatilsynet far-gebyr-for-ulovlig-videresending-av-e-post)The company was fined 250,000 NOK for forwarding an employee’s emails without a legal basis. The authority found that this breached the GDPR and the rules governing employer access to employee email accounts.NODatatilsynetGDPR€24,378
01 Mar 2021COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The entity was fined EUR 2,000 by the AEPD for installing cameras without the informed consent of the property owners' association. The conduct may have affected third-party rights and data protection obligations.ESAEPDGDPR€2,000
26 Feb 2021PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles.ESAEPDGDPR€10,000
25 Feb 2021Mistore Canarias, S.L.U.Mistore Canarias, S.L.U. was fined by the AEPD 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account.ESAEPDGDPR€5,000
24 Feb 2021UNIÓN FINANCIERA ASTURIANA S.A. E.F.C.UNIÓN FINANCIERA ASTURIANA S.A. E.F.C. was fined by the AEPD 15,000 EUR for consulting personal data in the Asnef file without a contractual relationship. The authority found this breached GDPR Article 6.1.ESAEPDGDPR€15,000
23 Feb 2021SFAM ESPAÑA GENERAL S.L.SFAM ESPAÑA GENERAL S.L. was fined by the AEPD in the amount of 5,000 EUR. The case concerned unauthorized charges to a customer's bank account after a purchase, raised in a complaint about data misuse.ESAEPDGDPR€5,000
22 Feb 2021B.B.B.The entity was fined by the AEPD for a video surveillance system that was improperly oriented toward private areas. The authority also found that the area was not adequately signposted, breaching data protection rules.ESAEPDGDPR€3,000
22 Feb 2021B.B.B.A fine was imposed for installing a surveillance camera aimed at public and private spaces without justification. The authority found a breach of data protection principles.ESAEPDGDPR€1,500
20 Feb 2021FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements.ESAEPDGDPR€3,000
19 Feb 2021SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.The company was fined by the AEPD for deploying a biometric fingerprint system for employee attendance control without carrying out a data protection impact assessment. The authority found this to be a breach of Article 35 GDPR because the processing involved biometric data requiring prior risk assessment.ESAEPDGDPR€20,000
18 Feb 2021INFORMÁTICA MÉDICA, S.L.INFORMÁTICA MÉDICA, S.L. was fined by the AEPD 60,000 EUR for failing to have a proper data processing agreement with its processor, OUTENUVE. The authority treated this as a breach of Article 28 GDPR.ESAEPDGDPR€60,000
17 Feb 2021VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 10,000 EUR for sending an unsolicited commercial SMS to a complainant without prior consent. The authority found that the message was sent without the required authorization.ESAEPDePrivacy€10,000
15 Feb 2021KHR-be való adattovábbítás (létre nem jött szerződés esetén)The controller unlawfully transferred personal data to the Central Credit Information System (KHR) even though no contract had been concluded. The authority found a breach of Article 6 GDPR and imposed a fine of 1,500,000 HUF.HUNAIHGDPR€4,185
15 Feb 2021ANYTIME FITNESS IBERIA, S.L.ANYTIME FITNESS IBERIA, S.L. was fined by the AEPD 15,000 EUR for failing to delete personal data after a request and for sending promotional SMS messages without consent. The case concerns non-compliance with data subject rights and rules on direct marketing.ESAEPDePrivacy€15,000
12 Feb 2021A*** GmbHA*** GmbH was fined by the Austrian Data Protection Authority for failing to cooperate in three separate complaint procedures. The authority found a breach of Article 31 GDPR, which requires cooperation with the supervisory authority.ATDSBGDPR€3,000
12 Feb 2021KUKIMBIA S.L.KUKIMBIA S.L. was fined EUR 3,000 by the AEPD for leaving documents containing personal data unattended. The authority found this to be a breach of data security obligations under Article 32(1) of the GDPR.ESAEPDGDPR€3,000
12 Feb 2021HIGHCLIFFE ESTATES MARBELLA, S.L.The company was fined by the AEPD for not providing a legal notice, privacy policy, or consent checkbox on its website. The authority also found that it used an individual's image without consent, breaching GDPR Articles 13 and 6(1).ESAEPDGDPR€8,000
12 Feb 2021ELECTROTECNIA BASTIDA, S.L.ELECTROTECNIA BASTIDA, S.L. was fined by the AEPD 3,000 EUR for leaving employees’ confidential medical information abandoned in a field. The incident constituted a breach of data protection rules and required supervisory action.ESAEPDGDPR€3,000