Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Feb 2021Istituto Superiore Statale "Pitagora"Istituto Superiore Statale "Pitagora" was fined by the Garante 5,000 EUR for unlawful processing of personal data. The authority found failures to ensure data minimization and transparency toward data subjects.ITGaranteGDPR€5,000
11 Feb 2021Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR.NLAPGDPR€440,000
11 Feb 2021Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data.ITGaranteGDPR€45,000
11 Feb 2021ZCALL LEVANTE, S.L.ZCALL LEVANTE, S.L. was fined by the AEPD 20,000 EUR for making a commercial call to a number registered on the Robinson List. This conduct breached telecommunications and consumer protection rules.ESAEPDGDPR€20,000
11 Feb 2021Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code.ITGaranteGDPR€10,000
11 Feb 2021Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website.ITGaranteGDPR€5,000
11 Feb 2021Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing.ITGaranteGDPR€10,000
11 Feb 2021Политическа партия „Д.П.Б.“Political party “D.P.B.” was fined 1,000 BGN by CPDP for processing personal data without the consent of the data subjects. The breach occurred during the registration of election commission members and violated Article 6 GDPR.BGCPDPGDPR€511
11 Feb 2021Bonatti S.p.ABonatti S.p.A was fined EUR 40,000 by the Garante for violating data protection rules. The company improperly shared an employee's medical data with a third party.ITGaranteGDPR€40,000
11 Feb 2021Roma Servizi per La Mobilita S.r.l.Roma Servizi per La Mobilita S.r.l. was fined EUR 60,000 by the Garante for inadequate security measures. The weakness led to unauthorized access to personal data related to ZTL permits.ITGaranteGDPR€60,000
11 Feb 2021Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident.ITGaranteGDPR€6,500
11 Feb 2021Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da PietrelcinaThe foundation was fined by the Garante 5,000 EUR for processing personal data in breach of the principles of lawfulness, fairness, transparency, integrity, and confidentiality. The case concerned in particular the handling of health data.ITGaranteGDPR€5,000
11 Feb 2021Liceo Pepe CalamoLiceo Pepe Calamo was fined EUR 5,000 by the Garante for publishing teachers' personal data in public rankings on its institutional website. The authority found a breach of data minimization and transparency principles.ITGaranteGDPR€5,000
11 Feb 2021Krajową Szkołę Sądownictwa i Prokuratury z siedzibą w Z.,UODO imposed a PLN 100,000 administrative fine on the National School of Judiciary and Public Prosecution. The authority found that the entity failed to implement appropriate technical and organizational measures to ensure the ongoing confidentiality of processing services and breached GDPR Article 28(3).PLUODOGDPR€22,235
11 Feb 2021Roma CapitaleRoma Capitale was fined EUR 350,000 by the Garante for breaches of GDPR principles, including data minimization and security. The violations resulted in unauthorized access to personal data over an extended period.ITGaranteGDPR€350,000
11 Feb 2021Ministero dello Sviluppo EconomicoThe Ministry of Economic Development was fined by the Garante for publishing personal data, including managers' CVs, on its institutional website without a proper legal basis. The authority found this conduct to be in breach of GDPR requirements.ITGaranteGDPR€75,000
10 Feb 2021Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act.SEIMYePrivacy€248,000
10 Feb 2021CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules.ESAEPDGDPR€2,000
05 Feb 2021NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€1,000
03 Feb 2021Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion.NODatatilsynetGDPR€19,316