Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 May 2012CITIBANK ESPAÑA, S.A.CITIBANK ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails despite a prior request to be removed from its mailing list. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
07 Jun 2012HOTEL REY DON SANCHO S.A.HOTEL REY DON SANCHO S.A. was fined EUR 30,001 by the AEPD for continuing to send unsolicited commercial emails despite a request for data cancellation. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
27 Jun 2012OKANAOKANA was fined by the HDPA in the amount of 3,000 EUR for failing to adequately protect special-category personal data. Documents containing patients’ health data were found in trash bins, indicating a breach of data protection rules.GRHDPAGDPR€3,000
11 Jul 2012SOLUCIONES CORPORATIVAS IP, S.L.U.SOLUCIONES CORPORATIVAS IP, S.L.U. was fined 600 EUR by the AEPD for sending an unsolicited email. The conduct breached Article 21 of the LSSI, which restricts commercial communications without prior consent.ESAEPDePrivacy€600
11 Jul 2012Control Distribución Marketing, S.L.Control Distribución Marketing, S.L. was fined by the AEPD for sending unsolicited commercial emails. The company also failed to honor requests to stop such communications, breaching Article 21.1 of the LSSI.ESAEPDePrivacy€1,200
13 Jul 2012NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€33,001
17 Jul 2012FARMACIA INTERNACIONALFARMACIA INTERNACIONAL was fined by the AEPD EUR 1,800 for continuing to send electronic newsletters to a customer after the customer had unsubscribed. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,800
19 Jul 2012Biodiversity S.p.A.Biodiversity S.p.A. was fined by the Garante for failing to timely notify personal data processing activities related to molecular diagnostics. The obligation arose under the Italian Privacy Code.ITGaranteGDPR€10,000
26 Jul 2012Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€20,000
26 Jul 2012Meeting s.r.l.Meeting s.r.l. was fined by the Garante in the amount of 6,000 EUR for providing inadequate information to clients. The case concerned a breach of Article 13 of the Italian Data Protection Code, which requires proper notice to data subjects.ITGaranteGDPR€6,000
27 Jul 2012VIPVENTA, S.L.VIPVENTA, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails to the complainant. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
31 Jul 2012MEDIASTAY SASMEDIASTAY SAS was fined 30,001 EUR by the AEPD for sending commercial emails to a user despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€30,001
01 Aug 2012S.I.G.A.T. s.r.l.S.I.G.A.T. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 13,400. The case concerned the sending of unsolicited promotional faxes without prior consent from recipients.ITGaranteGDPR€13,400
01 Aug 2012Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules.ITGaranteGDPR€10,400
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information.GRHDPAGDPR€7,500
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data.GRHDPAGDPR€7,500
05 Sept 2012NOVOPRINT C.B.NOVOPRINT C.B. was fined by the AEPD in the amount of 38,000 EUR for sending commercial emails to LLACRUTECH, S.L. despite requests to remove the address from mailing lists. The authority found this to be a breach of the LSSI rules on electronic communications.ESAEPDePrivacy€38,000
06 Sept 2012BT Italia s.p.a.BT Italia s.p.a. was fined by the Garante EUR 75,000 for sending unsolicited promotional faxes without recipient consent. The conduct breached data protection and direct marketing rules.ITGaranteGDPR€75,000
06 Sept 2012One Italia S.p.A.One Italia S.p.A. was fined €20,000 by the Garante for sending promotional MMS messages without obtaining prior consent from recipients. The conduct breached Articles 23 and 130 of the Italian Data Protection Code.ITGaranteGDPR€20,000
06 Sept 2012Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules.ITGaranteGDPR€34,000