Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Jan 2021Dane anonimowe (M. Sp. z o.o. z siedzibą w Z. przy)The President of UODO imposed an administrative fine of PLN 21,397 on M. Sp. z o.o. The company failed to cooperate with the authority and did not provide information needed to assess a complaint concerning personal data processing.PLUODOGDPR€4,705
05 Jan 2021Dane anonimowe (Panią M. Z. prowadzącą działalność gospodarczą pod firmą K.)The President of UODO imposed a fine of PLN 85,588 on an individual conducting business under the name K. The authority found that an order contained in an administrative decision on personal data protection had not been complied with.PLUODOGDPR€18,822
05 Jan 2021DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach.PLUODOGDPR€5,498
04 Jan 2021MACASVER S.L.MACASVER S.L. was fined €8,000 by the AEPD for incorrectly identifying the driver of a vehicle involved in a traffic violation. The authority found a breach of the GDPR data accuracy principle.ESAEPDGDPR€8,000
04 Jan 2021Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing.NODatatilsynetGDPR€95,750
01 Jan 2021ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD 5,000 EUR for failing to comply with a data deletion request and for sending unsolicited marketing emails without consent. The case indicates non-compliance with data subject rights and rules on direct marketing communications.ESAEPDGDPR€5,000
01 Jan 2021LA MAISON DU BAMBOULA MAISON DU BAMBOU was fined EUR 3,000 by the AEPD for sending commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
01 Jan 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined €3,000 by the AEPD for failing to comply with information requests. The case concerned Article 58(1) GDPR and the duty to cooperate with the supervisory authority.ESAEPDGDPR€3,000
01 Jan 2021PAGE GROUP EUROPEPAGE GROUP EUROPE was fined by the AEPD 300,000 EUR for breaches of GDPR principles on data minimization and transparency. The case concerned the improper handling of a data subject access request submitted through its Dutch website.ESAEPDGDPR€300,000
01 Jan 2021MARINS PLAYA, S.A.MARINS PLAYA, S.A. was fined by the AEPD in the amount of EUR 30,000 for unlawfully scanning a customer's passport during hotel registration. The authority found that this breached Article 6 of the GDPR because there was no valid legal basis for the processing.ESAEPDGDPR€30,000
01 Jan 2021MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined by the AEPD 4,000 EUR for sending spam emails without recipient consent. The authority also found unlawful processing of personal data collected from public websites without proper legal basis.ESAEPDGDPR€4,000
01 Jan 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for breaching data protection rules. The case concerned deficiencies in the security and integrity of data processing.ESAEPDGDPR€50,000
01 Jan 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication.ESAEPDGDPR€800,000
01 Jan 2021INMARÁN ASESORES, S.L.INMARÁN ASESORES, S.L. was fined 2,000 EUR by the AEPD for recording telephone conversations without informing the data subject or obtaining consent. The authority found this to be a breach of the GDPR information obligations.ESAEPDGDPR€2,000
01 Jan 2021RECLAMADOR, S.L.RECLAMADOR, S.L. was fined €2,000 by the AEPD for sending a commercial electronic communication after the recipient had exercised the right to erasure. The authority found this conduct breached GDPR and LSSI requirements.ESAEPDGDPR€2,000
01 Jan 2021B.B.B.B.B.B. was fined by the AEPD 10,000 EUR for publishing personal data, including DNI/NIF, on a website. The authority found a breach of data minimization principles and GDPR requirements.ESAEPDGDPR€10,000
01 Jan 2021COMUNIDAD.1The entity was fined by the AEPD EUR 1,000 for installing a video surveillance system that captured third parties without adequate data protection measures. The authority found breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
01 Jan 2021COMUNIDAD DE PROPIETARIOS R.R.R.The community of property owners was fined by the AEPD for collecting excessive personal data in connection with access to the community pool. The authority also found that users were not properly informed about the processing of their personal data.ESAEPDGDPR€6,000
01 Jan 2021COMUNIDAD PROPIETARIOS ***DIRECCIÓN.1The Community of Property Owners was fined by the AEPD EUR 500 for posting on notice boards a list of owners in arrears together with personal data. The information was accessible to third parties, which constituted a breach of data protection rules.ESAEPDGDPR€500
01 Jan 2021ASOCIACIÓN JEREZ CAPITALThe entity was fined by the AEPD for failing to comply with data protection rules in relation to its website cookie policy. Non-essential cookies were placed on the site without prior user consent.ESAEPDGDPR€1,000