Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2021DAVISER SERVICIOS, S.L.DAVISER SERVICIOS, S.L. was fined by the AEPD 20,000 EUR for using biometric data from fingerprint readers and surveillance cameras without properly informing employees. The authority found this to be a breach of data protection principles.ESAEPDGDPR€20,000
01 Jan 2021LYNGUAL GMBHLYNGUAL GMBH was fined by the AEPD 3,000 EUR for sending unsolicited commercial emails. The messages continued despite the recipient’s attempts to unsubscribe and requests to stop communications.ESAEPDePrivacy€3,000
01 Jan 2021B.B.B.The sanctioned individual installed a video surveillance camera covering common areas without informed consent. This breached data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€1,500
01 Jan 2021JUBASER DE CONTROL, S.L.JUBASER DE CONTROL, S.L. was fined by the AEPD 5,000 EUR for unlawful processing of personal data. The case concerned improper handling of a customer's ID and personal information, which later appeared on an adult contact website.ESAEPDGDPR€5,000
01 Jan 2021Dña. B.B.B.The entity was fined for publishing personal images and contact numbers on a dating website without proper consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€2,000
01 Jan 2021RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€5,000
01 Jan 2021ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD for sending advertising emails without the recipients’ consent. It also failed to comply with a request to delete personal data from its databases.ESAEPDePrivacy€5,000
01 Jan 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 100,000 EUR by the AEPD for requiring customers to submit photographs of both sides of their ID cards as a condition for package delivery. The authority found that this practice breached data protection principles.ESAEPDGDPR€100,000
01 Jan 2021ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings.ESAEPDGDPR€70,000
01 Jan 2021CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose.ESAEPDGDPR€4,000
01 Jan 2021Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR.PTComissão Nacional de Proteção de DadosGDPR€1,250,000
01 Jan 2021ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules.ESAEPDGDPR€5,000
30 Dec 2020B.B.B.The entity was fined by the AEPD in the amount of 1,500 EUR. The violation concerned installing surveillance cameras directed toward public areas without the required authorization and without compliant informational signage.ESAEPDGDPR€1,500
23 Dec 2020Anonymizováno (ÚOOÚ UOOU-02528/20-14)The entity was fined by the UOOU for breaching a legal prohibition on disclosing personal data under another regulation. The case concerned information about criminal proceedings and the persons involved.CZUOOUGDPR€38
22 Dec 2020Anonymizováno (ÚOOÚ UOOU-004103/19-31)The company was fined for unlawfully processing personal data of members of homeowners' associations by publishing the data on its website without consent. The authority found this conduct to be in breach of the GDPR.CZUOOUGDPR€1,141
17 Dec 2020Dane anonimowe (J.)The UODO imposed a fine of PLN 1,069,850 on Anonymous data (J.) for breaching personal data protection rules. The case concerned unlawful processing of personal data.PLUODOGDPR€240,000
17 Dec 2020University College DublinThe Irish DPC imposed a fine of EUR 70,000 on University College Dublin in inquiry IN-19-7-4. The fine has been collected.IEDPCGDPR€70,000
17 Dec 2020Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users.ITGaranteGDPR€500,000
17 Dec 2020Comune di Santo Stefano BelboComune di Santo Stefano Belbo was fined for unlawfully disclosing personal data, including names and legal information, on its website without a proper legal basis. The case concerned the publication of data that should not have been made publicly available.ITGaranteGDPR€4,000
17 Dec 2020Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements.ITGaranteGDPR€100,000