Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Dec 2020Comune di LuinoComune di Luino was fined EUR 10,000 by the Garante for unlawfully disclosing personal data online. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
17 Dec 2020Ordine degli Assistenti Sociali della Regione LazioOrdine degli Assistenti Sociali della Regione Lazio was fined EUR 2,000 by the Garante. The authority found that the entity failed to respond to a request for access to personal data, which is a breach of GDPR Article 15.ITGaranteGDPR€2,000
17 Dec 2020LABORATORIO OCTOGÓN, S.L.LABORATORIO OCTOGÓN, S.L. was fined by the AEPD €1,000 for improperly positioning a surveillance camera. The camera captured third-party areas without justification, which breached data protection principles.ESAEPDGDPR€1,000
17 Dec 2020Miropass S.r.l.Miropass S.r.l. was fined EUR 40,000 by the Italian supervisory authority Garante. The case concerned violations related to data processing activities.ITGaranteGDPR€40,000
16 Dec 2020[...].Kft.The company breached GDPR by failing to provide accessible information about data processing and by not responding to access requests within one month. It also gave incomplete responses to access requests, photographed guests’ ID documents, and uploaded those photos to a WhatsApp group.HUNAIHGDPR€1,012
16 Dec 2020Babaváró kölcsönnel összefüggésben végzett adatkezelés – várandósgondozási könyvekről való másolatkészítés jogszerűségeThe supervisory authority found that the entity processed personal and health data from maternity care records without a legal basis in connection with Babaváró loan applications. It also failed to provide clear and transparent information about the processing, breaching GDPR principles.HUNAIHGDPR€98,350
14 Dec 2020Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f).SEIMYGDPR€29,433
10 Dec 2020Ítélet a NAIH/2020/54/H. sz. ügyben (Fővárosi Törvényszék 105.K.707.432/2020/17.)The entity was fined for processing scholarship applicants' personal data without a legal basis, including sensitive data. The authority also found that the data subjects were not adequately informed about the processing.HUNAIHGDPR€22,480
10 Dec 2020Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds.HUNAIHGDPR€22,480
10 Dec 2020Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements.SEIMYGDPR€53,713
09 Dec 2020Dane anonimowe (Z. Sp. z o.o. z siedzibą w U. przy ul.)The President of the Personal Data Protection Office (UODO) imposed a fine of PLN 12,838.2 on Z. Sp. z o.o. The sanction was issued for failing to cooperate with the authority and for not providing access to personal data and other information necessary for the performance of its duties.PLUODOGDPR€2,902
09 Dec 2020Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization.HUNAIHGDPR€2,240
09 Dec 2020Guldborgsund KommuneGuldborgsund Kommune was fined 50,000 DKK by Datatilsynet for a data breach. Sensitive information was mistakenly sent to an unauthorized recipient, causing significant consequences for the affected individuals.DKDatatilsynetGDPR€6,718
09 Dec 2020ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident.HUNAIHGDPR€56,000
09 Dec 2020Twitter International CompanyThe Irish DPC imposed a fine of EUR 450,000 on Twitter International Company in inquiry IN-19-1-1. The fine was collected.IEDPCGDPR€450,000
09 Dec 2020DKN.5131.5.2020StatusprawomocnaTytuA monetary penalty was imposed for failing to report a personal data breach to the President of UODO and for failing to notify the affected individuals. The case concerns non-compliance with breach notification obligations after a data security incident.PLUODOGDPR€19,344
04 Dec 2020BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website.ESAEPDePrivacy€8,000
04 Dec 2020BEINNOVA.ESBEINNOVA.ES was fined by the AEPD EUR 2,000 for sending unsolicited marketing emails without the recipient's consent. This conduct breached Article 21 of the LSSI on electronic commercial communications.ESAEPDePrivacy€2,000
03 Dec 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 75,000 EUR for failing to properly verify the identity of individuals requesting changes in line ownership. This failure resulted in unauthorized access and processing of personal data.ESAEPDGDPR€75,000
03 Dec 2020Dane anonimowe (W. Polska Sp. z o.o. z siedzibą w G.)UODO imposed a fine of PLN 1,968,524 on W. Polska Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing subscribers’ personal data in IT systems.PLUODOGDPR€440,000