Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Nov 2020B.B.B.B.B.B. was fined by the AEPD EUR 2,000 for operating a video surveillance system directed toward public space. The measure affected the rights of third parties without justified cause and raised data protection compliance concerns.ESAEPDGDPR€2,000
05 Nov 2020B.B.B.The entity was fined by the AEPD EUR 2,000 for using security cameras that recorded public spaces extensively without justification. The authority found that this breached data protection principles.ESAEPDGDPR€2,000
05 Nov 2020DR MARÍN CIRUGIA PLÁSTICA, S.L.P.DR MARÍN CIRUGIA PLÁSTICA, S.L.P. was fined EUR 4,000 by the AEPD. The authority found that the company failed to provide a privacy policy on its website and used personal data for marketing purposes without consent.ESAEPDePrivacy€4,000
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1).ESAEPDGDPR€70,000
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD after a contract was entered into using another person's identity. The case concerns a breach of data protection rules and insufficient identity verification.ESAEPDGDPR€60,000
03 Nov 2020CANARYCLICK CONSULTING SLCANARYCLICK CONSULTING SL was fined EUR 8,000 by the AEPD for improper management of its cookie policy on its websites. The authority also found that user consent was collected in a generic manner, in breach of data protection rules.ESAEPDGDPR€8,000
03 Nov 2020LOSADA ADVOCATS S.L.LOSADA ADVOCATS S.L. was fined by the AEPD EUR 10,000 for sending an email without using BCC. This exposed recipients’ email addresses and breached data protection principles.ESAEPDGDPR€10,000
29 Oct 2020Ministero dell’InternoThe Italian Data Protection Authority fined the Ministry of the Interior EUR 50,000 for the incorrect disclosure of personal data to a limited number of organizations. It also ordered the Ministry to consider training initiatives to improve data accuracy.ITGaranteGDPR€50,000
29 Oct 2020Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration.ITGaranteGDPR€8,000
29 Oct 2020Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met.ITGaranteGDPR€4,000
29 Oct 2020Gaypa s.r.l.Gaypa s.r.l. was fined EUR 20,000 by the Garante for continuing to use a personalized email account of a former employee after the employment ended. The authority found this conduct inconsistent with GDPR principles of lawfulness and purpose limitation.ITGaranteGDPR€20,000
27 Oct 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for requesting payment for services contracted without the complainant’s consent. The case concerns a data protection breach linked to processing and debt collection without a valid legal basis.ESAEPDGDPR€50,000
26 Oct 2020***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information.ESAEPDGDPR€10,000
26 Oct 2020ESTILO 1221, S.C.ESTILO 1221, S.C. was fined by the AEPD EUR 1,500 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent.ESAEPDePrivacy€1,500
22 Oct 2020Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access.HUNAIHGDPR€5,480
21 Oct 2020HEREDAD DE UREÑA, S.L.HEREDAD DE UREÑA, S.L. was fined by the AEPD EUR 4,000 for not having a privacy policy on its website, lacking a cookies policy, and sending unsolicited marketing emails without consent. The case indicates failures in basic transparency obligations and consent requirements for electronic communications.ESAEPDGDPR€4,000
21 Oct 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for processing personal data without proper consent. The case involved a customer receiving a notification of a purchase they had not made, indicating improper use of personal data.ESAEPDGDPR€60,000
19 Oct 2020Anonymisiert (DSB 2020-0.550.322)An individual was fined for unlawfully processing image data by using a smartphone to record a person in a restroom. The authority found a breach of the principles of lawfulness, fairness, and transparency under Art. 5 GDPR and no legal basis under Art. 6 GDPR.ATDSBGDPR€150
19 Oct 2020Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis.ATDSBGDPR€600
19 Oct 2020PREDASE SERVICIOS INTEGRALES SOCIEDAD LIMITADAPREDASE SERVICIOS INTEGRALES S.L. was fined EUR 5,000 by the AEPD for failing to publish a privacy policy on its website and for misleadingly using the AEPD logo. The conduct could imply an association with the authority and influence user decisions.ESAEPDGDPR€5,000