Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Oct 2020Comune di CollegnoComune di Collegno was fined by the Garante for failing to respond in time to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,000
14 Oct 2020Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring.HUNAIHGDPR€1,925
08 Oct 2020Servicio de Alojamientos Responsables, S.L.The entity was fined by the AEPD 6,000 EUR for processing personal data without a legal basis. The breach involved signing a contract on behalf of an individual without authorization.ESAEPDGDPR€6,000
08 Oct 2020Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations.CZUOOUGDPR€6,459
07 Oct 2020UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles.ESAEPDGDPR€5,000
06 Oct 2020PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD 12,000 EUR for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€12,000
05 Oct 2020Pontosság elvének megsértéseThe controller was fined for processing inaccurate personal data, in breach of the accuracy principle under GDPR Art. 5(1)(d). The authority also ordered correction of the complainant’s address data.HUNAIHGDPR€1,674
02 Oct 2020INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine.ESAEPDePrivacy€3,000
02 Oct 2020GRUPO OCIO DESARROLLO Y SERVICIOS, S.L.The entity was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited commercial communications via WhatsApp. The authority found a breach of the complainant's rights to data protection and to object to data processing.ESAEPDePrivacy€1,500
01 Oct 2020Asociația de proprietari Militari R, comuna Chiajna, județul IlfovThe homeowners' association was fined by ANSPDCP €2,000 for failing to respond to a data subject's request. The authority treated this as a breach of GDPR rules on the exercise of individual rights.ROANSPDCPGDPR€2,000
01 Oct 2020Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information.ITGaranteGDPR€20,000
01 Oct 2020Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined EUR 3,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with certain personal data protection obligations.ROANSPDCPGDPR€3,000
30 Sept 2020Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis.HUNAIHGDPR€2,740
29 Sept 2020PLAY ORENES, S.L.PLAY ORENES, S.L. was fined by the AEPD €20,000 for improperly positioning surveillance cameras. The cameras captured public areas, which breached data protection rules.ESAEPDGDPR€20,000
29 Sept 2020GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€2,500
29 Sept 2020Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation.BEAPDGDPR€5,000
29 Sept 2020Vodafone Magyarország Távközlési Zártkörűen Működő RészvénytársaságThe NAIH imposed a 60,000,000 HUF fine on Vodafone Magyarország for unlawful voice recording practices at customer service offices. The authority found GDPR breaches relating to legal basis, transparency, purpose limitation, and data minimization.HUNAIHGDPR€163,000
25 Sept 2020SINDICATO DE TRABAJADORES DE LA ADMINISTRACIÓN PÚBLICA (STAP-CGT)The labor union STAP-CGT was fined EUR 3,000 by the AEPD for unlawful processing of personal data. The case concerned publishing a video of a court hearing on YouTube without proper consent, in breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
25 Sept 2020THE WASHPOINT S.L.THE WASHPOINT S.L. was fined by the AEPD 2,000 EUR for lacking a privacy policy and for having an improper cookie policy on its website. The breach concerned Article 13 of the GDPR and Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
24 Sept 2020BRONSON BAR, S.L.BRONSON BAR, S.L. was fined 2,000 EUR by the AEPD. The company used the reverse side of a contract to create an inventory, which was then publicly displayed, breaching data integrity and confidentiality principles.ESAEPDGDPR€2,000