Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Sept 2020VENU SANZ CHEF, S.L.VENU SANZ CHEF, S.L. used a client's personal data, including full name, profile photo, and health information, for advertising purposes without consent. The AEPD found this conduct to be a breach of data protection rules.ESAEPDGDPR€3,000
21 Sept 2020CONSEGURIDAD S.L.CONSEGURIDAD S.L. was fined 50,000 EUR by the AEPD for failing to appoint a Data Protection Officer. The authority found a breach of Article 37(1)(b) of the GDPR.ESAEPDGDPR€50,000
21 Sept 2020AVATA HISPANIA, S.L.AVATA HISPANIA, S.L. was fined by the AEPD 5,000 EUR for using personal data after the contract had ended. The company acted as a data processor, and continued use of the data was inconsistent with its obligations in that role.ESAEPDGDPR€5,000
17 Sept 2020Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing.ITGaranteGDPR€80,000
17 Sept 2020Scanshare s.r.l.Scanshare s.r.l. was fined by the Garante 60,000 EUR for inadequate technical and organizational measures in handling candidate data during a hospital recruitment process. The authority also found a breach of GDPR Article 13 because the required information was not provided to candidates.ITGaranteGDPR€60,000
11 Sept 2020BODEGAS DINASTIA, S.L.BODEGAS DINASTIA, S.L. was fined by the AEPD EUR 2,000 for non-compliance with data protection rules on its websites. The issues concerned the privacy policy and the way cookie consent was obtained.ESAEPDePrivacy€2,000
08 Sept 2020Sanatatea Press Group S.R.L.Sanatatea Press Group S.R.L. was fined EUR 2,000 by ANSPDCP for a data security breach during an online event. Login details were mistakenly sent to incorrect email addresses, resulting in disclosure of information to unauthorized recipients.ROANSPDCPGDPR€2,000
08 Sept 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD €40,000 for processing personal data without a legal basis. The case involved fraudulent contracts created in individuals’ names without their consent, breaching the principle of lawful processing.ESAEPDGDPR€40,000
03 Sept 2020Comune di CasaloldoComune di Casaloldo was fined by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The conduct breached the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
03 Sept 2020Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data.HUNAIHGDPR€55,800
01 Sept 2020Asociația de proprietari Bl. FC 5, orașul Năvodari, județul ConstanțaThe homeowners' association was fined by ANSPDCP EUR 500 for unlawfully processing an individual's image from the video surveillance system. The image was displayed on the building's notice board, which breached data processing principles.ROANSPDCPGDPR€500
01 Sept 2020Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures.BEAPDGDPR€2,000
01 Sept 2020Iweb Internet Learning, S.L.Iweb Internet Learning, S.L. was fined by the AEPD EUR 13,000 for failing to inform data subjects about the processing of their personal data. The authority also found the use of storage and retrieval devices without the required notice or consent.ESAEPDePrivacy€13,000
01 Sept 2020B.B.B.The entity was fined by the AEPD €5,000 for using a webcam to record video and audio without justification. The conduct infringed privacy by monitoring private conversations and activities inside a rented residence.ESAEPDGDPR€5,000
26 Aug 2020Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services.CZUOOUePrivacy€228,000
24 Aug 2020Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records.PLUODOGDPR€22,735
21 Aug 2020ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations.PLUODOGDPR€11,369
19 Aug 2020Anonymizováno (ÚOOÚ UOOU-05284/19-36)The entity was fined for publishing a partially anonymized criminal order on Facebook that still contained personal data. The authority found a breach of GDPR principles governing lawful processing and personal data protection.CZUOOUGDPR€383
18 Aug 2020HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected.IEDPCGDPR€65,000
13 Aug 2020Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis.HUNAIHGDPR€5,800