Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Aug 2020TuslaThe Irish DPC fined Tusla EUR 85,000 in inquiry IN-18-11-4. The fine has been collected.IEDPCGDPR€85,000
11 Aug 2020FEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓNFEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓN was fined by the AEPD 5,000 EUR for the unauthorized disclosure of personal data. The data included names, DNI numbers, and signatures, which were published in a newspaper and on social media.ESAEPDGDPR€5,000
11 Aug 2020DERDIX 5000 SLThe entity published photos of minors in a magazine without obtaining consent, which constitutes a breach of data protection rules. The case concerns the unauthorized disclosure of children’s images and was sanctioned by the AEPD.ESAEPDGDPR€2,000
07 Aug 2020TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for unauthorized access to a customer's data and harassment through excessive calls and messages. The case indicates failures in data protection controls and customer contact practices.ESAEPDGDPR€75,000
06 Aug 2020Hozzáférési jog, adatpontosság és átláthatóság elvének megsértéseThe decision concerned unlawful processing of personal data during debt collection and breaches of access rights and information obligations under the GDPR. Both entities involved in the case were fined for their actions.HUNAIHGDPR€5,780
05 Aug 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation.ESAEPDGDPR€50,000
04 Aug 2020PrivatBo A.M.B.A. af 1993PrivatBo was reported to the police, and Datatilsynet recommended a fine of 150,000 DKK for inadequate data security measures. The incident led to the unintended disclosure of tenants' confidential information on USB drives.DKDatatilsynetGDPR€20,145
31 Jul 2020ASOCIACIÓN DE VIGILANTES DE SEGURIDAD DEL AEROPUERTO DE BARCELONAThe organization was fined by the AEPD in the amount of 3,000 EUR for sending an electoral census of workers to private phones via WhatsApp. The authority found a breach of data protection principles.ESAEPDGDPR€3,000
29 Jul 2020CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data.ESAEPDGDPR€4,000
28 Jul 2020Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
28 Jul 2020Anonymizováno (ÚOOÚ UOOU-05226/19-22)The entity was fined for publishing personal data of court proceeding participants on a website. The authority found this to be a breach of data protection law.CZUOOUGDPR€1,905
24 Jul 2020I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.UI-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U was fined by the AEPD EUR 200,000 for sending letters to customers without a legal basis. The authority found that this breached the principles of data minimization and purpose limitation.ESAEPDGDPR€200,000
24 Jul 2020IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia Líneas Aéreas de España, S.A. Operadora Unipersonal 30,000 EUR. The authority found that the website did not provide users with an option to reject cookies in line with consent requirements.ESAEPDePrivacy€30,000
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by NAIH 2,500,000 HUF for publishing personal data without a proper legal basis. The authority also found that the company failed to provide adequate information to the data subjects in connection with the Forbes publication.HUNAIHGDPR€7,200
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe authority found that Mediarey Hungary Services Zrt. unlawfully processed personal data related to Forbes magazine publications. It also failed to adequately inform data subjects about their rights, resulting in breaches of several GDPR provisions.HUNAIHGDPR€5,760
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,500,000 HUF for failing to provide adequate information to data subjects about processing and their rights. The authority also found that the company did not demonstrate compelling legitimate grounds for continued processing after objections were raised.HUNAIHGDPR€7,200
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe NAIH imposed a 2,500,000 HUF fine on Mediarey Hungary Services Zrt. for unlawful data processing related to Forbes magazine publications. The authority found that data subjects were not adequately informed and that their rights to object and erasure were not respected.HUNAIHGDPR€7,200
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,000,000 HUF for insufficient data protection measures in its Forbes publications. The authority also found that data subjects were not adequately informed and that several GDPR provisions were breached.HUNAIHGDPR€5,760
23 Jul 2020Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed.FITSVGDPR€7,000
20 Jul 2020CENTRO DE INVESTIGACIÓN Y ESTUDIO PARA LA OBESIDAD, S.L.The entity unlawfully transferred personal data without consent, in breach of Article 6 of the GDPR. The case resulted in an administrative fine of 50,000 EUR.ESAEPDGDPR€50,000