Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jul 2020CABRERA & GIL ABOGADOS, S.L.P.CABRERA & GIL ABOGADOS, S.L.P. was fined by the AEPD €2,000 for disclosing personal data without consent. The case concerns Article 6 GDPR, which requires a valid legal basis for processing personal data.ESAEPDGDPR€2,000
20 Jul 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD €75,000 for charging a complainant for services linked to a third-party mobile number without consent. The authority found a breach of Article 6(1) GDPR because there was no lawful basis for the processing and related charges.ESAEPDGDPR€75,000
17 Jul 2020Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness.HUNAIHGDPR€1,415
16 Jul 2020TELEFÓNICA DE ESPAÑA, S.A.U.TELEFÓNICA DE ESPAÑA, S.A.U. was fined EUR 55,000 by the AEPD for processing personal data without consent. The company registered phone lines and charged invoices to an individual who had not authorized these actions.ESAEPDGDPR€55,000
10 Jul 2020COMUNIDAD.1The entity was fined for installing surveillance cameras with audio in common areas without proper notice to affected persons. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,000
10 Jul 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1.ESAEPDGDPR€100,000
09 Jul 2020YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners.BEAPDGDPR€5,000
09 Jul 2020Második ítélet a NAIH/2020/974 sz. ügyben (Fővárosi Törvényszék 105.K.701.565/2022/2)The controller collected personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The conduct breached multiple GDPR provisions, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria Kfv. II.37.001/2021/6)The controller processed personal data without a legal basis for a political campaign. It also failed to provide adequate information about the processing, resulting in breaches of several GDPR provisions.HUNAIHGDPR€2,820
09 Jul 2020Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent.ITGaranteGDPR€20,000
09 Jul 2020Istituto Comprensivo Statale Crucoli TorrettaIstituto Comprensivo Statale Crucoli Torretta was fined EUR 2,000 by the Garante for unlawfully publishing a list of students on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
09 Jul 2020dr. Hadházy Ákos ÁnyosThe controller processed personal data without a legal basis and did not provide adequate information about the processing linked to a petition concerning accession to the European Public Prosecutor's Office. The case indicates breaches of core transparency and lawfulness obligations.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles.HUNAIHGDPR€2,820
09 Jul 2020Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing.ITGaranteGDPR€16,729,000
09 Jul 2020Comune di BaronissiComune di Baronissi was fined by the Garante for publishing personal data online without a proper legal basis. The authority found a breach of the data minimization principle.ITGaranteGDPR€2,000
09 Jul 2020Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention.ITGaranteGDPR€800,000
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine.HUNAIHGDPR€2,820
09 Jul 2020Merlini s.r.l.Merlini s.r.l. was fined 200,000 EUR by the Garante. The authority found that the collection of potential clients' personal data did not comply with GDPR consent requirements and that call-center activities were carried out outside the telemarketing procedures established by Wind Tre.ITGaranteGDPR€200,000
06 Jul 2020Bureau Krediet Registratie (BKR)Bureau Krediet Registratie (BKR) was fined EUR 830,000 by the AP for not providing free electronic access to personal data. The authority found this practice breached the GDPR right of access.NLAPGDPR€830,000
03 Jul 2020IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 40,000 EUR for failing to provide the complainant access to their personal data, including telephone recordings. The authority found a breach of the right of access to personal data.ESAEPDGDPR€40,000