Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Jul 2020Mapei S.p.A.Mapei S.p.A. was fined EUR 15,000 by the Italian authority Garante. The case concerned the failure to respond to a request for access to email communications and the failure to delete an email account after employment ended, in breach of GDPR principles.ITGaranteGDPR€15,000
02 Jul 2020Głównego Geodetę Kraju z siedzibą w Warszawie przy ul.UODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland based in Warsaw. The sanction concerned failure to provide access during an inspection to rooms, equipment and tools used for personal data processing, as well as access to personal data and information.PLUODOGDPR€22,351
02 Jul 2020Istituto Nazionale della Previdenza Sociale-Direzione Provinciale di BresciaThe Italian Data Protection Authority fined the INPS Brescia Provincial Directorate for failing to respond to a request for access to personal health data. The authority found a breach of data protection rules.ITGaranteGDPR€5,000
02 Jul 2020Istituto Comprensivo di Uggiano La ChiesaIstituto Comprensivo di Uggiano La Chiesa was fined €2,000 by the Garante for posting lists at the school entrance that included minors' names, dates of birth, addresses, phone numbers, and vaccination status. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€2,000
02 Jul 2020Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis.ITGaranteGDPR€4,000
02 Jul 2020GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations.ITGaranteGDPR€3,000
02 Jul 2020Comune di ManduriaComune di Manduria was fined by the Garante in the amount of 2,000 EUR for breaching data protection principles, including lawfulness, fairness, and transparency. The authority found that personal data had been improperly disseminated through journalistic outlets.ITGaranteGDPR€2,000
02 Jul 2020Comune di Greve in ChiantiComune di Greve in Chianti was fined by the Garante for unlawfully disclosing personal data relating to criminal convictions and proceedings. The conduct breached the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€4,000
02 Jul 2020CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI.ESAEPDePrivacy€1,000
01 Jul 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The breach concerned cooperation obligations under data protection rules.ESAEPDGDPR€5,000
01 Jul 2020ANMAVAS 61, S.L. (LA CUEVA SEX CLUB)ANMAVAS 61, S.L. did not respond to a data subject’s request for erasure. The AEPD imposed a fine of EUR 2,000 for breaching GDPR obligations.ESAEPDGDPR€2,000
01 Jul 2020COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD for publishing a resident’s personal data on a community notice board. The conduct breached data protection rules.ESAEPDGDPR€10,000
01 Jul 2020CAFÉ RESTAURANTE B.B.B.The entity installed a surveillance camera facing a public space, despite recommendations from the local police. This breached data protection regulations.ESAEPDGDPR€1,500
30 Jun 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 15,000 EUR for incorrectly listing a customer's ex-spouse as the account holder, even though the customer's data appeared on invoices. The company acknowledged responsibility and paid the reduced fine.ESAEPDGDPR€15,000
30 Jun 2020AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient.DELandesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-WürttembergGDPR€1,240,000
30 Jun 2020Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors.DKDatatilsynetGDPR€6,709
29 Jun 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for unauthorized processing of personal data. The case involved a fraudulent contract and the porting of a customer's phone line without a valid legal basis.ESAEPDGDPR€60,000
29 Jun 2020NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations.GRHDPAGDPR€5,000
26 Jun 2020ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
24 Jun 2020Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code.ITGaranteGDPR€10,000