Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Jun 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for continuing to send promotional SMS messages to an individual whose personal data had previously been deleted. The authority found this conduct to be in breach of Article 6 GDPR.ESAEPDGDPR€75,000
24 Jun 2020MIGUEL IBÁÑEZ BEZANILLA S.L.The entity was fined for failing to implement adequate security measures on its website and for providing insufficient privacy policy information. Non-compliance with cookie policy requirements was also identified.ESAEPDGDPR€3,000
23 Jun 2020B.B.B.B.B.B. was fined by the AEPD EUR 3,000 for improperly identifying an individual as the author of a traffic violation. The authority found that this conduct breached GDPR data protection principles.ESAEPDGDPR€3,000
23 Jun 2020SALBEGAP, S.L.SALBEGAP, S.L. was fined by the AEPD EUR 2,000 for installing surveillance cameras in common areas without authorization from the homeowners' association. The authority found that this breached data protection principles.ESAEPDGDPR€2,000
23 Jun 2020COMUNIDAD DE PROPIETAROS R.R.R.The entity was fined for installing video surveillance cameras without the required informational signage. The case concerned a breach of data protection rules and the obligation to properly inform individuals subject to monitoring.ESAEPDGDPR€2,000
22 Jun 2020ARANOW PACKAGING MACHINERY, S.L.ARANOW PACKAGING MACHINERY, S.L. was fined by the AEPD for non-compliance of its website with data protection rules. The breach concerned the absence of compliant Privacy and Cookie Policies.ESAEPDePrivacy€3,000
22 Jun 2020PARTIT DELS SOCIALISTES DE CATALUNYA (PSC-PSOE)PSC-PSOE was fined by the AEPD 5,000 EUR for using personal data obtained in a doctor-patient relationship to send requests for political support. The authority found this breached purpose limitation rules for data processing.ESAEPDGDPR€5,000
19 Jun 2020IBERDROLA CLIENTES, SAUThe AEPD fined IBERDROLA CLIENTES, SAU EUR 40,000 for emailing a customer's electricity bill, which contained sensitive personal data, to an unrelated third party. The incident indicates a breach of confidentiality and personal data protection obligations.ESAEPDGDPR€40,000
18 Jun 2020CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing.ESAEPDGDPR€2,100,000
18 Jun 2020Azienda Pluriservizi Macerata S.p.A.Azienda Pluriservizi Macerata S.p.A. was fined EUR 4,000 by the Garante for processing colleagues’ personal data in a manner that did not comply with data protection principles. The authority cited breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
18 Jun 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles.ESAEPDGDPR€30,000
17 Jun 2020LA CASA COMPROMETIDA, S.Coop.The entity was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding its website cookie policy. The case concerned deficiencies in the required information or consent related to cookies.ESAEPDePrivacy€3,000
16 Jun 2020REAL SPORTING DE GIJÓN, S.A.D.REAL SPORTING DE GIJÓN, S.A.D. was fined EUR 5,000 by the AEPD for breaching GDPR Article 7 on consent requirements. The case arose from a complaint by the Ministry of Finance concerning advertising practices.ESAEPDGDPR€5,000
16 Jun 2020SAUNIER-TEC, MANTENIMIENTOS DE CALOR Y FRIO, S.LSAUNIER-TEC was fined EUR 6,000 by the AEPD for a data breach. The incident involved unauthorized access to personal data and bank account information, breaching GDPR Articles 33 and 34.ESAEPDGDPR€6,000
16 Jun 2020SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.U.SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.U. was fined by the AEPD 5,000 EUR for breaching the GDPR information obligations under Article 13. The case followed a complaint from the Madrid City Council's Consumer Unit.ESAEPDGDPR€5,000
15 Jun 2020Bostadsrättsförening HalmstadBRF Gårdsbjörken was fined by IMY for unlawful video and audio surveillance in common areas. The authority found breaches of GDPR principles, including data minimization and transparency.SEIMYGDPR€1,898
11 Jun 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the AEPD for failing to provide requested information. The breach concerned the duty to cooperate with the data protection authority during its proceedings.ESAEPDGDPR€5,000
11 Jun 2020XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined EUR 55,000 by the AEPD for linking a phone number to a third party’s data. This created unauthorized access and a risk of data alteration, breaching data protection rules.ESAEPDGDPR€55,000
10 Jun 2020UniCredit S.p.A.UniCredit S.p.A. was fined by Garante EUR 600,000 for a data breach. The incident involved unauthorized access to personal data of about 762,000 individuals after an intrusion using credentials of employees from an external partner.ITGaranteGDPR€600,000
10 Jun 2020Comune di MontevagoComune di Montevago was fined by the Garante 2,000 EUR for the unlawful online publication of personal data without an appropriate legal basis. The case concerned a breach of the principles of lawful processing and data protection in the public disclosure of information online.ITGaranteGDPR€2,000