Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 May 2020Geanonimiseerd (APD 24/2020)The decision concerns an insurance company that failed to provide sufficient transparency in its privacy policy. It involved the use of health data without explicit consent for purposes beyond hospitalization insurance.BEAPDGDPR€50,000
14 May 2020Anonymizováno (ÚOOÚ UOOU-1936/19-68)The entity was fined 1,500,000 CZK by the UOOU. The authority found that required corrective measures under the Czech Data Processing Act were not implemented.CZUOOUGDPR€54,405
12 May 2020B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for installing a video surveillance system without justified cause. The measure infringed a tenant’s privacy and resulted in unlawful processing of personal data.ESAEPDGDPR€2,000
11 May 2020Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32.SEIMYGDPR€11,321
30 Apr 2020vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR.NLAPGDPR€725,000
27 Apr 2020Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34.HUNAIHGDPR€21,150
09 Apr 2020Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF.HUNAIHGDPR€1,410
06 Apr 2020PETROLIS INDEPENDENTS, S.L.PETROLIS INDEPENDENTS, S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding cookie policies on its website. The case concerned information requirements and the compliance of cookie mechanisms with privacy rules.ESAEPDePrivacy€3,000
02 Apr 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 52,000 by the AEPD for sending SMS messages to a complainant about another customer's unpaid bills. The authority found that this disclosure breached data protection rules.ESAEPDGDPR€52,000
02 Apr 2020HAPPY FRIDAY, S.L.HAPPY FRIDAY, S.L. was fined by the AEPD in the amount of 2,500 EUR for failing to comply with data protection rules on the use of cookies. The authority found that the company did not provide the required information or obtain user consent.ESAEPDePrivacy€2,500
26 Mar 2020Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights.ITGaranteGDPR€10,000
26 Mar 2020Ügyfélszám téves rögzítésével összefüggő jogellenes adatkezelés és célhoz kötöttség elvének megsértéseThe controller unlawfully processed personal data related to a loan agreement, breaching the GDPR purpose limitation principle. NAIH imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
24 Mar 2020VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 1,500 EUR for retaining personal data after a deletion request. The case also involved sending an email to a former member despite consent being withdrawn, which breached GDPR requirements.ESAEPDGDPR€1,500
19 Mar 2020Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle.HUNAIHGDPR€5,620
11 Mar 2020SALAD MARKET S.L.SALAD MARKET S.L. was fined by the AEPD €3,000 for using video cameras to monitor employees without informing them. The company also added employees to WhatsApp groups without consent, which breached data protection rules.ESAEPDePrivacy€3,000
11 Mar 2020Google, rätten att få sökresultat borttagnaGoogle LLC was fined by IMY for processing sensitive personal data without a valid legal basis and for handling data relating to criminal offenses without authorization. The authority also found that Google did not respond promptly to requests for data removal, in breach of several GDPR provisions.SEIMYGDPR€6,993,000
10 Mar 2020Hørsholm KommuneThe Danish DPA reported Gladsaxe and Hørsholm Municipalities to the police for inadequate data security measures. The court fined Hørsholm Municipality DKK 50,000 for failing to encrypt computers containing sensitive personal data, which led to a data breach.DKDatatilsynetGDPR€6,692
09 Mar 2020OLIVEROS USTRELL, S.L.OLIVEROS USTRELL, S.L. was fined 10,000 EUR by the AEPD for unauthorized processing of a customer's personal and banking data. The case involved a fraudulent mobile contract and number portability carried out without a valid legal basis.ESAEPDGDPR€10,000
09 Mar 2020Személyes adat a természetes személy állandó használatában lévő telefonszámThe controller was fined for unlawfully processing the complainant's phone number. The authority found a breach of the GDPR principles of lawfulness and accuracy in personal data processing.HUNAIHGDPR€891
09 Mar 2020Dane anonimowe (V. Sp. z o.o. w likwidacji z siedzibą w Z. przy ul.)The President of UODO imposed a PLN 20,000 fine on V. Sp. z o.o. in liquidation for failing to provide access to personal data, other information, and premises. This prevented the authority from carrying out inspection activities necessary for its duties.PLUODOGDPR€4,637