Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jan 2020COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images.ESAEPDGDPR€5,000
29 Jan 2020CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules.ESAEPDGDPR€10,000
24 Jan 2020Adatbiztonsági intézkedések és incidenskezelési gyakorlat hiányosságaiThe entity failed to implement appropriate technical and organizational measures to protect data, including storing access data in printed form. Its internal incident management policy also did not regulate the obligation to notify the supervisory authority.HUNAIHGDPR€1,490
23 Jan 2020Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5.ITGaranteGDPR€80,000
23 Jan 2020Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures.ITGaranteGDPR€30,000
22 Jan 2020Res iudicata terjedelme a hozzáférési kérelem elbírálása kapcsánThe controller did not adequately respond to the data subject’s access request, breaching Article 15 GDPR. NAIH imposed a fine of HUF 2,000,000.HUNAIHGDPR€5,960
16 Jan 2020VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt.ESAEPDGDPR€120,000
15 Jan 2020TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules.ITGaranteGDPR€27,802,000
15 Jan 2020Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action.ITGaranteGDPR€10,000
14 Jan 2020REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules.ESAEPDGDPR€6,000
12 Jan 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for charging a customer for a service that had not been contracted. The case concerned non-compliance with consent requirements linked to data processing and service billing.ESAEPDGDPR€100,000
10 Jan 2020AUTOMOCION X.X.X. S.L.The company was fined EUR 1,000 by the AEPD for placing an individual's photo, name, and phone number on an adult contact website without consent. The disclosure led to unwanted calls and constituted a breach of personal data protection rules.ESAEPDGDPR€1,000
10 Jan 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information.ESAEPDGDPR€30,000
07 Jan 2020CHENMING YE (BAZAR REAL)CHENMING YE (BAZAR REAL) was fined EUR 900 by the AEPD. The authority found that the required visible notice identifying the data controller was missing, which breached data protection rules.ESAEPDGDPR€900
06 Jan 2020дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR.BGCPDPGDPR€5,113
01 Jan 2020B.B.B.B.B.B. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial SMS to the complainant after confirming deletion of the complainant’s personal data. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
01 Jan 2020BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€5,000
01 Jan 2020Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status.ESAEPDGDPR€5,000
01 Jan 2020PERSONAL MARK, S.L.PERSONAL MARK, S.L. was fined by the AEPD 10,000 EUR for failing to diligently delete personal data from its databases despite the complainant’s requests. The case indicates inadequate handling of data erasure obligations.ESAEPDGDPR€10,000
01 Jan 2020DOUGLAS SPAIN, S.A.U.DOUGLAS SPAIN, S.A.U. was fined by the AEPD 2,700 EUR for continuing to send advertising emails to a complainant after confirming deletion of the complainant’s personal data. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,700