Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jul 2020Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed.FITSVGDPR€7,000
05 Jul 2021Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose.FITSVGDPR€25,000
14 May 2020Anonymizováno (ÚOOÚ spr-563809-118)The entity was fined for operating a camera system without meeting the information obligations required under Czech data protection law. The case concerns a breach of transparency duties toward individuals subject to surveillance.CZUOOUGDPR€145
14 Jun 2018Anonymizováno (ÚOOÚ UOOU-00051/18-14)The entity was fined for processing the personal data of apartment building residents through a camera system without their consent. The authority found this to be a breach of Czech data protection law.CZUOOUGDPR€2,339
24 Jul 2018Anonymizováno (ÚOOÚ UOOU-00078/17-47)The entity was fined CZK 400,000 by the UOOU for processing customers' personal data without their consent. The authority found this conduct to be in breach of the Czech Data Protection Act.CZUOOUGDPR€15,528
20 Dec 2019Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€4,716
08 Oct 2020Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations.CZUOOUGDPR€6,459
25 Oct 2021Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services.CZUOOUePrivacy€1,166
11 Dec 2018Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR.CZUOOUGDPR€3,869
22 Dec 2020Anonymizováno (ÚOOÚ UOOU-004103/19-31)The company was fined for unlawfully processing personal data of members of homeowners' associations by publishing the data on its website without consent. The authority found this conduct to be in breach of the GDPR.CZUOOUGDPR€1,141
07 Aug 2023Anonymizováno (ÚOOÚ UOOU-00414.23-30)The decision confirms a fine for a healthcare entity for failing to notify data subjects and document a personal data breach after a cyberattack. The authority found breaches of GDPR transparency and notification obligations.CZUOOUGDPR€12,756
23 Mar 2021Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules.CZUOOUePrivacy€382
19 Jul 2018Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules.CZUOOUGDPR€386
15 Dec 2021Anonymizováno (ÚOOÚ UOOU-01071/21-30)The entity was fined by the UOOU for repeatedly sending unsolicited commercial communications to electronic contacts without prior consent. The messages also failed to clearly identify the sender or label the content as commercial.CZUOOUePrivacy€11,871
24 Oct 2019Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified.CZUOOUePrivacy€391
18 Jan 2017Anonymizováno (ÚOOÚ UOOU-01178/17-265)The company was fined for repeatedly sending unsolicited commercial communications without a legal basis. The case concerned a breach of the Czech law on certain information society services.CZUOOUePrivacy€14,064
08 Aug 2016Anonymizováno (ÚOOÚ UOOU-01297/16-48)The individual was fined for operating surveillance cameras that recorded personal data without a legal basis. The case concerns a breach of privacy and personal data protection rules.CZUOOUGDPR€185
21 Sept 2018Anonymizováno (ÚOOÚ UOOU-01895/18-25)The entity was fined by the UOOU for processing personal data without consent and for failing to implement adequate security measures. The authority found these actions to be in breach of Czech data protection law.CZUOOUGDPR€1,173
04 Mar 2021Anonymizováno (ÚOOÚ UOOU-02022/20-24)The entity was fined for unauthorized publication of personal data of thirty individuals on a website. The authority found a breach of the basic principles of personal data processing under GDPR.CZUOOUGDPR€5,724
23 Dec 2020Anonymizováno (ÚOOÚ UOOU-02528/20-14)The entity was fined by the UOOU for breaching a legal prohibition on disclosing personal data under another regulation. The case concerned information about criminal proceedings and the persons involved.CZUOOUGDPR€38