Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Jun 2019Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed.HUNAIHGDPR€3,090
31 May 2019Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach.HUNAIHGDPR€2,156
29 May 2019Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights.ITGaranteGDPR€10,000
28 May 2019Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
27 May 2019VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined 35,000 EUR by the AEPD for processing personal data without consent. The case involved charging a former customer for services not contracted due to a technical error.ESAEPDGDPR€35,000
23 May 2019Ítélet a NAIH/2019/1189/11 sz. ügyben (Fővárosi Törvényszék 105.K.700.364/2019/11)The controller did not provide the requested personal data or information beyond a 2012 lease agreement. This breached the data subject’s access rights under the GDPR.HUNAIHGDPR€918
23 May 2019Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects.HUNAIHGDPR€91,800
23 May 2019Telenor Magyarország Zrt.Telenor Magyarország Zrt. was fined by the Hungarian NAIH 300,000 HUF for failing to comply with a data subject access request under the GDPR. The authority also found that the company did not inform the data subject of the right to an effective legal remedy.HUNAIHGDPR€918
23 May 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD for assigning a customer's DNI to a third party. This enabled unauthorized access to personal data and invoices, constituting a data protection breach.ESAEPDGDPR€60,000
23 May 2019Ordinanza ingiunzione - 23 maggio 2019 [9124593]The Garante imposed a fine of EUR 1,250 for the loss of medical documentation related to a patient's health assessment. The records were not found in either paper or electronic form, which constituted a breach of data protection rules.ITGaranteGDPR€1,250
23 May 2019Bérleti jogviszony során keletkezett dokumentumok másolatban történő kiadásaThe controller did not comply with the data subject's access request for personal data beyond the 2012 lease agreement. The authority treated this as a breach of access-right obligations and imposed a fine.HUNAIHGDPR€918
23 May 2019Comune di FerraraComune di Ferrara was fined 2,400 EUR by the Garante for violations linked to its online registry service. The system allowed citizens to obtain personal and civil status certificates at municipal pharmacies without adequate data protection measures.ITGaranteGDPR€2,400
23 May 2019Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing.HUNAIHGDPR€918
21 May 2019Ferencvárosi Szociális és Gyermekjóléti Intézmények IgazgatóságaThe Ferencvárosi Social and Child Welfare Institutions Directorate was fined for failing to report a personal data breach within the required deadline. The incident involved documents sent to the wrong address, triggering the notification duty under GDPR Article 33.HUNAIHGDPR€306
16 May 2019ANANEOSI MONOPROSOPI E.P.E.The company was fined for making unsolicited marketing calls to subscribers registered on the opt-out list. It also failed to properly identify itself during the calls, which hindered data subjects’ ability to exercise their rights.GRHDPAePrivacy€5,000
16 May 2019SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects.ITGaranteGDPR€4,000
06 May 2019Regione AbruzzoThe Garante fined Regione Abruzzo EUR 4,000 for violations linked to data processing through public service apps. The authority found that adequate data protection and security measures were not ensured.ITGaranteGDPR€4,000
06 May 2019ENDESA ENERGÍA XXI, S.L.U.ENDESA ENERGÍA XXI, S.L.U. was fined by the AEPD 100,000 EUR for a data protection breach. An agent mistakenly altered a contract, replacing the complainant’s data with that of a third party.ESAEPDGDPR€100,000
25 Apr 2019Dane anonimowe (E. z siedzibą w O. przy ul.)The UODO found a breach of rules on the security and confidentiality of processed personal data. As a result, a fine of PLN 55,750.50 was imposed.PLUODOGDPR€12,980
11 Apr 2019AD Sphera Group s.r.l.AD Sphera Group s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400