Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Apr 2019Vincall s.r.l.sVincall s.r.l.s was fined EUR 2,018,000 by the Garante for failing to provide required information to individuals contacted during telemarketing activities. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,018,000
10 Apr 2019Anonymizováno (ÚOOÚ UOOU-06298/18-38)The entity was fined for repeatedly sending commercial communications without recipients’ consent. This breached § 7(2) of the Czech Act on Certain Information Society Services.CZUOOUePrivacy€1,406
05 Apr 2019Budapesti Műszaki és Gazdaságtudományi EgyetemBudapest University of Technology and Economics was fined 600,000 HUF by NAIH. The authority found that the university failed to comply with a data subject's request for access to personal data.HUNAIHGDPR€1,872
04 Apr 2019Ordinanza ingiunzione - 4 aprile 2019 [9117119]A municipal councillor was fined by the Garante for unlawfully disclosing personal data obtained from a document without legal justification. The authority found a breach of the principles of lawful processing and data protection.ITGaranteGDPR€4,000
04 Apr 2019Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
01 Apr 2019EL GYM IBERIA, S.L.EL GYM IBERIA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited marketing emails. This occurred despite a prior request to cancel personal data.ESAEPDePrivacy€2,500
01 Apr 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD EUR 60,000 for sending a marketing email that exposed the email addresses and names of more than eighty recipients. The authority found this breached the principles of data integrity and confidentiality.ESAEPDGDPR€60,000
28 Mar 2019Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose.ITGaranteGDPR€4,000
28 Mar 2019Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€8,000
26 Mar 2019А.Р. ЕООДThe CPDP imposed a 10,000 BGN fine on А.Р. ЕООД for processing personal data without consent. The case also involved registering an employment contract for an imprisoned individual, which breached Article 6 GDPR.BGCPDPGDPR€5,113
25 Mar 2019Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000.DKDatatilsynetGDPR€33,493
21 Mar 2019Demokratikus KoalícióThe Democratic Coalition was fined by NAIH 11,000,000 HUF for failing to meet incident notification and data subject communication obligations. The case involved a data breach affecting high-risk special category data.HUNAIHGDPR€34,980
21 Mar 2019Demokratikus KoalícióDemocratic Coalition was fined HUF 11,000,000 by the NAIH for failing to report a personal data breach. The authority also found that affected individuals were not informed, contrary to GDPR Articles 33 and 34.HUNAIHGDPR€34,980
19 Mar 2019Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees.ITGaranteGDPR€80,000
15 Mar 2019Dane anonimowe (X. Sp. z o.o., za naruszenie stwierdzone w niniejszej decyzji,)UODO found that X. Sp. z o.o. failed to comply with its information obligation. The decision ordered remediation of the breach and imposed a fine of PLN 943,470.PLUODOGDPR€219,000
14 Mar 2019Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
13 Mar 2019Anonymizováno (ÚOOÚ UOOU-12081/17-63)The entity was fined CZK 23,000 by the UOOU for repeatedly sending unsolicited commercial communications without recipients’ consent. The authority found this conduct breached Section 7 of the Czech Act on Certain Information Society Services.CZUOOUePrivacy€896
12 Mar 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending continuous SMS messages to a complainant despite a prior request to cancel personal data. The authority found this conduct to be a breach of data protection principles.ESAEPDGDPR€45,000
07 Mar 2019Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data.ITGaranteGDPR€10,000
28 Feb 2019Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period.ITGaranteGDPR€4,000