Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2019LINEA DIRECTA ASEGURADORA, S.A.LINEA DIRECTA ASEGURADORA, S.A. was fined by the AEPD for sending unsolicited advertising emails without a prior relationship with the recipient. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
01 Jan 2019GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR.ESAEPDGDPR€25,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
20 Dec 2018Anonymisiert (DSB DSB-D550.037/0003-DSB/2018)The DSB imposed a fine of EUR 2,200 for unlawful video surveillance covering common areas and neighboring properties without consent. The conduct breached GDPR principles of data minimization and purpose limitation.ATDSBGDPR€2,200
18 Dec 2018ORGANIZACION NACIONAL DE CIEGOS (ONCE)ONCE was fined EUR 40,000 by the AEPD for sending more than 200 unsolicited commercial emails without prior consent. The authority found this to be a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€40,000
13 Dec 2018Anonymizováno (ÚOOÚ UOOU-08001/18-14)The entity was fined 40,000 CZK by the UOOU for insufficient security measures in the processing of personal data. The authority cited inadequate audit logs and a lack of regular access checks to electronic health records.CZUOOUGDPR€1,549
13 Dec 2018Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine.ITGaranteGDPR€8,000
13 Dec 2018Ministero dell’Istruzione, dell’Università e della Ricerca – Ufficio Scolastico Regionale per la Lombardia – Ufficio III – Ambito territoriale di BergamoThe Ministry of Education’s regional office in Bergamo was fined for unlawfully publishing personal data related to disciplinary proceedings on its website. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
11 Dec 2018Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR.CZUOOUGDPR€3,869
29 Nov 2018Wind Tre S.p.A.Wind Tre S.p.A. was fined EUR 600,000 by the Garante for unsolicited promotional calls and SMS. The authority found breaches of several provisions of the Italian Data Protection Code.ITGaranteGDPR€600,000
29 Nov 2018Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
21 Nov 2018Legea s.p.a.Legea s.p.a. was fined for processing personal data through forms on its website without providing the required information notice to data subjects. The case concerned a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
19 Nov 2018VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 5,000 EUR for breaching data quality principles. The company incorrectly included personal data in a creditworthiness file despite a prior order to correct billing errors.ESAEPDGDPR€5,000
19 Nov 2018Anonymizováno (ÚOOÚ UOOU-04674/18-33)The entity was fined for repeatedly sending unsolicited commercial communications to email addresses without the recipients’ consent. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€577
07 Nov 2018Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
07 Nov 2018Comune di Castel MaggioreComune di Castel Maggiore was fined by the Garante for publishing personal data on its institutional website without a legal basis. The case concerned a breach of data protection rules and unauthorized disclosure of information.ITGaranteGDPR€4,000
01 Nov 2018UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures.NLAPGDPR€150,000
09 Oct 2018WIND HELLAS TELECOMMUNICATIONS S.A.The fine was imposed for making unsolicited marketing calls to subscribers who had opted out of such contact. This conduct breached privacy and data protection rules.GRHDPAePrivacy€150,000
09 Oct 2018Vodafone-PanafonVodafone-Panafon was fined by the HDPA for making unsolicited marketing calls to subscribers who had opted out of such contact. The authority found that the conduct breached privacy and data protection rules.GRHDPAePrivacy€12,000