Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Oct 2018OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact.GRHDPAePrivacy€150,000
09 Oct 2018CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules.GRHDPAePrivacy€150,000
27 Sept 2018Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ATDSBGDPR€300
27 Sept 2018Anonymizováno (ÚOOÚ UOOU-05291/17-44)The entity was fined for repeatedly sending commercial communications to specified electronic addresses without consent and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€3,111
26 Sept 2018VILAN DATAMINING SLVILAN DATAMINING SL was fined by the AEPD €800 for sending unsolicited commercial emails. The messages did not provide a way to exercise the rights of access, rectification, cancellation, or objection.ESAEPDePrivacy€800
21 Sept 2018XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD in the amount of 4,000 EUR for sending unsolicited commercial SMS messages without the recipient’s consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for marketing communications.ESAEPDePrivacy€4,000
21 Sept 2018Anonymizováno (ÚOOÚ UOOU-01895/18-25)The entity was fined by the UOOU for processing personal data without consent and for failing to implement adequate security measures. The authority found these actions to be in breach of Czech data protection law.CZUOOUGDPR€1,173
17 Sept 2018TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 900 for sending unsolicited advertising emails to an individual who was not a customer. The case concerns a breach of data protection rules governing direct marketing communications.ESAEPDePrivacy€900
14 Sept 2018IAHORRO BUSINESS SOLUTIONS SLIAHORRO BUSINESS SOLUTIONS SL was fined by the AEPD €1,000 for sending unsolicited commercial electronic communications. The company also failed to provide a procedure for exercising rights of access, rectification, cancellation, or objection.ESAEPDePrivacy€1,000
29 Aug 2018Anonymizováno (ÚOOÚ UOOU-08277/18-40)The entity was fined for sending unsolicited commercial communications by electronic means without recipients' consent. This breached Czech rules on information society services.CZUOOUePrivacy€3,496
21 Aug 2018Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements.GRHDPAGDPR€5,000
21 Aug 2018Alpha BankAlpha Bank was fined by the HDPA for failing to maintain and process accurate data of its debtors. The authority found that the bank’s conduct breached data protection requirements.GRHDPAGDPR€10,000
21 Aug 2018National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations.GRHDPAGDPR€5,000
20 Aug 2018Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services.CZUOOUePrivacy€54,460
09 Aug 2018InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000.NLAPGDPR€48,000
30 Jul 2018А.С.К. УМБАЛ ЕООДThe CPDP found that “А.С.К. УМБАЛ ЕООD” unlawfully processed personal data by providing it to “МБАЛ-В. ЕООD” without consent. This breached data protection rules and resulted in a fine of BGN 1,000.BGCPDPGDPR€511
27 Jul 2018Anonymizováno (ÚOOÚ UOOU-08596/17-64)The individual was fined for publishing the personal data of a municipal social department employee on Facebook. The authority found a breach of confidentiality obligations under Czech law.CZUOOUGDPR€117
26 Jul 2018Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
26 Jul 2018Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data.ITGaranteGDPR€10,000
26 Jul 2018Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules.ITGaranteGDPR€26,000