Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 May 2018Mercuri SalvatoreMercuri Salvatore was fined by the Garante EUR 60,000 for making unsolicited promotional calls to individuals whose phone numbers were listed in the opposition register. This conduct infringed their right to object to such communications.ITGaranteGDPR€60,000
09 May 2018Telefonika s.r.l.sTelefonika s.r.l.s was fined by the Italian data protection authority, Garante, in the amount of EUR 42,000. The sanction concerned numerous unsolicited promotional phone calls made without proper consent.ITGaranteGDPR€42,000
09 May 2018Sioufas and Partners Law FirmThe law firm was fined for operating a video surveillance system that covered workspaces without proper justification. It also failed to notify the authority in a timely manner and did not inform individuals about the surveillance, breaching several provisions of Greek data protection law.GRHDPAGDPR€50,000
09 May 2018SO.LOG. SrlSO.LOG. Srl was fined EUR 8,000 by the Italian data protection authority, Garante. The sanction concerned the failure to properly notify processing activities related to vehicle geolocation, in breach of the Italian Privacy Code.ITGaranteGDPR€8,000
09 May 2018Ditta individuale “La Scuola della Salute di Francesco Parisi”The Garante imposed a 15,000 EUR fine on Ditta individuale “La Scuola della Salute di Francesco Parisi” for providing inadequate privacy information to clients and for related consent issues. The conduct was found to violate provisions of the privacy code.ITGaranteGDPR€15,000
09 May 2018Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures.ITGaranteGDPR€20,000
03 May 2018Marconi RobertoMarconi Roberto, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum security measures to protect patients' personal and sensitive data were not adopted, allowing unauthorized access to the healthcare system.ITGaranteGDPR€10,000
03 May 2018Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
03 May 2018Omis s.p.a.Omis s.p.a. was fined by the Garante 8,000 EUR for failing to notify the processing of geolocation data from vehicles. This notification was required under privacy regulations.ITGaranteGDPR€8,000
03 May 2018Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code.ITGaranteGDPR€20,000
26 Apr 2018Gianluigi GuarinoGianluigi Guarino, director of the online newspaper Casertace.net, was fined by the Garante. The sanction concerned his failure to respond to an information request about data processing, which breached Article 164 of the Italian Privacy Code.ITGaranteGDPR€20,000
26 Apr 2018Falotico Luca CarmeloFalotico Luca Carmelo, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
26 Apr 2018MTS s.r.l.s.MTS s.r.l.s. was fined EUR 76,000 by the Garante for making unsolicited promotional calls. The company also failed to respond to the authority's request for information, which constituted a data protection breach.ITGaranteGDPR€76,000
26 Apr 2018Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions.ITGaranteGDPR€10,000
26 Apr 2018Raffaele FrancescoRaffaele Francesco was fined by the Garante for processing the personal data of five patients without the required consent during dental services. The conduct breached the Italian Privacy Code.ITGaranteGDPR€20,000
23 Apr 2018Anonymizováno (ÚOOÚ UOOU-06702/17-47)The entity was fined CZK 50,000 by the UOOU for failing to cooperate during an inspection. The authority found a breach of the duty to create conditions for the inspection and provide necessary assistance.CZUOOUGDPR€1,968
18 Apr 2018Consorzio “Marte Euroservice”Consorzio “Marte Euroservice” was fined EUR 30,000 by the Garante for sending promotional emails without recipients’ consent. The company also exposed email addresses to multiple recipients, creating an additional data protection breach.ITGaranteGDPR€30,000
18 Apr 2018Anonymizováno (ÚOOÚ UOOU-09774/17-25)The entity was fined for processing personal data of hundreds of thousands of individuals without consent or another legal basis. The authority found this to be a breach of § 5(2) of the Czech Data Protection Act.CZUOOUGDPR€31,616
18 Apr 2018Futur3 s.r.l.Futur3 s.r.l. was fined EUR 50,000 by the Garante for requiring users to give mandatory consents for marketing and profiling purposes that were not directly related to the requested Wi‑Fi service. The authority found this to be a breach of data protection rules.ITGaranteGDPR€50,000
18 Apr 2018Anas S.p.A.Anas S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to designate employees as data processors and for not issuing instructions on the proper use of surveillance and geolocation systems. The authority found that these omissions breached data protection rules.ITGaranteGDPR€20,000