Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Mar 2017Cigno d’Argento s.r.l.Cigno d’Argento s.r.l. was fined by the Garante 36,000 EUR for data protection violations. The case concerned the improper use of video surveillance systems without the required authorization.ITGaranteGDPR€36,000
18 Apr 2013Tel. Com. s.r.l.Tel. Com. s.r.l. was fined EUR 36,000 by the Garante for registering numerous phone cards to unaware third parties. The company failed to provide the required information on data processing, which breached privacy rules.ITGaranteGDPR€36,000
21 Sept 2017Unidata s.p.a.Unidata s.p.a. was fined EUR 36,000 by the Garante for failing to implement adequate security measures for personal data processing. The authority noted, among other issues, the use of passwords shorter than eight characters, which breached data protection requirements.ITGaranteGDPR€36,000
17 Nov 2011Impresa individuale Implantomat di Guidi CristianoThe company was fined EUR 36,000 by the Garante for unlawfully publishing and distributing advertising flyers that featured an individual's image without consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€36,000
04 Dec 2014Value Retail Managment s.r.l.Value Retail Managment s.r.l. was fined EUR 36,000 by the Garante. The authority found that the company failed to provide adequate simplified information about its video surveillance system, in breach of data protection rules.ITGaranteGDPR€36,000
06 Jun 2018Azienda Unità Sanitaria Locale di PiacenzaAzienda Unità Sanitaria Locale di Piacenza was fined by the Garante EUR 36,000 for creating electronic health records without informing patients or obtaining their consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€36,000
05 Mar 2012GRANDES ALMACENES FNAC ESPAÑA S.A.The AEPD fined GRANDES ALMACENES FNAC ESPAÑA S.A. 36,000 EUR for sending unsolicited marketing emails to a customer who had opted out. The conduct breached the LSSI rules on electronic communications and recipient consent.ESAEPDePrivacy€36,000
29 Dec 2022Dane anonimowe (S. Sp. z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 36,558 on the company. The sanction concerned failure to cooperate with the authority and failure to provide information necessary for the performance of its tasks.PLUODOGDPR€7,802
24 Feb 2014DTS DISTRIBUIDORA DE TELEVISION DIGITAL, S.A.DTS DISTRIBUIDORA DE TELEVISION DIGITAL, S.A. was fined by the AEPD in the amount of EUR 37,000 for continuing to send unsolicited emails to a former customer. The conduct occurred after the customer requested deletion of their data and breached Article 21 of the LSSI.ESAEPDePrivacy€37,000
05 Sept 2012NOVOPRINT C.B.NOVOPRINT C.B. was fined by the AEPD in the amount of 38,000 EUR for sending commercial emails to LLACRUTECH, S.L. despite requests to remove the address from mailing lists. The authority found this to be a breach of the LSSI rules on electronic communications.ESAEPDePrivacy€38,000
01 Jan 2015TEKOA CANAL TV S.L.TEKOA CANAL TV S.L. was fined EUR 39,000 by the AEPD for sending 29 commercial SMS messages without prior consent from recipients. The messages also did not include an opt-out option, in breach of the LSSI.ESAEPDePrivacy€39,000
21 Feb 2014INSTITUCIÓN EUROAMERICANA DE FORMACIÓN E.I.R.L.The entity was fined by the AEPD in the amount of 39,000 EUR for sending unsolicited commercial emails without prior recipient consent. This constituted a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€39,000
13 May 2015Iperal S.p.A.Iperal S.p.A. was fined EUR 40,000 by the Garante for activating 11 phone cards in the names of 5 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€40,000
15 Aug 2024Coastal Windows & Conservatories (UK) LimitedCoastal Windows & Conservatories (UK) Limited made more than 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people who said they had not consented to the calls or continued to receive them after asking for the calls to stop.GBICOGDPR€46,720
10 Oct 2024Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice.GBICOePrivacy€47,796
01 Jan 2019VODAFONE ESPAÑA, S.A.U.Vodafone España was fined 40,000 EUR by the AEPD for charging a customer for a Netflix service that had not been contracted. The authority found a breach of GDPR Article 6 due to the lack of a lawful basis for the charge and related processing.ESAEPDGDPR€40,000
20 Oct 2011Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users.ITGaranteGDPR€40,000
06 Sept 2023Simply Connecting LtdSimply Connecting Ltd sent 441,830 direct marketing text messages to individuals in breach of regulation 22 of PECR. The ICO imposed a £40,000 fine and issued an enforcement notice.GBICOePrivacy€46,780
14 Feb 2013Face2Face s.r.l.Face2Face s.r.l. was fined EUR 40,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide the required privacy notice and did not obtain specific consent from data subjects before processing their data.ITGaranteGDPR€40,000
02 Feb 2012Casa di cura Villa Giustina s.r.l.Casa di cura Villa Giustina s.r.l. was fined 40,000 EUR by the Garante. The authority found that the company failed to submit the required notification for personal data processing activities under the Italian Data Protection Code.ITGaranteGDPR€40,000