Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Jan 2018Trivenet s.r.l.Trivenet s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company retained call data longer than permitted under data protection rules.ITGaranteGDPR€40,000
25 Jan 2018Scaramuzza MarioScaramuzza Mario was fined EUR 140,000 by the Garante for the unauthorized activation of multiple payment cards using personal data without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and the absence of a valid legal basis.ITGaranteGDPR€140,000
25 Jan 2018ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles.ITGaranteGDPR€20,000
18 Jan 2018Telecom Italia S.p.A.Telecom Italia S.p.A. was fined EUR 840,000 by the Garante for making promotional phone calls to individuals who had not consented to the processing of their data for marketing purposes. The case indicates a breach of lawful processing rules and consent requirements.ITGaranteGDPR€840,000
18 Jan 2018C.S. GROUP S.p.a.C.S. GROUP S.p.a. was fined by the Italian Garante in the amount of €60,000. The case concerned profiling and the processing of personal data without a proper legal basis in connection with vehicle rental services.ITGaranteGDPR€60,000
18 Jan 2018KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code.ITGaranteGDPR€180,000
18 Jan 2018Italia Consulenza e Formazione s.r.l.Italia Consulenza e Formazione s.r.l. was fined EUR 32,000 by the Garante for sending promotional emails without proper consent. The case concerns a breach of data protection rules governing direct marketing.ITGaranteGDPR€32,000
15 Jan 2018Alkis Alqi Zarbala ZarballaA fine was imposed for operating a video surveillance system without the required notification and for monitoring employee workspaces. These actions breached data protection rules.GRHDPAGDPR€1,000
11 Jan 2018N.J.L. & Time di Bernasconi NadiaN.J.L. & Time di Bernasconi Nadia was fined 68,000 EUR by the Garante. The authority found that promotional emails were sent without proper consent, in breach of data protection rules.ITGaranteGDPR€68,000
01 Jan 2018VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 20,000 EUR by the AEPD for sending unsolicited marketing emails. The authority found that recipients were not given an effective unsubscribe option, despite a request to be removed from the mailing list.ESAEPDePrivacy€20,000
01 Jan 2018IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia 5,700 EUR for sending unsolicited commercial emails to a complainant. The company had previously confirmed the cancellation of the complainant’s personal data, yet it continued marketing communications, breaching Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
01 Jan 2018CANARY ISLANDS CAR S.L.CANARY ISLANDS CAR S.L. was fined by the AEPD 45,000 EUR for inaccurate processing of personal data. As a result, a traffic violation was incorrectly attributed to a person who had not rented the vehicle.ESAEPDGDPR€45,000
01 Jan 2018CAFETERÍA NAGASAKICAFETERÍA NAGASAKI was fined by the AEPD 1,500 EUR for using surveillance cameras to capture images of public sidewalks without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
01 Jan 2018LIGA NACIONAL DE FÚTBOL PROFESIONALThe Spanish Data Protection Agency (AEPD) fined LIGA NACIONAL DE FÚTBOL PROFESIONAL for using a mobile app to indiscriminately capture ambient sounds. This could have resulted in the processing of personal data without the consent of the individuals concerned.ESAEPDGDPR€500,000
01 Jan 2018MAISONS DU MONDE ESPAÑA, S.L.MAISONS DU MONDE ESPAÑA, S.L. was fined by the AEPD 15,000 EUR for sending unsolicited commercial SMS messages. The company did not provide recipients with an effective opt-out mechanism, despite prior requests to unsubscribe.ESAEPDePrivacy€15,000
01 Jan 2018ZARA LIBRO S.L. (DIFUSIÓN DEL LIBRO)ZARA LIBRO S.L. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial email without a prior commercial relationship. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
01 Jan 2018PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited promotional emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic commercial communications.ESAEPDePrivacy€1,000
01 Jan 2018SHANA RETAIL S.L.SHANA RETAIL S.L. was fined by the AEPD for improperly disposing of documents containing personal data. The breach concerned data protection rules and the need to prevent unauthorized disclosure of information.ESAEPDGDPR€15,000
01 Jan 2018ADGOALS MEDIA S.L.ADGOALS MEDIA S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS advertisements without prior recipient consent. The authority also found that no opt-out mechanism was provided, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,500
01 Jan 2018G.L. GISOFT ANÁLISIS Y DISEÑO, S.L.G.L. GISOFT ANÁLISIS Y DISEÑO, S.L. was fined 600 EUR by the AEPD. The case concerned the sending of unsolicited commercial emails, which breaches Article 21.1 of the LSSI.ESAEPDePrivacy€600