Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Dec 2014Value Retail Managment s.r.l.Value Retail Managment s.r.l. was fined EUR 36,000 by the Garante. The authority found that the company failed to provide adequate simplified information about its video surveillance system, in breach of data protection rules.ITGaranteGDPR€36,000
23 Jan 2014Valter Mancinelli BottoniValter Mancinelli Bottoni was fined 2,400 EUR by the Garante. The case concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system at a non-profit association.ITGaranteGDPR€2,400
26 Nov 2021Valoris Center S.R.L.Valoris Center S.R.L. was fined by ANSPDCP EUR 2,000 for a personal data processing security breach. The incident was caused by a call center employee.ROANSPDCPGDPR€2,000
18 Dec 2023Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles.HUNAIHGDPR€1,295
05 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated attempts to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€15,000
04 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD €20,000 for sending unauthorized commercial communications to a user after they had unsubscribed from the newsletter. The case indicates a failure to respect consent and opt-out requirements for marketing communications.ESAEPDePrivacy€20,000
30 Oct 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD €15,000 for sending unsolicited marketing emails despite the recipient’s attempts to unsubscribe. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€15,000
24 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 20,000 for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€20,000
03 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD EUR 20,000 for continuing to send marketing emails to a user who had repeatedly requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
06 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 15,000 for failing to honor unsubscribe requests from commercial newsletters. The case concerned a breach of Article 21.1 of the LSSI and indicates inadequate handling of marketing opt-out requests.ESAEPDePrivacy€15,000
30 Oct 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD 20,000 EUR for sending unsolicited commercial emails. The messages continued despite multiple requests from the recipient to unsubscribe.ESAEPDePrivacy€20,000
03 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined EUR 20,000 by the AEPD for continuing to send newsletters to the complainant despite multiple unsubscribe requests. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
31 Mar 2015VACACIONES EDREAMS, S.L.U.VACACIONES EDREAMS, S.L.U. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails despite the recipient’s request to unsubscribe. The case concerned a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request for direct marketing.ESAEPDePrivacy€2,500
01 Jan 2023VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€10,000
05 Jul 2022Üzleti titokra való hivatkozással hanganyag korlátozott felhasználhatósággal történő rendelkezésre bocsátásaThe authority fined the controller for failing to properly handle a data subject request. The case concerned a breach of the obligations under Article 12 GDPR.HUNAIHGDPR€4,900
01 Nov 2018UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures.NLAPGDPR€150,000
23 Nov 2020Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data.SEIMYGDPR€391,000
03 Oct 2023Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR.SEIMYGDPR€68,744
07 Oct 2020UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles.ESAEPDGDPR€5,000
06 Jun 2022URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L. was fined by the AEPD 2,000 EUR for failing to notify a personal data breach in time. The case concerns the Article 33 GDPR obligation to report breaches to the supervisory authority.ESAEPDGDPR€2,000