Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Oct 2017Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
04 Oct 2017PRENATAL SAPRENATAL SA was fined by the AEPD EUR 20,000 for sending commercial SMS messages without providing recipients with an opt-out mechanism. The case concerns a breach of electronic communications rules and marketing consent requirements.ESAEPDePrivacy€20,000
21 Sept 2017Tra.n.sider S.p.A.Tra.n.sider S.p.A. was fined EUR 20,000 by the Italian Garante. The case concerned the failure to notify the installation of a geolocation system on company vehicles, breaching data protection notification requirements.ITGaranteGDPR€20,000
21 Sept 2017AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
21 Sept 2017Unidata s.p.a.Unidata s.p.a. was fined EUR 36,000 by the Garante for failing to implement adequate security measures for personal data processing. The authority noted, among other issues, the use of passwords shorter than eight characters, which breached data protection requirements.ITGaranteGDPR€36,000
19 Sept 2017CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€3,300
13 Sept 2017Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication.ITGaranteGDPR€20,000
13 Sept 2017NO QUIERO PERDER EL TIEMPO, S.L.The company was fined by the AEPD for displaying the AEPD quality seal and another association’s seal on its website without authorization. The authority also found inadequate information and no valid consent for data collection.ESAEPDePrivacy€8,000
13 Sept 2017Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller.ITGaranteGDPR€14,800
13 Sept 2017MASTERZEN, S.L.MASTERZEN, S.L. was fined by the AEPD €4,500 for sending unsolicited marketing emails without the recipient’s consent. The emails were sent despite the recipient’s objection, indicating a breach of rules on direct electronic marketing.ESAEPDePrivacy€4,500
13 Sept 2017Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
12 Sept 2017Little Kook - K. Tzortzis – I. Thanos I.K.EThe company was fined EUR 7,000 by the HDPA for operating a video surveillance system without proper notification to the authority. It also monitored employee workspaces, which breached privacy requirements.GRHDPAGDPR€7,000
06 Sept 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending commercial SMS messages without consent. The authority also found that recipients were not given an effective option to object, in breach of the LSSI rules.ESAEPDePrivacy€66,000
04 Aug 2017VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations.GRHDPAGDPR€5,000
04 Aug 2017STAPLES PRODUCTOS DE OFICINA S.L.U.STAPLES PRODUCTOS DE OFICINA S.L.U. was fined EUR 2,000 by the AEPD for sending unsolicited commercial emails. The breach involved continuing to contact recipients despite requests to cancel consent.ESAEPDePrivacy€2,000
04 Aug 2017VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing.GRHDPAGDPR€10,000
04 Aug 2017VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD in the amount of 6,000 EUR for making numerous advertising calls to numbers registered on the Robinson List. The conduct breached privacy rules and the right to object to direct marketing.ESAEPDePrivacy€6,000
26 Jul 2017Equilibra s.r.l.Equilibra s.r.l. was fined by the Garante for failing to provide adequate data protection information to individuals and for not appointing the required data processing officers. The case concerned breaches of the Italian Data Protection Code.ITGaranteGDPR€12,400
26 Jul 2017Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements.ITGaranteGDPR€4,000
26 Jul 2017Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules.ITGaranteGDPR€40,000