Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2017SERVICIOS DE INFORMACIÓN SOBRE LOS FICHEROS DE MOROSOS S.L.The entity sent commercial emails and SMS without proper consent and did not honor recipients’ objections. These actions breached data protection rules.ESAEPDePrivacy€1,000
01 Jan 2017ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior recipient consent.ESAEPDePrivacy€5,000
01 Jan 2017SOCIEDAD AIR FRANCE, S.A.Air France was fined by the AEPD EUR 7,000 for sending emails to a complainant despite a request to delete the personal data. The case concerns a breach of data protection rules and improper processing after a deletion request.ESAEPDePrivacy€7,000
22 Dec 2016Comune di VergatoComune di Vergato was fined by the Garante for retaining surveillance footage beyond the permitted period. The case concerned non-compliance with data protection rules on storage limitation and video retention.ITGaranteGDPR€12,000
22 Dec 2016Planetel s.r.l.Planetel s.r.l. was fined by the Garante in the amount of EUR 30,000 for using inadequate authentication procedures to access telecommunication traffic data. The authority also found that required security measures for data storage were not implemented.ITGaranteGDPR€30,000
15 Dec 2016Ordinanza ingiunzione - 15 dicembre 2016 [6526145]The Garante imposed a EUR 72,000 fine for sending promotional SMS messages without the recipients’ consent. The contact data came from a database obtained through agreements with a German company, which involved the transfer of personal data abroad.ITGaranteGDPR€72,000
15 Dec 2016Stireria Rosa di HU XINStireria Rosa di HU XIN was fined 2,400 EUR by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system covering public areas.ITGaranteGDPR€2,400
01 Dec 2016Adda Gestioni Industriali e Mobiliari s.p.a.Adda Gestioni Industriali e Mobiliari S.p.a. was fined by the Garante 2,400 EUR for improper data processing through a video surveillance system. The authority found that adequate notices were not provided for external cameras monitoring the parking area.ITGaranteGDPR€2,400
01 Dec 2016Wu KuanzhaoWu Kuanzhao was fined EUR 2,400 by the Garante. The authority found that data subjects were not informed about the processing of personal data through a video surveillance system.ITGaranteGDPR€2,400
01 Dec 2016L'ABBONDANZA s.r.l.L'ABBONDANZA s.r.l. was fined 2,400 EUR by the Garante. The authority found that the company failed to provide data subjects with information about the processing of personal data through a video surveillance system.ITGaranteGDPR€2,400
24 Nov 2016Minerv@ s.r.l.Minerv@ s.r.l. was fined by the Garante 10,000 EUR for sending promotional emails to a complainant after they objected and requested deletion of their data. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€10,000
24 Nov 2016Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules.ITGaranteGDPR€10,000
24 Nov 2016Unione Comunale del Chianti fiorentinoUnione Comunale del Chianti fiorentino was fined by the Garante 10,000 EUR for publishing on its website the personal data of individuals who were not admitted to a financial benefit. The conduct breached data protection rules.ITGaranteGDPR€10,000
24 Nov 2016Provincia di VercelliProvincia di Vercelli was fined EUR 10,000 by the Garante for unlawfully publishing personal data on its institutional website. The disclosed information included photocopies of identity cards and bank account numbers, without an appropriate legal basis.ITGaranteGDPR€10,000
10 Nov 2016Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined for making an unauthorized advertising phone call. The company also failed to respond to information requests from the Garante.ITGaranteGDPR€4,000
10 Nov 2016Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined by the Garante for making an unsolicited promotional call to a number listed in the public opposition registry. The conduct breached data protection rules.ITGaranteGDPR€10,000
10 Nov 2016Comune di Sant'AgnelloComune di Sant'Agnello was fined EUR 4,000 by the Garante. The authority found that personal data of children had been published on the municipality's website, in breach of privacy rules.ITGaranteGDPR€4,000
10 Nov 2016Funworld s.r.l.Funworld s.r.l. was fined €2,400 by the Garante for failing to respond to a request for information concerning the unlawful processing of personal data through a video surveillance system. The case concerned a failure to cooperate with the supervisory authority.ITGaranteGDPR€2,400
27 Oct 2016Studio Medico Odontoiatrico Associato Gimmelli B. & G.Studio Medico Odontoiatrico Associato Gimmelli B. & G. was fined by the Garante for unlawfully processing personal data by disclosing it to Ina Assitalia s.p.a. without obtaining the required informed consent from the data subject. The case reflects a breach of core lawful-processing requirements.ITGaranteGDPR€6,400
27 Oct 2016Porto di Imperia s.p.a.Porto di Imperia s.p.a. was fined by the Italian Garante in the amount of €2,400. The authority found a data protection breach linked to the use of a video surveillance system because individuals entering the port were not provided with simplified information.ITGaranteGDPR€2,400