Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jul 2016Impresa Individuale Autosalone Ag. Car di Vitale AldoThe company collected personal data, including name and email address, through its website. It did not provide the required privacy notice, which breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
22 Jun 2016Aemme Car S.r.l.Aemme Car S.r.l. was fined by the Garante in the amount of 2,400 EUR for collecting personal data through its website without providing users with the required information notice. This conduct breached the Italian data protection code.ITGaranteGDPR€2,400
22 Jun 2016Autoverde 07 s.r.l.Autoverde 07 s.r.l. was fined by the Garante in the amount of 2,400 EUR for processing customers’ personal data through its website without providing adequate information. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,400
22 Jun 2016Istituto Maria Angelica Miliziano s.r.l.Istituto Maria Angelica Miliziano s.r.l. was fined by the Garante 2,400 EUR for collecting users’ personal data through its website without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
22 Jun 2016Società Territorio Turismo & Sport s.r.l.Società Territorio Turismo & Sport s.r.l. was fined by the Garante 2,400 EUR. The case concerned collecting personal data, including name and email, via its website without providing users with the required information notice.ITGaranteGDPR€2,400
21 Jun 2016Česká republika – Ministerstvo školství, mládeže a tělovýchovyThe Czech Republic’s Ministry of Education, Youth and Sports was fined by the UOOU for processing sensitive personal data about students’ disabilities without a legal basis. The case indicates a breach of personal data protection rules and requires review of the lawful basis and data scope.CZUOOUGDPR€7,390
09 Jun 2016Angela BellavitaAngela Bellavita was fined EUR 2,400 by the Italian Garante. The case concerned the collection of personal data, including name, surname, and email address, through a website contact form without providing users with adequate information.ITGaranteGDPR€2,400
09 Jun 2016Montanaro Auto s.r.l.Montanaro Auto s.r.l. was fined by the Garante in the amount of 4,800 EUR for failing to provide data subjects with information about data processing. The breach concerned a video surveillance system and a web form, in violation of the Italian Data Protection Code.ITGaranteGDPR€4,800
09 Jun 2016Comune di LevantoThe Municipality of Levanto was fined EUR 4,000 by the Garante for publishing on its website a list of candidates for regional contributions. The disclosure of personal data lacked sufficient legal basis and breached data protection rules.ITGaranteGDPR€4,000
02 Jun 2016TELEFONICA MOVILES ESPAÑA, S.A.U.Telefónica Móviles España was fined €20,000 by the AEPD for using “supercookies” without properly informing users or obtaining their consent. The authority found this conduct to be in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€20,000
01 Jun 2016Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
01 Jun 2016Ordinanza ingiunzione - 1 giugno 2016 [5423590]A paramedical professional processed clients’ personal data for health purposes without providing the required privacy notice or obtaining consent. The Garante found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€6,400
01 Jun 2016Azienda per i servizi sanitari n. 2 IsontinaAzienda per i servizi sanitari n. 2 Isontina was fined for unlawfully publishing personal data, including negative performance evaluations, of an individual on its institutional website. The conduct breached data protection rules.ITGaranteGDPR€4,000
01 Jun 2016Liceo Scientifico di Stato G. BattagliniLiceo Scientifico di Stato G. Battaglini was fined by the Garante 10,400 EUR for processing staff biometric data without providing the required information. The authority also found that the processing had not been notified as required by law.ITGaranteGDPR€10,400
30 May 2016UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L.UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L. was fined EUR 800 by the AEPD for sending unsolicited commercial emails. The authority found that the messages continued despite the recipient’s attempts to unsubscribe.ESAEPDePrivacy€800
19 May 2016GRUPO YAMM COMIDA A DOMICILIO, S.L.GRUPO YAMM COMIDA A DOMICILIO, S.L. was fined by the AEPD €1,400 for sending unsolicited commercial emails to a complainant despite requests to stop. The case concerns a breach of the LSSI rules on marketing communications.ESAEPDePrivacy€1,400
18 May 2016Istituto Robert Kennedy s.r.l.Istituto Robert Kennedy s.r.l. was fined EUR 2,400 by the Italian Garante for providing clients with inadequate information about data processing. The authority found a breach of the information duties under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
18 May 2016Accademia Dante Alighieri s.r.l.Accademia Dante Alighieri s.r.l. was fined by the Garante 2,400 EUR for collecting personal data from users through its websites without providing the required information or obtaining consent. The conduct breached Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 May 2016Auto 2000 s.p.a.Auto 2000 s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 May 2016Auto 2000 s.p.a.Auto 2000 s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400