Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Feb 2014Regione PugliaRegione Puglia was fined EUR 20,000 by the Italian data protection authority, Garante. The breach involved unlawfully publishing health data of individuals with disabilities on its institutional website.ITGaranteGDPR€20,000
06 Feb 2014Genesis Consulting s.r.l.Genesis Consulting s.r.l. was fined EUR 4,000 by the Garante. The authority found that personal data collected through a website form were used for marketing purposes without adequate notice and without specific consent.ITGaranteGDPR€4,000
06 Feb 2014Anthea Preziosi s.a.s.Anthea Preziosi s.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned the collection of personal data through a website form without providing the required information notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
06 Feb 2014Oreiade s.r.l.Oreiade s.r.l. was fined by the Garante for installing a video surveillance system at Hotel Blu Inn without adequate safeguards. The authority found a breach of data protection rules.ITGaranteGDPR€24,400
30 Jan 2014impresa individuale Otelma di Belelli Marco AmletoThe sole proprietorship Otelma di Belelli Marco Amleto was fined EUR 6,400 by the Garante for failing to implement minimum security measures when processing sensitive data via its website. The breaches included not appointing a data processor and not preparing a security program document.ITGaranteGDPR€6,400
30 Jan 2014Orovicenza di Picaro CristinaOrovicenza di Picaro Cristina was fined EUR 4,800 by the Garante. The authority found that the website’s contact and registration forms did not provide the required data protection information, in breach of the Italian data protection code.ITGaranteGDPR€4,800
30 Jan 2014Comune di Reggio Emilia – Comando Polizia municipaleThe Municipality of Reggio Emilia's Police Command was fined EUR 2,400 by the Garante for operating a video surveillance system without simplified information signage. The authority found a breach of Article 13 of the Privacy Code.ITGaranteGDPR€2,400
24 Jan 2014TEMAR Y ASOCIADOS S.L.TEMAR Y ASOCIADOS S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€600
23 Jan 2014Impresa individuale Destro AnnaImpresa individuale Destro Anna was fined EUR 4,800 by the Garante. The violation concerned collecting personal data through a website form and using a video surveillance system without the required privacy information notice.ITGaranteGDPR€4,800
23 Jan 2014Valter Mancinelli BottoniValter Mancinelli Bottoni was fined 2,400 EUR by the Garante. The case concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system at a non-profit association.ITGaranteGDPR€2,400
17 Jan 2014CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD in the amount of 30,001 EUR for sending unsolicited commercial SMS messages. The authority also found that the messages did not include information on how to revoke consent, in breach of Article 21.2 of the LSSI.ESAEPDePrivacy€30,001
16 Jan 2014VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 41,000 EUR for sending commercial communications by email and SMS without the recipients’ consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for such messages.ESAEPDePrivacy€41,000
16 Jan 2014Bios Marx s.r.l.Bios Marx s.r.l. was fined by the Italian Garante in the amount of EUR 16,000 for providing an inadequate privacy notice during a medical initiative. The authority also found that personal data were shared with third parties without obtaining specific consent.ITGaranteGDPR€16,000
16 Jan 2014Hu ShaozengHu Shaozeng was fined EUR 2,400 by the Garante. The breach concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system in a commercial establishment.ITGaranteGDPR€2,400
09 Jan 2014Ordinanza ingiunzione - 9 gennaio 2014 [4785574]The Garante imposed a fine of EUR 4,000 for sending promotional emails without prior valid consent from recipients. The case concerns a breach of data protection rules and electronic marketing requirements.ITGaranteGDPR€4,000
09 Jan 2014Goldenbridge s.r.l.Goldenbridge s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice when collecting personal data through a website contact form. The authority found this to be a breach of the Italian data protection rules.ITGaranteGDPR€2,400
09 Jan 2014Giallooro s.r.lGiallooro s.r.l was fined EUR 2,400 by the Garante for collecting personal data through a website contact form without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
09 Jan 2014Virano s.n.c. di Virano Franco & C.Virano s.n.c. was fined by the Garante for collecting personal data through its website without providing an adequate privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
01 Jan 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD EUR 3,000 for sending unsolicited spam messages without providing an opt-out mechanism. The conduct breached Article 21 of the LSSI and failed to meet basic requirements for marketing communications.ESAEPDePrivacy€3,000
01 Jan 2014CTI WEB SERVICIOS INFORMATICOS S.L.CTI WEB SERVICIOS INFORMATICOS S.L. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited commercial emails. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€3,000