Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Dec 2013Anonymised (HDPA 154/2013)The HDPA imposed a fine of EUR 3,000 on the company for unlawfully collecting an individual's creditworthiness data. The case concerned processing without a valid legal basis, which breaches data protection rules.GRHDPAGDPR€3,000
18 Dec 2013Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database.GRHDPAGDPR€5,000
18 Dec 2013Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website.ITGaranteGDPR€8,000
05 Dec 2013Comune di San Felice CirceoThe Garante fined Comune di San Felice Circeo EUR 6,000 for failing to provide the information required under Art. 13 and for not updating the security program document under Art. 33. The authority also found non-compliance with a prior order.ITGaranteGDPR€6,000
05 Dec 2013Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority.ITGaranteGDPR€30,000
05 Dec 2013Langella AlessandroLangella Alessandro was fined EUR 2,400 by the Garante. The case concerned the failure to provide the required privacy notice on www.orofirst.it, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
28 Nov 2013Axa società cooperativa a responsabilità limitataAxa società cooperativa a responsabilità limitata was fined by the Garante 46,000 EUR for using biometric systems to monitor employee attendance and working hours. The authority found that the processing took place without proper consent and required notifications, in breach of data protection rules.ITGaranteGDPR€46,000
28 Nov 2013Ma.CI.E. s.a.s di Favaro Stefano & C.Ma.CI.E. s.a.s was fined EUR 2,400 by the Garante for failing to provide the simplified information required under data protection rules. The breach concerned the use of a video surveillance system at the company’s premises.ITGaranteGDPR€2,400
30 Oct 2013Continental Terme srlContinental Terme srl was fined EUR 12,400 by the Garante for providing inadequate privacy notices and obtaining a single consent for multiple data processing activities. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€12,400
30 Oct 2013Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€80,000
30 Oct 2013Regione LazioRegione Lazio was fined EUR 12,000 by the Garante for collecting personal data through web forms without providing adequate information to data subjects. The authority found this to be a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€12,000
30 Oct 2013Comune di BolzanoComune di Bolzano was fined 10,000 EUR by the Garante for publishing sensitive health-related information about an employee’s absence on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
30 Oct 2013Ye BiYe Bi was fined by the Garante EUR 2,400 for operating a video surveillance system at Bar Millennium without the required signage. The authority found a breach of privacy regulations.ITGaranteGDPR€2,400
29 Oct 2013ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 35,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests to be removed from the mailing list.ESAEPDePrivacy€35,000
28 Oct 2013LEGALITAS ASISTENCIA LEGAL, S.L.LEGALITAS ASISTENCIA LEGAL, S.L. was fined by the AEPD 33,000 EUR for sending unsolicited commercial communications. The conduct continued despite requests for data cancellation, which breached Article 21 of the LSSI.ESAEPDePrivacy€33,000
28 Oct 2013HERBORISTERÍA TRÉBOL-HIDROLINFA C.B.HERBORISTERÍA TRÉBOL-HIDROLINFA C.B. was fined EUR 600 by the AEPD for sending a commercial email without providing a valid electronic address for recipients to object to the processing of their data for advertising purposes. The authority found a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€600
24 Oct 2013Comune di Torre CajetaniComune di Torre Cajetani was fined by the Garante for unlawfully publishing an individual's health data on a public notice board. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
24 Oct 2013Stadek sncStadek snc was fined EUR 4,000 by the Garante for non-compliant video surveillance signage. The case concerns a breach of data protection requirements related to informing individuals about surveillance.ITGaranteGDPR€4,000
24 Oct 2013Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate.ITGaranteGDPR€4,000
24 Oct 2013SANITAS S.A.SANITAS S.A. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails. The authority found that the required information clause was missing, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200