Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jun 2013Comune di PadovaComune di Padova was fined by the Garante 10,000 EUR for unlawfully publishing personal data online beyond the legally permitted period. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,000
20 Jun 2013ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems.ITGaranteGDPR€18,000
20 Jun 2013Terme di Montecatini s.p.a.Terme di Montecatini s.p.a. was fined by the Garante in the amount of 10,000 EUR. The company processed personal and sensitive data of national health service patients undergoing spa treatments without obtaining consent, in breach of Article 23 of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Jun 2013Terme di Agnano s.p.a.Terme di Agnano s.p.a. was fined EUR 16,000 by the Garante for processing personal and sensitive data of individuals undergoing thermal treatments without the required notice and consent. The authority also found that personal data of job applicants were processed without providing the mandatory information notice.ITGaranteGDPR€16,000
13 Jun 2013Mafeco S.r.l.Mafeco S.r.l. was fined by the Garante in the amount of EUR 6,000 for failing to provide the required privacy notice when collecting personal data through website forms. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
13 Jun 2013BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€64,000
13 Jun 2013Vito GiacoiaVito Giacoia was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice for a video surveillance system at the “Fratelli Venaria” club, in breach of the Italian Privacy Code.ITGaranteGDPR€2,400
13 Jun 2013Hotel Villa Las Tronas s.r.l.Hotel Villa Las Tronas s.r.l. was fined EUR 2,400 by the Garante for failing to provide simplified information about video surveillance. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,400
11 Jun 2013MUNDO TOUR ESPAÑA, S.L.MUNDO TOUR ESPAÑA, S.L. was fined by the AEPD EUR 1,200 for sending commercial emails without the recipients’ consent. The conduct breached Article 21.2 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€1,200
04 Jun 2013UN LUGAR DIFERENTE. S.L.UN LUGAR DIFERENTE. S.L. was fined by the AEPD for sending unauthorized commercial SMS messages to a customer. The messages were sent despite the customer's prior request to opt out.ESAEPDePrivacy€600
03 Jun 2013BBVA SERVICIOS, S.A.BBVA SERVICIOS, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
24 May 2013RIZOS S.L.RIZOS S.L. was fined by the AEPD EUR 1,800 for sending commercial messages without providing information on how to opt out. This breached Article 21.2 of the LSSI, which requires a clear unsubscribe option for recipients.ESAEPDePrivacy€1,800
24 May 2013ARGATEL SOLUTIONS SLARGATEL SOLUTIONS SL was fined EUR 600 by the AEPD. The sanction concerned sending unsolicited premium SMS advertisements without recipient consent, in breach of Article 21.2 of the LSSI.ESAEPDePrivacy€600
22 May 2013Romulus PopescuRomulus Popescu was fined EUR 16,000 by the Garante. The sanction concerned sending unsolicited promotional communications to a minor without proper consent.ITGaranteGDPR€16,000
22 May 2013Margiotta Pietro Antonio e ASL TA 1 – Azienda Sanitaria Locale di TarantoThe Garante fined Margiotta Pietro Antonio and ASL TA 1 10,000 EUR for failing to implement minimum security measures. In some departments, unauthorized personnel accessed patient data and shared authentication credentials were used.ITGaranteGDPR€10,000
15 May 2013Chen JingChen Jing was fined by the Italian Garante in the amount of EUR 2,400 for providing inadequate information about a video surveillance system at Ottimoda S.a.s. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
15 May 2013You & Me di Borille FabrizoYou & Me di Borille Fabrizo was fined EUR 4,000 by the Italian Garante. The sanction concerned the failure to respond to requests for information about surveillance cameras, which breached data protection rules.ITGaranteGDPR€4,000
15 May 2013HU YonghuHU Yonghu was fined EUR 6,000 by the Garante for failing to provide the required privacy notice for the restaurant surveillance system. The case concerned non-compliance with the Italian Data Protection Code.ITGaranteGDPR€6,000
08 May 2013Agro Informatica di Buracchi GinoAgro Informatica di Buracchi Gino was fined 32,000 EUR by the Garante for sending unsolicited promotional emails without prior explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€32,000
08 May 2013Profile 2100 srlProfile 2100 srl was fined EUR 10,400 by the Garante for sending unsolicited promotional communications by fax without valid consent. The case concerned a breach of data protection rules and direct marketing requirements.ITGaranteGDPR€10,400