Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Oct 2012MYID ESPAÑA S.L.MYID ESPAÑA S.L. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,200
11 Oct 2012Casa di cura Eretenia S.p.a.The Garante fined Casa di cura Eretenia S.p.a. €30,000 for failing to provide proper data protection notices in its video surveillance system. The authority found a breach of privacy rules and the duty to inform individuals subject to monitoring.ITGaranteGDPR€30,000
11 Oct 2012Professional Pneus sccrlProfessional Pneus sccrl was fined EUR 10,400 by the Garante. The authority found that personal data were processed without giving users the option to refuse consent for marketing purposes, breaching transparency requirements.ITGaranteGDPR€10,400
11 Oct 2012Azienda sanitaria provinciale di Vibo ValentiaAzienda sanitaria provinciale di Vibo Valentia was fined by the Garante EUR 15,000 for failing to adopt the required minimum security measures. The authority found that the Security Programmatic Document (DPS) was not updated by the deadline required under the Italian Privacy Code.ITGaranteGDPR€15,000
04 Oct 2012Abbanoa s.p.a.Abbanoa s.p.a. was fined EUR 28,000 by the Garante for failing to provide the required privacy notice in its video surveillance systems. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€28,000
04 Oct 2012Ministero dell'Istruzione, dell'Università e della Ricerca - Direzione generale per l'università, lo studente e il diritto allo studio universitarioThe Ministry of Education, University and Research was fined by the Garante for unlawfully disclosing personal data on its website. The authority found no legal basis for the processing.ITGaranteGDPR€20,000
04 Oct 2012American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing.ITGaranteGDPR€40,000
26 Sept 2012DIGITARAN, S.L.U.DIGITARAN, S.L.U. was fined by the AEPD 3,000 EUR for sending unsolicited advertising SMS messages to a user registered on the Robinson List. The conduct breached Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
20 Sept 2012Casa di cura privata Montevergine s.p.a.The private clinic Montevergine was fined 50,000 EUR by the Garante. The authority found that it processed employees' biometric data for attendance tracking without first notifying the supervisory authority.ITGaranteGDPR€50,000
20 Sept 2012Policlinico Sassarese s.p.a.Policlinico Sassarese s.p.a. was fined EUR 64,000 by the Garante for inadequate data protection measures. The authority cited insufficient video surveillance notices and missing consent documentation for the processing of sensitive data.ITGaranteGDPR€64,000
13 Sept 2012Ruzzo Reti S.p.a.Ruzzo Reti S.p.a. was fined EUR 4,000 by the Italian Garante. The authority found that the company failed to designate data processors, meaning it did not adopt the minimum security measures required by the Italian Privacy Code.ITGaranteGDPR€4,000
13 Sept 2012YVES ROCHER ESPAÑA, S.A.YVES ROCHER ESPAÑA, S.A. was fined EUR 47,001 by the AEPD for continuing to send advertising emails to an individual who had requested data deletion and confirmation of that deletion. The authority found that marketing communications continued despite the request.ESAEPDePrivacy€47,001
10 Sept 2012GRUPO ENLACE FOCAM S.L.U.GRUPO ENLACE FOCAM S.L.U. was fined by the AEPD EUR 600 for sending an unsolicited commercial email without the recipient’s consent. The case concerned Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent.ESAEPDePrivacy€600
06 Sept 2012BT Italia s.p.a.BT Italia s.p.a. was fined by the Garante EUR 75,000 for sending unsolicited promotional faxes without recipient consent. The conduct breached data protection and direct marketing rules.ITGaranteGDPR€75,000
06 Sept 2012One Italia S.p.A.One Italia S.p.A. was fined €20,000 by the Garante for sending promotional MMS messages without obtaining prior consent from recipients. The conduct breached Articles 23 and 130 of the Italian Data Protection Code.ITGaranteGDPR€20,000
06 Sept 2012Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules.ITGaranteGDPR€34,000
05 Sept 2012NOVOPRINT C.B.NOVOPRINT C.B. was fined by the AEPD in the amount of 38,000 EUR for sending commercial emails to LLACRUTECH, S.L. despite requests to remove the address from mailing lists. The authority found this to be a breach of the LSSI rules on electronic communications.ESAEPDePrivacy€38,000
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information.GRHDPAGDPR€7,500
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data.GRHDPAGDPR€7,500
01 Aug 2012S.I.G.A.T. s.r.l.S.I.G.A.T. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 13,400. The case concerned the sending of unsolicited promotional faxes without prior consent from recipients.ITGaranteGDPR€13,400