Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jul 2013Patronato ENCALPatronato ENCAL was fined by the Garante 10,000 EUR for failing to implement minimum security measures in the assignment and use of authentication credentials for access to INPS databases. The breach concerned inadequate access control over systems containing sensitive data.ITGaranteGDPR€10,000
11 Jul 2013Slots R Us srlSlots R Us srl was fined EUR 6,000 by the Garante for failing to provide the required information notice for its video surveillance system. The case concerned non-compliance with data protection rules on informing individuals subject to CCTV monitoring.ITGaranteGDPR€6,000
11 Jul 2013Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data.ITGaranteGDPR€14,400
15 Jul 2013ENTABAN SERVICIOS, S.C.ENTABAN SERVICIOS, S.C. was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The messages did not include a means for recipients to opt out, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
18 Jul 2013Hu YonglianHu Yonglian was fined by the Garante in the amount of EUR 2,400 for inadequate data protection notice in a retail store video surveillance system. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€2,400
18 Jul 2013Yang YijieYang Yijie was fined EUR 6,000 by the Garante for failing to provide the required privacy notice in connection with a video surveillance system at his business. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€6,000
19 Jul 2013ALL THE WORLD - COSMOS ONLINEThe company was fined for sending unsolicited marketing emails without obtaining prior consent from recipients. This conduct breached ePrivacy rules governing electronic communications.GRHDPAePrivacy€8,000
25 Jul 2013Anonymised (HDPA 90/2013)The HDPA imposed a EUR 500 fine on the anonymised entity for sending unsolicited marketing emails. The conduct breached the requirement to obtain subscriber consent before sending such communications.GRHDPAePrivacy€500
25 Jul 2013Fast-typeThe HDPA imposed a fine of EUR 1,000 on Fast-type for the illegal collection and further processing of personal data. The case concerns a breach of core data processing legality requirements.GRHDPAGDPR€1,000
25 Jul 2013Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements.GRHDPAGDPR€1,000
25 Jul 2013Axis Strategic Vision srlAxis Strategic Vision srl was fined by the Garante in the amount of 4,800 EUR for providing inadequate privacy notices on its websites. The authority found that the notices did not meet data protection requirements.ITGaranteGDPR€4,800
25 Jul 2013Fast-typeFast-type was fined EUR 500 by the HDPA for sending unsolicited marketing emails without subscriber consent. The case concerns a failure to obtain prior consent for marketing communications.GRHDPAePrivacy€500
29 Jul 2013ENDESA, S.A.ENDESA, S.A. was fined EUR 600 by the AEPD for sending commercial emails to a former customer despite requests to delete personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
30 Jul 2013GLOBAL GREECE M.E.P.EThe company was fined for sending marketing emails without obtaining subscribers' consent. The authority found a breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€5,000
09 Aug 2013General Secretariat for Information SystemsThe General Secretariat for Information Systems was fined EUR 150,000 by the HDPA for failing to implement appropriate security measures. The breach led to unauthorized processing of Greek taxpayers’ personal tax data from 2000 to 2012.GRHDPAGDPR€150,000
05 Sept 2013Top Secret S.r.l.Top Secret S.r.l. was fined by the Garante 6,000 EUR for collecting personal data through forms on its website without the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
05 Sept 2013Ri.Dat. di Boldetti RenatoRi.Dat. di Boldetti Renato was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional emails without proper consent, in breach of data protection rules.ITGaranteGDPR€4,000
05 Sept 2013Iniziative Commerciali S.r.l.Iniziative Commerciali S.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This breached the Italian Data Protection Code.ITGaranteGDPR€4,800
05 Sept 2013Perini GianfrancoPerini Gianfranco was fined EUR 2,400 by the Garante. The authority found that individuals were given inadequate data protection information, in breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
05 Sept 2013CURTIPETRIZZILANDIA S.a.sCURTIPETRIZZILANDIA S.a.s was fined by the Garante in the amount of 2,400 EUR for providing inadequate data protection information on its website booking form. The case concerned breaches of the information duties under the Italian Data Protection Code.ITGaranteGDPR€2,400