Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Oct 2013Continental Terme srlContinental Terme srl was fined EUR 12,400 by the Garante for providing inadequate privacy notices and obtaining a single consent for multiple data processing activities. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€12,400
30 Oct 2013Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€80,000
30 Oct 2013Regione LazioRegione Lazio was fined EUR 12,000 by the Garante for collecting personal data through web forms without providing adequate information to data subjects. The authority found this to be a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€12,000
30 Oct 2013Comune di BolzanoComune di Bolzano was fined 10,000 EUR by the Garante for publishing sensitive health-related information about an employee’s absence on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
30 Oct 2013Ye BiYe Bi was fined by the Garante EUR 2,400 for operating a video surveillance system at Bar Millennium without the required signage. The authority found a breach of privacy regulations.ITGaranteGDPR€2,400
28 Nov 2013Axa società cooperativa a responsabilità limitataAxa società cooperativa a responsabilità limitata was fined by the Garante 46,000 EUR for using biometric systems to monitor employee attendance and working hours. The authority found that the processing took place without proper consent and required notifications, in breach of data protection rules.ITGaranteGDPR€46,000
28 Nov 2013Ma.CI.E. s.a.s di Favaro Stefano & C.Ma.CI.E. s.a.s was fined EUR 2,400 by the Garante for failing to provide the simplified information required under data protection rules. The breach concerned the use of a video surveillance system at the company’s premises.ITGaranteGDPR€2,400
05 Dec 2013Comune di San Felice CirceoThe Garante fined Comune di San Felice Circeo EUR 6,000 for failing to provide the information required under Art. 13 and for not updating the security program document under Art. 33. The authority also found non-compliance with a prior order.ITGaranteGDPR€6,000
05 Dec 2013Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority.ITGaranteGDPR€30,000
05 Dec 2013Langella AlessandroLangella Alessandro was fined EUR 2,400 by the Garante. The case concerned the failure to provide the required privacy notice on www.orofirst.it, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
18 Dec 2013Google Inc.Google Inc. was fined EUR 1 million by the Italian Data Protection Authority, Garante. The authority found that individuals were not adequately informed during data collection by Google cars for the Street View service.ITGaranteGDPR€1,000,000
18 Dec 2013Anonymised (HDPA 154/2013)The HDPA imposed a fine of EUR 3,000 on the company for unlawfully collecting an individual's creditworthiness data. The case concerned processing without a valid legal basis, which breaches data protection rules.GRHDPAGDPR€3,000
18 Dec 2013Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database.GRHDPAGDPR€5,000
18 Dec 2013Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website.ITGaranteGDPR€8,000
01 Jan 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD EUR 3,000 for sending unsolicited spam messages without providing an opt-out mechanism. The conduct breached Article 21 of the LSSI and failed to meet basic requirements for marketing communications.ESAEPDePrivacy€3,000
01 Jan 2014CTI WEB SERVICIOS INFORMATICOS S.L.CTI WEB SERVICIOS INFORMATICOS S.L. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited commercial emails. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€3,000
01 Jan 2014DREAM RING, S.L.DREAM RING, S.L. was fined by the AEPD EUR 6,000 for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior recipient consent.ESAEPDePrivacy€6,000
01 Jan 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD €3,000 for sending unsolicited commercial messages by electronic means. The conduct breached Article 21 of the LSSI, which prohibits such communications without prior consent.ESAEPDePrivacy€3,000
01 Jan 2014COMERCIAL POLINDUS 21, SLUCOMERCIAL POLINDUS 21, SLU was fined by the AEPD EUR 1,200 for sending an SMS to a number listed on the Robinson List. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€1,200
01 Jan 2014STAGE ENTERTAINMENT ESPAÑA, S.L.STAGE ENTERTAINMENT ESPAÑA, S.L. was fined by the AEPD 2,000 EUR for continuing to send commercial emails to a user despite repeated requests to delete their data and stop communications. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,000