Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Jun 2014Ecaterina GypjasEcaterina Gypjas was fined by the Garante for failing to provide adequate simplified information about the use of a video surveillance system in her hotel. The authority found a breach of data protection rules.ITGaranteGDPR€2,400
05 Jun 2014Comune di TerniThe Garante fined Comune di Terni €4,000 for publishing personal data on its website for longer than the legally permitted 15 days. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
05 Jun 2014Ministero della GiustiziaThe Ministry of Justice was fined for unlawfully publishing personal data on its institutional website without a legal basis. The disclosure included names, dates of birth, and tax codes, in breach of data protection rules.ITGaranteGDPR€4,000
05 Jun 2014Ing. Claudio ZiniThe individual enterprise of Ing. Claudio Zini was fined for sending unsolicited promotional emails. The authority also found that the required information notice under Article 13 of the Italian Privacy Code was not provided.ITGaranteGDPR€2,400
12 Jun 2014Poligrafici Editoriale s.p.a.Poligrafici Editoriale s.p.a. was fined by the Garante 12,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found improper collection of personal data through subscription coupons.ITGaranteGDPR€12,400
12 Jun 2014Mediolanum Hotel s.r.l.Mediolanum Hotel s.r.l. was fined by the Garante 2,400 EUR for processing personal data related to job applications without providing the required notice under Article 13 of the Italian Data Protection Code. The breach concerned the absence of the mandatory privacy information for job applicants.ITGaranteGDPR€2,400
12 Jun 2014H3g s.p.a.H3g s.p.a. was fined EUR 75,000 by the Garante for violations related to customer profiling without the required consent. The case concerned personal data processing that did not comply with data protection requirements.ITGaranteGDPR€75,000
12 Jun 2014La Pergola s.r.l.La Pergola s.r.l. was fined EUR 4,800 by the Garante for collecting personal data through its website without the required information notice. This breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€4,800
12 Jun 2014Istituto Poligrafico e Zecca dello Stato S.p.AIstituto Poligrafico e Zecca dello Stato S.p.A was fined EUR 60,000 by the Garante. The authority found that the company did not fully implement required security measures, in particular the logging of system administrator access to electronic archives.ITGaranteGDPR€60,000
26 Jun 2014CO.RE.MA. di Gian Luigi Morando & C. s.a.s.CO.RE.MA. was fined by the Garante EUR 12,000 for using an integrated video surveillance system that allowed viewing images from workplaces. Required safeguards were not implemented, including logical separation of recordings from different data controllers.ITGaranteGDPR€12,000
26 Jun 2014Omnia energia s.p.a.Omnia energia s.p.a. was fined EUR 8,400 by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority also found that required information was not provided on the company’s website, in breach of data protection rules.ITGaranteGDPR€8,400
26 Jun 2014Sudmetal s.r.l.Sudmetal s.r.l. was fined for using an integrated video surveillance system that allowed images from workplaces to be viewed without the required safeguards. The authority found this to be a breach of privacy regulations.ITGaranteGDPR€12,000
26 Jun 2014Mitomet s.r.l.Mitomet s.r.l. was fined 12,000 EUR by the Garante for using an integrated video surveillance system. The system allowed viewing images from workplaces without implementing the required privacy safeguards.ITGaranteGDPR€12,000
30 Jun 2014ATRAPALO, S.L.ATRAPALO, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails to a user who had previously requested to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
03 Jul 2014Tenacta Group s.p.a.Tenacta Group s.p.a. was fined 10,000 EUR by the Garante for making unsolicited promotional phone calls. The company failed to consult the public opposition register, thereby violating the subscriber's right to object.ITGaranteGDPR€10,000
10 Jul 2014Clinica Siligato s.r.l.Clinica Siligato s.r.l. was fined for failing to notify the Garante of certain processing activities involving health data. The case concerned data used to detect infectious diseases and HIV status, which had to be reported under the Italian Data Protection Code.ITGaranteGDPR€8,000
10 Jul 2014Comune di OrbetelloThe Municipality of Orbetello was fined EUR 10,000 by the Italian data protection authority, Garante. The sanction concerned the publication of individuals’ personal health data on the municipality’s official website, in breach of privacy rules.ITGaranteGDPR€10,000
10 Jul 2014Onbrand Call s.r.lOnbrand Call s.r.l was fined by the Garante for processing personal data through a web form without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
24 Jul 2014Future srlFuture srl was fined EUR 36,000 by the Garante for making unsolicited promotional phone calls without proper consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€36,000
24 Jul 2014Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000