Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Mar 2015Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data.ITGaranteGDPR€10,000
19 Mar 2015Liceo Statale "Farnesina"Liceo Statale Farnesina was fined EUR 4,000 by the Garante for unlawfully publishing lists of student names on its institutional website without a legal basis. The conduct breached data protection rules.ITGaranteGDPR€4,000
19 Mar 2015Trust Center A.E.The company was fined for failing to adequately inform data subjects about the processing of their creditworthiness data. The authority found a breach of Article 11 of the Greek data protection law.GRHDPAGDPR€3,000
20 Mar 2015IANO OIKONOMIKE EKDOSEIS AEIANO OIKONOMIKE EKDOSEIS AE was fined EUR 30,000 by the HDPA for sending unsolicited electronic communications. The company collected a large number of email addresses without consent, breaching data protection rules.GRHDPAePrivacy€30,000
26 Mar 2015Comune di SortinoComune di Sortino was fined for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the improper disclosure of sensitive data.ITGaranteGDPR€10,000
26 Mar 2015Artsana s.p.a.Artsana s.p.a. was fined by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
26 Mar 2015Lo.Ma. S.r.l.Lo.Ma. S.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned the activation of SIM cards without the knowledge of the individuals concerned, which breached data protection rules.ITGaranteGDPR€5,000
26 Mar 2015Okcom S.p.a.Okcom S.p.a. was fined EUR 40,000 by the Italian Garante. The authority found non-compliance with strong authentication requirements and a failure to notify the Garante about compliance with data protection measures.ITGaranteGDPR€40,000
26 Mar 2015Comune di Santa NinfaComune di Santa Ninfa was fined EUR 4,000 by the Garante for unlawfully publishing personal data on its institutional website. The data remained available for longer than the legally permitted 15 days, constituting a data protection breach.ITGaranteGDPR€4,000
31 Mar 2015VACACIONES EDREAMS, S.L.U.VACACIONES EDREAMS, S.L.U. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails despite the recipient’s request to unsubscribe. The case concerned a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request for direct marketing.ESAEPDePrivacy€2,500
31 Mar 2015GRAMMATA, S.L.GRAMMATA, S.L. was fined by the AEPD 1,100 EUR for sending unsolicited advertising emails. The authority also found that the company failed to provide a functional opt-out mechanism, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,100
02 Apr 2015Ministero dell'Interno – Dipartimento della Pubblica SicurezzaThe Ministry of the Interior – Department of Public Security was fined 4,000 EUR for publishing a ranking list containing personal data without a legal or regulatory basis. This constituted a breach of Article 19 of the Italian Privacy Code.ITGaranteGDPR€4,000
02 Apr 2015Comune di AccianoComune di Acciano was fined 4,000 EUR by the Garante for unlawfully processing personal data by keeping a council resolution online beyond the legally permitted period. The case concerned non-compliance with data protection rules on retention and publication limits.ITGaranteGDPR€4,000
02 Apr 2015Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization.ITGaranteGDPR€4,000
02 Apr 2015Ales Groupe Italia S.p.A.Ales Groupe Italia S.p.A. was fined EUR 20,000 by the Garante for violations related to data processing on its website. Users were asked to provide personal data without proper consent mechanisms.ITGaranteGDPR€20,000
02 Apr 2015Comune di FolloComune di Follo was fined for unlawfully communicating personal data of children under three years old to a private company. The authority found this breached Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
02 Apr 2015Regione CampaniaThe Garante fined Regione Campania EUR 4,000 for failing to provide requested information related to a disciplinary procedure. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
02 Apr 2015Schioppetti RaffaellaSchioppetti Raffaella was fined by the Italian data protection authority, Garante, in the amount of 15,000 EUR. The sanction concerned activating phone cards in individuals' names without their knowledge, which breached data protection rules.ITGaranteGDPR€15,000
02 Apr 2015Regione CalabriaRegione Calabria was fined EUR 80,000 by the Garante for failing to designate data processing officers and for only partially implementing IT security measures. The authority also noted a failure to respond to information requests, which required further investigation.ITGaranteGDPR€80,000
02 Apr 2015Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€15,000