Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 May 2015V.V.S. s.r.l. Viaggi Vacanze Soggiorni StudioV.V.S. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €2,400. The case concerned the collection of personal data through website forms without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
07 May 2015Comune di BagnoregioComune di Bagnoregio was fined by the Garante for unlawfully publishing personal data on its website. The conduct breached the conditions set out in the Italian data protection code.ITGaranteGDPR€4,000
13 May 2015Iperal S.p.A.Iperal S.p.A. was fined EUR 40,000 by the Garante for activating 11 phone cards in the names of 5 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€40,000
13 May 2015Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images.ITGaranteGDPR€16,800
13 May 2015HellastatHellastat was fined by the HDPA EUR 5,000 for the illegal collection and use of data. The case concerned a breach of data protection laws.GRHDPAGDPR€5,000
13 May 2015Provincia di NapoliProvincia di Napoli was fined for unlawfully publishing personal data, including health information, on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
13 May 2015HellastatHellastat was fined EUR 3,000 by the HDPA for failing to inform data subjects. The authority found a breach of data protection rules requiring transparent notice to individuals.GRHDPAGDPR€3,000
13 May 2015Gelpi Elettrodomestici S.r.l.Gelpi Elettrodomestici S.r.l. was fined 30,000 EUR by the Garante. The case concerned the activation of SIM cards in individuals' names without their knowledge, which breached data protection rules.ITGaranteGDPR€30,000
13 May 2015Ottodue s.r.l.Ottodue s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 98 days. This exceeded the 7-day retention limit set out in the video surveillance guidelines.ITGaranteGDPR€12,000
13 May 2015ASL Napoli 2 NordASL Napoli 2 Nord was fined 20,000 EUR by the Garante for publishing personal data on its website. The disclosed information could reveal individuals' health status, which breached privacy rules.ITGaranteGDPR€20,000
13 May 2015Comune di LandrianoComune di Landriano was fined for processing personal data of children enrolling in the municipal nursery without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
13 May 2015Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images.ITGaranteGDPR€16,800
18 May 2015ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 5,000 EUR for sending commercial emails to a recipient who had requested to unsubscribe. The case concerns a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request.ESAEPDePrivacy€5,000
21 May 2015BONANZA DIGITAL SERVICES, S.L.BONANZA DIGITAL SERVICES, S.L. was fined EUR 35,000 by the AEPD for sending 20 unsolicited advertising SMS messages without prior consent. The company also failed to provide an opt-out mechanism, breaching the LSSI.ESAEPDePrivacy€35,000
28 May 2015Xpedite Systems s.r.l.Xpedite Systems s.r.l. was fined 64,000 EUR by the Garante for sending unsolicited promotional faxes without the required notice and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€64,000
28 May 2015El Dom S.a.s.El Dom S.a.s. was fined EUR 174,000 by the Garante for activating 185 phone cards under the names of 58 individuals without their knowledge. The case involved a breach of data protection rules and the unauthorized use of personal identification data.ITGaranteGDPR€174,000
28 May 2015People & Comunication s.r.l.People & Comunication s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company retained telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code.ITGaranteGDPR€20,000
28 May 2015Tex97 s.r.l.Tex97 s.r.l. was fined EUR 20,000 by the Italian data protection authority, Garante. The company retained customers' telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code.ITGaranteGDPR€20,000
04 Jun 2015SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent.ITGaranteGDPR€4,000
04 Jun 2015Comune di Vico EquenseThe Municipality of Comune di Vico Equense was fined 20,000 EUR by the Garante. The authority found that the security program document was not updated and data processing officers were not appointed, which allowed unauthorized access to sensitive data.ITGaranteGDPR€20,000