Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Jun 2015Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry.ITGaranteGDPR€4,000
04 Jun 2015Direzione Casa Circondariale di BariDirezione Casa Circondariale di Bari was fined €10,000 by the Garante for unlawfully processing sensitive data. The authority found that it collected, stored, and communicated the names of participants in a union demonstration without initiating any disciplinary proceedings, in breach of data protection law.ITGaranteGDPR€10,000
11 Jun 2015Banca Nazionale del Lavoro S.p.a.Banca Nazionale del Lavoro S.p.a. was fined by the Garante 32,000 EUR for processing personal data without first informing the data subjects and without obtaining their consent. The case concerns a breach of core notice and consent obligations in personal data processing.ITGaranteGDPR€32,000
11 Jun 2015Quotidiano Il Tempo s.r.l.Quotidiano Il Tempo s.r.l. was fined by the Garante EUR 8,400 for processing personal data without providing adequate information to subscribers. The authority also found that the company used a video surveillance system without the simplified notice required under privacy rules.ITGaranteGDPR€8,400
11 Jun 2015Allevi BortoloAllevi Bortolo was fined EUR 15,000 by the Garante for activating fourteen phone cards in the names of five individuals without their knowledge. The conduct breached data protection rules and led to supervisory enforcement.ITGaranteGDPR€15,000
12 Jun 2015ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data.GRHDPAGDPR€100,000
12 Jun 2015JAZZ TELECOM S.A.U.JAZZ TELECOM S.A.U. was fined by the AEPD EUR 2,900 for continuing to send advertising SMS messages to a user despite multiple requests to stop. The authority found a breach of Article 21 of the LSSI on unsolicited marketing communications.ESAEPDePrivacy€2,900
12 Jun 2015ALPHA BANKALPHA BANK was fined 30,000 EUR by the HDPA. The authority found that the bank failed to notify the location and facilities used for ICAP data processing.GRHDPAGDPR€30,000
12 Jun 2015Tiresias AETiresias AE was fined for failing to implement measures to control access to personal data files. This failure led to unauthorized access by ICAP.GRHDPAGDPR€30,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed for failing to maintain appropriate organizational and technical security measures. This led to unauthorized employee access to the complainant's personal data.GRHDPAGDPR€5,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed on Eurobank Ergasias AE for unlawful processing of the complainant’s personal data. The case concerned a breach of data protection rules by the bank.GRHDPAGDPR€5,000
18 Jun 2015Azienda USL5 di PisaAzienda USL5 di Pisa was fined EUR 6,000 for unlawful processing of personal data through a video surveillance system. The authority found that the required information notice was not provided to individuals, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
18 Jun 2015Wind Telecomunicazioni SpaWind Telecomunicazioni Spa was fined EUR 130,000 by the Garante. The case concerned the unlawful disclosure of mobile phone numbers in the White Pages directory without proper consent.ITGaranteGDPR€130,000
18 Jun 2015Azienda Ospedaliera Ospedale di Circolo Fondazione MacchiAzienda Ospedaliera Ospedale di Circolo Fondazione Macchi was fined by the Garante 4,000 EUR for processing sensitive personal data without obtaining written consent. This breached the Italian Data Protection Code. The case highlights the need for a valid legal basis before processing special-category data.ITGaranteGDPR€4,000
18 Jun 2015Martino MarangellaMartino Marangella was fined EUR 2,400 by the Garante for failing to provide simplified information about the use of a video surveillance system. The authority treated this as a breach of data protection rules.ITGaranteGDPR€2,400
18 Jun 2015Comune di MurosComune di Muros was fined EUR 12,000 by the Garante. The authority found that the municipality failed to provide information and unlawfully published personal data revealing health status on its website.ITGaranteGDPR€12,000
19 Jun 2015TEKOA CANALTV, S.L.TEKOA CANALTV, S.L. was fined by the AEPD in the amount of 55,000 EUR for sending 25 commercial SMS messages without prior consent from recipients. The authority also noted the absence of an opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€55,000
24 Jun 2015Telefónica Móviles España SAUTelefónica Móviles España SAU was fined by the AEPD 12,500 EUR for sending unauthorized commercial SMS messages. The authority also found that the company failed to provide a simple opt-out mechanism, in breach of LSSI rules.ESAEPDePrivacy€12,500
25 Jun 2015San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data.ITGaranteGDPR€24,000
25 Jun 2015Comune di ParmaComune di Parma was fined EUR 4,000 by the Garante for unlawfully publishing candidates' personal data on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€4,000