Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2016AUTOCLUB MUTUA MADRILEÑA S.L.AUTOCLUB MUTUA MADRILEÑA S.L. was fined by the AEPD 5,000 EUR for sending an unsolicited commercial SMS without prior consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2016PROSAD CONSULTORES S.L.PROSAD CONSULTORES S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The recipient had not given prior consent and was listed on the Robinson List, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€800
01 Jan 2016WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD €4,100 for sending unsolicited commercial communications by electronic means. The authority found that the legal requirements for such communications were not met.ESAEPDePrivacy€4,100
01 Jan 2016HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI.ESAEPDePrivacy€3,400
01 Jan 2016BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI.ESAEPDePrivacy€8,000
01 Jan 2016TELE PIZZA S.A.U.TELE PIZZA S.A.U. was fined EUR 2,500 by the AEPD for sending commercial emails without providing a valid electronic address for exercising ARCO rights. This breached Article 21.2 of the LSSI and indicates a failure to meet required recipient information obligations.ESAEPDePrivacy€2,500
01 Jan 2016TOYS CENTRE, S.L.TOYS CENTRE, S.L. continued sending promotional emails to a complainant even after confirming removal from the mailing list. The AEPD fined the company for failing to comply with the requirements for commercial communications.ESAEPDePrivacy€6,200
01 Jan 2016PROCTER & GAMBLE ESPAÑAProcter & Gamble España was fined 20,000 EUR by the AEPD for continuing to send marketing emails to a complainant after unsubscribe requests. The authority found this conduct breached the LSSI rules on electronic communications.ESAEPDePrivacy€20,000
01 Jan 2016VODAFONE ONO, S.A.U.Vodafone Ono, S.A.U. was fined by the AEPD 6,000 EUR for sending unsolicited advertising SMS messages to a complainant. The complainant's data had previously been canceled, indicating a breach of data handling and marketing communication rules.ESAEPDePrivacy€6,000
01 Jan 2016ORANGE ESPAGNE S.A.U.ORANGE ESPAGNE S.A.U. was fined by the AEPD 2,500 EUR for sending unsolicited commercial communications by electronic means without the recipient's consent. The case indicates a breach of electronic marketing rules and the requirement for prior consent.ESAEPDePrivacy€2,500
14 Jan 2016Comune di Santa FlaviaThe Garante fined Comune di Santa Flavia €10,000 for unlawfully publishing documents on its website that disclosed individuals' health data. The case involved the disclosure of sensitive personal data without a lawful basis.ITGaranteGDPR€10,000
14 Jan 2016Q.12 s.r.l.Q.12 s.r.l. was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€2,400
21 Jan 2016Federico FabiFederico Fabi was fined by the Garante for failing to provide the required information to data subjects when collecting personal data through forms on the company’s website. The case concerns a breach of transparency and notice obligations under data protection rules.ITGaranteGDPR€2,400
21 Jan 2016Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
21 Jan 2016Comune di AdriaComune di Adria was fined EUR 4,000 by the Garante for unlawfully disclosing personal data of third parties. The authority sent photographic results to a complainant that contained data relating to other individuals, breaching data protection rules.ITGaranteGDPR€4,000
21 Jan 2016CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 10,500 for sending unsolicited advertising SMS messages without prior recipient consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI.ESAEPDePrivacy€10,500
21 Jan 2016Malta Games di Belgiorno Chiara & C. s.a.s.Malta Games di Belgiorno Chiara & C. s.a.s. was fined EUR 2,400 by the Garante. The authority found that the company failed to provide the required information to data subjects about personal data processing through a video surveillance system.ITGaranteGDPR€2,400
27 Jan 2016Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€20,000
27 Jan 2016Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules.ITGaranteGDPR€10,000
27 Jan 2016Punto Fermo s.r.l.Punto Fermo s.r.l. was fined by the Garante EUR 12,000 for retaining surveillance footage for 25 days. This exceeded the one-week limit set by the general rules on video surveillance.ITGaranteGDPR€12,000