Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Feb 2023ROMBOC COMUNICACIONESROMBOC COMUNICACIONES was fined by the AEPD in the amount of 2,000 EUR for making misleading advertising calls without explicit consent from recipients. The case indicates a breach of data protection and direct marketing rules.ESAEPDGDPR€2,000
16 Mar 2017Roma TPL s.c.a.r.l.Roma TPL s.c.a.r.l. was fined EUR 8,000 by the Garante for processing personal data through AVM systems on buses without full compliance with data protection rules. The case concerned improper use of monitoring and data-processing systems affecting passengers.ITGaranteGDPR€8,000
11 Feb 2021Roma Servizi per La Mobilita S.r.l.Roma Servizi per La Mobilita S.r.l. was fined EUR 60,000 by the Garante for inadequate security measures. The weakness led to unauthorized access to personal data related to ZTL permits.ITGaranteGDPR€60,000
21 Apr 2016Romana Supernegozi s.r.l.Romana Supernegozi s.r.l. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The case concerned breaches of data protection information duties.ITGaranteGDPR€2,400
05 Nov 2015Romagna Giochi srlRomagna Giochi srl was fined EUR 4,800 by the Italian Garante. The authority found that the company failed to provide adequate notice about video surveillance at its premises, breaching data protection rules.ITGaranteGDPR€4,800
06 Jul 2023Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements.ITGaranteGDPR€10,000
12 Oct 2017Roma Gestioni s.r.l.Roma Gestioni s.r.l. was fined EUR 30,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under privacy rules.ITGaranteGDPR€30,000
27 Jan 2021Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
27 Apr 2023Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach.ITGaranteGDPR€176,000
17 Dec 2020Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users.ITGaranteGDPR€500,000
22 Jul 2021Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects.ITGaranteGDPR€800,000
13 Feb 2014Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€10,000
11 Feb 2021Roma CapitaleRoma Capitale was fined EUR 350,000 by the Garante for breaches of GDPR principles, including data minimization and security. The violations resulted in unauthorized access to personal data over an extended period.ITGaranteGDPR€350,000
01 Jan 2021RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€5,000
01 Jan 2017ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior recipient consent.ESAEPDePrivacy€5,000
16 Feb 2016ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined EUR 30,000 by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated requests to unsubscribe. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,000
10 Oct 2016ROCK INTERNET S.L.ROCK INTERNET S.L. was fined 3,800 EUR by the AEPD. The case concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,800
05 Mar 2024ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR.ESAEPDGDPR€5,000
31 Aug 2023Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children.ITGaranteGDPR€25,000
09 Dec 2020ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident.HUNAIHGDPR€56,000