Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Feb 2017Lucini & Lucini Communication LtdLucini & Lucini Communication Ltd was fined EUR 72,000 by the Garante. The authority found that the company collected personal data through its websites and sent promotional emails without proper consent.ITGaranteGDPR€72,000
23 Feb 2017Sisal S.p.A.Sisal S.p.A. was fined by the Garante in the amount of EUR 20,000 for installing a geolocation system on smartphones provided to employees without proper compliance with data protection rules. The case concerned the processing of location data in an employment context and insufficient legal safeguards.ITGaranteGDPR€20,000
24 Feb 2017Geoanalysis S.A.Geoanalysis S.A. was fined EUR 10,000 by the HDPA for improper installation and operation of a video surveillance system. The authority found data protection breaches, including failure to notify the authority and inadequate employee information.GRHDPAGDPR€10,000
28 Feb 2017DALMORRIS, S.L.DALMORRIS, S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts this type of communication without prior consent.ESAEPDePrivacy€600
01 Mar 2017CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily.ESAEPDePrivacy€10,000
01 Mar 2017A.A.A.A.A.A. was fined €3,000 by the AEPD. The authority found that cookies were installed on its websites without prior information and consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
01 Mar 2017CGPN, SARLCGPN, SARL was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without prior consent. This conduct breached Spanish data protection rules.ESAEPDePrivacy€2,000
01 Mar 2017PACSOLUTOR S.L.U.PACSOLUTOR S.L.U. was fined by the AEPD in the amount of 3,000 EUR for failing to provide adequate information about cookies on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
01 Mar 2017ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 2,500 by the AEPD for continuing to send commercial emails to a customer after confirming deletion of the customer’s personal data. The authority found this to be a breach of electronic communications and data protection rules.ESAEPDePrivacy€2,500
01 Mar 2017FRONTERA SISTEMAS DE ESPAÑA SLFRONTERA SISTEMAS DE ESPAÑA SL was fined EUR 3,000 by the AEPD for installing cookies on users' devices without prior consent. The authority found this breached the information and consent requirements for data storage and retrieval devices.ESAEPDePrivacy€3,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 20,000 by the Garante for making unsolicited promotional calls. The calls were placed to a number listed in the public opt-out register, which breached data protection rules.ITGaranteGDPR€20,000
02 Mar 2017Trilogy s.r.l.Trilogy s.r.l. and Fastweb s.p.a. were fined for making unsolicited promotional calls to a phone number listed in the public opt-out register. The conduct breached data protection rules.ITGaranteGDPR€20,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 16,000 by the Italian Garante. The case concerned promotional calls made without providing the required data protection information and without obtaining consent, in breach of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€16,000
02 Mar 2017Trilogy s.r.l.Trilogy s.r.l. was fined EUR 48,000 by the Garante for making unsolicited marketing calls. The authority found that the company failed to provide the required information and did not obtain consent, in breach of the Italian Data Protection Code.ITGaranteGDPR€48,000
08 Mar 2017Elliniki Etaireia Systimikon MeletonThe company was fined by the HDPA for illegally collecting and using personal data for direct marketing purposes. The infringement involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€3,000
09 Mar 2017Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing.ITGaranteGDPR€14,400
14 Mar 2017GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€7,100
16 Mar 2017ABELHAS.PT LIMITEDABELHAS.PT LIMITED was fined EUR 5,000 by the AEPD for failing to provide the required information and procedures to reject data processing on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
16 Mar 2017Roma TPL s.c.a.r.l.Roma TPL s.c.a.r.l. was fined EUR 8,000 by the Garante for processing personal data through AVM systems on buses without full compliance with data protection rules. The case concerned improper use of monitoring and data-processing systems affecting passengers.ITGaranteGDPR€8,000
16 Mar 2017Welcome s.a.s. di Somma MicheleWelcome s.a.s. di Somma Michele was fined EUR 16,000 by the Garante for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained.ITGaranteGDPR€16,000