Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 May 2017Bianalisi s.p.a.Bianalisi s.p.a. was fined by the Italian data protection authority, Garante, for failing to update its notification concerning the processing of genetic data. The obligation arose under the Italian Privacy Code and was intended to ensure proper disclosure of sensitive data processing.ITGaranteGDPR€20,000
11 May 2017Laboratorio Villafranca sncLaboratorio Villafranca snc was fined EUR 20,000 by the Italian data protection authority, Garante. The case concerned a failure to properly notify data processing activities under the Italian data protection code.ITGaranteGDPR€20,000
12 May 2017Strategy MentorThe fine was imposed for sending unsolicited marketing emails to a large number of recipients without prior consent. This conduct breached ePrivacy rules governing electronic marketing communications.GRHDPAePrivacy€75,000
12 May 2017RED UNIVERSAL DE MARKETING Y BOOKINGS ONLINE S.A.The entity sent unsolicited commercial emails. It continued sending them despite requests to delete the data, which breached electronic communications rules.ESAEPDePrivacy€4,500
18 May 2017Brennercom s.p.a.Brennercom s.p.a. was fined 10,000 EUR by the Garante for inadequate password security measures. The authority found that the company's practices breached data protection rules.ITGaranteGDPR€10,000
18 May 2017Terrecablate reti e servizi s.r.l.Terrecablate reti e servizi s.r.l. was fined by the Garante €10,000 for inadequate security measures. The violation concerned weak password authentication on servers storing telephone traffic data.ITGaranteGDPR€10,000
24 May 2017Call Solution s.r.l.Call Solution s.r.l. was fined EUR 40,000 by the Garante for making unsolicited promotional calls to numbers listed in the public opt-out registry. The conduct breached data protection rules and the requirements governing telephone marketing.ITGaranteGDPR€40,000
24 May 2017LAM Centro Biomedico s.r.l.LAM Centro Biomedico s.r.l. was fined by the Garante for failing to notify the corporate name change following a merger. The case involved processing sensitive personal data, which required informing the supervisory authority.ITGaranteGDPR€8,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined €32,000 by the Italian authority Garante. The case concerned unsolicited promotional calls made without the required information notice and without obtaining consent, in breach of data protection rules.ITGaranteGDPR€32,000
31 May 2017LEAD CONVERSIÓN, S.L.LEAD CONVERSIÓN, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial emails. The conduct breached rules on electronic communications and recipient consent.ESAEPDePrivacy€2,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined by the Garante EUR 10,000 for making unsolicited promotional calls to a number listed in the public opt-out register. The conduct breached data protection rules and telephone marketing requirements.ITGaranteGDPR€10,000
06 Jun 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages continued despite requests to stop such communications.ESAEPDePrivacy€5,000
08 Jun 2017THE PHONE HOUSE SPAIN, S.L.U.THE PHONE HOUSE SPAIN, S.L.U. was fined by the AEPD 2,500 EUR for sending commercial text messages without providing recipients with a simple and free way to object to the processing of their data for promotional purposes. The case concerned non-compliance with the LSSI rules on marketing communications.ESAEPDePrivacy€2,500
12 Jun 2017VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 3,300 EUR for sending commercial communications to a former customer after a request for data cancellation. The authority also noted an allegation of sharing personal data with third parties without consent.ESAEPDePrivacy€3,300
14 Jun 2017DALMORRIS, S.L.DALMORRIS, S.L. was fined by the AEPD in the amount of 600 EUR for sending an unsolicited commercial email. The conduct breached Article 21.1 of the LSSI, which prohibits unwanted marketing communications.ESAEPDePrivacy€600
15 Jun 2017F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante 16,000 EUR for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained, in breach of data protection rules.ITGaranteGDPR€16,000
15 Jun 2017Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code.ITGaranteGDPR€10,000
15 Jun 2017F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing.ITGaranteGDPR€10,000
22 Jun 2017Bolos & SynergatesThe law firm Bolos & Synergates was fined EUR 1,000 by the HDPA for unlawfully collecting and using personal data for direct marketing. The violation involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€1,000
22 Jun 2017Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules.ITGaranteGDPR€20,000