Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Jun 2017Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules.ITGaranteGDPR€62,000
22 Jun 2017Vodafone-PanafonVodafone-Panafon was fined EUR 10,000 by the HDPA for a significant delay in responding to a data subject access request. The authority found a breach of Article 12 of Law L.2472/1997.GRHDPAGDPR€10,000
26 Jun 2017LEAD CONVERSION S.L.LEAD CONVERSION S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without prior recipient consent. The conduct breached electronic communications rules and marketing consent requirements.ESAEPDePrivacy€2,500
05 Jul 2017Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Jul 2017Klik s.r.l.Klik s.r.l. was fined EUR 30,000 by the Garante for retaining telephone traffic data for more than 24 months. The authority found this to be a breach of data protection rules.ITGaranteGDPR€30,000
05 Jul 2017Compagnia Generale Trattori S.p.A.Compagnia Generale Trattori S.p.A. was fined by the Garante EUR 20,000 for using a GPS/GPRS system to monitor employee activities without proper notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
05 Jul 2017Vodafone Omnitel N.V.Vodafone Omnitel N.V. was fined by the Italian data protection authority, Garante, in the amount of 40,000 EUR. The sanction concerned the use of a group authentication credential to access personal data, which breached the security measures required under the Italian Data Protection Code.ITGaranteGDPR€40,000
14 Jul 2017BARCLAYS BANK PLC Sucursal en EspañaBARCLAYS BANK PLC Sucursal en España was fined by the AEPD 5,000 EUR for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The breach occurred despite the recipient's request to cancel their personal data.ESAEPDePrivacy€5,000
20 Jul 2017Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact.ITGaranteGDPR€64,000
20 Jul 2017S.I.T. s.r.l.S.I.T. s.r.l. was fined by the Garante in the amount of EUR 6,400 for unauthorized access to surveillance images and for processing customer data without proper notice to data subjects. The authority found that these actions breached data protection rules.ITGaranteGDPR€6,400
20 Jul 2017InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information.ITGaranteGDPR€40,000
20 Jul 2017Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules.ITGaranteGDPR€20,400
20 Jul 2017Aria S.p.a.Aria S.p.a. was fined 20,000 EUR by the Garante. The authority found a data protection breach for failing to designate employees as data processors.ITGaranteGDPR€20,000
26 Jul 2017Equilibra s.r.l.Equilibra s.r.l. was fined by the Garante for failing to provide adequate data protection information to individuals and for not appointing the required data processing officers. The case concerned breaches of the Italian Data Protection Code.ITGaranteGDPR€12,400
26 Jul 2017Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements.ITGaranteGDPR€4,000
26 Jul 2017Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules.ITGaranteGDPR€40,000
04 Aug 2017VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations.GRHDPAGDPR€5,000
04 Aug 2017STAPLES PRODUCTOS DE OFICINA S.L.U.STAPLES PRODUCTOS DE OFICINA S.L.U. was fined EUR 2,000 by the AEPD for sending unsolicited commercial emails. The breach involved continuing to contact recipients despite requests to cancel consent.ESAEPDePrivacy€2,000
04 Aug 2017VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing.GRHDPAGDPR€10,000
04 Aug 2017VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD in the amount of 6,000 EUR for making numerous advertising calls to numbers registered on the Robinson List. The conduct breached privacy rules and the right to object to direct marketing.ESAEPDePrivacy€6,000