Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 May 2018Conafi Prestitò s.p.a.Conafi Prestitò s.p.a. was fined by the Garante for failing to notify certain data processing activities related to loan management. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€20,000
22 May 2018Alessandro SabatiniAlessandro Sabatini, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum personal data security measures were not implemented, which allowed unauthorized access to a health information system.ITGaranteGDPR€10,000
22 May 2018Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 May 2018Parnofiello AntonellaParnofiello Antonella, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to a healthcare system.ITGaranteGDPR€10,000
22 May 2018C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules.ITGaranteGDPR€28,000
22 May 2018Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9037459]A general practitioner failed to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 May 2018Luigi PagnanelliLuigi Pagnanelli, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 May 2018De Nittis MicheleDe Nittis Michele, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This deficiency allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 May 2018Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 May 2018Wind Tre s.p.a.Wind Tre s.p.a. was fined by the Garante EUR 600,000 for conducting marketing campaigns without obtaining the required user consent. The conduct breached data protection rules.ITGaranteGDPR€600,000
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data.ITGaranteGDPR€10,000
23 May 2018BELEADER INTERNET MARKETING S.L.BELEADER INTERNET MARKETING S.L. was fined 5,000 EUR by the AEPD. The authority found that the company sent unsolicited emails and did not honor unsubscribe requests.ESAEPDePrivacy€5,000
25 May 2018Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the AEPD for sending unsolicited commercial SMS messages to a non-customer without consent. The case concerns a breach of direct marketing rules and the requirement to obtain prior consent.ESAEPDePrivacy€3,300
25 May 2018Anonymizováno (ÚOOÚ UOOU-07350/18-21)The entity was fined 50,000 CZK by UOOU for failing to provide the necessary cooperation during an inspection. The breach concerned the legal duty to assist the supervisory authority.CZUOOUGDPR€1,941
30 May 2018Alpha BankAlpha Bank was fined by the HDPA for failing to respond to a data subject access request within the prescribed timeframe. The case concerned Article 12 of Law 2472/1997 and the bank’s obligations to facilitate data subject rights.GRHDPAGDPR€10,000
31 May 2018Iqbal QasimIqbal Qasim was fined by the Garante in the amount of EUR 70,000 for registering phone SIM cards to third parties without their consent. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€70,000
31 May 2018Autosat S.p.A.Autosat S.p.A. was fined by the Italian Garante in the amount of EUR 30,000 for breaches of data protection rules. The case concerned the handling of personal data and the security measures used in the company’s IT systems.ITGaranteGDPR€30,000
31 May 2018Mingardi Medical Center s.r.l.Mingardi Medical Center s.r.l. was fined by the Garante in the amount of EUR 86,000 for making unsolicited promotional calls. The conduct breached data protection rules governing telemarketing activities.ITGaranteGDPR€86,000
31 May 2018IDEASORRISO S.R.L.IDEASORRISO S.R.L. was fined by the Garante EUR 86,000 for making unsolicited promotional calls without the recipients’ consent. The case concerned data protection rules applicable to telemarketing activities.ITGaranteGDPR€86,000