Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jul 2018Comune di VollaComune di Volla was fined by the Garante EUR 10,000 for allowing all employees access to sensitive and judicial personal data through its electronic protocol system. The authority found that this setup failed to meet required data protection safeguards.ITGaranteGDPR€10,000
11 Jul 2018CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules.ITGaranteGDPR€12,400
11 Jul 2018BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules.ITGaranteGDPR€10,000
11 Jul 2018General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met.ITGaranteGDPR€7,200
19 Jul 2018Active Network S.p.a.Active Network S.p.a. was fined by the Garante 20,000 EUR for retaining telematic traffic data for more than 12 months. The authority found that this practice breached data protection rules in the context of crime detection and repression.ITGaranteGDPR€20,000
19 Jul 2018Go Internet S.p.AGo Internet S.p.A was fined by the Garante in the amount of 40,000 EUR for processing and retaining telephone and internet traffic data beyond the permitted period. The authority found this conduct contrary to the Italian Data Protection Code.ITGaranteGDPR€40,000
19 Jul 2018Idroservice Italia s.r.l.Idroservice Italia s.r.l. was fined by the Garante for failing to respond to a request for information. The authority treated this as a breach of data protection rules.ITGaranteGDPR€20,000
19 Jul 2018Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules.CZUOOUGDPR€386
19 Jul 2018BUTALI S.P.A.BUTALI S.P.A. was fined €16,000 by the Garante for activating a SIM card without providing the required privacy information and obtaining the customer’s specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
24 Jul 2018Anonymizováno (ÚOOÚ UOOU-00078/17-47)The entity was fined CZK 400,000 by the UOOU for processing customers' personal data without their consent. The authority found this conduct to be in breach of the Czech Data Protection Act.CZUOOUGDPR€15,528
24 Jul 2018TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD 8,100 EUR for sending unsolicited advertising emails without prior recipient consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing practices.ESAEPDePrivacy€8,100
26 Jul 2018Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
26 Jul 2018Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data.ITGaranteGDPR€10,000
26 Jul 2018Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules.ITGaranteGDPR€26,000
26 Jul 2018MEVALUATE ITALIA S.R.L.MEVALUATE ITALIA S.R.L. was fined by the Garante 26,000 EUR for sending promotional emails without obtaining specific consent. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€26,000
26 Jul 2018VILAN DATAMINING, S.L.VILAN DATAMINING, S.L. was fined by the AEPD in the amount of 1,600 EUR for sending unsolicited commercial emails without the required consent. The conduct breached article 21.1 of the LSSI.ESAEPDePrivacy€1,600
27 Jul 2018Anonymizováno (ÚOOÚ UOOU-08596/17-64)The individual was fined for publishing the personal data of a municipal social department employee on Facebook. The authority found a breach of confidentiality obligations under Czech law.CZUOOUGDPR€117
30 Jul 2018А.С.К. УМБАЛ ЕООДThe CPDP found that “А.С.К. УМБАЛ ЕООD” unlawfully processed personal data by providing it to “МБАЛ-В. ЕООD” without consent. This breached data protection rules and resulted in a fine of BGN 1,000.BGCPDPGDPR€511
09 Aug 2018InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000.NLAPGDPR€48,000
20 Aug 2018Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services.CZUOOUePrivacy€54,460