Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Aug 2018Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements.GRHDPAGDPR€5,000
21 Aug 2018Alpha BankAlpha Bank was fined by the HDPA for failing to maintain and process accurate data of its debtors. The authority found that the bank’s conduct breached data protection requirements.GRHDPAGDPR€10,000
21 Aug 2018National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations.GRHDPAGDPR€5,000
29 Aug 2018Anonymizováno (ÚOOÚ UOOU-08277/18-40)The entity was fined for sending unsolicited commercial communications by electronic means without recipients' consent. This breached Czech rules on information society services.CZUOOUePrivacy€3,496
14 Sept 2018IAHORRO BUSINESS SOLUTIONS SLIAHORRO BUSINESS SOLUTIONS SL was fined by the AEPD €1,000 for sending unsolicited commercial electronic communications. The company also failed to provide a procedure for exercising rights of access, rectification, cancellation, or objection.ESAEPDePrivacy€1,000
17 Sept 2018TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 900 for sending unsolicited advertising emails to an individual who was not a customer. The case concerns a breach of data protection rules governing direct marketing communications.ESAEPDePrivacy€900
21 Sept 2018XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD in the amount of 4,000 EUR for sending unsolicited commercial SMS messages without the recipient’s consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for marketing communications.ESAEPDePrivacy€4,000
21 Sept 2018Anonymizováno (ÚOOÚ UOOU-01895/18-25)The entity was fined by the UOOU for processing personal data without consent and for failing to implement adequate security measures. The authority found these actions to be in breach of Czech data protection law.CZUOOUGDPR€1,173
26 Sept 2018VILAN DATAMINING SLVILAN DATAMINING SL was fined by the AEPD €800 for sending unsolicited commercial emails. The messages did not provide a way to exercise the rights of access, rectification, cancellation, or objection.ESAEPDePrivacy€800
27 Sept 2018Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ATDSBGDPR€300
27 Sept 2018Anonymizováno (ÚOOÚ UOOU-05291/17-44)The entity was fined for repeatedly sending commercial communications to specified electronic addresses without consent and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€3,111
09 Oct 2018WIND HELLAS TELECOMMUNICATIONS S.A.The fine was imposed for making unsolicited marketing calls to subscribers who had opted out of such contact. This conduct breached privacy and data protection rules.GRHDPAePrivacy€150,000
09 Oct 2018Vodafone-PanafonVodafone-Panafon was fined by the HDPA for making unsolicited marketing calls to subscribers who had opted out of such contact. The authority found that the conduct breached privacy and data protection rules.GRHDPAePrivacy€12,000
09 Oct 2018OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact.GRHDPAePrivacy€150,000
09 Oct 2018CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules.GRHDPAePrivacy€150,000
01 Nov 2018UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures.NLAPGDPR€150,000
07 Nov 2018Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
07 Nov 2018Comune di Castel MaggioreComune di Castel Maggiore was fined by the Garante for publishing personal data on its institutional website without a legal basis. The case concerned a breach of data protection rules and unauthorized disclosure of information.ITGaranteGDPR€4,000
19 Nov 2018VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 5,000 EUR for breaching data quality principles. The company incorrectly included personal data in a creditworthiness file despite a prior order to correct billing errors.ESAEPDGDPR€5,000
19 Nov 2018Anonymizováno (ÚOOÚ UOOU-04674/18-33)The entity was fined for repeatedly sending unsolicited commercial communications to email addresses without the recipients’ consent. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€577