Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Nov 2018Legea s.p.a.Legea s.p.a. was fined for processing personal data through forms on its website without providing the required information notice to data subjects. The case concerned a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
29 Nov 2018Wind Tre S.p.A.Wind Tre S.p.A. was fined EUR 600,000 by the Garante for unsolicited promotional calls and SMS. The authority found breaches of several provisions of the Italian Data Protection Code.ITGaranteGDPR€600,000
29 Nov 2018Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
11 Dec 2018Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR.CZUOOUGDPR€3,869
13 Dec 2018Anonymizováno (ÚOOÚ UOOU-08001/18-14)The entity was fined 40,000 CZK by the UOOU for insufficient security measures in the processing of personal data. The authority cited inadequate audit logs and a lack of regular access checks to electronic health records.CZUOOUGDPR€1,549
13 Dec 2018Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine.ITGaranteGDPR€8,000
13 Dec 2018Ministero dell’Istruzione, dell’Università e della Ricerca – Ufficio Scolastico Regionale per la Lombardia – Ufficio III – Ambito territoriale di BergamoThe Ministry of Education’s regional office in Bergamo was fined for unlawfully publishing personal data related to disciplinary proceedings on its website. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
18 Dec 2018ORGANIZACION NACIONAL DE CIEGOS (ONCE)ONCE was fined EUR 40,000 by the AEPD for sending more than 200 unsolicited commercial emails without prior consent. The authority found this to be a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€40,000
20 Dec 2018Anonymisiert (DSB DSB-D550.037/0003-DSB/2018)The DSB imposed a fine of EUR 2,200 for unlawful video surveillance covering common areas and neighboring properties without consent. The conduct breached GDPR principles of data minimization and purpose limitation.ATDSBGDPR€2,200
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
01 Jan 2019IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
01 Jan 2019VODAFONE ESPAÑA, S.A.U.Vodafone España was fined 40,000 EUR by the AEPD for charging a customer for a Netflix service that had not been contracted. The authority found a breach of GDPR Article 6 due to the lack of a lawful basis for the charge and related processing.ESAEPDGDPR€40,000
01 Jan 2019ELECTRIC RENTING GROUP, S.L.ELECTRIC RENTING GROUP, S.L. was fined by the AEPD EUR 2,500 for sending a promotional email without using BCC. This exposed recipients’ email addresses and breached data protection rules.ESAEPDGDPR€2,500
01 Jan 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for incorrectly including personal data in a creditworthiness file. The authority found a breach of the GDPR accuracy principle under Article 5(1)(d).ESAEPDGDPR€60,000
01 Jan 2019ZHANG BORDETA 2006, S.L.ZHANG BORDETA 2006, S.L. was fined EUR 6,000 by the AEPD for disproportionate video surveillance of public areas. The authority also found that no informational notice was provided inside the establishment, breaching data protection rules.ESAEPDGDPR€6,000
01 Jan 2019AVON COSMETICS SAUAVON COSMETICS SAU was fined by the AEPD 60,000 EUR for improper processing of personal data. The company included an individual in a creditworthiness file without first verifying the person’s identity.ESAEPDGDPR€60,000
01 Jan 2019VIAQUA XESTIÓN INTEGRAL DE AUGAS DE GALICIA, S.A.The company changed contract data without authorization, which constituted a breach of Article 6 of the GDPR. The AEPD imposed a fine of 60,000 EUR.ESAEPDGDPR€60,000
01 Jan 2019VODAFONE ESPAÑA, S.A.UVodafone España, S.A.U was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited advertising messages to a business phone number without consent. The case concerned Article 21 of the LSSI, which governs marketing communications without prior recipient consent.ESAEPDePrivacy€2,500
01 Jan 2019IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 20,000 EUR for continuing to send emails to a customer who had requested removal from the loyalty program and deletion of personal data. The authority found this conduct to be a breach of GDPR Article 6.ESAEPDGDPR€20,000