Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Sept 2010Provincia di FoggiaProvincia di Foggia was fined by the Garante for making health-related personal data publicly accessible through Google and its website. The case involved improper disclosure of sensitive data, which breached data protection rules.ITGaranteGDPR€20,000
16 Sept 2010VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD 30,001 EUR for sending advertising messages to a customer who had previously opted out. The authority found this breached Article 21 of the LSSI on marketing communications without the recipient’s consent.ESAEPDePrivacy€30,001
22 Sept 2010JET MULTIMEDIA ESPAÑA S.A.JET MULTIMEDIA ESPAÑA S.A. was fined by the AEPD EUR 600 for sending unsolicited commercial SMS messages. Recipients were not given a simple and free way to object to the use of their data for marketing purposes.ESAEPDePrivacy€600
23 Sept 2010Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules.ITGaranteGDPR€40,000
27 Sept 2010GESTEVISION TELECINCO, S.A.GESTEVISION TELECINCO, S.A. was fined by the AEPD 50,000 EUR for sending mass promotional SMS messages. The authority found that recipients were not given a simple and free way to object to the processing of their data for marketing purposes, in breach of Article 21.2 of the LSSI.ESAEPDePrivacy€50,000
28 Sept 2010WORKING MARESME S.L.WORKING MARESME S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€600
07 Oct 2010Easynetwork s.r.l.Easynetwork s.r.l. was fined EUR 6,000 by the Italian data protection authority, Garante. The sanction concerned the sending of promotional communications by fax without providing data subjects with the required information. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
08 Oct 2010A.A.A.A.A.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The case concerned continued email marketing despite a request to be removed from the mailing list, in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
15 Oct 2010Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority.ITGaranteGDPR€10,000
19 Oct 2010BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U.BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U. was fined by the AEPD for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent.ESAEPDePrivacy€1,200
21 Oct 2010Palmeto s.r.l.Palmeto s.r.l. was fined EUR 12,000 by the Italian supervisory authority, Garante. The case concerned failure to provide the required data protection information to individuals in connection with video surveillance and personal data collection via the company website.ITGaranteGDPR€12,000
21 Oct 2010Giomi s.p.a. - Gestione Istituti Ortopedici nel mezzogiorno d'ItaliaGiomi s.p.a. was fined €30,000 by the Italian data protection authority, Garante. The case concerned data processing activities carried out without the required notification under the Italian data protection code.ITGaranteGDPR€30,000
21 Oct 2010Baldomero **** y Jesús ***** CBBaldomero **** y Jesús ***** CB was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
02 Nov 2010VODAFONE ESPAÑA, S.A.Vodafone España, S.A. was fined 600 EUR by the AEPD for sending commercial communications to a complainant who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€600
02 Nov 2010VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial communications in breach of Article 21 of the LSSI. The infringement was classified as serious because a technical error resulted in 18 such messages being sent.ESAEPDePrivacy€30,001
04 Nov 2010Casa di Cura Tortorella S.p.aCasa di Cura Tortorella S.p.a was fined by the Garante for failing to notify certain data processing activities and for providing inadequate information to data subjects. The case concerns breaches of the Italian Data Protection Code and points to deficiencies in basic notification and transparency obligations.ITGaranteGDPR€20,000
10 Nov 2010Fitness Solution società sportiva dilettantistica s.r.l.Fitness Solution was fined EUR 10,000 by the Garante. The authority found that biometric personal data were processed without proper consent and retained longer than necessary.ITGaranteGDPR€10,000
16 Nov 2010INGORA SERAI S.L.INGORA SERAI S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications.ESAEPDePrivacy€600
17 Nov 2010Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations.ITGaranteGDPR€20,000
18 Nov 2010G.L. GISOFT ANÁLISIS Y DISEÑO S.L.G.L. GISOFT ANÁLISIS Y DISEÑO S.L. was fined by the AEPD in the amount of €600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such marketing communications without recipient consent.ESAEPDePrivacy€600