Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Jan 2019Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system.ITGaranteGDPR€16,000
31 Jan 2019Istituto Statale di Istruzione Superiore “Guglielmo Marconi”Istituto Statale di Istruzione Superiore “Guglielmo Marconi” was fined by the Garante €4,000 for unlawfully processing personal data. The school published teacher rankings on its website that disclosed health information, breaching privacy rules.ITGaranteGDPR€4,000
31 Jan 2019CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules.ITGaranteGDPR€12,000
01 Feb 2019CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis.ESAEPDGDPR€6,500,000
02 Feb 2019Ordinanza ingiunzione - 2 febbraio 2019 [9100784]The Garante imposed an administrative fine for violating data protection rules. The case concerned retaining surveillance footage for longer than the permitted 7 days.ITGaranteGDPR€11,940
02 Feb 2019XX S.r.l.The company was fined EUR 4,000 by the Garante. The authority found that it processed personal data for promotional purposes without obtaining valid consent from the data subjects.ITGaranteGDPR€4,000
14 Feb 2019Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
20 Feb 2019Érintetti joggyakorlásra vonatkozó kérelem elbírálásaThe supervisory authority fined the controller for failing to facilitate the exercise of data subject rights and for not meeting transparency requirements when handling a deletion request. The case concerned an improperly handled request for erasure and insufficient information provided to the requester.HUNAIHGDPR€1,575
21 Feb 2019Anonymizováno (ÚOOÚ UOOU-05185/14-53)The entity was fined by UOOU for publishing information about wiretaps and telecommunications records without consent. The authority treated this as a breach of privacy and personal data protection rules.CZUOOUGDPR€7,018
22 Feb 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD €2,500 for sending commercial communications by phone and SMS without the complainant’s consent. This breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
26 Feb 2019телекомуникационен операторThe telecommunications operator was fined BGN 53,000 by the CPDP for processing personal data without consent. The case involved changing a subscription plan to a prepaid service without the data subject's knowledge or agreement.BGCPDPGDPR€27,099
28 Feb 2019Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period.ITGaranteGDPR€4,000
28 Feb 2019Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF.HUNAIHGDPR€3,160
28 Feb 2019Casinò di Venezia Meeting & Dining S.r.l.Casinò di Venezia Meeting & Dining S.r.l. was fined EUR 4,000 by the Garante. The authority found that adequate security measures had not been implemented, in breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€4,000
07 Mar 2019Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data.ITGaranteGDPR€10,000
12 Mar 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending continuous SMS messages to a complainant despite a prior request to cancel personal data. The authority found this conduct to be a breach of data protection principles.ESAEPDGDPR€45,000
13 Mar 2019Anonymizováno (ÚOOÚ UOOU-12081/17-63)The entity was fined CZK 23,000 by the UOOU for repeatedly sending unsolicited commercial communications without recipients’ consent. The authority found this conduct breached Section 7 of the Czech Act on Certain Information Society Services.CZUOOUePrivacy€896
14 Mar 2019Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
15 Mar 2019Dane anonimowe (X. Sp. z o.o., za naruszenie stwierdzone w niniejszej decyzji,)UODO found that X. Sp. z o.o. failed to comply with its information obligation. The decision ordered remediation of the breach and imposed a fine of PLN 943,470.PLUODOGDPR€219,000
19 Mar 2019Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees.ITGaranteGDPR€80,000