Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 May 2019Ítélet a NAIH/2019/1189/11 sz. ügyben (Fővárosi Törvényszék 105.K.700.364/2019/11)The controller did not provide the requested personal data or information beyond a 2012 lease agreement. This breached the data subject’s access rights under the GDPR.HUNAIHGDPR€918
23 May 2019Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects.HUNAIHGDPR€91,800
23 May 2019Telenor Magyarország Zrt.Telenor Magyarország Zrt. was fined by the Hungarian NAIH 300,000 HUF for failing to comply with a data subject access request under the GDPR. The authority also found that the company did not inform the data subject of the right to an effective legal remedy.HUNAIHGDPR€918
23 May 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD for assigning a customer's DNI to a third party. This enabled unauthorized access to personal data and invoices, constituting a data protection breach.ESAEPDGDPR€60,000
23 May 2019Ordinanza ingiunzione - 23 maggio 2019 [9124593]The Garante imposed a fine of EUR 1,250 for the loss of medical documentation related to a patient's health assessment. The records were not found in either paper or electronic form, which constituted a breach of data protection rules.ITGaranteGDPR€1,250
23 May 2019Bérleti jogviszony során keletkezett dokumentumok másolatban történő kiadásaThe controller did not comply with the data subject's access request for personal data beyond the 2012 lease agreement. The authority treated this as a breach of access-right obligations and imposed a fine.HUNAIHGDPR€918
23 May 2019Comune di FerraraComune di Ferrara was fined 2,400 EUR by the Garante for violations linked to its online registry service. The system allowed citizens to obtain personal and civil status certificates at municipal pharmacies without adequate data protection measures.ITGaranteGDPR€2,400
23 May 2019Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing.HUNAIHGDPR€918
27 May 2019VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined 35,000 EUR by the AEPD for processing personal data without consent. The case involved charging a former customer for services not contracted due to a technical error.ESAEPDGDPR€35,000
28 May 2019Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
29 May 2019Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights.ITGaranteGDPR€10,000
31 May 2019Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach.HUNAIHGDPR€2,156
03 Jun 2019Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed.HUNAIHGDPR€3,090
10 Jun 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages were sent despite the recipient’s request not to receive such communications.ESAEPDePrivacy€10,000
14 Jun 2019Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users.ITGaranteGDPR€1,000,000
17 Jun 2019TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD for incorrect processing of personal data. The error caused billing mistakes because one customer’s data was mixed with another subscriber’s information.ESAEPDGDPR€60,000
18 Jun 2019A hozzáférési kérelem pontosítása; a hozzáférési kérelem elektronikus formában való teljesítéseThe controller did not facilitate the data subject’s right of access. It also failed to provide complete information about the personal data processed, including how to access files stored on a DVD.HUNAIHGDPR€1,550
19 Jun 2019VF JEANSWEAR ESPAÑA S.L.VF Jeanswear España S.L. was fined by the AEPD 5,000 EUR for using cookies on its website without obtaining user consent. The case concerns a breach of data protection rules and consent requirements for cookies.ESAEPDePrivacy€5,000
20 Jun 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls.ESAEPDGDPR€65,000
24 Jun 2019MADRILEÑA RED DE GAS S.A.U.Madrileña Red de Gas S.A.U. was fined by the AEPD 12,000 EUR for failing to ensure adequate security and confidentiality of personal data. This led to unauthorized access by a tenant to the contract holder’s data.ESAEPDGDPR€12,000