Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Jun 2019Budapesti Rendőr-főkapitányságBudapesti Rendőr-főkapitányság was fined by NAIH 5,000,000 HUF for failing to report a personal data breach within the 72-hour deadline. The incident involved the loss of a pendrive containing personal data, in breach of GDPR Article 33.HUNAIHGDPR€15,400
26 Jun 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség és adattakarékosság elvének megsértéseThe controller did not comply with the data subject’s request to delete personal data, including phone numbers. The authority found unlawful processing and a breach of the principles of purpose limitation and data minimization.HUNAIHGDPR€3,090
26 Jun 2019Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations.HUNAIHGDPR€3,090
28 Jun 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 60,000 EUR by the AEPD for a data protection breach. Personal data of a third party was accessible through its mobile application, and the issue was not resolved promptly after it was reported.ESAEPDGDPR€60,000
02 Jul 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for failing to implement adequate security measures. This allowed unauthorized access to personal data through its website.ESAEPDGDPR€60,000
05 Jul 2019VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined €120,000 by the AEPD for failing to exercise due diligence in response to a fraudulent situation involving unauthorized service contracts. The authority found a breach of Article 6 GDPR.ESAEPDGDPR€120,000
11 Jul 2019Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent.ATDSBGDPR€10,000
16 Jul 2019Stichting HagaZiekenhuisStichting HagaZiekenhuis was fined by the AP for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found these shortcomings breached Article 32 GDPR on appropriate security measures.NLAPGDPR€460,000
17 Jul 2019Bírák érdek-képviseleti egyesületi tagságra vonatkozó adatának jogellenes kezeléseBudapest Környéki Törvényszék unlawfully processed personal data by listing and sharing association membership information without a proper purpose or legal basis. The authority found a breach of the GDPR principles of purpose limitation and lawful processing.HUNAIHGDPR€9,180
22 Jul 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending an SMS to a third party with a link to a customer's purchase summary. This disclosed personal data without proper authorization.ESAEPDGDPR€50,000
22 Jul 2019SANTI 3000, S.L.SANTI 3000, S.L. was fined by the AEPD for using video surveillance footage without informing employees. The authority treated this as a breach of data protection principles.ESAEPDGDPR€5,500
23 Jul 2019община К.The Municipality of K. unlawfully processed the complainant’s personal data by sharing it with third parties without consent. The authority found a GDPR breach and imposed a 500 BGN fine.BGCPDPGDPR€256
24 Jul 2019НОИThe National Social Security Institute (НОИ) was fined for failing to implement adequate technical and organizational measures to prevent employees from accessing personal data without authorization. The authority found this to be a breach of GDPR Article 25.BGCPDPGDPR€2,557
25 Jul 2019CONTAPUBLI RIOJA, S.L. (GESTIRIOJA)CONTAPUBLI RIOJA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails. The conduct continued despite the recipient's objection and request for data deletion.ESAEPDePrivacy€2,500
25 Jul 2019VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined by the AEPD 60,000 EUR for failing to ensure adequate security of personal data. The breach resulted in unauthorized or unlawful processing, indicating deficiencies in security controls.ESAEPDGDPR€60,000
25 Jul 2019SOCIEDAD ESTATAL CORREOS Y TELEGRAFOS. S.A.The entity delivered correspondence to the wrong recipient, which constitutes a breach of the data protection principles in Article 5 of the GDPR. AEPD imposed a fine of EUR 40,000.ESAEPDGDPR€40,000
25 Jul 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined EUR 60,000 by the AEPD for a security breach in its customer portal. The incident allowed unauthorized access to a third party's personal data, indicating insufficient access controls.ESAEPDGDPR€60,000
08 Aug 2019Zala Megyei Kormányhivatal Keszthelyi Járási FöldhivatalThe Zala Megyei Kormányhivatal Keszthelyi Járási Földhivatal was fined 600,000 HUF by NAIH for breaching the principles of data minimization and transparency. The authority found that personal data was made accessible to third parties without clear information about the processing.HUNAIHGDPR€1,848
20 Aug 2019Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data.SEIMYGDPR€18,578
02 Sept 2019LA SALA 2015 S.L.U.LA SALA 2015 S.L.U. was fined by the AEPD 1,500 EUR for improper processing of personal data through a video surveillance system. The cameras captured images disproportionately from public sidewalks without the required legal basis.ESAEPDGDPR€1,500