Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Oct 2019Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP for failing to notify the supervisory authority of a data breach without undue delay and for unauthorized processing of personal data. The violations resulted in a loss of data confidentiality and indicate inadequate compliance controls.ROANSPDCPGDPR€150,000
15 Oct 2019Munkavállaló munkaeszközeinek ellenőrzéseThe controller unlawfully processed the complainant's personal data by reviewing and monitoring their email account without prior notice. This breached the principle of fair processing.HUNAIHGDPR€3,010
16 Oct 2019Dane anonimowe (S. Sp. z o.o. z siedzibą w P., karę pieniężną w kwocie 201 559,50 PLN)UODO imposed a fine of PLN 201,559.50 on S. Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority also found that personal data were processed without a lawful basis, which led to the sanction.PLUODOGDPR€46,923
17 Oct 2019VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 75,000 for incorrectly charging a customer's account and retaining inaccurate personal data. The case concerns breaches of data protection principles, including data accuracy and proper processing.ESAEPDGDPR€75,000
18 Oct 2019National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach.BGCommission for Personal Data ProtectionGDPR€2,607,000
18 Oct 2019Dane anonimowe (Burmistrza G. karę pieniężną w kwocie 40.000 zł)UODO found a breach of the principles of lawful processing and confidentiality. A fine of PLN 40,000 was imposed, together with an order to bring processing operations into compliance with data protection rules.PLUODOGDPR€9,336
21 Oct 2019Anonymizováno (ÚOOÚ UOOU-02928/19-13)The entity was fined for publishing personal data related to criminal proceedings on its website. The authority found a breach of GDPR rules on the processing and disclosure of personal data.CZUOOUGDPR€1,561
22 Oct 2019IBERDROLA COMERCIALIZACIÓN DE ÚLTIMO RECURSO, S.A.U. (CURENERGIA COMERCIALIZADORA DE ULTIMO RECURSO, S.A.U.)CURENERGIA was fined EUR 75,000 by the AEPD for using a former client's personal data without consent. The data was used to carry out a fraudulent contract registration. The case indicates a breach of lawful processing and personal data protection requirements.ESAEPDGDPR€75,000
23 Oct 2019CERRAJERIA CARLOS RODRIGUEZ S.L.CERRAJERIA CARLOS RODRIGUEZ S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
23 Oct 2019CERRAJERIA VERIN S.L.CERRAJERIA VERIN S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to data subjects. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
23 Oct 2019SHOP MACOYN, S.L. (YBL ABOGADOS)SHOP MACOYN, S.L. was fined EUR 5,000 by the AEPD for disclosing email addresses in promotional emails. The case concerned a breach of data protection principles and the confidentiality of recipients’ personal data.ESAEPDGDPR€5,000
24 Oct 2019Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH for failing to report a data breach involving a patient's application form within 72 hours. The authority also found that the organization lacked an internal incident management policy.HUNAIHGDPR€7,600
24 Oct 2019Magyar Honvédség Egészségügyi KözpontThe Hungarian Defence Forces Health Centre did not report a data breach within 72 hours and lacked internal incident management procedures. NAIH found this to be a breach of GDPR obligations and imposed a fine of 2,500,000 HUF.HUNAIHGDPR€7,600
24 Oct 2019Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified.CZUOOUePrivacy€391
24 Oct 2019Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register.HUNAIHGDPR€7,600
29 Oct 2019JOKER PREMIUM INVEX, S.L.JOKER PREMIUM INVEX, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited commercial communications. The company used personal data taken from public sources without the individuals’ consent.ESAEPDGDPR€10,000
31 Oct 2019Partito Democratico, Coordinamento Metropolitano di FirenzePartito Democratico, Coordinamento Metropolitano di Firenze was fined by the Garante €4,000 for a data protection breach. The incident resulted from a cyber attack on its website that exposed personal data of party members.ITGaranteGDPR€4,000
04 Nov 2019Coöperatie Menzis U.A.The Dutch Data Protection Authority, AP, imposed a fine of EUR 150,000 on Coöperatie Menzis U.A. The authority found that the company had inadequate technical measures to prevent unauthorized access to personal health data.NLAPGDPR€150,000
04 Nov 2019Coöperatie VGZ U.A.The Autoriteit Persoonsgegevens imposed a EUR 150,000 penalty on Coöperatie VGZ U.A. for failing to implement appropriate technical measures to protect personal data from unauthorized access. The authority found a breach of data protection law.NLAPGDPR€150,000
04 Nov 2019Coöperatie Menzis U.A.Menzis was fined by the AP for failing to implement appropriate technical measures to protect personal data. The authority found a breach of Article 32 GDPR.NLAPGDPR€50,000