Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Nov 2019CERRAJERO ONLINE S.L.CERRAJERO ONLINE S.L. was fined EUR 1,500 by the AEPD for collecting personal data without providing the required information to data subjects. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,500
06 Nov 2019TODOTECNICOS24H S.L.TODOTECNICOS24H S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,500
07 Nov 2019Comune di TivoliThe Municipality of Tivoli was fined by the Italian data protection authority, Garante, for unlawfully publishing personal data on its institutional website. The publication also included information about a pending criminal proceeding, breaching the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
11 Nov 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség, adattakarékosság és átláthatóság elvének megsértéseThe supervisory authority found that the controller did not comply with requests to erase personal data and unlawfully processed phone numbers. It also identified breaches of purpose limitation, data minimization, and transparency principles.HUNAIHGDPR€4,485
12 Nov 2019CONFEDERACION GENERAL DEL TRABAJOCONFEDERACION GENERAL DEL TRABAJO was fined by the AEPD €5,000 for disclosing the complainant’s personal data without consent. The disclosure included details of a verbal abuse and harassment case, family relations, pregnancy status, and home address, shared with about 400 union members.ESAEPDGDPR€5,000
14 Nov 2019ASL n. 2 SavoneseASL n. 2 Savonese was fined EUR 8,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data, including failures to comply with lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
15 Nov 2019Raiffeisen Bank Zrt.Raiffeisen Bank Zrt. was fined by the NAIH 25,000,000 HUF for processing personal data of non-advisory service clients without a legal basis. The authority also found that the bank failed to provide adequate information about the processing of personal data collected through MiFID questionnaires.HUNAIHGDPR€74,750
15 Nov 2019HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined by the AEPD 60,000 EUR for sending a patient's medical report to an insurance company without proper consent. The case concerns a breach of data protection rules and the special protection applicable to health data.ESAEPDGDPR€60,000
18 Nov 2019EUSKALTEL, S.A.EUSKALTEL, S.A. was fined by the AEPD 50,000 EUR for a data protection incident. Due to incorrect handling of customer information, personal data was sent to the wrong individuals.ESAEPDGDPR€50,000
22 Nov 2019MEGASTAR, S.L.MEGASTAR, S.L. was fined by the AEPD EUR 2,000 for surveillance cameras that were improperly oriented and captured disproportionate images. The authority also found that the required informational signage was missing, constituting a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€2,000
22 Nov 2019CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles.ESAEPDGDPR€3,000
25 Nov 2019YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
26 Nov 2019EDP COMERCIALIZADORA, S.A.U.EDP COMERCIALIZADORA, S.A.U. was fined by the AEPD 75,000 EUR for processing personal data without consent. The case involved data linked to a gas contract unrelated to the complainant, which breached Article 6(1) of the GDPR.ESAEPDGDPR€75,000
29 Nov 2019GRUPO VALSOR Y LOSAN, S.L.The real estate management company improperly disclosed personal data of third parties during a property purchase process. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€2,500
29 Nov 2019Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 75,000 by the AEPD for continuing to send communications to a complainant after a request for data deletion. The issue was caused by an IT error that left the complainant’s email address in the system.ESAEPDGDPR€75,000
29 Nov 2019BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules.ESAEPDePrivacy€10,000
29 Nov 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending a customer's personal data to the wrong address. The authority found this to be a breach of data security requirements under GDPR Article 5(1)(f).ESAEPDGDPR€50,000
02 Dec 2019GARANTIZA AUTOMOCIÓN, S.L.The company was fined by the AEPD in the amount of EUR 3,000 for failing to provide information or obtain consent for the use of cookies on its website. The breach concerned LSSI requirements on transparency and user consent.ESAEPDePrivacy€3,000
02 Dec 2019CONSULTING DE SEGURIDAD E INVESTIGACION MIRA DP MADRID, S.L.The company was fined by the AEPD for collecting and processing personal data without the data subjects’ consent. The conduct also included sending unsolicited advertising, which breached Article 6 of the GDPR.ESAEPDGDPR€5,000
02 Dec 2019IMNOVA RESORT, S.L.IMNOVA RESORT, S.L. was fined by the AEPD EUR 3,000 for installing cookies on its online store without obtaining user consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€3,000