Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jan 2020AUTOMOCION X.X.X. S.L.The company was fined EUR 1,000 by the AEPD for placing an individual's photo, name, and phone number on an adult contact website without consent. The disclosure led to unwanted calls and constituted a breach of personal data protection rules.ESAEPDGDPR€1,000
10 Jan 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information.ESAEPDGDPR€30,000
12 Jan 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for charging a customer for a service that had not been contracted. The case concerned non-compliance with consent requirements linked to data processing and service billing.ESAEPDGDPR€100,000
14 Jan 2020REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules.ESAEPDGDPR€6,000
15 Jan 2020TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules.ITGaranteGDPR€27,802,000
15 Jan 2020Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action.ITGaranteGDPR€10,000
16 Jan 2020VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt.ESAEPDGDPR€120,000
22 Jan 2020Res iudicata terjedelme a hozzáférési kérelem elbírálása kapcsánThe controller did not adequately respond to the data subject’s access request, breaching Article 15 GDPR. NAIH imposed a fine of HUF 2,000,000.HUNAIHGDPR€5,960
23 Jan 2020Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5.ITGaranteGDPR€80,000
23 Jan 2020Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures.ITGaranteGDPR€30,000
24 Jan 2020Adatbiztonsági intézkedések és incidenskezelési gyakorlat hiányosságaiThe entity failed to implement appropriate technical and organizational measures to protect data, including storing access data in printed form. Its internal incident management policy also did not regulate the obligation to notify the supervisory authority.HUNAIHGDPR€1,490
29 Jan 2020B.B.B.The AEPD fined B.B.B. EUR 2,000 for using a phone number for a purpose other than the one for which it was originally collected. The authority found this to be a breach of the GDPR principle of purpose limitation.ESAEPDGDPR€2,000
29 Jan 2020COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images.ESAEPDGDPR€5,000
29 Jan 2020CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules.ESAEPDGDPR€10,000
30 Jan 2020Liceo Nobel di Torre del GrecoLiceo Nobel di Torre del Greco was fined EUR 4,000 by the Garante for publishing a teacher ranking list on its website. The conduct breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
30 Jan 2020Comune di ColledaraComune di Colledara was fined EUR 4,000 by the Garante for publishing personal data in the provisional ranking of a competition on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
04 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish data protection authority, AEPD, in the amount of 5,000 EUR. The sanction concerned obstruction of the authority’s inspection function, which breaches Article 58(1) GDPR.ESAEPDGDPR€5,000
04 Feb 2020VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 50,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for sending an SMS indicating a contract using incorrect personal data. The authority found a breach of Article 6 GDPR concerning the lawful basis for processing.ESAEPDGDPR€50,000
04 Feb 2020TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 75,000 EUR by the AEPD for processing personal data without consent. The case concerned unauthorized portability of a phone line.ESAEPDGDPR€75,000
04 Feb 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for a data protection violation. The case involved unauthorized data processing and signature forgery by an employee, which led to a fraudulent service transfer.ESAEPDGDPR€60,000