Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Feb 2020BAZAR SUSANABAZAR SUSANA was fined EUR 4,000 by the AEPD for improperly obtaining and disseminating personal images from a video surveillance system. The case concerns a breach of data protection rules and the unlawful processing of CCTV footage.ESAEPDGDPR€4,000
05 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 75,000 by the AEPD for processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€75,000
05 Feb 2020TELEFONICA MÓVILES ESPAÑA, S.A.U.TELEFONICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 30,000 EUR for failing to comply with a resolution concerning the GDPR right of access. The case indicates non-implementation of an obligation set out in a prior supervisory authority decision.ESAEPDGDPR€30,000
06 Feb 2020R.T.I. - Reti Televisive Italiane s.p.a.R.T.I. - Reti Televisive Italiane s.p.a. was fined EUR 20,000 by the Garante for broadcasting a segment on “Le Iene”. The segment made the complainant identifiable through her voice and personal information, breaching data protection rules.ITGaranteGDPR€20,000
06 Feb 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for a personal data breach. An error in assigning identification numbers allowed one customer to access another customer's personal data.ESAEPDGDPR€70,000
06 Feb 2020Liceo Artistico Statale di NapoliLiceo Artistico Statale di Napoli was fined EUR 4,000 by the Garante for publishing an outdated teacher ranking on its institutional website. The authority found this breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
06 Feb 2020Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements.ITGaranteGDPR€10,000
07 Feb 2020SOLO EMBRAGUE, S.L.SOLO EMBRAGUE, S.L. was fined by the AEPD 3,000 EUR for failing to provide information about its privacy policy and for not obtaining consent for cookies on its website. The case concerns breaches of transparency obligations and consent requirements under data protection rules.ESAEPDePrivacy€3,000
10 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD for processing personal data without valid consent. The case concerned a debt claim made against an individual for a contract they had not entered into.ESAEPDGDPR€60,000
11 Feb 2020AMALFI SERVICIOS DE RESTAURACIÓN S.L.AMALFI SERVICIOS DE RESTAURACIÓN S.L. was fined by the AEPD 6,000 EUR for installing surveillance cameras without proper consent. The authority also found that the cameras captured images of public spaces without sufficient justification, breaching data protection rules.ESAEPDGDPR€6,000
11 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The conduct breached Article 58(1) of the GDPR and hindered the authority’s supervisory powers.ESAEPDGDPR€5,000
12 Feb 2020AEMA HISPANICA, S.L.AEMA HISPANICA, S.L. was fined by the AEPD 6,000 EUR for sending one employee's payroll to another employee. The incident constituted a breach of data protection rules.ESAEPDGDPR€6,000
13 Feb 2020Comune di Urago d'OglioComune di Urago d'Oglio was fined EUR 4,000 by the Garante for improper processing and online publication of special-category personal data, including health data. The authority found insufficient legal basis and inadequate transparency toward the data subjects.ITGaranteGDPR€4,000
18 Feb 2020Equifax Iberica, S.L.Equifax Iberica, S.L. was fined by the AEPD in the amount of 75,000 EUR for processing personal data without a proper legal basis. The authority cited a breach of Article 6(1)(f) of the GDPR.ESAEPDGDPR€75,000
18 Feb 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for incorrectly linking a customer's phone lines to another person's details. The case concerned a breach of data protection rules and indicated deficiencies in personal data processing.ESAEPDGDPR€70,000
18 Feb 2020ZSZZS.440.768.2018StatusuchylonaTytuUODO found a breach related to the processing of children’s biometric data in connection with use of the school canteen. A fine of PLN 20,000 was imposed.PLUODOGDPR€4,679
19 Feb 2020CITRICOS Y FRUTALES DEL SURESTE, S.L.CITRICOS Y FRUTALES DEL SURESTE, S.L. was fined by the AEPD 3,000 EUR for installing video surveillance in common areas without approval from the property owners' association and without obtaining explicit consent from affected individuals. The authority found breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
24 Feb 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD EUR 50,000 for sending commercial advertising by postal mail to a customer who had objected to the processing of their data for advertising purposes. The authority found this conduct contrary to GDPR Article 6(1)(f).ESAEPDGDPR€50,000
25 Feb 2020Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation.HRAZOPGDPR€145,000
26 Feb 2020Comune di Fogliano RedipugliaThe Municipality of Comune di Fogliano Redipuglia was fined by the Garante for unlawfully publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€6,000