Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Feb 2020Comune di AstiComune di Asti was fined EUR 8,000 by the Garante for unlawfully publishing personal data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000
27 Feb 2020Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent.ITGarante per la protezione dei dati personaliGDPR€27,800,000
03 Mar 2020SANGIL Y GARCÍA, S.L.SANGIL Y GARCÍA, S.L. was fined by the AEPD 1,800 EUR for sending promotional emails using personal data obtained from the Boletín Oficial de la Propiedad Industrial. The company had no prior client relationship with the recipients, which breached data protection rules.ESAEPDePrivacy€1,800
03 Mar 2020Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle.NLAPGDPR€525,000
04 Mar 2020Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook.HUNAIHGDPR€299
05 Mar 2020S.Á.Á.S.Á.Á. was fined for a data breach in which a former employee received sensitive patient information. The authority found that technical and organizational measures were inadequate.ISPersónuverndGDPR€21,090
05 Mar 2020Fjölbrautaskólinn í BreiðholtiFjölbrautaskólinn í Breiðholti was fined by Persónuvernd after a teacher accidentally sent sensitive personal data about students to unauthorized recipients. The authority found that the school had not implemented adequate technical and organizational measures to protect data security.ISPersónuverndGDPR€9,139
05 Mar 2020Comune di San Giorgio JonicoComune di San Giorgio Jonico was fined by the Garante for publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€3,000
05 Mar 2020CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation.NLAutoriteit PersoonsgegevensGDPR€40,000
05 Mar 2020Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place.ITGaranteGDPR€8,000
06 Mar 2020IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD in the amount of EUR 5,000 for failing to provide requested information to the data protection authority. The conduct breached Article 58(1) of the GDPR.ESAEPDGDPR€5,000
06 Mar 2020B.B.B.A private individual was fined by the AEPD €1,000 for installing surveillance cameras without the required informational signage. The case concerned a breach of data protection rules linked to proper notice for video surveillance.ESAEPDGDPR€1,000
06 Mar 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency.ESAEPDGDPR€60,000
09 Mar 2020OLIVEROS USTRELL, S.L.OLIVEROS USTRELL, S.L. was fined 10,000 EUR by the AEPD for unauthorized processing of a customer's personal and banking data. The case involved a fraudulent mobile contract and number portability carried out without a valid legal basis.ESAEPDGDPR€10,000
09 Mar 2020Személyes adat a természetes személy állandó használatában lévő telefonszámThe controller was fined for unlawfully processing the complainant's phone number. The authority found a breach of the GDPR principles of lawfulness and accuracy in personal data processing.HUNAIHGDPR€891
09 Mar 2020Dane anonimowe (V. Sp. z o.o. w likwidacji z siedzibą w Z. przy ul.)The President of UODO imposed a PLN 20,000 fine on V. Sp. z o.o. in liquidation for failing to provide access to personal data, other information, and premises. This prevented the authority from carrying out inspection activities necessary for its duties.PLUODOGDPR€4,637
10 Mar 2020Hørsholm KommuneThe Danish DPA reported Gladsaxe and Hørsholm Municipalities to the police for inadequate data security measures. The court fined Hørsholm Municipality DKK 50,000 for failing to encrypt computers containing sensitive personal data, which led to a data breach.DKDatatilsynetGDPR€6,692
11 Mar 2020SALAD MARKET S.L.SALAD MARKET S.L. was fined by the AEPD €3,000 for using video cameras to monitor employees without informing them. The company also added employees to WhatsApp groups without consent, which breached data protection rules.ESAEPDePrivacy€3,000
11 Mar 2020Google, rätten att få sökresultat borttagnaGoogle LLC was fined by IMY for processing sensitive personal data without a valid legal basis and for handling data relating to criminal offenses without authorization. The authority also found that Google did not respond promptly to requests for data removal, in breach of several GDPR provisions.SEIMYGDPR€6,993,000
19 Mar 2020Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle.HUNAIHGDPR€5,620