Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Mar 2020VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 1,500 EUR for retaining personal data after a deletion request. The case also involved sending an email to a former member despite consent being withdrawn, which breached GDPR requirements.ESAEPDGDPR€1,500
26 Mar 2020Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights.ITGaranteGDPR€10,000
26 Mar 2020Ügyfélszám téves rögzítésével összefüggő jogellenes adatkezelés és célhoz kötöttség elvének megsértéseThe controller unlawfully processed personal data related to a loan agreement, breaching the GDPR purpose limitation principle. NAIH imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
02 Apr 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 52,000 by the AEPD for sending SMS messages to a complainant about another customer's unpaid bills. The authority found that this disclosure breached data protection rules.ESAEPDGDPR€52,000
02 Apr 2020HAPPY FRIDAY, S.L.HAPPY FRIDAY, S.L. was fined by the AEPD in the amount of 2,500 EUR for failing to comply with data protection rules on the use of cookies. The authority found that the company did not provide the required information or obtain user consent.ESAEPDePrivacy€2,500
06 Apr 2020PETROLIS INDEPENDENTS, S.L.PETROLIS INDEPENDENTS, S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding cookie policies on its website. The case concerned information requirements and the compliance of cookie mechanisms with privacy rules.ESAEPDePrivacy€3,000
09 Apr 2020Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF.HUNAIHGDPR€1,410
27 Apr 2020Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34.HUNAIHGDPR€21,150
30 Apr 2020vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR.NLAPGDPR€725,000
11 May 2020Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32.SEIMYGDPR€11,321
12 May 2020B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for installing a video surveillance system without justified cause. The measure infringed a tenant’s privacy and resulted in unlawful processing of personal data.ESAEPDGDPR€2,000
14 May 2020Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements.BEAPDGDPR€50,000
14 May 2020Anonymizováno (ÚOOÚ spr-563809-118)The entity was fined for operating a camera system without meeting the information obligations required under Czech data protection law. The case concerns a breach of transparency duties toward individuals subject to surveillance.CZUOOUGDPR€145
14 May 2020Geanonimiseerd (APD 24/2020)The decision concerns an insurance company that failed to provide sufficient transparency in its privacy policy. It involved the use of health data without explicit consent for purposes beyond hospitalization insurance.BEAPDGDPR€50,000
14 May 2020Anonymizováno (ÚOOÚ UOOU-1936/19-68)The entity was fined 1,500,000 CZK by the UOOU. The authority found that required corrective measures under the Czech Data Processing Act were not implemented.CZUOOUGDPR€54,405
15 May 2020JobTeam A/SJobTeam A/S was reported to the police, and Datatilsynet recommended a fine of 50,000 DKK for breaching GDPR principles. The company deleted personal data after a data subject access request, which hindered the exercise of the individual's rights.DKDatatilsynetGDPR€6,705
18 May 2020Digi Távközlési és Szolgáltató Kft.Digi Távközlési és Szolgáltató Kft. was fined by the NAIH 100,000,000 HUF for failing to delete a test database containing personal data after its intended use. The authority also found inadequate security measures, which led to unauthorized access to personal data.HUNAIHGDPR€283,000
21 May 2020TuslaThe Irish DPC imposed a fine of EUR 40,000 on Tusla in case IN-19-12-8. The fine was collected.IEDPCGDPR€40,000
28 May 2020Azienda Teatro del GiglioAzienda Teatro del Giglio was fined 6,000 EUR by the Garante for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€6,000
29 May 2020Dane anonimowe (R. Sp. z o.o. z siedzibą w D. przy ul.)UODO imposed a fine of PLN 15,000 on R. Sp. z o.o. The sanction concerned the failure to provide information required by the authority.PLUODOGDPR€3,371