Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Jun 2020MALAGATROM, S.L.U.MALAGATROM, S.L.U. was fined by the AEPD 4,000 EUR for processing and disclosing personal data on Amazon without consent. The authority found this conduct to be contrary to Article 6 of the GDPR.ESAEPDGDPR€4,000
03 Jun 2020Dane anonimowe (Panią A. T. prowadzącą działalność gospodarczą pod nazwą)UODO imposed a PLN 5,000 administrative fine on Dane anonimowe (Panią A. T. prowadzącą działalność gospodarczą pod nazwą). The case concerned a failure to provide information requested by the supervisory authority.PLUODOGDPR€1,133
04 Jun 2020AUTO DESGUACES IGLESIAS, S.L.AUTO DESGUACES IGLESIAS, S.L. was fined by the AEPD 1,500 EUR for using cameras that recorded public spaces without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
04 Jun 2020PRA IBERIA, S.L.PRA IBERIA, S.L. was fined by the AEPD 60,000 EUR for unlawful processing of personal data and for failing to provide access to personal data information. The breaches concerned Articles 6(1) and 15 of the GDPR.ESAEPDGDPR€60,000
05 Jun 2020EDP Energía, S.A.U.EDP Energía, S.A.U. was fined €50,000 by the AEPD for processing personal data without consent. The authority found this conduct to be in breach of Article 6(1) of the GDPR.ESAEPDGDPR€50,000
05 Jun 2020BUBO MEDIA, S.L.BUBO MEDIA, S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS messages to individuals without their consent. The conduct breached data protection and electronic communications rules.ESAEPDePrivacy€1,500
05 Jun 2020FURNISHYOURSPACE SL.FURNISHYOURSPACE SL. was fined by the AEPD EUR 3,000 for failing to provide information or obtain consent regarding data storage and retrieval devices on its websites. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
06 Jun 2020GLOBAL BUSINESS TRAVEL SPAIN S.L.U.An employee of GLOBAL BUSINESS TRAVEL SPAIN S.L.U. improperly accessed and disclosed an individual's health data. The AEPD found this to be a breach of the integrity and confidentiality principles under data protection law.ESAEPDGDPR€5,000
08 Jun 2020Volt munkavállaló munkavégzési célú elektronikus leveleihez való hozzáféréseThe controller unlawfully denied access to the complainant's archived personal emails from 2018. It also failed to provide transparent information about the actions taken in response to the data subject's request.HUNAIHGDPR€582
08 Jun 2020B.B.B.B.B.B. was fined by the AEPD 1,500 EUR for maintaining a video surveillance camera directed toward common areas without justified cause. The conduct caused anxiety to the complainant and was treated as a data protection breach.ESAEPDGDPR€1,500
08 Jun 2020G.L.P. Instalaciones 86, S.L.G.L.P. Instalaciones 86, S.L. was fined by the AEPD EUR 60,000 for processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€60,000
08 Jun 2020de heer YThe APD Litigation Chamber fined de heer Y 5,000 EUR. It found that personal data from the municipal staff list was processed for election propaganda, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
10 Jun 2020UniCredit S.p.A.UniCredit S.p.A. was fined by Garante EUR 600,000 for a data breach. The incident involved unauthorized access to personal data of about 762,000 individuals after an intrusion using credentials of employees from an external partner.ITGaranteGDPR€600,000
10 Jun 2020Comune di MontevagoComune di Montevago was fined by the Garante 2,000 EUR for the unlawful online publication of personal data without an appropriate legal basis. The case concerned a breach of the principles of lawful processing and data protection in the public disclosure of information online.ITGaranteGDPR€2,000
10 Jun 2020Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis.ITGaranteGDPR€2,000
11 Jun 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the AEPD for failing to provide requested information. The breach concerned the duty to cooperate with the data protection authority during its proceedings.ESAEPDGDPR€5,000
11 Jun 2020XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined EUR 55,000 by the AEPD for linking a phone number to a third party’s data. This created unauthorized access and a risk of data alteration, breaching data protection rules.ESAEPDGDPR€55,000
15 Jun 2020Bostadsrättsförening HalmstadBRF Gårdsbjörken was fined by IMY for unlawful video and audio surveillance in common areas. The authority found breaches of GDPR principles, including data minimization and transparency.SEIMYGDPR€1,898
16 Jun 2020REAL SPORTING DE GIJÓN, S.A.D.REAL SPORTING DE GIJÓN, S.A.D. was fined EUR 5,000 by the AEPD for breaching GDPR Article 7 on consent requirements. The case arose from a complaint by the Ministry of Finance concerning advertising practices.ESAEPDGDPR€5,000
16 Jun 2020SAUNIER-TEC, MANTENIMIENTOS DE CALOR Y FRIO, S.LSAUNIER-TEC was fined EUR 6,000 by the AEPD for a data breach. The incident involved unauthorized access to personal data and bank account information, breaching GDPR Articles 33 and 34.ESAEPDGDPR€6,000