Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jul 2020dr. Hadházy Ákos ÁnyosThe controller processed personal data without a legal basis and did not provide adequate information about the processing linked to a petition concerning accession to the European Public Prosecutor's Office. The case indicates breaches of core transparency and lawfulness obligations.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles.HUNAIHGDPR€2,820
09 Jul 2020Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing.ITGaranteGDPR€16,729,000
09 Jul 2020Comune di BaronissiComune di Baronissi was fined by the Garante for publishing personal data online without a proper legal basis. The authority found a breach of the data minimization principle.ITGaranteGDPR€2,000
09 Jul 2020Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention.ITGaranteGDPR€800,000
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine.HUNAIHGDPR€2,820
09 Jul 2020Merlini s.r.l.Merlini s.r.l. was fined 200,000 EUR by the Garante. The authority found that the collection of potential clients' personal data did not comply with GDPR consent requirements and that call-center activities were carried out outside the telemarketing procedures established by Wind Tre.ITGaranteGDPR€200,000
10 Jul 2020COMUNIDAD.1The entity was fined for installing surveillance cameras with audio in common areas without proper notice to affected persons. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,000
10 Jul 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1.ESAEPDGDPR€100,000
16 Jul 2020TELEFÓNICA DE ESPAÑA, S.A.U.TELEFÓNICA DE ESPAÑA, S.A.U. was fined EUR 55,000 by the AEPD for processing personal data without consent. The company registered phone lines and charged invoices to an individual who had not authorized these actions.ESAEPDGDPR€55,000
17 Jul 2020Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness.HUNAIHGDPR€1,415
20 Jul 2020CENTRO DE INVESTIGACIÓN Y ESTUDIO PARA LA OBESIDAD, S.L.The entity unlawfully transferred personal data without consent, in breach of Article 6 of the GDPR. The case resulted in an administrative fine of 50,000 EUR.ESAEPDGDPR€50,000
20 Jul 2020CABRERA & GIL ABOGADOS, S.L.P.CABRERA & GIL ABOGADOS, S.L.P. was fined by the AEPD €2,000 for disclosing personal data without consent. The case concerns Article 6 GDPR, which requires a valid legal basis for processing personal data.ESAEPDGDPR€2,000
20 Jul 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD €75,000 for charging a complainant for services linked to a third-party mobile number without consent. The authority found a breach of Article 6(1) GDPR because there was no lawful basis for the processing and related charges.ESAEPDGDPR€75,000
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by NAIH 2,500,000 HUF for publishing personal data without a proper legal basis. The authority also found that the company failed to provide adequate information to the data subjects in connection with the Forbes publication.HUNAIHGDPR€7,200
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe authority found that Mediarey Hungary Services Zrt. unlawfully processed personal data related to Forbes magazine publications. It also failed to adequately inform data subjects about their rights, resulting in breaches of several GDPR provisions.HUNAIHGDPR€5,760
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,500,000 HUF for failing to provide adequate information to data subjects about processing and their rights. The authority also found that the company did not demonstrate compelling legitimate grounds for continued processing after objections were raised.HUNAIHGDPR€7,200
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe NAIH imposed a 2,500,000 HUF fine on Mediarey Hungary Services Zrt. for unlawful data processing related to Forbes magazine publications. The authority found that data subjects were not adequately informed and that their rights to object and erasure were not respected.HUNAIHGDPR€7,200
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,000,000 HUF for insufficient data protection measures in its Forbes publications. The authority also found that data subjects were not adequately informed and that several GDPR provisions were breached.HUNAIHGDPR€5,760
23 Jul 2020Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed.FITSVGDPR€7,000