Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Jul 2020I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.UI-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U was fined by the AEPD EUR 200,000 for sending letters to customers without a legal basis. The authority found that this breached the principles of data minimization and purpose limitation.ESAEPDGDPR€200,000
24 Jul 2020IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia Líneas Aéreas de España, S.A. Operadora Unipersonal 30,000 EUR. The authority found that the website did not provide users with an option to reject cookies in line with consent requirements.ESAEPDePrivacy€30,000
28 Jul 2020Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
28 Jul 2020Anonymizováno (ÚOOÚ UOOU-05226/19-22)The entity was fined for publishing personal data of court proceeding participants on a website. The authority found this to be a breach of data protection law.CZUOOUGDPR€1,905
29 Jul 2020CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data.ESAEPDGDPR€4,000
31 Jul 2020ASOCIACIÓN DE VIGILANTES DE SEGURIDAD DEL AEROPUERTO DE BARCELONAThe organization was fined by the AEPD in the amount of 3,000 EUR for sending an electoral census of workers to private phones via WhatsApp. The authority found a breach of data protection principles.ESAEPDGDPR€3,000
04 Aug 2020PrivatBo A.M.B.A. af 1993PrivatBo was reported to the police, and Datatilsynet recommended a fine of 150,000 DKK for inadequate data security measures. The incident led to the unintended disclosure of tenants' confidential information on USB drives.DKDatatilsynetGDPR€20,145
05 Aug 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation.ESAEPDGDPR€50,000
06 Aug 2020Hozzáférési jog, adatpontosság és átláthatóság elvének megsértéseThe decision concerned unlawful processing of personal data during debt collection and breaches of access rights and information obligations under the GDPR. Both entities involved in the case were fined for their actions.HUNAIHGDPR€5,780
07 Aug 2020TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for unauthorized access to a customer's data and harassment through excessive calls and messages. The case indicates failures in data protection controls and customer contact practices.ESAEPDGDPR€75,000
11 Aug 2020FEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓNFEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓN was fined by the AEPD 5,000 EUR for the unauthorized disclosure of personal data. The data included names, DNI numbers, and signatures, which were published in a newspaper and on social media.ESAEPDGDPR€5,000
11 Aug 2020DERDIX 5000 SLThe entity published photos of minors in a magazine without obtaining consent, which constitutes a breach of data protection rules. The case concerns the unauthorized disclosure of children’s images and was sanctioned by the AEPD.ESAEPDGDPR€2,000
12 Aug 2020TuslaThe Irish DPC fined Tusla EUR 85,000 in inquiry IN-18-11-4. The fine has been collected.IEDPCGDPR€85,000
13 Aug 2020Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis.HUNAIHGDPR€5,800
18 Aug 2020HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected.IEDPCGDPR€65,000
19 Aug 2020Anonymizováno (ÚOOÚ UOOU-05284/19-36)The entity was fined for publishing a partially anonymized criminal order on Facebook that still contained personal data. The authority found a breach of GDPR principles governing lawful processing and personal data protection.CZUOOUGDPR€383
21 Aug 2020ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations.PLUODOGDPR€11,369
24 Aug 2020Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records.PLUODOGDPR€22,735
26 Aug 2020Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services.CZUOOUePrivacy€228,000
01 Sept 2020Asociația de proprietari Bl. FC 5, orașul Năvodari, județul ConstanțaThe homeowners' association was fined by ANSPDCP EUR 500 for unlawfully processing an individual's image from the video surveillance system. The image was displayed on the building's notice board, which breached data processing principles.ROANSPDCPGDPR€500