Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Mar 2023Finopro IFN SAFinopro IFN SA was fined by ANSPDCP EUR 2,250 for a data security breach caused by a ransomware attack. The incident led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€2,250
03 Mar 2023SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE (procédure simplifiée)The CNIL imposed a EUR 15,000 fine on SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE under a simplified procedure. The case concerns a breach of personal data protection rules.FRCNILGDPR€15,000
02 Mar 2023H&M Hennes & Mauritz s.r.l.H&M Hennes & Mauritz s.r.l. was fined EUR 50,000 by the Garante for violations related to installing surveillance systems without the required authorization. Employees were informed about the systems, but this did not cure the underlying compliance breach.ITGaranteGDPR€50,000
02 Mar 2023Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality.ITGaranteGDPR€50,000
02 Mar 2023WILLOUGHBY COLLEGE, S.A.WILLOUGHBY COLLEGE, S.A. failed to provide requested information to the Spanish Data Protection Agency, which constituted a breach of Article 58.1 of the GDPR. A fine was imposed and reduced due to early payment and acknowledgment of responsibility.ESAEPDGDPR€1,500
02 Mar 2023Il Fatto Quotidiano S.p.A.The Garante fined Il Fatto Quotidiano S.p.A. EUR 20,000 for the unlawful dissemination of personal data linked to a judicial case involving the complainants' father. The authority found that the publication breached personal data protection rules.ITGaranteGDPR€20,000
02 Mar 2023Razmataz Live S.r.l.Razmataz Live S.r.l. was fined by the Garante 1,000 EUR for failing to take measures to mitigate or eliminate the consequences of a data protection breach linked to promotional activities. The authority also noted that informed consent for commercial communications was not ensured.ITGaranteGDPR€1,000
02 Mar 2023Flowers R di Malalan MitjaMalalan Mitja was fined by the Garante in the amount of 5,000 EUR for sending unsolicited promotional emails. The messages were sent to randomly generated email addresses, which constituted a breach of GDPR requirements.ITGaranteGDPR€5,000
01 Mar 2023Spółdzielnie Mieszkaniową „UODO imposed an administrative fine of PLN 51,876 on the controller for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected data subject was not informed about the breach.PLUODOGDPR€11,098
01 Mar 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial communications by text messages and phone calls. The conduct continued despite the recipient’s request to stop contacting them and not to share their phone number for commercial purposes.ESAEPDGDPR€20,000
01 Mar 2023ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing.ESAEPDGDPR€3,000
28 Feb 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for processing personal data without consent. The case concerned a mobile line contracted in the complainant’s name without proper identity verification.ESAEPDGDPR€70,000
28 Feb 2023PELAYO MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJAPelayo Mutua de Seguros y Reaseguros A Prima Fija was fined 70,000 EUR by the AEPD. The authority found that the company disclosed personal data to a third party without consent, breaching GDPR confidentiality and security obligations.ESAEPDGDPR€70,000
27 Feb 2023B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for installing surveillance cameras that could capture images of a neighbor's property without authorization. The authority found this to be a breach of the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€300
27 Feb 2023Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected.IEDPCGDPR€750,000
27 Feb 2023SIA “FitsyproA monetary fine of EUR 1,000 was imposed. The decision is final and has entered into force.LVDVIGDPR€1,000
27 Feb 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for breaching Article 6(1) GDPR after a SIM card was duplicated without consent. The incident enabled unauthorized access to a customer's bank accounts, indicating serious failures in verification and data protection controls.ESAEPDGDPR€200,000
27 Feb 2023Adatkezelési tájékoztatás átláthatóságaThe entity did not provide data subjects with transparent and accurate information about the purposes and legal bases of processing. This breached GDPR Articles 6, 12, and 13, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,630
23 Feb 2023TECH TALENTS, S.L.TECH TALENTS, S.L. was fined EUR 2,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications sent without prior consent.ESAEPDePrivacy€2,000
23 Feb 2023Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected.IEDPCGDPR€460,000