Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Feb 2023Ediscom S.p.A.Ediscom S.p.A. was fined by the Garante 300,000 EUR for lacking clarity and transparency when obtaining user consent for marketing purposes. The authority also found that data was processed despite objections from data subjects.ITGaranteGDPR€300,000
23 Feb 2023TársasházThe NAIH imposed a 200,000 HUF fine on Társasház for GDPR breaches linked to its electronic surveillance system. The authority found deficiencies in the processing purposes, legal basis, and information provided to data subjects.HUNAIHGDPR€524
23 Feb 2023Okmánymásolás és fényképek készítése és közzététele munkahelyenThe authority imposed a fine for copying applicants’ identity documents and for failing to provide adequate information to data subjects during the recruitment process. The case concerned breaches of information duties and personal data processing rules in the workplace.HUNAIHGDPR€524
22 Feb 2023MUNDOVIAJES2010, S.L.MUNDOVIAJES2010, S.L. was fined by the AEPD in the amount of 7,000 EUR for processing personal data without consent. The authority also found a failure to provide the required information about data processing, in breach of GDPR Articles 6(1) and 14.ESAEPDGDPR€7,000
22 Feb 2023ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD 70,000 EUR for changing an individual's electricity provider without consent. The authority found a breach of Article 6 GDPR, which requires a lawful basis for processing personal data.ESAEPDGDPR€70,000
22 Feb 2023B.B.B.The entity was fined by the AEPD 300 EUR for installing a surveillance camera that could capture images of a neighboring property without authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€300
22 Feb 2023CONGREGACIÓN DEL SANTÍSIMO REDENTOR CURIA PROVINCIALThe entity was fined 500 EUR by the AEPD for installing a video surveillance system that could capture public areas without prior administrative authorization. The authority found this to be a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€500
21 Feb 2023C.C.C.The entity was fined by the AEPD in the amount of EUR 300 for installing a video surveillance system that captured public areas. This conduct breached data protection rules.ESAEPDGDPR€300
20 Feb 2023Mindenki Magyarországa MozgalomNAIH imposed a HUF 3,000,000 fine on Mindenki Magyarországa Mozgalom and Márki-Zay Péter for GDPR violations. The authority found inadequate data processing information and failure to respect the right to object in Facebook Messenger communications.HUNAIHGDPR€7,830
20 Feb 2023B.B.B.B.B.B. installed a surveillance camera aimed at a private property without authorization. The AEPD found this to be a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€300
16 Feb 2023CONCENTRA CENTRAL DE COMPRAS Y SERVICIOS S.L.The entity was fined for making misleading advertising calls without explicit consent from recipients. The authority cited breaches of GDPR Articles 14 and 21(4).ESAEPDGDPR€2,000
16 Feb 2023BOX 24 2050 S.L.BOX 24 2050 S.L. was fined by the AEPD 2,000 EUR for making misleading advertising calls without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing.ESAEPDGDPR€2,000
15 Feb 2023It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR.GBICOePrivacy€225,000
14 Feb 2023MENZIES AVIATION SPAIN S.L.MENZIES AVIATION SPAIN S.L. was fined by the AEPD 2,000 EUR for sending emails to multiple recipients without using BCC. This exposed employees’ personal data to other recipients.ESAEPDGDPR€2,000
13 Feb 2023B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 2,000 for breaching Article 6 of the GDPR. The case concerned the unauthorized dissemination of a video on social media platforms, including Twitter.ESAEPDGDPR€2,000
13 Feb 2023FUNDACIÓN PRIVADA UNIVERSITARIA EADAThe entity used a participant’s image in a promotional activity without obtaining consent. This constituted a breach of data protection rules and resulted in a fine imposed by the AEPD.ESAEPDGDPR€2,000
10 Feb 2023SIA "SOAAR"SIA "SOAAR" was fined EUR 800 by the DVI. The decision entered into force on 10.02.2023.LVDVIGDPR€800
09 Feb 2023Anonymizováno (ÚOOÚ UOOU-04020/22-13)The entity was fined for repeatedly sending unsolicited commercial communications by electronic means without recipients' consent. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€1,688
08 Feb 2023SatsThe Norwegian DPA, Datatilsynet, fined Sats 10,000,000 NOK for breaches of GDPR requirements. The case concerned data subjects' rights to information, access, and erasure, as well as the lack of a legal basis for processing certain personal data.NODatatilsynetGDPR€906,000
08 Feb 2023Medijobs Platform SRLMedijobs Platform SRL was fined EUR 5,000 by ANSPDCP after unauthorized access to its IT infrastructure. The incident led to the downloading and deletion of certain personal data.ROANSPDCPGDPR€5,000