Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Feb 2023COMMUNE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on COMMUNE under a simplified procedure and issued an injunction. The case concerned a confirmed breach requiring corrective action.FRCNILGDPR€5,000
08 Feb 2023DKN.5131.50.2021StatusprawomocnaTytuUODO imposed a PLN 33,012 fine on the controller and the processor for failing to implement appropriate technical and organizational measures to secure personal data. The authority also found that the controller did not verify whether the processor provided sufficient guarantees of GDPR compliance and protection of data subjects' rights.PLUODOGDPR€6,967
08 Feb 2023SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE (procédure simplifiée)CNIL imposed a fine of 10,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
08 Feb 2023VODAFONE SERVICIOS, S.L.U.VODAFONE SERVICIOS, S.L.U. was fined by the AEPD 70,000 EUR for a SIM card duplication incident. The incident resulted in identity theft and unauthorized access to a bank account, indicating a breach of data protection rules.ESAEPDGDPR€70,000
08 Feb 2023MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on MEDECIN GENERALISTE under a simplified procedure. The authority also issued an injunction to remedy the identified deficiencies.FRCNILGDPR€3,000
07 Feb 2023Dane anonimowe (Wspólnotę Mieszkaniową „)UODO imposed an administrative fine on a housing community for entrusting personal data processing to an external provider without a written agreement and without verifying adequate technical and organizational safeguards. The authority also cited the failure to notify affected individuals without undue delay about the personal data breach.PLUODOGDPR€327
06 Feb 2023VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 200,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for breaching Article 6(1) GDPR. The case involved unauthorized SIM card duplication that enabled fraudulent bank charges.ESAEPDGDPR€200,000
06 Feb 2023ONEY SERVICIOS FINANCIEROS E.F.C., S.A.ONEY SERVICIOS FINANCIEROS E.F.C., S.A. was fined by the AEPD 50,000 EUR for inaccurately processing personal data. The company included incorrect debt information in credit information systems, breaching data protection principles.ESAEPDGDPR€50,000
06 Feb 2023I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes.HUNAIHGDPR€76,800
06 Feb 2023ROMBOC COMUNICACIONESROMBOC COMUNICACIONES was fined by the AEPD in the amount of 2,000 EUR for making misleading advertising calls without explicit consent from recipients. The case indicates a breach of data protection and direct marketing rules.ESAEPDGDPR€2,000
03 Feb 2023Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls.CYCyDPCGDPR€3,250
02 Feb 2023LEADDESK, S.L.LEADDESK, S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information to the authority, which constitutes a breach of Article 58.1 of the GDPR.ESAEPDGDPR€500
02 Feb 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without the complainant's consent. The incident led to attempts to gain unauthorized access to the complainant's bank accounts.ESAEPDGDPR€70,000
02 Feb 2023TRACTAMENT D'AIGUES TEIA, S.L.TRACTAMENT D'AIGUES TEIA, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a data subject's request to delete personal data. The case indicates non-compliance with GDPR obligations regarding the exercise of individual rights.ESAEPDGDPR€1,000
02 Feb 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for changing a customer's contract ownership and activating services without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
01 Feb 2023Tensa Art Design SAANSPDCP completed an investigation in January 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined EUR 1,000.ROANSPDCPGDPR€1,000
31 Jan 2023Dent Estet Clinic SADent Estet Clinic SA was fined by ANSPDCP EUR 1,000 for breaches of the transparency obligations under GDPR Articles 12–14. The case concerned inadequate compliance with information duties toward data subjects.ROANSPDCPGDPR€1,000
31 Jan 2023Dent Estet Clinic SADent Estet Clinic SA was fined EUR 1,000 by ANSPDCP for failing to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. The incident involved unauthorized disclosure of health data, which required prompt reporting under GDPR rules.ROANSPDCPGDPR€1,000
31 Jan 2023PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules.ESAEPDGDPR€3,000
30 Jan 2023COMUNIDAD DE PROPIETARIOS RÍO CANARIOThe entity did not provide the requested information to the Spanish Data Protection Agency (AEPD). The conduct breached Article 58(1) of the GDPR and resulted in a 500 EUR fine.ESAEPDGDPR€500