Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Dec 2022Comune di VicchioComune di Vicchio was fined by the Garante 8,000 EUR for using fingerprints to monitor employee attendance without appropriate legal basis and safeguards. The authority found that the biometric processing breached GDPR requirements.ITGaranteGDPR€8,000
15 Dec 2022Comune di BorgiaComune di Borgia was fined by the Garante 5,000 EUR for processing employees’ biometric data for attendance tracking without appropriate legislative measures and specific safeguards. The authority found this to be a breach of GDPR rules on special-category data.ITGaranteGDPR€5,000
15 Dec 2022Eurosanità S.P.A.Eurosanità S.P.A. was fined by the Garante in the amount of 30,000 EUR for violations related to the processing of health data. The authority cited inadequate personal data protection measures.ITGaranteGDPR€30,000
14 Dec 2022MÁRMOLES Y GRANITOS MEJIAS, S. L.The company was fined by the AEPD in the amount of 600 EUR for operating a video surveillance system without proper signage and required authorization. This may have infringed the rights of third parties and data protection rules.ESAEPDGDPR€600
14 Dec 2022Monetise Media LimitedBetween 28 July 2020 and 28 July 2021, Monetise Media Limited sent 3,506,157 direct marketing emails and text messages. The recipients had not provided valid consent, which breached regulation 22 of PECR.GBICOePrivacy€145,000
14 Dec 2022ODRIA COSTAS INTERNACIONAL, S.L.ODRIA COSTAS INTERNACIONAL, S.L. was fined EUR 10,000 by the AEPD for publishing images of minors without consent on a real estate website. The authority found this to be a breach of data protection rules.ESAEPDGDPR€10,000
13 Dec 2022Anonymisé (CNPD decision-23-fr-2022)The company failed to meet the transparency obligations under Article 12(1) GDPR by not providing the required information in a concise, transparent, and easily accessible manner. CNPD treated this as a breach of the information duties owed to data subjects.LUCNPDGDPR€1,300
13 Dec 2022Anonymisé (CNPD decision-18-fr-2022)The company unlawfully transmitted personal data to third parties without prior authorization. The authority also found breaches of GDPR data processing principles and data subject rights.LUCNPDGDPR€2,500
13 Dec 2022Anonymisé (CNPD decision-20-fr-2022)The entity failed to meet GDPR transparency obligations, particularly by not providing information in a clear and accessible manner. CNPD imposed a fine of 4,200 EUR.LUCNPDGDPR€4,200
13 Dec 2022CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company did not respond to a data access request and failed to publish information on data processing or the data controller on its website. AEPD treated this as a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€2,000
13 Dec 2022Anonymisé (CNPD decision-21-fr-2022)The company was fined EUR 3,700 by the CNPD for breaching the transparency obligations under Article 12(1) of the GDPR. The authority found that information was not sufficiently accessible to users.LUCNPDGDPR€3,700
13 Dec 2022Anonymisé (CNPD decision-19-fr-2022)The company failed to meet GDPR transparency obligations by not providing the required information in a concise, transparent, and easily accessible manner. CNPD imposed a fine of 1,000 EUR.LUCNPDGDPR€1,000
13 Dec 2022Anonymisé (CNPD decision-22-fr-2022)The CNPD found that the entity breached GDPR transparency obligations by failing to provide information in a concise, transparent, and easily accessible manner. The infringement concerned Articles 12 and 13 of the GDPR.LUCNPDGDPR€1,700
13 Dec 2022Anonymisé (CNPD decision-24-fr-2022)The entity failed to meet GDPR transparency obligations, particularly regarding the accessibility and comprehensibility of information provided to data subjects. CNPD imposed a fine of EUR 3,700.LUCNPDGDPR€3,700
09 Dec 2022Casa Rusu S.R.L.The company was fined for a data security breach on its online payment section. An unauthorized form was introduced there and collected customers’ card data.ROANSPDCPGDPR€2,000
08 Dec 2022Danske Shoppingcentre P/SDanske Shoppingcentre P/S was fined by Datatilsynet for unlawful CCTV surveillance of a toilet area in City2. The authority found a breach of the GDPR data minimization principle.DKDatatilsynetGDPR€47,054
02 Dec 2022IK "Rigas Komunal Service"A fine of 500 EUR was imposed by the DVI. The decision was appealed.LVDVIGDPR€500
01 Dec 2022Regione CampaniaRegione Campania was fined by the Garante in the amount of EUR 10,000 for unauthorized access to personal data. The case concerned breaches of GDPR requirements on data protection and security measures.ITGaranteGDPR€10,000
01 Dec 2022Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules.ITGaranteGDPR€8,000
01 Dec 2022Regione LazioThe Garante fined Regione Lazio EUR 100,000 for unlawfully collecting metadata from employees' emails without a proper legal basis. The authority found that the processing did not meet the legal requirements for monitoring employee communications.ITGaranteGDPR€100,000