Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Nov 2022Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure.ITGaranteGDPR€1,000,000
24 Nov 2022dott.ssa Emilia ColosimoThe Garante imposed a EUR 1,000 fine on dott.ssa Emilia Colosimo for breaches of the principles of lawful, fair and transparent processing of personal data, data minimization, and data security. The authority also cited insufficient safeguards against unauthorized or unlawful processing.ITGaranteGDPR€1,000
24 Nov 2022Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data.ROANSPDCPGDPR€1,000
24 Nov 2022Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di CagliariOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari was fined €3,000 by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data related to an individual's employment.ITGaranteGDPR€3,000
23 Nov 2022Linee Stampalibera Società Cooperativa S.r.l.Linee Stampalibera Società Cooperativa S.r.l. was fined 1,000 EUR by the Garante for publishing personal data on its website without consent. The case also involved the full text of a property purchase contract, which breached data protection rules.ITGaranteGDPR€1,000
21 Nov 2022ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller.ROANSPDCPGDPR€20,000
18 Nov 2022Asociația de Proprietari Bld. Pipera 1-2EThe association was fined for failing to provide requested information within the legal deadline. The case concerns a breach of the duty to cooperate with the supervisory authority.ROANSPDCPGDPR€300
17 Nov 2022NUEVAS TECNOLOGIAS MEDITERRANEO, S.L.NUEVAS TECNOLOGIAS MEDITERRANEO, S.L. was fined by the AEPD EUR 800 for sending unsolicited advertising emails without prior consent. The case concerned a breach of Article 21 of the LSSI and unlawful direct marketing.ESAEPDePrivacy€800
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 3,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and the handling of security events.ROANSPDCPGDPR€3,000
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 5,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and required remedial action by the bank.ROANSPDCPGDPR€5,000
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined by ANSPDCP EUR 20,000 for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and security requirements. The decision highlights the need for effective technical and organizational controls.ROANSPDCPGDPR€20,000
15 Nov 2022GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity was fined for sending unsolicited commercial emails despite the recipient's explicit objection. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
15 Nov 2022Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000.HUNAIHGDPR€4,940
14 Nov 2022Megismételt eljárásban bírság kiszabásaThe authority imposed a fine for violations related to the processing of personal data and special categories of data, including health data, without proper notification and consent. The case also concerned actions linked to the termination of an employment relationship.HUNAIHGDPR€1,230
10 Nov 2022Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data.ITGaranteGDPR€20,000
10 Nov 2022Azienda Usl Valle d’AostaAzienda Usl Valle d’Aosta was fined EUR 40,000 by the Garante for unlawful access to a patient's health dossier. The access was made by a healthcare professional not involved in the patient's care, breaching GDPR data processing principles.ITGaranteGDPR€40,000
10 Nov 2022Conservatorio di Musica S. Cecilia di RomaThe Conservatorio di Musica S. Cecilia di Roma was fined €6,000 by the Garante. The authority found unlawful processing of personal data contained in an audio/video recording used in disciplinary proceedings against a student without a lawful basis.ITGaranteGDPR€6,000
10 Nov 2022SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEECNIL imposed a fine of 800,000 EUR on SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEE. The decision concerns a breach of rules covered by the authority’s enforcement action.FRCNILGDPR€800,000
10 Nov 2022Doctolib SrlDoctolib Srl was fined EUR 40,000 by the Italian Garante for violations linked to insufficient transparency in the online information provided to patients. The case concerned, in particular, how consent for processing health data was obtained.ITGaranteGDPR€40,000
10 Nov 2022Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online.ITGaranteGDPR€4,000