Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Nov 2022Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante. The authority found that promotional contacts were made without the required information and without obtaining the data subject’s consent, in breach of GDPR requirements.ITGaranteGDPR€500,000
10 Nov 2022Comune di Cisterna di LatinaComune di Cisterna di Latina was fined 5,000 EUR by the Garante for violating data protection principles, including data minimization. Improper handling of personal data led to unauthorized access by third parties.ITGaranteGDPR€5,000
09 Nov 2022SC Das Sense Society SRLSC Das Sense Society SRL was fined EUR 1,000 by ANSPDCP. The authority found a GDPR breach for failing to provide the requested information.ROANSPDCPGDPR€1,000
08 Nov 2022B.B.B.The entity installed a surveillance camera on the facade of a residence without the required administrative authorization. The camera captured public areas and the complainant’s home entrance, breaching data protection principles.ESAEPDGDPR€300
08 Nov 2022SC Prestige Media PHG SRLSC Prestige Media PHG SRL was fined by ANSPDCP in the amount of 5,000 EUR for breaching the data processing principles under Article 5 of the GDPR. The case concerned unlawful processing of personal data.ROANSPDCPGDPR€5,000
07 Nov 2022Compania Națională Poșta Română SAIn October 2022, ANSPDCP completed an investigation into Compania Națională Poșta Română SA and found a breach of GDPR provisions. The company was fined EUR 2,000 following a data security incident reported by a data operator.ROANSPDCPGDPR€2,000
03 Nov 2022DKN.5131.18.2022StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 250,000 on the company. The authority found that the company failed to notify the supervisory authority within 24 hours of detecting the personal data breach and did not promptly inform the affected data subject.PLUODOGDPR€53,090
03 Nov 2022FINCAS MARTIN 2, S.L.FINCAS MARTIN 2, S.L. was fined by the AEPD 5,000 EUR for failing to provide the information required under Article 13 GDPR when collecting personal data through a website contact form. The authority found that users were not properly informed about the processing of their data at the time of collection.ESAEPDGDPR€5,000
02 Nov 2022Dane anonimowe (Wójta Gminy U. za naruszenie przepisów art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679)The Polish DPA (UODO) imposed an administrative fine of PLN 8,000 on the Mayor of U. Commune. The authority found that personal data were processed without adequate security, in breach of Articles 5, 25 and 32 of the GDPR.PLUODOGDPR€1,701
02 Nov 2022QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the AEPD for processing personal data without a valid legal basis and for failing to comply with data deletion requests. The violations concerned Articles 6 and 17 of the GDPR.ESAEPDGDPR€20,000
31 Oct 2022B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization.GRHDPAGDPR€10,000
31 Oct 2022TECNO MOTOR LA MUELA, S.L.L.TECNO MOTOR LA MUELA, S.L.L. was fined by the AEPD €600 for installing surveillance cameras oriented toward public areas without prior administrative authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€600
31 Oct 2022FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD EUR 40,000 for sending personalized marketing messages using personal data without a legal basis. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€40,000
28 Oct 2022FORMAESTUDIO, C.B.FORMAESTUDIO, C.B. was fined €6,000 by the AEPD for requiring students to disclose their COVID vaccination status and present a passport as a condition for participating in teaching practice. The authority found that this processing breached data protection rules.ESAEPDGDPR€6,000
27 Oct 2022COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
26 Oct 2022FUNDACIÓN CITIZENGOFUNDACIÓN CITIZENGO was fined by the AEPD EUR 5,000 for sending unsolicited emails without recipients’ consent. The authority found a breach of Article 7 GDPR on valid consent.ESAEPDGDPR€5,000
21 Oct 2022IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury.BEAPDePrivacy€10,000
21 Oct 2022CASAL DE L'ESPLUGA DE FRANCOLÍCASAL DE L'ESPLUGA DE FRANCOLÍ was fined by the AEPD for publishing a video on social media without consent. The recording showed a minor during a sports event, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
20 Oct 2022I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk.ITGaranteGDPR€7,000
20 Oct 2022Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Garante in the amount of 10,000 EUR for making numerous unsolicited phone calls. The authority found that this conduct breached Article 5 of the GDPR.ITGaranteGDPR€10,000