Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Oct 2022Associazione Rescue Drones Network ODVAssociazione Rescue Drones Network ODV was fined by the Garante in the amount of 3,000 EUR for failing to comply with data access requests. The authority treated this as a breach of GDPR Article 5.ITGaranteGDPR€3,000
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR.ITGaranteGDPR€10,000
06 Oct 2022Alpha Exploration Co. Inc.Alpha Exploration Co. Inc. was fined by the Garante EUR 2,000,000 for violations related to data processing practices on its social media platform, Clubhouse. The case concerned irregularities in the way user data was processed.ITGaranteGDPR€2,000,000
05 Oct 2022Dane anonimowe (D. sp. z o.o. sp. k. z siedzibą w P. przy ul.)The President of UODO imposed a fine of PLN 9,139 on the company. The sanction was issued because the company failed to comply with an order contained in an administrative decision of the data protection authority.PLUODOGDPR€1,907
03 Oct 2022o persoana fizicăAn individual was fined 100 EUR for violating the General Data Protection Regulation. The case concerned a confirmed breach of obligations under the GDPR.ROANSPDCPGDPR€100
03 Oct 2022o persoana fizicăA fine of 50 EUR was imposed on an individual for violating a provision of the General Data Protection Regulation. The case was handled by ANSPDCP in Romania.ROANSPDCPGDPR€50
29 Sept 2022CITY OF SOUND 2010, S.L.CITY OF SOUND 2010, S.L. was fined EUR 800 by the AEPD for sending at least one commercial SMS to the complainant after the complainant had requested removal from the database. The authority found this to be a breach of Article 21 of the LSSI on unsolicited marketing communications.ESAEPDePrivacy€800
29 Sept 2022SIA "Deprus"DVI imposed a fine of 500 EUR on SIA "Deprus". The decision is final and has entered into force.LVDVIGDPR€500
27 Sept 2022Anonymised (HDPA 18/2022)A fine was imposed for sending unsolicited political communication via SMS without prior consent. The case concerns a breach of consent requirements for political and marketing communications.GRHDPAePrivacy€2,000
27 Sept 2022ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
26 Sept 2022FONTANORTE, S.L.FONTANORTE, S.L. was fined 2,000 EUR by the AEPD for breaching Article 32 GDPR. The company improperly disposed of documents containing personal data in public waste containers, making them accessible to third parties.ESAEPDGDPR€2,000
26 Sept 2022B.B.B.B.B.B. was fined EUR 300 by the AEPD for failing to provide adequate information about a video surveillance system. The camera captured a public area without proper notice to affected individuals, breaching Article 13 GDPR.ESAEPDGDPR€300
26 Sept 2022HERON CITY VALENCIA MANAGEMENT S.L.HERON CITY VALENCIA MANAGEMENT S.L. was fined by the AEPD in the amount of 10,000 EUR for refusing to provide access to surveillance footage. This conduct breached the data subject’s rights, in particular the right of access under Article 15 of the GDPR.ESAEPDGDPR€10,000
26 Sept 2022TV2 Média Csoport Zrt.NAIH imposed a 10,000,000 HUF fine on TV2 Média Csoport Zrt. for insufficient user information and improper consent management on its websites. The authority found that these practices breached the principles of fair and transparent data processing.HUNAIHGDPR€24,500
26 Sept 2022ECOMM MOVADGENCY S.L.ECOMM MOVADGENCY S.L. was fined by the AEPD for sending commercial communications without the recipient’s consent. The company continued sending emails despite the recipient’s objection, which breached Article 21 GDPR.ESAEPDGDPR€1,000
22 Sept 2022Bitfactor SRLBitfactor SRL was fined EUR 2,000 by ANSPDCP after a data security incident caused by a malfunctioning application. The application sent marketing communications, resulting in a breach of personal data confidentiality affecting 1,757 users.ROANSPDCPGDPR€2,000
22 Sept 2022Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police.GRHDPAGDPR€3,000
21 Sept 2022Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32.CYCyDPCGDPR€5,000
21 Sept 2022Curtea Veche Publishing SRLCurtea Veche Publishing SRL was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
21 Sept 2022GUUDJOB WORLDWIDE S.L.GUUDJOB WORLDWIDE S.L. failed to delete personal data after a data subject request, breaching GDPR Articles 12 and 17. The AEPD imposed a fine of EUR 1,000, reduced to EUR 800 for early payment.ESAEPDGDPR€1,000