Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Oct 2025The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data.GGODPAGDPR€115,000
28 Feb 2024Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach.GRHDPAGDPR€2,995,000
08 Aug 2014THE GOLDEN ATHENS SPAThe company processed personal data without consent, breaching the principles of lawfulness and data minimization under Greek law. HDPA imposed a fine of EUR 1,000.GRHDPAGDPR€1,000
25 Jul 2022MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing.GRHDPAGDPR€5,000
04 Aug 2017VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations.GRHDPAGDPR€5,000
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data.GRHDPAGDPR€8,000
24 Feb 2017Geoanalysis S.A.Geoanalysis S.A. was fined EUR 10,000 by the HDPA for improper installation and operation of a video surveillance system. The authority found data protection breaches, including failure to notify the authority and inadequate employee information.GRHDPAGDPR€10,000
12 May 2021A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications.GRHDPAGDPR€5,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined EUR 150,000 by the HDPA for inadequate technical and organizational security measures. The authority found a violation of Article 12 of Law 3471/2006.GRHDPAePrivacy€150,000
07 May 2015Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification.GRHDPAGDPR€3,000
27 Jun 2012OKANAOKANA was fined by the HDPA in the amount of 3,000 EUR for failing to adequately protect special-category personal data. Documents containing patients’ health data were found in trash bins, indicating a breach of data protection rules.GRHDPAGDPR€3,000
12 Jun 2015ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data.GRHDPAGDPR€100,000
25 Jul 2013Anonymised (HDPA 90/2013)The HDPA imposed a EUR 500 fine on the anonymised entity for sending unsolicited marketing emails. The conduct breached the requirement to obtain subscriber consent before sending such communications.GRHDPAePrivacy€500
16 Jun 2010Anonymised (HDPA 29/2010)The company was fined EUR 3,000 by the HDPA for sending unsolicited marketing emails and faxes without subscriber consent. This conduct breached ePrivacy rules on electronic marketing communications.GRHDPAePrivacy€3,000
31 Oct 2022B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization.GRHDPAGDPR€10,000
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation.GRHDPAGDPR€10,000
27 Dec 2012Euro-Catering O.E.The company installed a CCTV system without notifying the supervisory authority, failed to display required informational signs, and collected excessive data. These actions breached privacy protection rules.GRHDPAGDPR€20,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006.GRHDPAePrivacy€100,000
04 Apr 2022Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action.GRHDPAGDPR€10,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed for failing to maintain appropriate organizational and technical security measures. This led to unauthorized employee access to the complainant's personal data.GRHDPAGDPR€5,000