Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Sept 2022LISMARTSA, S.L.LISMARTSA, S.L. was fined EUR 1,200 by the AEPD for sending emails to multiple recipients without using BCC. This exposed personal email addresses and breached data protection and security requirements.ESAEPDGDPR€1,200
19 Sept 2022Banca Comercială Română SAThe supervisory authority completed an investigation into Banca Comercială Română SA and found a breach of data processing security requirements. The issue was caused by a technical error in the operator’s IT application, which led to improper data processing.ROANSPDCPGDPR€2,000
19 Sept 2022Vodafone România SAVodafone România SA was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
16 Sept 2022B.B.B.B.B.B. was fined EUR 300 by the AEPD for installing a surveillance camera. The authority found that the device may have recorded images of a neighboring property without consent, potentially breaching data protection rules.ESAEPDGDPR€300
16 Sept 2022D.A.S. DEFENSA DEL AUTOMOVILISTA Y DE SINIESTROS-INTERNACIONAL, S.A. DE SEGUROS Y REASEGUROSD.A.S. Seguros was fined by the AEPD 50,000 EUR for breaching data protection principles. The company improperly disclosed personal and financial data related to an insurance policy to a third party.ESAEPDGDPR€50,000
16 Sept 2022SUPER 24H LOS ROSALES, S.L.The company was fined EUR 300 by the AEPD for operating an external surveillance camera without visible signage. It also failed to provide information on the data controller and data subject rights required under GDPR.ESAEPDGDPR€300
15 Sept 2022Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation.ITGaranteGDPR€100,000
15 Sept 2022Immobiliare Riscostruzione Meloria s.r.l.The company was fined by the Garante in the amount of 2,000 EUR for installing a video surveillance system without the required informational signage. This breached GDPR rules on transparency and the duty to inform individuals subject to monitoring.ITGaranteGDPR€2,000
15 Sept 2022Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17.ITGaranteGDPR€10,000
15 Sept 2022FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€40,000
15 Sept 2022Sofisticated Luxury Flats s.r.l.Sofisticated Luxury Flats s.r.l. was fined €2,000 by the Garante for using a biometric device to monitor employee attendance without a proper legal basis. The authority found that this practice breached data protection rules.ITGaranteGDPR€2,000
15 Sept 2022Comune di ThieneComune di Thiene was fined EUR 3,000 by the Garante for violating data protection principles. The authority found that personal data related to a disciplinary dismissal case was improperly disclosed online.ITGaranteGDPR€3,000
15 Sept 2022HOTEL VILLA SORO, S.L.The company was fined by the AEPD EUR 1,000 for installing surveillance cameras that could capture public areas without proper signage. The authority considered this a breach of data protection rules.ESAEPDGDPR€1,000
15 Sept 2022ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined by the AEPD for obstructing the data protection authority’s inspection. The conduct breached Article 58(1) GDPR.ESAEPDGDPR€3,000
15 Sept 2022EDITORIAL RIBADEO S.L.EDITORIAL RIBADEO S.L. was fined EUR 1,000 by the AEPD for failing to meet the information obligations under Articles 12 and 13 of the GDPR. The authority also noted non-compliance with previous data protection decisions.ESAEPDGDPR€1,000
12 Sept 2022Magyar Éremkibocsátó Kft.The Hungarian data protection authority, NAIH, imposed a fine of 30,000,000 HUF on Magyar Éremkibocsátó Kft. The authority found that personal data were processed without a proper legal basis, specific purpose, or valid consent, and that GDPR transparency and information obligations were breached.HUNAIHGDPR€75,900
12 Sept 2022ROMESTONE, S.L.ROMESTONE, S.L. was fined by the AEPD 6,000 EUR for installing a surveillance camera in a shared rental property without tenant consent. The case concerns a privacy breach in the context of personal data processing.ESAEPDGDPR€6,000
09 Sept 2022MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD for processing personal data without a lawful basis. The company failed to respond properly to a data access request and incorrectly linked an individual to insurance policies and claims.ESAEPDGDPR€30,000
09 Sept 2022COMUNIDAD PROPIETARIO R.R.R.The entity installed a video surveillance system without approval from the property owners' association. The authority found this to be a breach of data protection rules and imposed a fine of 1,500 EUR.ESAEPDGDPR€1,500
09 Sept 2022B.B.B.A private individual was fined 600 EUR by the AEPD for using a webcam oriented toward a public street without prior authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€600