Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Aug 2022Hangfelvétel készítése szerelési munkák soránThe authority found that the entity breached the GDPR by recording audio during installation work without a proper legal basis. It also failed to meet transparency and data protection principle requirements.HUNAIHGDPR€762
08 Aug 2022CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. (CASER)CASER was fined 40,000 EUR by the AEPD for modifying insurance policy data without the policyholder’s consent. The authority found that this breached GDPR data processing principles.ESAEPDGDPR€40,000
05 Aug 2022Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship.ITGaranteGDPR€20,000
05 Aug 2022Mister Brick S.a.s.Mister Brick S.a.s. was fined EUR 1,000 by the Garante for sending an unsolicited promotional email without obtaining prior consent from the recipient. The authority found this to be a breach of GDPR requirements on lawful processing and consent.ITGaranteGDPR€1,000
05 Aug 2022Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent.ITGaranteGDPR€1,000
04 Aug 2022Sephora Cosmetics România SASephora Cosmetics România SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
04 Aug 2022LEASE PLAN SERVICIOS, S.A.U.LEASE PLAN SERVICIOS, S.A.U. was fined by the AEPD EUR 1,500 for failing to properly handle a request to restrict the processing of personal data. This led to unauthorized commercial communications being sent.ESAEPDePrivacy€1,500
04 Aug 2022AUTOBIZ, S.A. SUCURSAL EN ESPAÑAAUTOBIZ, S.A. Sucursal en España was fined by the AEPD €800 for sending unsolicited marketing messages. The authority also found that the company failed to provide a functional opt-out mechanism, breaching Article 21 of the LSSI.ESAEPDePrivacy€800
03 Aug 2022SOCIETE SPECIALISEE DANS LE SECTEUR DE L'HOTELLERIECNIL imposed a fine of 600,000 EUR on SOCIETE SPECIALISEE DANS LE SECTEUR DE L'HOTELLERIE. The case concerns a breach of rules supervised by the French data protection authority.FRCNILGDPR€600,000
03 Aug 2022Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined EUR 70,000 by the AEPD for providing a SIM card duplicate to a third party without the data subject’s consent. The authority found this conduct to be a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
03 Aug 2022LORENT 2013, S.L.LORENT 2013, S.L. was fined EUR 900 by the AEPD for operating video surveillance without proper signage. The cameras were also directed toward public areas without authorization, which breached data protection rules.ESAEPDGDPR€900
02 Aug 2022BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR.HUNAIHGDPR€75,600
02 Aug 2022Oraculum 2020 Korlátolt Felelősségű TársaságNAIH fined Oraculum 2020 Kft. and SzondaPhone Kft. for unlawful data processing during telephone surveys. The authority found breaches of GDPR principles of lawfulness, transparency, data minimization, and accountability.HUNAIHGDPR€17,640
29 Jul 2022LA CASA DEL BAMBÚLA CASA DEL BAMBÚ was fined €200 by the AEPD for continuing to send marketing emails to a customer after an unsubscribe request. The authority found this to be a breach of Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€200
29 Jul 2022COMUNIDAD DE PROPIETARIOSA community of property owners was fined by the AEPD €300 for installing a surveillance camera without proper signage. The notice did not identify the data controller or provide contact details for exercising data subject rights.ESAEPDGDPR€300
28 Jul 2022Ordinanza ingiunzione - 28 luglio 2022 [9813385]The Garante imposed a fine of EUR 1,000 on the website administrator for failing to remove or de-index a page containing a Corriere della Sera article about a judicial case involving the complainant's father. The authority found a violation of the right to be forgotten.ITGaranteGDPR€1,000
28 Jul 2022Auto Hi-Fi System S.n.cAuto Hi-Fi System S.n.c was fined EUR 2,000 by the Garante. The surveillance camera captured public areas and private property without proper notice, breaching data protection principles.ITGaranteGDPR€2,000
28 Jul 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures.ITGaranteGDPR€100,000
25 Jul 2022MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing.GRHDPAGDPR€5,000
23 Jul 2022GESTIONES AUTO LOW COST S. LThe entity was fined for not having a privacy policy on its website. The breach concerned Article 13 of the GDPR, which requires specific information to be provided to data subjects.ESAEPDGDPR€1,000