Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Jun 2022Anonymisé (CNPD decision-13-fr-2022)The company breached GDPR by failing to respect data retention limits and by not providing employees with adequate information about the vehicle geolocation system. The CNPD imposed a fine of EUR 5,600.LUCNPDGDPR€5,600
30 Jun 2022Continental Automotive Romania SRLThe company was fined for failing to implement adequate technical and organizational measures and for not periodically assessing those measures in relation to employee video processing. The breach concerned the security of video processing and the prevention of unauthorized processing.ROANSPDCPGDPR€2,000
28 Jun 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR.ESAEPDGDPR€3,000
28 Jun 2022AUDIO STOCK, S.L.AUDIO STOCK, S.L. was fined €2,000 by the AEPD for sending commercial SMS messages despite the recipient's objection. The authority found this conduct breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€2,000
28 Jun 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined EUR 70,000 by the AEPD for a SIM card duplication incident. The incident enabled unauthorized attempts to access the complainant's bank accounts and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
28 Jun 2022YEGUADA SENILLOSA, S.L.Yeguada Senillosa, S.L. was fined by the AEPD 2,000 EUR for failing to comply with cookie requirements on its website. The authority found the use of non-essential third-party cookies without proper consent and adequate information to users.ESAEPDePrivacy€2,000
27 Jun 2022NAVThe Norwegian DPA fined NAV 5,000,000 NOK for making CVs available on arbeidsplassen.no without a lawful basis under the GDPR. The case concerned unauthorized processing of personal data relating to job seekers and employees.NODatatilsynetGDPR€480,000
23 Jun 2022B.B.B.The entity was fined EUR 300 by the AEPD for positioning surveillance cameras so that they captured public spaces without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€300
22 Jun 2022Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles.LUCNPDGDPR€4,000
22 Jun 2022B.B.B.An individual's personal data was used without consent to publish an online advertisement for sexual services, resulting in harassment. The responsible entity was fined for violating Article 6(1) of the GDPR.ESAEPDGDPR€10,000
22 Jun 2022Gyldendal A/SGyldendal A/S was fined 1,000,000 DKK by Datatilsynet for retaining data of 685,000 book club members longer than necessary. The authority found a breach of data retention principles.DKDatatilsynetGDPR€134,000
20 Jun 2022Asociația de Proprietari Aviației ParkAsociația de Proprietari Aviației Park was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
20 Jun 2022SC Interactions Marketing SRLSC Interactions Marketing SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The authority stated that the company acted as a processor for another controller.ROANSPDCPGDPR€1,000
20 Jun 2022Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights.GRHDPAGDPR€2,000
20 Jun 2022Asociația de Proprietari Aviației ParkThe operator was fined by ANSPDCP for violating the GDPR. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
20 Jun 2022PLANET COSTA DORADA SOCIEDAD LIMITADAThe company was fined by the AEPD EUR 300 for operating video surveillance that captured public space without proper signage. The authority found a breach of GDPR Articles 5 and 13.ESAEPDGDPR€300
16 Jun 2022Deutsche Bank S.p.A.Deutsche Bank S.p.A. was fined EUR 20,000 by the Garante for unlawfully processing personal data. The bank reported an individual's name to CRIF S.p.A. without prior notice, which breached data protection rules.ITGaranteGDPR€20,000
16 Jun 2022Rapido Finance, S.L.Rapido Finance, S.L. was fined 2,000 EUR by the AEPD for unlawfully processing personal data. The company continued to pursue a debt that had already been paid, which breached Article 6(1) GDPR.ESAEPDGDPR€2,000
16 Jun 2022Federazione Italiana NuotoFederazione Italiana Nuoto was fined EUR 2,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 of the GDPR.ITGaranteGDPR€2,000
15 Jun 2022S.C.In May 2022, the Romanian supervisory authority ANSPDCP completed an investigation into the operator S.C. and found a violation of GDPR provisions. A fine of 3,000 EUR was imposed.ROANSPDCPGDPR€3,000