Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 May 2022B.B.B.The entity was fined for improperly directing a surveillance camera toward public space without justification. The authority considered this a breach of data protection rules.ESAEPDGDPR€400
26 May 2022Azienda Sanitaria Locale Roma 1The Garante fined Azienda Sanitaria Locale Roma 1 EUR 46,000 for the unauthorized publication of health-related personal data on its institutional website. The case concerned a breach of data protection rules through the disclosure of sensitive information without a lawful basis.ITGaranteGDPR€46,000
26 May 2022Comune di AfragolaComune di Afragola was fined EUR 10,000 by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The authority found that personal data had been handled improperly.ITGaranteGDPR€10,000
26 May 2022COMUNIDAD.1The owners’ community installed a video surveillance system in common areas without informed consent from all property owners. The AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,000
26 May 2022Regione ToscanaThe Garante fined Regione Toscana EUR 16,000 for publishing unnecessary personal data on the web. The data were later removed, but the authority still found a sanctionable breach.ITGaranteGDPR€16,000
26 May 2022PREICO JURIDICOS, S.L.PREICO JURIDICOS, S.L. was fined by the AEPD 3,000 EUR for failing to respond to information requests linked to a data breach investigation. The authority found a breach of Article 58(1) GDPR.ESAEPDGDPR€3,000
26 May 2022Università Agraria di NettunoUniversità Agraria di Nettuno was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found unlawful handling of personal data, including failures in lawfulness, fairness, transparency, and data minimization, involving information publicly accessible online since 2019.ITGaranteGDPR€4,000
26 May 2022PREICO JURIDICOS S.L.PREICO JURIDICOS S.L. was fined EUR 6,000 by the AEPD for failing to provide required information. The case concerned a breach of Article 58(1) GDPR.ESAEPDGDPR€6,000
26 May 2022Intesa Sanpaolo S.p.A.Intesa Sanpaolo S.p.A. was fined EUR 100,000 by the Garante for unlawfully disclosing personal banking data to unauthorized third parties. The case concerned a breach of data protection rules and required review of the bank’s data-sharing controls.ITGaranteGDPR€100,000
26 May 2022Azienda sanitaria universitaria Friuli OccidentaleAzienda sanitaria universitaria Friuli Occidentale was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the electronic health dossier. The authority found non-compliance with GDPR requirements.ITGaranteGDPR€5,000
26 May 2022Kalemci MusaThe sole proprietorship “Turkish City” was fined 2,000 EUR by the Garante. The authority found that its video surveillance system did not meet the information requirements under GDPR Article 13.ITGaranteGDPR€2,000
25 May 2022Roularta Media GroupRoularta Media Group was fined EUR 50,000 by the APD for using cookies on its media websites without obtaining valid user consent. The authority found this practice breached GDPR and ePrivacy Directive requirements.BEAPDePrivacy€50,000
25 May 2022CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L.CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L. was fined 500 EUR by the AEPD. The case concerned sending unsolicited commercial communications by email without consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€500
25 May 2022RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000.BEAutorité de protection des donnéesGDPR€50,000
24 May 2022Anonymised (HDPA 26/2022)A fine of EUR 2,000 was imposed for sending unsolicited political communication by SMS without the recipient's prior consent. The authority treated this as a breach of data protection and electronic communications rules.GRHDPAePrivacy€2,000
24 May 2022MEDLIFE S.A.In April 2022, ANSPDCP completed an investigation into MEDLIFE S.A. and found a breach of GDPR provisions. As a result, a fine of EUR 5,000 was imposed.ROANSPDCPGDPR€5,000
24 May 2022NAVThe Norwegian DPA, Datatilsynet, notified NAV of a NOK 5 million fine for making job seekers’ CVs available on arbeidsplassen.no without a legal basis. The issue affected more than 1.8 million people.NODatatilsynetGDPR€485,000
24 May 2022Geanonimiseerd (APD 84/2022)The case concerns a complaint by the Ordre des Barreaux Francophones de Belgique against sos-services.be and sos-avocats.be. The authority found that lawyers were listed without a legal basis and with incorrect information, in breach of GDPR and ePrivacy rules.BEAPDePrivacy€10,000
23 May 2022ANOIXISThe fine was imposed for sending unsolicited SMS messages for direct marketing without prior consent. The company also failed to provide a valid opt-out address, affecting data subjects’ rights of access and objection.GRHDPAePrivacy€54,000
23 May 2022EL DIARIO DE PRENSA DIGITAL, S.L.EL DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of the GDPR data minimization principle.ESAEPDGDPR€50,000