Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Dec 2021Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation.ITGaranteGDPR€5,000
02 Dec 2021Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€100,000
03 Dec 2021MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications.ESAEPDePrivacy€2,000
03 Dec 2021Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR.HUNAIHGDPR€825
03 Dec 2021GARLEX SOLUTIONS, S.L.GARLEX SOLUTIONS, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. The case concerned an unsolicited contract offer for electricity supply.ESAEPDGDPR€15,000
06 Dec 2021Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021 and imposed a fine for GDPR violations. The case concerned deficiencies identified during the supervisory authority’s review.ROANSPDCPGDPR€1,000
06 Dec 2021Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021. As a result, a fine of EUR 5,000 was imposed for GDPR violations.ROANSPDCPGDPR€5,000
06 Dec 2021Societatea Civilă Medicală Policlinica TommedANSPDCP completed an investigation at Societatea Civilă Medicală Policlinica Tommed and found breaches of GDPR provisions. The operator was fined and required to align data collection and processing activities with data protection requirements to prevent unauthorized disclosure of personal data.ROANSPDCPGDPR€2,000
07 Dec 2021Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws.NLAPGDPR€2,750,000
09 Dec 2021RESTAURANTE FUENTEBRO, S.C.The entity was fined for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€1,500
09 Dec 2021***COMUNIDAD.1The entity installed surveillance cameras in a community property without proper authorization from all owners. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
09 Dec 2021Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected.IEDPCGDPR€110,000
13 Dec 2021SC Nobiotic Pharma SRLSC Nobiotic Pharma SRL was fined €2,000 by ANSPDCP for failing to respond to information requests. The authority treated this as a breach of GDPR obligations.ROANSPDCPGDPR€2,000
14 Dec 2021MALAGATROM, S.L.UMALAGATROM, S.L.U was fined by the AEPD in the amount of EUR 1,000 for failing to comply with a prior decision. That decision required the removal of comments containing personal data from its Amazon page and the implementation of measures to prevent similar incidents in the future.ESAEPDGDPR€1,000
15 Dec 2021Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR.LUCNPDGDPR€11,600
15 Dec 2021Anonymizováno (ÚOOÚ UOOU-01071/21-30)The entity was fined by the UOOU for repeatedly sending unsolicited commercial communications to electronic contacts without prior consent. The messages also failed to clearly identify the sender or label the content as commercial.CZUOOUePrivacy€11,871
15 Dec 2021GrindrNorway's Datatilsynet imposed an administrative fine of NOK 65 million on Grindr on 15.12.2021. The case concerned violations of the GDPR consent requirements.NODatatilsynetGDPR€6,355,000
16 Dec 2021FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data.ITGaranteGDPR€20,000
16 Dec 2021Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties.ITGaranteGDPR€100,000
16 Dec 2021Frederiksberg KommuneFrederiksberg Kommune was fined by Datatilsynet for failing to implement adequate security measures in a self-service solution. This led to unauthorized access to protected personal data.DKDatatilsynetGDPR€6,724