Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Apr 2022Anonymised (HDPA 15/2022)The former mayor disclosed a municipal employee’s personal data without consent or a lawful basis. The authority found this to be a breach of GDPR principles of lawfulness and purpose limitation.GRHDPAGDPR€5,000
04 Apr 2022B.B.B.B.B.B. was fined 1,000 EUR by the AEPD for failing to comply with Article 13 of the GDPR. The authority found that the privacy policy did not provide adequate information on data retention periods and transfers to third parties.ESAEPDGDPR€1,000
04 Apr 2022B.B.B.The entity was fined by the AEPD in the amount of EUR 10,000 for publishing personal data, including images and videos, without the consent of the data subjects. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
01 Apr 2022SOPHIE ET VOILA, S.L.SOPHIE ET VOILA, S.L. was fined EUR 10,000 by the AEPD for publishing a photo on Instagram without the data subject’s consent. The authority found a breach of Article 6 GDPR on lawful processing.ESAEPDGDPR€10,000
31 Mar 2022ALQUILER SEGURO, S.A.U.ALQUILER SEGURO, S.A.U. accessed personal data from Asnef for purposes other than those intended. The AEPD found this to be a breach of data protection rules and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000
31 Mar 2022Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31.CYCyDPCGDPR€1,500
31 Mar 2022FUNDACIÓ ESCOLA PRIVADA DE GESTIÓThe entity was fined by the AEPD 5,000 EUR for failing to implement adequate security measures under Article 32 of the GDPR. This deficiency led to a personal data breach.ESAEPDGDPR€5,000
29 Mar 2022SIA "8 LOUNGE"A fine of EUR 500 was imposed. The decision has entered into force.LVDVIGDPR€500
29 Mar 2022Munkahelyi kamerás megfigyelés jogalapjának és arról való tájékoztatásnak jogszerűségeThe entity was fined for configuring CCTV cameras to monitor employees more broadly than necessary. The authority also found that the data processing notice was inadequate and that the legal basis was incorrectly set on employee consent instead of legitimate interest.HUNAIHGDPR€1,350
28 Mar 2022Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making.SEIMYGDPR€719,000
28 Mar 2022CENTRO MÉDICO SALUS BALEARES, S.L.CENTRO MÉDICO SALUS BALEARES, S.L. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned displaying patients’ body temperatures in a way that could be seen by unauthorized third parties, which compromised confidentiality.ESAEPDGDPR€30,000
28 Mar 2022VUELING AIRLINES, S.A.Vueling Airlines, S.A. was fined EUR 30,000 by the AEPD for breaching data protection rules. The company required customers to accept commercial data sharing in order to purchase tickets on its website, without providing an option to refuse cookies.ESAEPDePrivacy€30,000
24 Mar 2022Uber B.V. e Uber Technologies Inc.Uber B.V. and Uber Technologies Inc. were fined by the Italian authority Garante EUR 2,120,000 for a data protection breach linked to the 2016 incident. The breach affected the personal data of about 57 million users worldwide, including users in Italy.ITGaranteGDPR€2,120,000
24 Mar 2022Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa.ITGaranteGDPR€10,000
24 Mar 2022Azienda sanitaria provinciale di CaltanissettaAzienda sanitaria provinciale di Caltanissetta was fined for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct breached GDPR Article 37.ITGaranteGDPR€6,000
24 Mar 2022NOTAIRECNIL imposed EUR 1,000 on NOTAIRE in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the settlement of the penalty for non-compliance.FRCNILGDPR€1,000
24 Mar 2022Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
23 Mar 2022Dane anonimowe (Pana P. K. zam.)UODO imposed a monetary penalty on an individual for failing to provide required information and for not granting access to personal data needed by the supervisory authority to perform its duties. The authority also found a lack of cooperation during the proceedings.PLUODOGDPR€486
21 Mar 2022RESTAURANTCNIL imposed a fine of EUR 10,000 on RESTAURANT. The case concerned a regulatory breach, with no further details provided.FRCNILGDPR€10,000
21 Mar 2022B.B.B.The AEPD imposed a 300 EUR fine on B.B.B. for improperly directing a camera toward a transit area. The case concerned non-compliance with data protection rules governing video surveillance.ESAEPDGDPR€300