Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2022MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€20,000
01 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for unlawfully duplicating a customer's SIM card without consent. The incident led to unauthorized access to the customer's personal and banking data.ESAEPDGDPR€70,000
01 Jan 2022RIANLU EUROPA S.L.RIANLU EUROPA S.L. was fined EUR 30,010 by the AEPD for sending commercial SMS messages without providing recipients with an opt-out mechanism. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€30,010
01 Jan 2022INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR.ESAEPDGDPR€40,000
04 Jan 2022BEAUTY & AESTHETIC BALEARIC, SL.BEAUTY & AESTHETIC BALEARIC, SL. was fined by the AEPD €1,000 for sending marketing emails without an opt-out mechanism. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
05 Jan 2022Egnatia Odos S.A.Egnatia Odos S.A. was fined by the HDPA EUR 1,000 for failing to provide the complainant with access to personal data related to a toll violation. The authority found a breach of the right of access under the GDPR.GRHDPAGDPR€1,000
05 Jan 2022CONTIMAG INVEST, S.L.CONTIMAG INVEST, S.L. was fined by the AEPD 1,200 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR on transparency and information duties.ESAEPDGDPR€1,200
05 Jan 2022B.B.B.A camera was installed in a vehicle parked in a community garage and recorded communal areas. The community was not informed and no required signage was displayed, resulting in a breach of data protection rules.ESAEPDGDPR€1,500
05 Jan 2022CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing.ESAEPDePrivacy€5,000
06 Jan 2022B.B.B.A fine was imposed for the mass dissemination of a video recorded without the victim’s consent on social media and via WhatsApp. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
07 Jan 2022Elektro & Automasjon Systemer ASElektro & Automasjon Systemer AS was fined NOK 200,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The company checked a co-owner of another company despite having no business relationship or justification for the credit check.NODatatilsynetGDPR€19,942
07 Jan 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
09 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without proper authorization. The incident enabled unauthorized access to a customer's bank account.ESAEPDGDPR€70,000
13 Jan 2022Villa Masi Residenza per anzianiVilla Masi Residenza per anziani was fined EUR 1,000 by the Garante for a video surveillance system that did not comply with GDPR Article 13. The authority found that the required information notices for monitored individuals were not properly provided.ITGaranteGDPR€1,000
13 Jan 2022Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13.ITGaranteGDPR€7,500
13 Jan 2022Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€4,000
13 Jan 2022IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 70,000 by the AEPD for changing an electricity supply contract without the customer's knowledge or consent. The authority found that this conduct breached data protection rules.ESAEPDGDPR€70,000
13 Jan 2022ADVANS BROKERS CORREDURIA DE SEGUROS S.L.ADVANS BROKERS CORREDURIA DE SEGUROS S.L. was fined by the AEPD EUR 80,000 for a data breach affecting 55,000 individuals, including minors. The authority found that the incident was reported to the AEPD with delay.ESAEPDGDPR€80,000
13 Jan 2022A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements.ITGaranteGDPR€6,000
13 Jan 2022Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented.ITGaranteGDPR€14,000