Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Mar 2022GRUPO TECNOPOLE FABRICACIÓN Y MONTAJES, S.L.The company was fined by the AEPD €800 for sending an unsolicited commercial email without the required consent. The breach concerned Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€800
15 Mar 2022Meta (Facebook)The Irish DPC fined Meta (Facebook) EUR 17,000,000 in case IN-18-11-5. The penalty has been collected.IEDPCGDPR€17,000,000
15 Mar 2022PRODESSPA DECORATIUS I PINTURES, S.L.PRODESSPA DECORATIUS I PINTURES, S.L. was fined by the AEPD 15,000 EUR for unlawfully processing personal data. The company included a former employee’s data in a credit information system without proper legal justification.ESAEPDGDPR€15,000
15 Mar 2022CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine.ESAEPDePrivacy€7,000
15 Mar 2022JUNTA ADMINISTRADORA A.A.A.The entity was fined for displaying complainants’ personal data on a public notice board. This breached data protection rules and created a risk of unauthorized disclosure of personal information.ESAEPDGDPR€2,000
14 Mar 2022LISMARTSA, S.L.LISMARTSA, S.L. was fined EUR 3,000 by the AEPD for improperly sending the personal data of 74 employees by email. The authority found a breach of data protection rules.ESAEPDGDPR€3,000
14 Mar 2022RAMONA FILMS, S.LRAMONA FILMS, S.L was fined by the AEPD for failing to provide requested information to the Spanish Data Protection Agency. The breach concerned the duty to cooperate under GDPR Article 58(1).ESAEPDGDPR€30,000
14 Mar 2022Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected.IEDPCGDPR€463,000
14 Mar 2022Tullverket, tjänstemobilerThe Swedish Customs Agency (Tullverket) was fined by IMY 300,000 SEK for failing to implement adequate technical and organizational measures. This led to unauthorized storage of personal data in a cloud service.SEIMYePrivacy€28,473
14 Mar 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 70,000 EUR for issuing a bill despite confirming that no debt existed and that personal data had been deleted. The authority found this conduct to be contrary to Article 6(1) of the GDPR.ESAEPDGDPR€70,000
11 Mar 2022CINCON S.C.CINCON S.C. was fined EUR 500 by the AEPD for failing to provide adequate information about the retention period of personal data collected through a website form. The authority found a breach of Article 13 GDPR because data subjects were not given the required notice.ESAEPDGDPR€500
11 Mar 2022SHOPERY NETWORKS SPAIN, S.L.SHOPERY NETWORKS SPAIN, S.L. was fined 3,000 EUR by the AEPD for a security breach. The authority found a violation of Article 32 GDPR, which requires appropriate technical and organizational measures.ESAEPDGDPR€3,000
10 Mar 2022Anonymisé (CNPD decision-07-fr-2022)The CNPD found that Société A breached the GDPR by failing to comply with data minimization, retention limitation, and information provision requirements. The case concerned improper personal data processing in relation to compliance obligations.LUCNPDGDPR€3,500
10 Mar 2022Agenzia Regionale per la Tutela dell'Ambiente dell'AbruzzoThe Regional Agency for Environmental Protection of Abruzzo was fined by the Garante €8,000 for breaches of data protection principles. The violations concerned lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
10 Mar 2022Briza Land S.R.L.The National Supervisory Authority completed an investigation on 24.02.2022 at Briza Land S.R.L. and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
08 Mar 2022Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ISPersónuverndGDPR€6,850
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for improperly handling a SIM card duplication request. The failure led to unauthorized transactions on a customer's bank account and was found to breach Article 6(1) GDPR.ESAEPDGDPR€70,000
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card to a third party without proper identity verification. The incident enabled unauthorized access to a bank account and resulted in financial loss.ESAEPDGDPR€70,000
04 Mar 2022ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined EUR 50,000 by the AEPD for a personal data protection violation. The case involved unauthorized changes to a contract holder's information, resulting in a security breach under Article 32 of the GDPR.ESAEPDGDPR€50,000
03 Mar 2022AUTOMOVILES FERSAN, S.A.AUTOMOVILES FERSAN, S.A. used personal data without consent to include it in a vehicle purchase contract. The AEPD imposed a fine of EUR 5,000 for breaching data protection rules.ESAEPDGDPR€5,000