Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Jan 2022B.B.B.The online pet store mascotagadget.com was fined EUR 500 by the AEPD. The authority found that customer data was transferred to third parties without consent and that users were not properly informed, breaching Article 13 of the GDPR.ESAEPDGDPR€500
17 Jan 2022SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A.SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A. was fined 20,000 EUR by the AEPD. The authority found that the company failed to properly handle a data subject’s request for erasure, which led to continued processing of personal data despite the prior deletion request.ESAEPDGDPR€20,000
17 Jan 2022***EMPRESA.1The entity was fined for improperly orienting surveillance cameras so they captured public pedestrian areas without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
18 Jan 2022BAZARDELALEGION.COMBAZARDELALEGION.COM was fined by the AEPD for failing to provide the required information on its website under Article 13 GDPR. The breach concerned the website’s information duties toward individuals whose data are collected online.ESAEPDGDPR€3,000
18 Jan 2022MAJESTIC SOLUTIONS S.L.MAJESTIC SOLUTIONS S.L. was fined by the AEPD 10,000 EUR for failing to provide all required information to affected individuals after a personal data security breach. The authority found a breach of Article 34(2) GDPR.ESAEPDGDPR€10,000
19 Jan 2022DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data, including the name of a minor, that was not necessary for the intended purpose. The authority found this to be a breach of data protection principles.ESAEPDGDPR€50,000
19 Jan 2022Dane anonimowe (U.)UODO imposed an administrative fine of 545,748 PLN on Dane anonimowe (U.) for failing to notify data subjects without undue delay about a personal data breach. The case concerns the obligation to promptly inform affected individuals under data protection rules.PLUODOGDPR€120,000
22 Jan 2022SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILESCNIL imposed a fine of 3,000 EUR on SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILES and issued an injunction under penalty. The case concerns a confirmed compliance breach.FRCNILGDPR€3,000
22 Jan 2022Dane anonimowe (C. S.A. z siedzibą w M. przy ul.)UODO imposed an administrative fine on the controller and the processor for failing to implement appropriate technical and organizational measures to protect personal data. The breach resulted in a loss of confidentiality, and the controller also failed to properly verify the processor.PLUODOGDPR€1,083,000
24 Jan 2022Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff.NODatatilsynetGDPR€196,000
26 Jan 2022ESTUDIO INMOBILIARIO SAN ISIDRO, S.L.UESTUDIO INMOBILIARIO SAN ISIDRO, S.L.U was fined by the AEPD EUR 5,000 for unlawfully obtaining personal data and visiting the complainant's home to promote real estate services without proper consent. The case concerns unlawful processing and improper direct marketing contact.ESAEPDGDPR€5,000
26 Jan 2022B.B.B.The entity installed a video surveillance system covering public transit areas without a justified cause. This breached data protection principles.ESAEPDGDPR€500
26 Jan 2022Slane Credit UnionThe Irish DPC imposed a fine of EUR 5,000 on Slane Credit Union in inquiry IN-19-7-5. The penalty has been collected.IEDPCGDPR€5,000
26 Jan 2022Region Uppsala, personuppgifts­incidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place.SEIMYGDPR€28,710
27 Jan 2022Musicraiser S.r.l.Musicraiser S.r.l. was fined 1,000 EUR by the Garante for continuing to send newsletters to a user despite multiple requests to be removed. The case concerns a breach of data protection rules on respecting opt-out and cancellation requests for marketing communications.ITGaranteGDPR€1,000
27 Jan 2022Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals.ITGaranteGDPR€2,000
27 Jan 2022MIRACLE IBIZA S.L.MIRACLE IBIZA S.L. was fined by the AEPD in the amount of EUR 500 for improperly positioning a surveillance camera. The camera captured the entrance to a private residence, affecting the privacy of individuals.ESAEPDGDPR€500
27 Jan 2022T.S.M. s.r.l.T.S.M. s.r.l. was fined EUR 40,000 by the Italian supervisory authority, the Garante. The sanction concerned the failure to respond to information requests, which breached GDPR obligations related to data subject rights.ITGaranteGDPR€40,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000
28 Jan 2022SEAN SERIOS S.L.SEAN SERIOS S.L. was fined by the AEPD 12,000 EUR for publishing personal data of candidates from a selection process on its website without a legal basis. The authority found a breach of GDPR Article 6(1).ESAEPDGDPR€12,000