Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Jan 2022IBERCAJA BANCO, S.A.IBERCAJA BANCO, S.A. was fined by the AEPD EUR 100,000 for unlawfully processing personal data linked to a family inheritance matter. The breach included opening a bank account for a minor without consent and disclosing personal data to third parties without authorization.ESAEPDGDPR€100,000
29 Jan 2022COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing.ESAEPDGDPR€5,000
01 Feb 2022SC Grupex 2000 SRLSC Grupex 2000 SRL was fined by ANSPDCP for unlawfully processing the personal data of institutionalized patients. The data appeared in filmed material available on the company's website.ROANSPDCPGDPR€1,000
02 Feb 2022Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000.LUCNPDGDPR€10,000
02 Feb 2022IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority identified issues with transparency, the legal basis for processing, and the security of personal data.BEAPDGDPR€250,000
02 Feb 2022SUPERCOR, S.A.SUPERCOR, S.A. was fined by the AEPD for using surveillance cameras in employee rest areas without proper notification. The authority found this conduct to be in breach of GDPR Article 6.ESAEPDGDPR€70,000
02 Feb 2022TARIFER SERVICIOS, S.L.TARIFER SERVICIOS, S.L. was fined by the AEPD 2,000 EUR for using non-essential cookies without user consent. The authority also found that the website did not provide the required cookie information.ESAEPDePrivacy€2,000
02 Feb 2022IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority cited lack of transparency, improper processing of personal data, and failure to meet GDPR obligations.BEAPDGDPR€250,000
02 Feb 2022Anonymisé (CNPD decision-02-fr-2022)The company was fined by the CNPD 6,600 EUR for breaches of GDPR requirements. The authority found deficiencies in data minimization, retention, security of processing, and the information provided to data subjects in connection with video surveillance and geolocation systems.LUCNPDGDPR€6,600
03 Feb 2022B.B.B.The entity was fined by the AEPD 600 EUR for operating a surveillance camera system that excessively recorded private and public areas. The authority found that this infringed personal and family privacy.ESAEPDGDPR€600
03 Feb 2022DOOR2DOOR SPAIN, S.L.DOOR2DOOR SPAIN, S.L. did not comply with a decision of the Spanish Data Protection Agency (AEPD) requiring measures to inform individuals whose personal data were collected. The authority treated this as a breach of Article 58(2) GDPR and imposed a fine of EUR 1,000.ESAEPDGDPR€1,000
03 Feb 2022DIGI SPAIN TELECOM, S.L.DIGI Spain Telecom, S.L. was fined by the AEPD in the amount of EUR 70,000 for a breach of Article 6(1) GDPR. The case concerned the unauthorized duplication of a SIM card in an identity theft incident, which resulted in financial losses for the complainant.ESAEPDGDPR€70,000
03 Feb 2022Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent.CYCyDPCGDPR€2,000
03 Feb 2022FLORAQUEEN FLOWERING THE WORLD S.L.FLORAQUEEN FLOWERING THE WORLD S.L. was fined 3,000 EUR by the AEPD for failing to provide requested information. The case concerned the duty to cooperate with the Spanish data protection authority under GDPR Article 58(1).ESAEPDGDPR€3,000
04 Feb 2022CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle.ESAEPDGDPR€2,000
07 Feb 2022JIMBO NETWORKS, S.L.JIMBO NETWORKS, S.L. was fined by the AEPD for unlawful processing of personal data obtained from emails and for cookie policy violations on its website. The authority found that users were not properly informed and that valid consent was not obtained where required.ESAEPDGDPR€15,000
07 Feb 2022IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined €30,000 by the AEPD for using non-essential cookies on its website without obtaining prior user consent. The case concerns non-compliance with cookie consent rules and related user information requirements.ESAEPDePrivacy€30,000
07 Feb 2022DESPACHO IBERFORO MADRID SLPDESPACHO IBERFORO MADRID SLP was fined EUR 1,000 by the AEPD for failing to comply with a decision concerning the right to erasure. The authority found a breach of Article 58(2) GDPR.ESAEPDGDPR€1,000
08 Feb 2022Budapest Bank Zrt.Budapest Bank Zrt. was fined by NAIH for improper personal data processing related to the analysis of recorded phone conversations. The authority found violations of several GDPR provisions.HUNAIHGDPR€707,000
09 Feb 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations.ESAEPDGDPR€140,000