Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Feb 2022Anonymisé (CNPD decision-04-fr-2022)The CNPD found that the companies failed to meet the Article 13 GDPR information obligation toward data subjects, including employees and third parties. The breach concerned the lack of proper notice about data processing activities.LUCNPDGDPR€3,100
15 Feb 2022ASOCIACIÓN DE AFICIONADOS Y PEQUEÑOS ACCIONISTAS UNIDAD HERCULANAThe organization was fined by the AEPD 3,000 EUR for failing to provide a privacy policy compliant with Article 13 of the GDPR on its website. It collected personal data through various forms but did not provide the required information to data subjects.ESAEPDGDPR€3,000
15 Feb 2022EMPRESA.1The company was fined EUR 300 by the AEPD for improperly orienting surveillance cameras toward public spaces without prior authorization. The conduct breached data protection rules.ESAEPDGDPR€300
15 Feb 2022Organismos Limenos Irakleiou A.E.Organismos Limenos Irakleiou A.E. was fined 30,000 EUR by the HDPA for breaching the data subject’s right of access. The company failed to provide requested video footage and incorrectly claimed that the data had been deleted.GRHDPAGDPR€30,000
14 Feb 2022COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD.ESAEPDGDPR€100,000
12 Feb 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for a data protection breach involving unauthorized SIM card duplication and an attempted line takeover. The authority found a violation of GDPR Article 6(1).ESAEPDGDPR€70,000
11 Feb 2022Etterforsker1 Gruppen ASEtterforsker1 Gruppen AS was fined NOK 50,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The assessment was carried out on behalf of a client who claimed to have a compensation claim against the complainant.NODatatilsynetGDPR€4,964
11 Feb 2022MOVALIA TRASLADOS, S.L.U.MOVALIA TRASLADOS, S.L.U. was fined EUR 2,000 by the AEPD for failing to allow users to give free and voluntary consent for data processing. The authority also found that the company did not properly inform affected individuals about the processing of their data, in breach of GDPR and LOPDGDD requirements.ESAEPDGDPR€2,000
10 Feb 2022Istituto Nazionale di StatisticaIstituto Nazionale di Statistica was fined €6,000 by the Garante for breaches of data protection rules. The case concerned inadequate security measures and data processing practices that did not meet compliance requirements.ITGaranteGDPR€6,000
10 Feb 2022Regione ToscanaRegione Toscana was fined by the Garante EUR 10,000 for failing to implement adequate security measures, which resulted in a data breach. The breach was mitigated by the region’s prompt response to reduce the negative effects on affected individuals.ITGaranteGDPR€10,000
10 Feb 2022Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements.ITGaranteGDPR€10,000
10 Feb 2022Comune di GuidizzoloComune di Guidizzolo was fined for publishing a complainant’s personal data, including name and professional qualification, in a public document without proper justification. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
10 Feb 2022Név2.The controller unlawfully processed and published personal data, including images, without consent, breaching multiple GDPR provisions. NAIH imposed a fine of 10,000,000 HUF.HUNAIHGDPR€28,200
09 Feb 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations.ESAEPDGDPR€140,000
08 Feb 2022Budapest Bank Zrt.Budapest Bank Zrt. was fined by NAIH for improper personal data processing related to the analysis of recorded phone conversations. The authority found violations of several GDPR provisions.HUNAIHGDPR€707,000
07 Feb 2022JIMBO NETWORKS, S.L.JIMBO NETWORKS, S.L. was fined by the AEPD for unlawful processing of personal data obtained from emails and for cookie policy violations on its website. The authority found that users were not properly informed and that valid consent was not obtained where required.ESAEPDGDPR€15,000
07 Feb 2022IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined €30,000 by the AEPD for using non-essential cookies on its website without obtaining prior user consent. The case concerns non-compliance with cookie consent rules and related user information requirements.ESAEPDePrivacy€30,000
07 Feb 2022DESPACHO IBERFORO MADRID SLPDESPACHO IBERFORO MADRID SLP was fined EUR 1,000 by the AEPD for failing to comply with a decision concerning the right to erasure. The authority found a breach of Article 58(2) GDPR.ESAEPDGDPR€1,000
04 Feb 2022CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle.ESAEPDGDPR€2,000
03 Feb 2022B.B.B.The entity was fined by the AEPD 600 EUR for operating a surveillance camera system that excessively recorded private and public areas. The authority found that this infringed personal and family privacy.ESAEPDGDPR€600