Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Feb 2022DOOR2DOOR SPAIN, S.L.DOOR2DOOR SPAIN, S.L. did not comply with a decision of the Spanish Data Protection Agency (AEPD) requiring measures to inform individuals whose personal data were collected. The authority treated this as a breach of Article 58(2) GDPR and imposed a fine of EUR 1,000.ESAEPDGDPR€1,000
03 Feb 2022DIGI SPAIN TELECOM, S.L.DIGI Spain Telecom, S.L. was fined by the AEPD in the amount of EUR 70,000 for a breach of Article 6(1) GDPR. The case concerned the unauthorized duplication of a SIM card in an identity theft incident, which resulted in financial losses for the complainant.ESAEPDGDPR€70,000
03 Feb 2022Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent.CYCyDPCGDPR€2,000
03 Feb 2022FLORAQUEEN FLOWERING THE WORLD S.L.FLORAQUEEN FLOWERING THE WORLD S.L. was fined 3,000 EUR by the AEPD for failing to provide requested information. The case concerned the duty to cooperate with the Spanish data protection authority under GDPR Article 58(1).ESAEPDGDPR€3,000
02 Feb 2022Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000.LUCNPDGDPR€10,000
02 Feb 2022IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority identified issues with transparency, the legal basis for processing, and the security of personal data.BEAPDGDPR€250,000
02 Feb 2022SUPERCOR, S.A.SUPERCOR, S.A. was fined by the AEPD for using surveillance cameras in employee rest areas without proper notification. The authority found this conduct to be in breach of GDPR Article 6.ESAEPDGDPR€70,000
02 Feb 2022TARIFER SERVICIOS, S.L.TARIFER SERVICIOS, S.L. was fined by the AEPD 2,000 EUR for using non-essential cookies without user consent. The authority also found that the website did not provide the required cookie information.ESAEPDePrivacy€2,000
02 Feb 2022IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority cited lack of transparency, improper processing of personal data, and failure to meet GDPR obligations.BEAPDGDPR€250,000
02 Feb 2022Anonymisé (CNPD decision-02-fr-2022)The company was fined by the CNPD 6,600 EUR for breaches of GDPR requirements. The authority found deficiencies in data minimization, retention, security of processing, and the information provided to data subjects in connection with video surveillance and geolocation systems.LUCNPDGDPR€6,600
01 Feb 2022SC Grupex 2000 SRLSC Grupex 2000 SRL was fined by ANSPDCP for unlawfully processing the personal data of institutionalized patients. The data appeared in filmed material available on the company's website.ROANSPDCPGDPR€1,000
29 Jan 2022COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing.ESAEPDGDPR€5,000
28 Jan 2022SEAN SERIOS S.L.SEAN SERIOS S.L. was fined by the AEPD 12,000 EUR for publishing personal data of candidates from a selection process on its website without a legal basis. The authority found a breach of GDPR Article 6(1).ESAEPDGDPR€12,000
28 Jan 2022IBERCAJA BANCO, S.A.IBERCAJA BANCO, S.A. was fined by the AEPD EUR 100,000 for unlawfully processing personal data linked to a family inheritance matter. The breach included opening a bank account for a minor without consent and disclosing personal data to third parties without authorization.ESAEPDGDPR€100,000
27 Jan 2022Musicraiser S.r.l.Musicraiser S.r.l. was fined 1,000 EUR by the Garante for continuing to send newsletters to a user despite multiple requests to be removed. The case concerns a breach of data protection rules on respecting opt-out and cancellation requests for marketing communications.ITGaranteGDPR€1,000
27 Jan 2022Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals.ITGaranteGDPR€2,000
27 Jan 2022MIRACLE IBIZA S.L.MIRACLE IBIZA S.L. was fined by the AEPD in the amount of EUR 500 for improperly positioning a surveillance camera. The camera captured the entrance to a private residence, affecting the privacy of individuals.ESAEPDGDPR€500
27 Jan 2022T.S.M. s.r.l.T.S.M. s.r.l. was fined EUR 40,000 by the Italian supervisory authority, the Garante. The sanction concerned the failure to respond to information requests, which breached GDPR obligations related to data subject rights.ITGaranteGDPR€40,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000
26 Jan 2022ESTUDIO INMOBILIARIO SAN ISIDRO, S.L.UESTUDIO INMOBILIARIO SAN ISIDRO, S.L.U was fined by the AEPD EUR 5,000 for unlawfully obtaining personal data and visiting the complainant's home to promote real estate services without proper consent. The case concerns unlawful processing and improper direct marketing contact.ESAEPDGDPR€5,000