Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Jan 2022B.B.B.The entity installed a video surveillance system covering public transit areas without a justified cause. This breached data protection principles.ESAEPDGDPR€500
26 Jan 2022Slane Credit UnionThe Irish DPC imposed a fine of EUR 5,000 on Slane Credit Union in inquiry IN-19-7-5. The penalty has been collected.IEDPCGDPR€5,000
26 Jan 2022Region Uppsala, personuppgifts­incidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place.SEIMYGDPR€28,710
24 Jan 2022Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff.NODatatilsynetGDPR€196,000
22 Jan 2022SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILESCNIL imposed a fine of 3,000 EUR on SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILES and issued an injunction under penalty. The case concerns a confirmed compliance breach.FRCNILGDPR€3,000
22 Jan 2022Dane anonimowe (C. S.A. z siedzibą w M. przy ul.)UODO imposed an administrative fine on the controller and the processor for failing to implement appropriate technical and organizational measures to protect personal data. The breach resulted in a loss of confidentiality, and the controller also failed to properly verify the processor.PLUODOGDPR€1,083,000
19 Jan 2022DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data, including the name of a minor, that was not necessary for the intended purpose. The authority found this to be a breach of data protection principles.ESAEPDGDPR€50,000
19 Jan 2022Dane anonimowe (U.)UODO imposed an administrative fine of 545,748 PLN on Dane anonimowe (U.) for failing to notify data subjects without undue delay about a personal data breach. The case concerns the obligation to promptly inform affected individuals under data protection rules.PLUODOGDPR€120,000
18 Jan 2022BAZARDELALEGION.COMBAZARDELALEGION.COM was fined by the AEPD for failing to provide the required information on its website under Article 13 GDPR. The breach concerned the website’s information duties toward individuals whose data are collected online.ESAEPDGDPR€3,000
18 Jan 2022MAJESTIC SOLUTIONS S.L.MAJESTIC SOLUTIONS S.L. was fined by the AEPD 10,000 EUR for failing to provide all required information to affected individuals after a personal data security breach. The authority found a breach of Article 34(2) GDPR.ESAEPDGDPR€10,000
17 Jan 2022SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A.SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A. was fined 20,000 EUR by the AEPD. The authority found that the company failed to properly handle a data subject’s request for erasure, which led to continued processing of personal data despite the prior deletion request.ESAEPDGDPR€20,000
17 Jan 2022***EMPRESA.1The entity was fined for improperly orienting surveillance cameras so they captured public pedestrian areas without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
16 Jan 2022B.B.B.The online pet store mascotagadget.com was fined EUR 500 by the AEPD. The authority found that customer data was transferred to third parties without consent and that users were not properly informed, breaching Article 13 of the GDPR.ESAEPDGDPR€500
13 Jan 2022Villa Masi Residenza per anzianiVilla Masi Residenza per anziani was fined EUR 1,000 by the Garante for a video surveillance system that did not comply with GDPR Article 13. The authority found that the required information notices for monitored individuals were not properly provided.ITGaranteGDPR€1,000
13 Jan 2022Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13.ITGaranteGDPR€7,500
13 Jan 2022Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€4,000
13 Jan 2022IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 70,000 by the AEPD for changing an electricity supply contract without the customer's knowledge or consent. The authority found that this conduct breached data protection rules.ESAEPDGDPR€70,000
13 Jan 2022ADVANS BROKERS CORREDURIA DE SEGUROS S.L.ADVANS BROKERS CORREDURIA DE SEGUROS S.L. was fined by the AEPD EUR 80,000 for a data breach affecting 55,000 individuals, including minors. The authority found that the incident was reported to the AEPD with delay.ESAEPDGDPR€80,000
13 Jan 2022A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements.ITGaranteGDPR€6,000
13 Jan 2022Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented.ITGaranteGDPR€14,000