Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Mar 2022Briza Land S.R.L.The National Supervisory Authority completed an investigation on 24.02.2022 at Briza Land S.R.L. and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
11 Mar 2022CINCON S.C.CINCON S.C. was fined EUR 500 by the AEPD for failing to provide adequate information about the retention period of personal data collected through a website form. The authority found a breach of Article 13 GDPR because data subjects were not given the required notice.ESAEPDGDPR€500
11 Mar 2022SHOPERY NETWORKS SPAIN, S.L.SHOPERY NETWORKS SPAIN, S.L. was fined 3,000 EUR by the AEPD for a security breach. The authority found a violation of Article 32 GDPR, which requires appropriate technical and organizational measures.ESAEPDGDPR€3,000
14 Mar 2022LISMARTSA, S.L.LISMARTSA, S.L. was fined EUR 3,000 by the AEPD for improperly sending the personal data of 74 employees by email. The authority found a breach of data protection rules.ESAEPDGDPR€3,000
14 Mar 2022RAMONA FILMS, S.LRAMONA FILMS, S.L was fined by the AEPD for failing to provide requested information to the Spanish Data Protection Agency. The breach concerned the duty to cooperate under GDPR Article 58(1).ESAEPDGDPR€30,000
14 Mar 2022Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected.IEDPCGDPR€463,000
14 Mar 2022Tullverket, tjänstemobilerThe Swedish Customs Agency (Tullverket) was fined by IMY 300,000 SEK for failing to implement adequate technical and organizational measures. This led to unauthorized storage of personal data in a cloud service.SEIMYePrivacy€28,473
14 Mar 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 70,000 EUR for issuing a bill despite confirming that no debt existed and that personal data had been deleted. The authority found this conduct to be contrary to Article 6(1) of the GDPR.ESAEPDGDPR€70,000
15 Mar 2022Meta (Facebook)The Irish DPC fined Meta (Facebook) EUR 17,000,000 in case IN-18-11-5. The penalty has been collected.IEDPCGDPR€17,000,000
15 Mar 2022PRODESSPA DECORATIUS I PINTURES, S.L.PRODESSPA DECORATIUS I PINTURES, S.L. was fined by the AEPD 15,000 EUR for unlawfully processing personal data. The company included a former employee’s data in a credit information system without proper legal justification.ESAEPDGDPR€15,000
15 Mar 2022CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine.ESAEPDePrivacy€7,000
15 Mar 2022JUNTA ADMINISTRADORA A.A.A.The entity was fined for displaying complainants’ personal data on a public notice board. This breached data protection rules and created a risk of unauthorized disclosure of personal information.ESAEPDGDPR€2,000
17 Mar 2022GRUPO TECNOPOLE FABRICACIÓN Y MONTAJES, S.L.The company was fined by the AEPD €800 for sending an unsolicited commercial email without the required consent. The breach concerned Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€800
21 Mar 2022RESTAURANTCNIL imposed a fine of EUR 10,000 on RESTAURANT. The case concerned a regulatory breach, with no further details provided.FRCNILGDPR€10,000
21 Mar 2022B.B.B.The AEPD imposed a 300 EUR fine on B.B.B. for improperly directing a camera toward a transit area. The case concerned non-compliance with data protection rules governing video surveillance.ESAEPDGDPR€300
23 Mar 2022Dane anonimowe (Pana P. K. zam.)UODO imposed a monetary penalty on an individual for failing to provide required information and for not granting access to personal data needed by the supervisory authority to perform its duties. The authority also found a lack of cooperation during the proceedings.PLUODOGDPR€486
24 Mar 2022Uber B.V. e Uber Technologies Inc.Uber B.V. and Uber Technologies Inc. were fined by the Italian authority Garante EUR 2,120,000 for a data protection breach linked to the 2016 incident. The breach affected the personal data of about 57 million users worldwide, including users in Italy.ITGaranteGDPR€2,120,000
24 Mar 2022Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa.ITGaranteGDPR€10,000
24 Mar 2022Azienda sanitaria provinciale di CaltanissettaAzienda sanitaria provinciale di Caltanissetta was fined for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct breached GDPR Article 37.ITGaranteGDPR€6,000
24 Mar 2022NOTAIRECNIL imposed EUR 1,000 on NOTAIRE in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the settlement of the penalty for non-compliance.FRCNILGDPR€1,000