Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Mar 2022Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
28 Mar 2022Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making.SEIMYGDPR€719,000
28 Mar 2022CENTRO MÉDICO SALUS BALEARES, S.L.CENTRO MÉDICO SALUS BALEARES, S.L. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned displaying patients’ body temperatures in a way that could be seen by unauthorized third parties, which compromised confidentiality.ESAEPDGDPR€30,000
28 Mar 2022VUELING AIRLINES, S.A.Vueling Airlines, S.A. was fined EUR 30,000 by the AEPD for breaching data protection rules. The company required customers to accept commercial data sharing in order to purchase tickets on its website, without providing an option to refuse cookies.ESAEPDePrivacy€30,000
29 Mar 2022SIA "8 LOUNGE"A fine of EUR 500 was imposed. The decision has entered into force.LVDVIGDPR€500
29 Mar 2022Munkahelyi kamerás megfigyelés jogalapjának és arról való tájékoztatásnak jogszerűségeThe entity was fined for configuring CCTV cameras to monitor employees more broadly than necessary. The authority also found that the data processing notice was inadequate and that the legal basis was incorrectly set on employee consent instead of legitimate interest.HUNAIHGDPR€1,350
31 Mar 2022ALQUILER SEGURO, S.A.U.ALQUILER SEGURO, S.A.U. accessed personal data from Asnef for purposes other than those intended. The AEPD found this to be a breach of data protection rules and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000
31 Mar 2022Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31.CYCyDPCGDPR€1,500
31 Mar 2022FUNDACIÓ ESCOLA PRIVADA DE GESTIÓThe entity was fined by the AEPD 5,000 EUR for failing to implement adequate security measures under Article 32 of the GDPR. This deficiency led to a personal data breach.ESAEPDGDPR€5,000
01 Apr 2022SOPHIE ET VOILA, S.L.SOPHIE ET VOILA, S.L. was fined EUR 10,000 by the AEPD for publishing a photo on Instagram without the data subject’s consent. The authority found a breach of Article 6 GDPR on lawful processing.ESAEPDGDPR€10,000
04 Apr 2022Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action.GRHDPAGDPR€10,000
04 Apr 2022Anonymised (HDPA 15/2022)The former mayor disclosed a municipal employee’s personal data without consent or a lawful basis. The authority found this to be a breach of GDPR principles of lawfulness and purpose limitation.GRHDPAGDPR€5,000
04 Apr 2022B.B.B.B.B.B. was fined 1,000 EUR by the AEPD for failing to comply with Article 13 of the GDPR. The authority found that the privacy policy did not provide adequate information on data retention periods and transfers to third parties.ESAEPDGDPR€1,000
04 Apr 2022B.B.B.The entity was fined by the AEPD in the amount of EUR 10,000 for publishing personal data, including images and videos, without the consent of the data subjects. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
05 Apr 2022B.B.B.B.B.B. was fined 300 EUR for installing a surveillance camera that recorded public areas and private property. The authority found this to be a breach of data protection rules.ESAEPDGDPR€300
06 Apr 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for processing personal data without consent. The case concerned a contract being formalized without the complainant’s consent, which breached lawful processing requirements.ESAEPDGDPR€70,000
06 Apr 2022BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error.ESAEPDGDPR€70,000
06 Apr 2022Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications.NLAPGDPR€565,000
07 Apr 2022Made in Italy s.r.l.s.Made in Italy s.r.l.s. was fined EUR 20,000 by the Garante for carrying out promotional contacts without obtaining consent. The authority also found that the company failed to respond to data subject rights requests, which is a breach of data protection obligations.ITGaranteGDPR€20,000
07 Apr 2022Tecnomed Trento s.r.l.Tecnomed Trento s.r.l. was fined by the Garante 10,000 EUR for operating a video surveillance system that did not comply with GDPR and the Italian Privacy Code. The authority found breaches of information duties and general data processing principles.ITGaranteGDPR€10,000