Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Apr 2022Rebirth s.r.l.Rebirth s.r.l. was fined by the Garante EUR 15,000 for operating a video surveillance system at “Caffè Antica Roma” in a manner that did not comply with data protection rules. The conduct breached the GDPR and provisions of the Italian Privacy Code.ITGaranteGDPR€15,000
07 Apr 2022Comune di OrteComune di Orte was fined for improper handling of personal data collected through video surveillance. The authority found a lack of transparency and insufficient data protection measures.ITGaranteGDPR€5,000
07 Apr 2022Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place.ITGaranteGDPR€40,000
07 Apr 2022ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR.ITGaranteGDPR€40,000
07 Apr 2022Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization.BGCPDPGDPR€1,534
07 Apr 2022Findomestic Banca spaFindomestic Banca spa was fined by the Garante 10,000 EUR for improperly contacting a third party, namely the debtor’s spouse, about a financial obligation. The authority found that this conduct constituted a GDPR violation.ITGaranteGDPR€10,000
07 Apr 2022Asociația de Proprietari din Str. Soporului 17, municipiul Cluj-NapocaThe homeowners' association was fined by ANSPDCP for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR.ROANSPDCPGDPR€500
07 Apr 2022Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System.HUNAIHGDPR€2,640
08 Apr 2022B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information.ESAEPDGDPR€3,000
08 Apr 2022AVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCAAVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCA was fined by the AEPD for failing to implement robust access controls. The weakness enabled attackers to encrypt files and demand a ransom, indicating significant gaps in technical and organizational safeguards.ESAEPDGDPR€40,000
08 Apr 2022SECURITAS DIRECT ESPAÑA, S.A.SECURITAS DIRECT ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for disclosing a customer's personal information to another client via email. The authority found a breach of confidentiality and insufficient security measures under the GDPR.ESAEPDGDPR€50,000
08 Apr 2022CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined EUR 1,000 by the AEPD for sending a commercial SMS to an individual who had already exercised the right to erasure. The authority found this conduct to be a breach of data protection rules.ESAEPDePrivacy€1,000
08 Apr 2022B.B.B.The entity was fined by the AEPD for recording audio through a video surveillance system without informing the employee. The authority treated this as a breach of data protection rules.ESAEPDGDPR€6,000
12 Apr 2022Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles.NLAPGDPR€3,700,000
13 Apr 2022PYRAMID CONSULTINGPYRAMID CONSULTING was fined by the AEPD EUR 30,000 for unlawful processing of personal data. The company incorrectly identified an individual as responsible for a traffic violation, which led to an improper administrative sanction.ESAEPDGDPR€30,000
15 Apr 2022SOCIETE D'EDITION DE LOGICIELS APPLICATIFSCNIL imposed a fine of 1,500,000 EUR on SOCIETE D'EDITION DE LOGICIELS APPLICATIFS. The record indicates a regulatory breach, but no further details are provided.FRCNILGDPR€1,500,000
16 Apr 2022ORI, S.l.ORI, S.l. was fined by the AEPD 2,000 EUR for failing to provide a privacy policy on its website. Personal data was collected through multiple forms, which constituted a breach of data protection rules.ESAEPDGDPR€2,000
18 Apr 2022SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.The company changed the electricity and gas supplier without the customer's consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€30,000
19 Apr 2022INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR.ESAEPDGDPR€10,000
20 Apr 2022Anonymisé (CNPD decision-09-fr-2022)The CNPD fined the company EUR 2,000 for failing to respond in time to a data subject access request and for not providing all required information under GDPR Articles 12 and 15. The company also failed to cooperate with the supervisory authority, contrary to Article 31 GDPR.LUCNPDGDPR€2,000