Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Apr 2022SIA "Your Move"SIA "Your Move" was fined EUR 1,464.13 by the DVI. The decision has entered into force.LVDVIGDPR€1,464
22 Apr 2022CÍTRICOS TANTA, S.L.CÍTRICOS TANTA, S.L. was fined by the AEPD for processing personal data without consent. The case involved registering an individual in the Social Security system without their knowledge or agreement.ESAEPDGDPR€5,000
22 Apr 2022Magyar Kétfarkú Kutya PártThe Hungarian party Magyar Kétfarkú Kutya Párt was fined by NAIH for failing to implement adequate security measures when storing supporter and activist data. The authority found breaches of GDPR Articles 32 and 5.HUNAIHGDPR€8,100
22 Apr 2022Anonymisé (CNPD decision-10-fr-2022)The public transport organization breached GDPR requirements on storage limitation, data minimization, and providing adequate information to data subjects. CNPD imposed a fine of EUR 4,000.LUCNPDGDPR€4,000
22 Apr 2022DISPLAY CONNECTORS, S.LDISPLAY CONNECTORS, S.L was fined EUR 300,000 by the AEPD for automatically publishing videos containing personal data without first ensuring the processing was lawful. The authority found this conduct breached data protection rules.ESAEPDGDPR€300,000
22 Apr 2022Anonymisé (CNPD decision-11-fr-2022)The company did not meet the information obligations under Article 13 GDPR in relation to video surveillance and employee geolocation systems. CNPD imposed an administrative fine of EUR 1,500.LUCNPDGDPR€1,500
24 Apr 2022SMART ELECTRIC SOLUTIONS, S.L.SMART ELECTRIC SOLUTIONS, S.L. was fined by the AEPD 800 EUR for installing a surveillance camera that captured public transit areas without proper warning signage. The authority found a breach of data minimization and the information duty under GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€800
25 Apr 2022Budapest Főváros XVIII. kerület Pestszentlőrinc - Pestszentimre ÖnkormányzataThe authority fined the municipality for failing to provide adequate information to data subjects about the collection and use of their personal data. It also found processing of personal and health data without a valid legal basis or proper consent.HUNAIHGDPR€8,010
26 Apr 2022CORPORACIÓN DE RADIO Y TELEVISIÓN ESPAÑOLA S.A.The company published audio of a victim's court statement in a high-profile case. The authority found a breach of the data minimization principle because excessive personal data was processed.ESAEPDGDPR€50,000
27 Apr 2022DIARIO ABC, S.L.DIARIO ABC, S.L. was fined 50,000 EUR by the AEPD for publishing audio of a victim's testimony in a high-profile court case. The authority found that the publication could identify the victim and therefore breached data protection rules.ESAEPDGDPR€50,000
27 Apr 202220 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim’s court statement in a high-profile case. The authority found a breach of data protection rules.ESAEPDGDPR€50,000
27 Apr 2022B.B.B.The entity was fined by the AEPD in the amount of EUR 300 for improperly positioning a surveillance camera. The authority found that the device could capture a private parking area and personal data without sufficient justification.ESAEPDGDPR€300
28 Apr 2022Liceo Statale “Isabella Gonzaga”Liceo Statale “Isabella Gonzaga” was fined by the Garante 2,500 EUR for publishing information on teachers' Law 104 benefits in an electronic register. The register was accessible to other teachers, which breached the GDPR and national privacy code provisions.ITGaranteGDPR€2,500
28 Apr 2022Comune di TarantoComune di Taranto was fined by the Garante in the amount of EUR 20,000 for violations related to the installation of surveillance cameras without proper data protection measures. The authority found a lack of transparency and a failure to provide the required information to data subjects.ITGaranteGDPR€20,000
28 Apr 2022Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services.ITGaranteGDPR€20,000
28 Apr 2022Ekss s.r.l.Ekss s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ITGaranteGDPR€2,000
28 Apr 2022DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data. The company published audio of a victim’s testimony without necessity, breaching the data minimisation principle under Article 5(1)(c) GDPR.ESAEPDGDPR€50,000
28 Apr 2022Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request.ITGaranteGDPR€40,000
28 Apr 2022Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information.ITGaranteGDPR€70,000
28 Apr 2022Direzione Didattica Statale 1° Circolo–EboliDirezione Didattica Statale 1° Circolo–Eboli was fined by the Garante 1,500 EUR for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned improper processing of personal data under the GDPR.ITGaranteGDPR€1,500