Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Dec 2021SC Nobiotic Pharma SRLSC Nobiotic Pharma SRL was fined €2,000 by ANSPDCP for failing to respond to information requests. The authority treated this as a breach of GDPR obligations.ROANSPDCPGDPR€2,000
09 Dec 2021RESTAURANTE FUENTEBRO, S.C.The entity was fined for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€1,500
09 Dec 2021***COMUNIDAD.1The entity installed surveillance cameras in a community property without proper authorization from all owners. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
09 Dec 2021Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected.IEDPCGDPR€110,000
07 Dec 2021Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws.NLAPGDPR€2,750,000
06 Dec 2021Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021 and imposed a fine for GDPR violations. The case concerned deficiencies identified during the supervisory authority’s review.ROANSPDCPGDPR€1,000
06 Dec 2021Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021. As a result, a fine of EUR 5,000 was imposed for GDPR violations.ROANSPDCPGDPR€5,000
06 Dec 2021Societatea Civilă Medicală Policlinica TommedANSPDCP completed an investigation at Societatea Civilă Medicală Policlinica Tommed and found breaches of GDPR provisions. The operator was fined and required to align data collection and processing activities with data protection requirements to prevent unauthorized disclosure of personal data.ROANSPDCPGDPR€2,000
03 Dec 2021MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications.ESAEPDePrivacy€2,000
03 Dec 2021Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR.HUNAIHGDPR€825
03 Dec 2021GARLEX SOLUTIONS, S.L.GARLEX SOLUTIONS, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. The case concerned an unsolicited contract offer for electricity supply.ESAEPDGDPR€15,000
02 Dec 2021Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.The Garante imposed a EUR 30,000 fine on Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting patient health data.ITGaranteGDPR€30,000
02 Dec 2021Teaching CouncilThe Irish DPC fined Teaching Council EUR 60,000 in inquiry IN-20-4-1. The fine has been collected.IEDPCGDPR€60,000
02 Dec 2021Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data.ITGaranteGDPR€7,000
02 Dec 2021La Duomo S.r.l.s.La Duomo S.r.l.s. was fined EUR 20,000 by the Garante for sending unsolicited promotional SMS messages without valid consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€20,000
02 Dec 2021Ica s.r.l.Ica s.r.l. was fined by the Garante EUR 30,000 for failing to implement adequate security measures in its online traffic-fine payment service. The weakness allowed unauthorized access to the personal data of fined citizens.ITGaranteGDPR€30,000
02 Dec 2021Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation.ITGaranteGDPR€5,000
02 Dec 2021Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€100,000
01 Dec 2021GrindrThe Norwegian DPA, Datatilsynet, fined Grindr NOK 65 million for sharing user data with third parties for marketing purposes without a legal basis. The authority found a breach of GDPR consent requirements.NODatatilsynetGDPR€6,360,000
01 Dec 2021Dane anonimowe (P. Sp. z o.o. z siedzibą we W. przy ul.)The UODO imposed an administrative fine of PLN 18,192 on P. Sp. z o.o. The case concerned a breach of applicable rules that resulted in an administrative sanction.PLUODOGDPR€3,931