Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Apr 2022Educationest s.r.l.Educationest s.r.l. was fined EUR 1,000 by the Italian data protection authority, Garante. The case concerned the unlawful disclosure of an employee’s pregnancy status to third parties via email, in breach of data protection rules.ITGaranteGDPR€1,000
28 Apr 2022Comune di Monte Sant’AngeloThe Municipality of Monte Sant’Angelo was fined 3,000 EUR by the Garante for breaching data protection principles. The authority found that personal data had been made accessible online in violation of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
28 Apr 2022Comune di PartannaComune di Partanna was fined by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The case concerned the improper handling of personal data in a disciplinary procedure.ITGaranteGDPR€2,000
28 Apr 2022Istituto Nazionale Assicurazione Infortuni sul LavoroIstituto Nazionale Assicurazione Infortuni sul Lavoro was fined by the Garante EUR 20,000. The authority found that inadequate technical and organizational measures led to a data breach.ITGaranteGDPR€20,000
28 Apr 2022Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
29 Apr 2022C.P. ***COMUNIDAD.1The entity installed surveillance cameras without informing the property owners. It also failed to provide the required information on the surveillance signs.ESAEPDGDPR€800
29 Apr 2022TelemarkkinointiyritysA telemarketing company was fined for failing to comply with a Data Protection Ombudsman's order to provide a data subject access to a call recording. The case concerned a breach of GDPR Article 15 on the right of access.FITSVGDPR€8,300
29 Apr 2022Fire Brigade HeadquartersFire Brigade Headquarters was fined EUR 5,000 by the HDPA. The authority found a failure to fulfill data protection officer duties required under national law.GRHDPAGDPR€5,000
29 Apr 2022Fire Brigade HeadquartersA fine was imposed for unlawful processing of personal data, which breached data protection principles and security obligations. The case concerned failures to ensure compliance with data protection requirements.GRHDPAGDPR€25,000
29 Apr 2022Fire Brigade HeadquartersA fine of EUR 5,000 was imposed for failing to respond to a data access request. The breach concerned access rights under the GDPR and national law.GRHDPAGDPR€5,000
29 Apr 2022TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined by the AEPD 1,500 EUR for sending unsolicited commercial communications after the complainant's data had been deleted. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,500
29 Apr 2022RADIO TELEVISION MADRID, S.A.RADIO TELEVISION MADRID, S.A. was fined by the AEPD 50,000 EUR for processing excessive personal data. The case concerned the publication of audio of a victim's court statement in a high-profile case, which breached the data minimization principle.ESAEPDGDPR€50,000
29 Apr 2022ECOZONO Y CULTURA, S.L.ECOZONO Y CULTURA, S.L. collected personal data through surveys without a valid legal basis. The data were intended for later marketing contact with the individuals concerned. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€6,000
29 Apr 2022EDITORIAL PRENSA CANARIA, S.A.The company was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of data protection principles.ESAEPDGDPR€50,000
01 May 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for unauthorized access to a former customer's account. The access enabled a third party to make purchases and subscriptions, indicating improper processing of personal data without consent.ESAEPDGDPR€70,000
03 May 2022TITANIA COMPAÑÍA EDITORIAL, S.L.TITANIA COMPAÑÍA EDITORIAL, S.L. was fined by the AEPD 50,000 EUR for publishing an audio recording of a victim’s testimony in a high-profile court case. The authority found that the company processed personal data excessively and breached data protection principles.ESAEPDGDPR€50,000
03 May 2022B.B.B.Y OTRO MAS C.B.The entity installed a video surveillance system without providing the required information to data subjects. The conduct breached Article 13 of the GDPR and resulted in a EUR 300 fine imposed by the AEPD.ESAEPDGDPR€300
03 May 2022ReykjavíkurborgReykjavíkurborg was fined ISK 5,000,000 by Persónuvernd for using the Seesaw student system in schools without adequate data protection measures. The case concerned children’s personal data and transfers of data to the United States.ISPersónuverndGDPR€36,350
03 May 2022Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined by ANSPDCP in the amount of EUR 4,000 for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR.ROANSPDCPGDPR€4,000
03 May 2022HEI – Medical TravelHEI – Medical Travel was fined ISK 1,500,000 by Persónuvernd for unlawfully collecting, recording, storing, and using email addresses without consent. The company also mishandled an access request by deleting personal data after the request had been made.ISPersónuverndGDPR€10,905