Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Nov 2021INCOPROSOL, S.L.INCOPROSOL, S.L. was fined EUR 5,000 by the AEPD for recording a customer's phone conversation without informing them. The authority treated this as a breach of data protection principles.ESAEPDGDPR€5,000
26 Nov 2021Valoris Center S.R.L.Valoris Center S.R.L. was fined by ANSPDCP EUR 2,000 for a personal data processing security breach. The incident was caused by a call center employee.ROANSPDCPGDPR€2,000
25 Nov 2021Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The hospital was fined by the Garante 50,000 EUR for unlawfully publishing on its website the personal data of participants in a competitive procedure, including health data. The authority found a breach of data protection principles.ITGaranteGDPR€50,000
25 Nov 2021Ordinanza ingiunzione - 25 novembre 2021 [9733002]A healthcare professional was fined by the Garante EUR 30,000 for unlawfully disclosing a patient's personal data, including unpaid medical bills and health information, to third parties. The authority found that the processing lacked a legal basis and breached the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€30,000
25 Nov 2021Società H San Raffaele Resnati s.r.l.The Garante imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. for violations of data protection rules in the health sector. The case involved a data breach incident, which triggered supervisory action.ITGaranteGDPR€6,000
24 Nov 2021FRUTAS Y VERDURAS LOS CAMPEONES, S.L.The company was fined by the AEPD EUR 1,500 for installing surveillance cameras without the required informational signage. The case concerned Article 13 GDPR, which requires data subjects to be informed about the processing.ESAEPDGDPR€1,500
23 Nov 2021atvinnuvega- og nýsköpunarráðuneytiðThe Icelandic DPA, Persónuvernd, fined atvinnuvega- og nýsköpunarráðuneytið for processing personal data in breach of core GDPR principles, including transparency and security. The case concerned the Ferðagjöf app, where the authority found deficiencies in data protection compliance.ISPersónuverndGDPR€50,850
22 Nov 2021SCF ZHU, S.L.SCF ZHU, S.L. was fined by the AEPD 1,000 EUR for failing to display visible information signs for its video surveillance system and for not maintaining a record of processing activities. The case reflects deficiencies in basic transparency and documentation obligations under data protection rules.ESAEPDGDPR€1,000
22 Nov 2021B.B.B.The entity installed a surveillance camera in a shared stairway without the consent of the affected persons. The camera captured an excessive area, including private spaces, which breached data protection principles.ESAEPDGDPR€2,000
22 Nov 2021COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined by the AEPD for operating a video surveillance system that recorded public transit areas without a justified basis. The authority found a breach of data protection principles.ESAEPDGDPR€3,000
19 Nov 2021MEETING PUERTO C.B.MEETING PUERTO C.B. was fined by the AEPD EUR 2,000 for unlawful processing of personal data. The breach involved posting images and comments on social media without the consent of the data subjects, contrary to Article 6(1) of the GDPR.ESAEPDGDPR€2,000
19 Nov 2021Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case.ESAEPDGDPR€40,000
13 Nov 2021IMPERIUM C.B.IMPERIUM C.B. was fined by the AEPD in the amount of 1,500 EUR for failing to provide informational signage about its video surveillance system. The authority found a breach of Article 13 GDPR because individuals on the premises were not given the required notice.ESAEPDGDPR€1,500
12 Nov 2021EUSKALTEL, S.A.EUSKALTEL, S.A. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without the required consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€5,000
12 Nov 2021Transavia Airlines C.V.Transavia Airlines C.V. was fined by the AP 400,000 EUR for failing to implement appropriate security measures to protect personal data. The Article 32 GDPR breach led to unauthorized access to systems containing data of approximately 25 million individuals.NLAPGDPR€400,000
11 Nov 2021Comune di Varano BorghiComune di Varano Borghi was fined EUR 1,000 by the Garante for unlawfully publishing personal data online. The authority found a breach of GDPR principles of data minimization and transparency.ITGaranteGDPR€1,000
11 Nov 2021COMUNIDAD DE PROPIETARIOS R.R.R.The community of property owners was fined by the AEPD EUR 2,000 for sharing residents’ personal data with a security company without proper authorization or a contract. The disclosure included names, addresses, and financial information.ESAEPDGDPR€2,000
09 Nov 2021Cyrana España General S.L.Cyrana España General S.L. was fined by the AEPD in the amount of 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account.ESAEPDGDPR€5,000
09 Nov 2021Anonymisé (CNPD decision-44-fr-2021)The company failed to meet the GDPR information obligations under Article 13 and the data minimization principle under Article 5(1)(c), particularly in connection with video surveillance. CNPD imposed a fine of 1,500 EUR.LUCNPDGDPR€1,500
03 Nov 2021B.B.B.The entity processed personal data without consent by using the complainant's data to make a purchase on Amazon. The authority found a breach of GDPR Article 6.ESAEPDGDPR€2,000