Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Jun 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for continuing to send investment reports by postal mail despite the complainant’s request to receive them by email. The authority found a breach of the right to object and to stop data processing.ESAEPDGDPR€70,000
02 Jun 2022B.B.B.The entity was fined by the AEPD for improperly positioning surveillance cameras toward public areas without proper signage. This conduct breached data protection requirements.ESAEPDGDPR€1,000
03 Jun 2022Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for failing to follow internal complaint procedures. This allowed a security guard to improperly access and misuse personal data, resulting in a breach of data confidentiality.ROANSPDCPGDPR€2,000
06 Jun 2022URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L. was fined by the AEPD 2,000 EUR for failing to notify a personal data breach in time. The case concerns the Article 33 GDPR obligation to report breaches to the supervisory authority.ESAEPDGDPR€2,000
06 Jun 2022Dane anonimowe (C.)UODO imposed an administrative fine of PLN 15,994 on Anonymous Data (C.). The case concerned the failure to report a personal data breach involving the loss of an employee’s employment certificate.PLUODOGDPR€3,491
08 Jun 2022Wens Experience SRLWens Experience SRL was fined EUR 1,500 by ANSPDCP for GDPR violations. The case concerned deficiencies by the company acting as a processor for a data controller.ROANSPDCPGDPR€1,500
08 Jun 2022INMUR JOYEROS, S.L.INMUR JOYEROS, S.L. was fined by the AEPD 300 EUR for failing to properly inform individuals about the video surveillance system in its premises. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€300
09 Jun 2022Webáruház adatkezelési tájékoztatójaThe authority found a GDPR breach because the website and online store did not provide clear and transparent information about personal data processing. A fine of 300,000 HUF was imposed.HUNAIHGDPRFt 300,000
09 Jun 2022Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5.ITGaranteGDPR€10,000
10 Jun 2022ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for processing personal data without consent. The breach resulted in identity theft in a phone contract.ESAEPDGDPR€50,000
10 Jun 2022WATYANA 786, S. L.WATYANA 786, S. L. was fined by the AEPD EUR 400 for failing to inform individuals about the use of video surveillance at its premises. The authority found a breach of Article 13 GDPR because the required information was not provided to data subjects.ESAEPDGDPR€400
13 Jun 2022AMADEUS IT GROUP, S.A.AMADEUS IT GROUP, S.A. was fined by the AEPD EUR 5,000 for failing to properly handle a data subject's requests to access and delete personal data. The authority found a breach of Article 12 GDPR because the company did not provide an adequate response.ESAEPDGDPR€5,000
13 Jun 2022SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULESCNIL imposed a liquidation of the penalty payment against SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULES in the amount of EUR 3,900. The measure relates to failure to comply with a prior obligation within the required deadline.FRCNILGDPR€3,900
15 Jun 2022S.C.In May 2022, the Romanian supervisory authority ANSPDCP completed an investigation into the operator S.C. and found a violation of GDPR provisions. A fine of 3,000 EUR was imposed.ROANSPDCPGDPR€3,000
16 Jun 2022Deutsche Bank S.p.A.Deutsche Bank S.p.A. was fined EUR 20,000 by the Garante for unlawfully processing personal data. The bank reported an individual's name to CRIF S.p.A. without prior notice, which breached data protection rules.ITGaranteGDPR€20,000
16 Jun 2022Rapido Finance, S.L.Rapido Finance, S.L. was fined 2,000 EUR by the AEPD for unlawfully processing personal data. The company continued to pursue a debt that had already been paid, which breached Article 6(1) GDPR.ESAEPDGDPR€2,000
16 Jun 2022Federazione Italiana NuotoFederazione Italiana Nuoto was fined EUR 2,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 of the GDPR.ITGaranteGDPR€2,000
20 Jun 2022Asociația de Proprietari Aviației ParkAsociația de Proprietari Aviației Park was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
20 Jun 2022SC Interactions Marketing SRLSC Interactions Marketing SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The authority stated that the company acted as a processor for another controller.ROANSPDCPGDPR€1,000
20 Jun 2022Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights.GRHDPAGDPR€2,000