Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Sept 2021COMUNIDAD DE PROPIETARIOS C/ ***DIRECCIÓN.1The community of property owners was fined by the AEPD 2,000 EUR for publishing personal data on a public notice board. This conduct breached data protection rules.ESAEPDGDPR€2,000
26 Aug 2021B.B.B.The entity was fined by the AEPD in the amount of EUR 1,500 for installing surveillance cameras that excessively recorded private areas of third parties. The authority found this to be a breach of data protection principles.ESAEPDGDPR€1,500
26 Aug 2021B.B.B.The entity was fined 1,500 EUR by the AEPD for improperly positioning its video surveillance system. The cameras were directed toward a public path, which breached data protection rules.ESAEPDGDPR€1,500
25 Aug 2021Amendă în aplicarea Legii nr. 190/2018The operator was fined for failing to respond to the authority's requests during an investigation. The case concerns non-cooperation with ANSPDCP in the course of supervisory proceedings.ROANSPDCPGDPR€2,029
24 Aug 2021Топлофикация София ЕАДThe Bulgarian data protection authority fined Toplofikatsia Sofia EAD 2,000 BGN for unlawful processing of personal data caused by a name coincidence. The error led to incorrect legal actions being taken against an individual.BGCPDPGDPR€1,023
23 Aug 2021VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for breaching data protection principles. The case involved issuing SIM card duplicates to unauthorized individuals, which compromised data integrity and confidentiality.ESAEPDGDPR€4,000,000
23 Aug 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD for failing to comply with a resolution concerning the right of access. The authority cited a breach of Article 83(6) GDPR.ESAEPDGDPR€15,000
20 Aug 2021WhatsApp Ireland LtdThe Irish DPC imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd in inquiry IN-18-12-2. The decision is currently under appeal.IEDPCGDPR€225,000,000
20 Aug 2021A.A.A. (FRUTERIA)The entity was fined for operating a video surveillance system without the required signage informing individuals of its presence. The authority treated this as a breach of Article 13 GDPR on transparency and information duties.ESAEPDGDPR€1,000
20 Aug 2021MOVE IrelandThe Irish DPC fined MOVE Ireland EUR 1,500 in case IN-20-7-1. The fine has been collected.IEDPCGDPR€1,500
18 Aug 2021EULEN SEGURIDAD, S.A.EULEN SEGURIDAD, S.A. was fined by the AEPD 3,000 EUR for disclosing employees' DNI numbers in a workplace notice. The authority found a breach of confidentiality and data security principles.ESAEPDGDPR€3,000
17 Aug 2021BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach.ESAEPDGDPR€100,000
17 Aug 2021UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers.DKDatatilsynetGDPR€20,171
12 Aug 2021NATURAL LOGISTICS, S.L.NATURAL LOGISTICS, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient's objection. This breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€3,000
09 Aug 2021ACONCAGUA JUEGOS S.A.ACONCAGUA JUEGOS S.A. was fined by the AEPD 10,000 EUR for failing to appoint a Data Protection Officer. The authority also found that the company did not address a data subject’s erasure request within the legal deadline.ESAEPDGDPR€10,000
07 Aug 2021SPORTIUM APUESTAS DIGITAL S.A.U.SPORTIUM APUESTAS DIGITAL S.A.U. was fined by the AEPD 5,000 EUR for sending marketing emails after a data deletion request and for having non-compliant cookie policies on its website. The case indicates failures in data protection and user consent controls.ESAEPDePrivacy€5,000
05 Aug 2021Anonymisé (CNPD decision-31-fr-2021)The company sent emails containing sensitive medical data to incorrect recipients. The authority also found a breach of data protection duties due to improper documentation of the incidents.LUCNPDGDPR€275,000
05 Aug 2021Anonymisiert (DSB 2021-0.518.795)An individual was fined for unlawfully processing and disclosing health-related personal data of a kindergarten teacher. The violation consisted of sending an email with sensitive information to her employer.ATDSBGDPR€600
05 Aug 2021COMUNIDAD DE VECINOS ***COMUNIDAD.1The community of neighbors was fined EUR 1,000 by the AEPD for failing to provide adequate information about video surveillance. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€1,000
05 Aug 2021HUBSIDE IBÉRICA S.L.HUBSIDE IBÉRICA S.L. was fined by the AEPD for charging a customer for services that were not contracted. Personal and bank account data were collected during a purchase, and the penalty was reduced due to early payment.ESAEPDGDPR€5,000