Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jun 2022Asociația de Proprietari Aviației ParkThe operator was fined by ANSPDCP for violating the GDPR. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
20 Jun 2022PLANET COSTA DORADA SOCIEDAD LIMITADAThe company was fined by the AEPD EUR 300 for operating video surveillance that captured public space without proper signage. The authority found a breach of GDPR Articles 5 and 13.ESAEPDGDPR€300
22 Jun 2022Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles.LUCNPDGDPR€4,000
22 Jun 2022B.B.B.An individual's personal data was used without consent to publish an online advertisement for sexual services, resulting in harassment. The responsible entity was fined for violating Article 6(1) of the GDPR.ESAEPDGDPR€10,000
22 Jun 2022Gyldendal A/SGyldendal A/S was fined 1,000,000 DKK by Datatilsynet for retaining data of 685,000 book club members longer than necessary. The authority found a breach of data retention principles.DKDatatilsynetGDPR€134,000
23 Jun 2022B.B.B.The entity was fined EUR 300 by the AEPD for positioning surveillance cameras so that they captured public spaces without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€300
27 Jun 2022NAVThe Norwegian DPA fined NAV 5,000,000 NOK for making CVs available on arbeidsplassen.no without a lawful basis under the GDPR. The case concerned unauthorized processing of personal data relating to job seekers and employees.NODatatilsynetGDPR€480,000
28 Jun 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR.ESAEPDGDPR€3,000
28 Jun 2022AUDIO STOCK, S.L.AUDIO STOCK, S.L. was fined €2,000 by the AEPD for sending commercial SMS messages despite the recipient's objection. The authority found this conduct breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€2,000
28 Jun 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined EUR 70,000 by the AEPD for a SIM card duplication incident. The incident enabled unauthorized attempts to access the complainant's bank accounts and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
28 Jun 2022YEGUADA SENILLOSA, S.L.Yeguada Senillosa, S.L. was fined by the AEPD 2,000 EUR for failing to comply with cookie requirements on its website. The authority found the use of non-essential third-party cookies without proper consent and adequate information to users.ESAEPDePrivacy€2,000
30 Jun 2022Anonymisé (CNPD decision-14-fr-2022)The company did not provide data subjects with adequate information about video surveillance, breaching GDPR transparency requirements. CNPD found violations of Articles 5, 12, and 13 GDPR and imposed a 1,000 EUR fine.LUCNPDGDPR€1,000
30 Jun 2022B.B.B.The entity was fined EUR 300 by the AEPD for failing to display the required signage informing individuals about video surveillance at its premises. The authority treated this as a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€300
30 Jun 2022Federazione Italiana Sommelier, Albergatori e RistoratoriFederazione Italiana Sommelier, Albergatori e Ristoratori was fined by the Garante 5,000 EUR for unlawful processing of personal data. The breach involved the improper communication of one member’s data to all associates.ITGaranteGDPR€5,000
30 Jun 2022Anonymisé (CNPD decision-13-fr-2022)The company breached GDPR by failing to respect data retention limits and by not providing employees with adequate information about the vehicle geolocation system. The CNPD imposed a fine of EUR 5,600.LUCNPDGDPR€5,600
30 Jun 2022Continental Automotive Romania SRLThe company was fined for failing to implement adequate technical and organizational measures and for not periodically assessing those measures in relation to employee video processing. The breach concerned the security of video processing and the prevention of unauthorized processing.ROANSPDCPGDPR€2,000
01 Jul 2022RCI BANQUE, S.A. SUCURSAL EN ESPAÑARCI Banque, S.A. Sucursal en España was fined by the AEPD for failing to properly handle a request for erasure under Article 17 GDPR. As a result, the data subject received unwanted communications about a debt they did not owe.ESAEPDGDPR€20,000
05 Jul 2022Global Greece MEPEThe company was fined for sending unsolicited marketing emails without obtaining the recipients’ prior explicit consent. The authority found this conduct to be in breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
05 Jul 2022Üzleti titokra való hivatkozással hanganyag korlátozott felhasználhatósággal történő rendelkezésre bocsátásaThe authority fined the controller for failing to properly handle a data subject request. The case concerned a breach of the obligations under Article 12 GDPR.HUNAIHGDPR€4,900
05 Jul 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules.ESAEPDGDPR€70,000