Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jun 2024METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure.GRHDPAGDPR€20,000
09 May 2018Sioufas and Partners Law FirmThe law firm was fined for operating a video surveillance system that covered workspaces without proper justification. It also failed to notify the authority in a timely manner and did not inform individuals about the surveillance, breaching several provisions of Greek data protection law.GRHDPAGDPR€50,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not inform data subjects about the processing of their personal data. The authority treated this as a GDPR breach and imposed a monetary fine.GRHDPAGDPR€3,000
25 Jul 2013Fast-typeThe HDPA imposed a fine of EUR 1,000 on Fast-type for the illegal collection and further processing of personal data. The case concerns a breach of core data processing legality requirements.GRHDPAGDPR€1,000
03 Sept 2014Anonymised (HDPA 119/2014)A fine was imposed for the unlawful collection and processing of personal data, including email addresses, and for sending unsolicited marketing emails without subscriber consent. The case concerns breaches of lawful processing requirements and the need for prior consent for marketing communications.GRHDPAePrivacy€4,000
01 Jan 2025SGKLegalThe Greek data protection authority, ΑΠΔΠΧ, imposed a fine of EUR 22,000 on SGKLegal for a GDPR violation. The case involved recorded conversations and deficiencies in personal data protection compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ)GDPR€22,000
09 Oct 2018WIND HELLAS TELECOMMUNICATIONS S.A.The fine was imposed for making unsolicited marketing calls to subscribers who had opted out of such contact. This conduct breached privacy and data protection rules.GRHDPAePrivacy€150,000
08 Aug 2014Anonymised (HDPA 115/2014)The controller was fined for processing personal data without consent and for sending unsolicited marketing messages. The case indicates breaches of core data protection and marketing communication obligations.GRHDPAePrivacy€1,500
16 Feb 2024Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee.GRHDPAGDPR€2,000
05 Aug 2016LinguaphoneLinguaphone was fined 25,000 EUR by the Greek HDPA for sending unsolicited marketing emails without prior recipient consent. The conduct breached Article 11 of Law 3471/2006.GRHDPAePrivacy€25,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 3,000 EUR for failing to implement appropriate technical and organizational measures to secure personal data. The deficiency resulted in unauthorized disclosure of personal data.GRHDPAGDPR€3,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity failed to provide the required information and to implement adequate data protection measures. HDPA imposed a fine of EUR 3,000 for breach of GDPR principles.GRHDPAGDPR€3,000
21 Aug 2018Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements.GRHDPAGDPR€5,000
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank for unlawful processing of the complainant’s creditworthiness data. The case concerned a breach of the rules governing lawful processing of personal data.GRHDPAGDPR€8,000
12 Sept 2017Little Kook - K. Tzortzis – I. Thanos I.K.EThe company was fined EUR 7,000 by the HDPA for operating a video surveillance system without proper notification to the authority. It also monitored employee workspaces, which breached privacy requirements.GRHDPAGDPR€7,000
12 May 2017Strategy MentorThe fine was imposed for sending unsolicited marketing emails to a large number of recipients without prior consent. This conduct breached ePrivacy rules governing electronic marketing communications.GRHDPAePrivacy€75,000
26 Feb 2015Anonymised (HDPA 26/2015)The company was fined for unlawful collection and processing of personal data, and for sending unsolicited marketing emails without recipients’ consent. The case concerns breaches of core data protection principles and the requirement to obtain prior consent for marketing communications.GRHDPAePrivacy€1,000
22 Jun 2017Bolos & SynergatesThe law firm Bolos & Synergates was fined EUR 1,000 by the HDPA for unlawfully collecting and using personal data for direct marketing. The violation involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€1,000
06 Sept 2013Groupon Greece Monoprosopi Etaireia Periorismenis EfthynisGroupon Greece was fined by the HDPA for failing to inform customers that their credit card data was stored by a third party. The authority found this to be a breach of data protection law.GRHDPAePrivacy€1,500
14 Jul 2021Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules.GRHDPAGDPR€2,000