Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jul 2022Uniwersyteckie CentrumThe Polish DPA (UODO) imposed an administrative fine of PLN 10,000 on Uniwersyteckie Centrum Kliniczne Uniwersytetu Medycznego. The authority found that the entity failed to report the personal data breach without undue delay and did not notify the affected individuals without undue delay.PLUODOGDPR€2,096
07 Jul 2022Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data.ITGaranteGDPR€45,000
07 Jul 2022E Software Concept SRLE Software Concept SRL was fined EUR 3,000 by ANSPDCP. The authority found that the company had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the processing risk.ROANSPDCPGDPR€3,000
07 Jul 2022SIA "DEPO DIY"DVI imposed a fine of 17,495 EUR on SIA "DEPO DIY". The decision concerns a breach of obligations and has entered into force.LVDVIGDPR€17,495
07 Jul 2022Anonymisé (CNPD decision-15-fr-2022)The company was fined by the CNPD EUR 10,500 for breaching the data minimization principle and for failing to adequately inform individuals about video surveillance systems. The authority cited violations of GDPR Articles 5(1)(c) and 13.LUCNPDGDPR€10,500
07 Jul 2022B.B.B.A private individual was fined 600 EUR by the AEPD for improperly positioning surveillance cameras. The cameras were directed toward public areas, which breached data protection rules.ESAEPDGDPR€600
07 Jul 2022B.B.B.The entity installed a surveillance camera without proper signage, covering common areas. This breached the data protection rights of affected individuals and the applicable transparency requirements.ESAEPDGDPR€600
07 Jul 2022Intesa Sanpaolo Vita S.p.a.Intesa Sanpaolo Vita S.p.a. was fined by the Garante EUR 20,000 for unlawfully disclosing personal data related to a life insurance policy to unauthorized third parties. The breach resulted from an operational error and raised concerns about personal data protection and access controls.ITGaranteGDPR€20,000
07 Jul 2022SOCIETE DE LOCATION DE VEHICULESCNIL imposed a fine of EUR 175,000 on SOCIETE DE LOCATION DE VEHICULES. The case concerned a breach of personal data protection rules.FRCNILGDPR€175,000
07 Jul 2022E Software Concept SRLE Software Concept SRL was fined EUR 1,000 by ANSPDCP. The sanction was imposed for failing to provide requested information to the supervisory authority.ROANSPDCPGDPR€1,000
07 Jul 2022Głównego Geodetę Kraju z siedzibą w Warszawie, przy ul.UODO imposed a PLN 60,000 administrative fine on the Chief Geodesist of Poland. The authority found that the personal data breach was not reported to the supervisory authority without undue delay and that affected individuals were not notified.PLUODOGDPR€12,573
08 Jul 2022Anonymizováno (ÚOOÚ UOOU-03988/20-54)The entity was fined for processing personal data without a legal basis. The infringement involved sending unsolicited offers using data obtained from the business register.CZUOOUGDPR€2,844
08 Jul 2022SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L.SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L. was fined by the AEPD 2,000 EUR for breaching data retention and confidentiality principles. The company improperly used personal data to file a police report and shared it with multiple parties.ESAEPDGDPR€2,000
08 Jul 2022Egészségügyi dokumentáció másolatának kiadásaThe controller breached the GDPR by failing to provide adequate access to personal health data and by not ensuring transparency and information rights. As a result, the authority imposed a fine of HUF 600,000.HUNAIHGDPR€1,488
11 Jul 2022Hírlevekkel kapcsolatos adatkezelésThe entity was fined by NAIH in the amount of HUF 500,000 for processing personal data for direct marketing purposes without a legal basis. The authority also found a lack of transparent information and delayed handling of data subject requests.HUNAIHGDPR€1,225
11 Jul 2022S.C. (Sameday)S.C. (Sameday) was fined EUR 3,000 by ANSPDCP for failing to implement adequate technical and organizational security measures. The deficiency led to unauthorized access to the personal data of 26,566 individuals.ROANSPDCPGDPR€3,000
11 Jul 2022Anonymizováno (ÚOOÚ UOOU-04856/21-13)The entity was fined by the UOOU 250,000 CZK for sending unsolicited commercial communications by email to approximately 266,607 recipients without their consent. This conduct violated Czech rules on certain information society services.CZUOOUePrivacy€10,165
12 Jul 2022B.B.B.B.B.B. was fined by the AEPD EUR 800 for sending commercial emails without the recipient's consent. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€800
12 Jul 2022PUNTO ROJO LIBROS, S.LPUNTO ROJO LIBROS, S.L was fined EUR 800 by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for this type of communication.ESAEPDePrivacy€800
12 Jul 2022LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €6,000 for sending commercial emails without the recipients’ consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing activity.ESAEPDePrivacy€6,000