Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Jul 2022GRUPO TRANSAHER, S.L.GRUPO TRANSAHER, S.L. was fined by the AEPD 50,000 EUR for installing surveillance cameras in employee rest areas. The authority found that the company did not properly inform employees and may have infringed their privacy under the GDPR.ESAEPDGDPR€50,000
14 Jul 2022SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident.DKDatatilsynetGDPR€67,180
15 Jul 2022URBANO DIVERTIA, S.L.URBANO DIVERTIA, S.L. was fined by the AEPD 2,000 EUR for sending clients documents that contained personal data of third parties. The company also failed to include a reference to its privacy policy in corporate emails, which breached data protection requirements.ESAEPDGDPR€2,000
15 Jul 2022FEDERACIÓN DE ATENCIÓN A LA CIUDADANÍA DE LA UNIÓN SINDICAL OBRERA (FAC-USO)The organization continued sending emails to an individual after they requested deletion of their personal data. The AEPD found a breach of Article 6 of the GDPR and imposed a EUR 3,000 fine.ESAEPDGDPR€3,000
15 Jul 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle.ESAEPDGDPR€70,000
21 Jul 2022Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured.ITGaranteGDPR€5,000
21 Jul 2022Global Service s.r.l.Global Service s.r.l. was fined by the Garante EUR 2,000 for installing a video surveillance system without the required informational signage. The case concerned a breach of data protection rules and the duty to properly inform individuals under surveillance.ITGaranteGDPR€2,000
21 Jul 2022WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures.ESAEPDGDPR€3,000
21 Jul 2022Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended.ITGaranteGDPR€10,000
21 Jul 2022Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions.ITGaranteGDPR€10,000
21 Jul 2022Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures.ITGaranteGDPR€3,000
21 Jul 2022Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context.ITGaranteGDPR€20,000
22 Jul 2022MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined EUR 4,000 by the AEPD for sending commercial emails without the required authorization. The case concerned a breach of Article 21 of the LSSI and involved unauthorized marketing communications.ESAEPDePrivacy€4,000
23 Jul 2022GESTIONES AUTO LOW COST S. LThe entity was fined for not having a privacy policy on its website. The breach concerned Article 13 of the GDPR, which requires specific information to be provided to data subjects.ESAEPDGDPR€1,000
25 Jul 2022MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing.GRHDPAGDPR€5,000
28 Jul 2022Ordinanza ingiunzione - 28 luglio 2022 [9813385]The Garante imposed a fine of EUR 1,000 on the website administrator for failing to remove or de-index a page containing a Corriere della Sera article about a judicial case involving the complainant's father. The authority found a violation of the right to be forgotten.ITGaranteGDPR€1,000
28 Jul 2022Auto Hi-Fi System S.n.cAuto Hi-Fi System S.n.c was fined EUR 2,000 by the Garante. The surveillance camera captured public areas and private property without proper notice, breaching data protection principles.ITGaranteGDPR€2,000
28 Jul 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures.ITGaranteGDPR€100,000
29 Jul 2022LA CASA DEL BAMBÚLA CASA DEL BAMBÚ was fined €200 by the AEPD for continuing to send marketing emails to a customer after an unsubscribe request. The authority found this to be a breach of Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€200
29 Jul 2022COMUNIDAD DE PROPIETARIOSA community of property owners was fined by the AEPD €300 for installing a surveillance camera without proper signage. The notice did not identify the data controller or provide contact details for exercising data subject rights.ESAEPDGDPR€300