Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jun 2021Anonymisé (CNPD decision-24-fr-2021)The company was fined EUR 17,000 by the CNPD for breaching the data minimization principle and for failing to provide adequate information to data subjects. The deficiencies concerned employees and third parties in relation to processing activities.LUCNPDGDPR€17,000
28 Jun 2021ELEGA ENERGÍA, S.L.ELEGA ENERGÍA, S.L. was fined EUR 2,000 by the AEPD for failing to provide information about cookies and for not obtaining user consent before placing them. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
24 Jun 2021NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR.ESAEPDGDPR€50,000
24 Jun 2021Comune di FiscianoComune di Fisciano was fined EUR 1,000 by the Garante for improper handling of personal data. The data were removed after the complaint, and the case concerned transparency and data protection obligations.ITGaranteGDPR€1,000
24 Jun 2021B.B.B.The entity was fined by the AEPD EUR 1,000 for installing a surveillance camera in a hair salon without informing individuals about the video surveillance area. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€1,000
24 Jun 2021BAZTANDIS, S.L.BAZTANDIS, S.L. was fined EUR 1,000 by the AEPD for deficiencies in signage related to video surveillance. The authority found a breach of Article 13 GDPR concerning the information duties owed to individuals under surveillance.ESAEPDGDPR€1,000
24 Jun 2021Comune di Cogollo del CengioThe Municipality of Comune di Cogollo del Cengio was fined by the Garante 1,000 EUR for unlawfully publishing personal data related to a disciplinary procedure. The authority found no legal basis for the disclosure and held that it breached the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€1,000
24 Jun 2021Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data.NODatatilsynetGDPR€49,145
24 Jun 2021Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” di NovaraThe Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” in Novara was fined by the Garante EUR 2,000. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
24 Jun 2021Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency.ITGaranteGDPR€30,000
24 Jun 2021Ospedale Pediatrico Bambino GesùOspedale Pediatrico Bambino Gesù was fined by the Garante 15,000 EUR for breaches involving a data incident and improper handling of patient health data. The authority cited violations of GDPR Articles 5 and 32 on lawful processing and security of personal data.ITGaranteGDPR€15,000
23 Jun 2021Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject.HUNAIHGDPR€2,860
22 Jun 2021VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections.NODatatilsynetGDPR€14,678
21 Jun 2021GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules.ESAEPDGDPR€200,000
21 Jun 2021DKN.5131.3.2021StatusprawomocnaTytuUODO imposed an administrative fine of PLN 159,176 on an insurance company. The authority found that the company failed to notify the President of UODO of a personal data breach within the required timeframe.PLUODOGDPR€35,116
21 Jun 2021Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization.SEIMYGDPR€1,566,000
18 Jun 2021DESPACHO TEJEDOR INFANTES CONSULTORES ASESORES, S.L.The entity unlawfully disclosed personal data to a third party, breaching the confidentiality principle under GDPR. The AEPD imposed a fine of 2,000 EUR.ESAEPDGDPR€2,000
18 Jun 2021Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed.HUNAIHGDPR€14,050
18 Jun 2021STAROFSERVICE SASSTAROFSERVICE SAS was fined by the AEPD 3,000 EUR for sending advertising emails without the recipient's consent. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
18 Jun 2021IZA OBRAS Y PROMOCIONES, S.A.IZA OBRAS Y PROMOCIONES, S.A. was fined by the AEPD 50,000 EUR for disclosing an employee’s health data and personal email address without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€50,000