Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 May 2023NOVA TELECOMMUNICATIONS & MEDIA MONOPROSOPI A.E.The company was fined for repeatedly sending unsolicited electronic communications for marketing purposes despite the complainant’s objections. The authority also found failures to comply with requests for access, objection, and restriction of processing.GRHDPAePrivacy€50,000
29 Apr 2022Fire Brigade HeadquartersA fine was imposed for unlawful processing of personal data, which breached data protection principles and security obligations. The case concerned failures to ensure compliance with data protection requirements.GRHDPAGDPR€25,000
11 Nov 2011Galineio Melathro Private ClinicThe clinic disclosed sensitive personal data without informing the data subject in advance. This breached the individual's right to object to the processing.GRHDPAGDPR€1,000
19 May 2011Anonymised (HDPA 59/2011)The company was fined for unlawfully processing email addresses without prior consent. The authority found this to be a breach of data protection law.GRHDPAGDPR€2,000
10 Aug 2015Anonymised (HDPA 95/2015)A fine was imposed on the residential complex “Lofos Edison” for installing additional surveillance cameras without authorization. The authority also noted that the installation was not properly notified to the competent authority.GRHDPAGDPR€1,000
09 Aug 2013General Secretariat for Information SystemsThe General Secretariat for Information Systems was fined EUR 150,000 by the HDPA for failing to implement appropriate security measures. The breach led to unauthorized processing of Greek taxpayers’ personal tax data from 2000 to 2012.GRHDPAGDPR€150,000
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data.GRHDPAGDPR€7,500
18 Dec 2013Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database.GRHDPAGDPR€5,000
06 Feb 2025ALPHA BANK ANONYMI ETAIREIAAlpha Bank was fined by the HDPA for failing to implement adequate security measures. This led to unauthorized access to the personal data of 6,176 employees after a system administrator role was not revoked following an internal transfer.GRHDPAGDPR€3,000
14 Nov 2014Geniki TrapezaThe bank failed to ensure the accuracy of personal data and did not respond adequately to a data access request. The case concerns breaches of data quality obligations and the handling of data subject rights.GRHDPAGDPR€30,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access.GRHDPAGDPR€10,000
09 Sept 2022Anonymised (HDPA 48/2022)The mayor of a municipality was fined for sending unsolicited emails without the recipients’ consent. The authority found breaches of GDPR transparency and purpose limitation principles.GRHDPAGDPR€2,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed on Eurobank Ergasias AE for unlawful processing of the complainant’s personal data. The case concerned a breach of data protection rules by the bank.GRHDPAGDPR€5,000
29 Jun 2020NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations.GRHDPAGDPR€5,000
12 May 2021KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued.GRHDPAGDPR€5,000
15 Jan 2018Alkis Alqi Zarbala ZarballaA fine was imposed for operating a video surveillance system without the required notification and for monitoring employee workspaces. These actions breached data protection rules.GRHDPAGDPR€1,000
22 Oct 2025εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€9,000
09 Oct 2018OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact.GRHDPAePrivacy€150,000
30 Mar 2026Κέντρο Εκπαίδευσης και Αποκατάστασης Τυφλών (ΚΕΑΤ)The Greek Data Protection Authority fined ΚΕΑΤ EUR 5,000 for an untimely and improper response to an employee’s request for access to CCTV footage. The case involved edited footage, missing material, and inadequate technical and organizational measures to support compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000.GRHDPAGDPR€3,000