Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Aug 2022AMPLIFON Magyarország Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságAMPLIFON Magyarország was fined by the NAIH 80,000,000 HUF for processing personal data for market research without proper notice to data subjects, without a specific and legitimate purpose, and without a valid legal basis. The authority found that the company’s conduct breached core GDPR principles.HUNAIHGDPRFt 80,000,000
11 Aug 2022Lakásszövetkezeti adatközlő lapon gyűjtött személyes adatokThe entity was fined for requiring housing cooperative members to provide unnecessary personal data and for giving inadequate information about data processing. The authority found violations of GDPR Articles 6 and 13.HUNAIHGDPR€508
11 Aug 2022Lolland KommuneLolland Kommune was fined 50,000 DKK for failing to implement basic security measures. Employees were able to disable passwords on mobile devices, exposing sensitive citizen data to unauthorized access.DKDatatilsynetGDPR€6,721
14 Aug 2022INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 2,000 EUR by the AEPD for failing to inform data subjects about the processing of their personal data. The authority treated this as a breach of Article 13 GDPR.ESAEPDGDPR€2,000
16 Aug 2022Fiziska personaA fine of EUR 200 was imposed. The decision has entered into force.LVDVIGDPR€200
16 Aug 2022Dane anonimowe (N. Ośrodek Kultury z siedzibą w N. przy ul.)UODO imposed an administrative fine of PLN 2,500 on the Cultural Centre. The authority found that personal data were entrusted for processing without a written data processing agreement and without verifying whether the processor provided sufficient technical and organizational safeguards under the GDPR.PLUODOGDPR€531
18 Aug 2022niegoThe Polish DPA (UODO) imposed an administrative fine of PLN 4,569 on an individual. The authority found a failure to cooperate with the President of UODO and a failure to provide access to information necessary for the performance of its duties.PLUODOGDPR€967
19 Aug 2022Fidesz-Magyar Polgári SzövetségFidesz-Magyar Polgári Szövetség was fined by NAIH 300,000 HUF for unlawfully processing personal data, including phone numbers, without a legal basis. The authority also found violations of the rights to erasure and access, as well as inadequate information provided during phone campaigns.HUNAIHGDPR€735
22 Aug 2022Enel Energie Muntenia S.A.The company was fined by ANSPDCP for failing to implement sufficient security measures. The breach concerned inadequate safeguards required to protect data.ROANSPDCPGDPR€10,000
22 Aug 2022COMUNIDAD DE PROPIETARIOS ***COMUNIDAD.1The entity installed a video surveillance camera in a common area without proper signage. This breached Article 13 GDPR because individuals in the monitored area were not given the required information.ESAEPDGDPR€300
23 Aug 2022Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed.ATDSBGDPR€25,000
23 Aug 2022Geanonimiseerd (APD 129/2022)The Litigation Chamber imposed a fine for insufficient technical and organizational measures to protect data security. This led to unauthorized access to personal documents.BEAPDGDPR€2,500
24 Aug 2022B.B.B.The entity installed a video surveillance camera covering common areas without authorization from the homeowners' association. The authority found this to be a breach of data protection rules.ESAEPDGDPR€600
25 Aug 2022COMUNIDAD PROPIETARIOS R.R.R.The community of owners COMUNIDAD PROPIETARIOS R.R.R. was fined EUR 150 by the AEPD for installing a video surveillance system in the building entrance hall without proper data protection compliance. The authority found a breach of Article 13 GDPR concerning the duty to inform data subjects.ESAEPDGDPR€150
25 Aug 2022B.B.B.A lawyer sent personal data without authorization via WhatsApp for professional promotion. The AEPD found a breach of GDPR Articles 6 and 5(1)(f) and imposed a fine of 4,000 EUR.ESAEPDGDPR€4,000
29 Aug 2022Alpha Bank România SAAlpha Bank România SA was fined EUR 1,000 by ANSPDCP for a data security breach. A document was mistakenly sent to the wrong recipient via WhatsApp.ROANSPDCPGDPR€1,000
30 Aug 2022Dane anonimowe (T. Spółkę z ograniczoną odpowiedzialnością z siedzibą w W.)The President of UODO imposed an administrative fine of PLN 31,988 on T. Ltd. The authority found that the company failed to provide access to information necessary for the President of UODO to carry out his duties.PLUODOGDPR€6,759
31 Aug 2022niegoThe President of UODO imposed a fine of PLN 6,854 on an individual for processing the complainant’s image through video surveillance. The breach consisted of failing to cooperate with the authority and not providing information necessary for it to perform its duties.PLUODOGDPR€1,450
01 Sept 2022Liceo Statale "Edoardo Amaldi” di Alzano LombardoLiceo Statale “Edoardo Amaldi” was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including sensitive data. The authority found that the processing lacked a proper legal basis and adequate safeguards.ITGaranteGDPR€4,000
01 Sept 2022B.B.B.The entity was fined for installing surveillance cameras that captured public areas without prior administrative authorization. This constituted a breach of data protection regulations.ESAEPDGDPR€300