Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Sept 2022B.B.B.The entity was fined by the AEPD 500 EUR for using a video surveillance system that captured an excessive area of public space. In addition, recordings were published on social media without proper authorization or legal basis.ESAEPDGDPR€500
02 Sept 2022Meta (Instagram)The Irish DPC imposed a fine of EUR 405,000,000 on Meta (Instagram) in inquiry IN-20-7-4. The decision is currently under appeal.IEDPCGDPR€405,000,000
02 Sept 2022Fiziska personaA fine of EUR 200 was imposed. The decision has entered into force.LVDVIGDPR€200
06 Sept 2022B.B.B.The entity failed to provide the information required under Article 13 GDPR when processing personal data. AEPD imposed a fine of EUR 2,000 for this breach.ESAEPDGDPR€2,000
06 Sept 2022MAE WEST SYSTEMS, S.L.MAE WEST SYSTEMS, S.L. was fined EUR 400 by the AEPD for failing to provide the required information on video surveillance signs. The authority found a breach of Article 13 GDPR because individuals under surveillance were not properly informed.ESAEPDGDPR€400
07 Sept 2022LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €1,000 for sending unsolicited commercial communications. The conduct occurred after the complainant had exercised the right to data deletion.ESAEPDePrivacy€1,000
08 Sept 2022Realmedia Network SARealmedia Network SA was fined EUR 8,000 by ANSPDCP for a data processing security breach. The incident involved a service used to operate the imobiliare.ro platform.ROANSPDCPGDPR€8,000
08 Sept 2022GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCECNIL imposed a fine of 250,000 EUR on GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCE. The record states that the sanction concerns a violation, but no further details are provided.FRCNILGDPR€250,000
09 Sept 2022MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD for processing personal data without a lawful basis. The company failed to respond properly to a data access request and incorrectly linked an individual to insurance policies and claims.ESAEPDGDPR€30,000
09 Sept 2022COMUNIDAD PROPIETARIO R.R.R.The entity installed a video surveillance system without approval from the property owners' association. The authority found this to be a breach of data protection rules and imposed a fine of 1,500 EUR.ESAEPDGDPR€1,500
09 Sept 2022B.B.B.A private individual was fined 600 EUR by the AEPD for using a webcam oriented toward a public street without prior authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€600
09 Sept 2022COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD 2,000 EUR for unauthorized access to and dissemination of video surveillance recordings. The case concerns a breach of data protection rules.ESAEPDGDPR€2,000
09 Sept 2022JOLY DIGITAL, S.L.U.JOLY DIGITAL, S.L.U. was fined by the AEPD EUR 20,000 for publishing the complainant’s private Instagram photo without consent. The authority found a breach of Article 6 GDPR because there was no lawful basis for processing the personal data.ESAEPDGDPR€20,000
09 Sept 2022SIA "TET"A fine of EUR 1,200,000 was imposed by the DVI. The case was appealed, and a court judgment was later recorded.LVDVIGDPR€1,200,000
09 Sept 2022SC Raiffeisen Bank SASC Raiffeisen Bank SA was fined by ANSPDCP in the amount of EUR 2,000 for violating Article 5 of the GDPR. The case concerned non-compliance with the basic principles for processing personal data set out in that provision.ROANSPDCPGDPR€2,000
09 Sept 2022Anonymised (HDPA 48/2022)The mayor of a municipality was fined for sending unsolicited emails without the recipients’ consent. The authority found breaches of GDPR transparency and purpose limitation principles.GRHDPAGDPR€2,000
12 Sept 2022Magyar Éremkibocsátó Kft.The Hungarian data protection authority, NAIH, imposed a fine of 30,000,000 HUF on Magyar Éremkibocsátó Kft. The authority found that personal data were processed without a proper legal basis, specific purpose, or valid consent, and that GDPR transparency and information obligations were breached.HUNAIHGDPR€75,900
12 Sept 2022ROMESTONE, S.L.ROMESTONE, S.L. was fined by the AEPD 6,000 EUR for installing a surveillance camera in a shared rental property without tenant consent. The case concerns a privacy breach in the context of personal data processing.ESAEPDGDPR€6,000
15 Sept 2022Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation.ITGaranteGDPR€100,000
15 Sept 2022Immobiliare Riscostruzione Meloria s.r.l.The company was fined by the Garante in the amount of 2,000 EUR for installing a video surveillance system without the required informational signage. This breached GDPR rules on transparency and the duty to inform individuals subject to monitoring.ITGaranteGDPR€2,000