Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Sept 2022Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17.ITGaranteGDPR€10,000
15 Sept 2022FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€40,000
15 Sept 2022Sofisticated Luxury Flats s.r.l.Sofisticated Luxury Flats s.r.l. was fined €2,000 by the Garante for using a biometric device to monitor employee attendance without a proper legal basis. The authority found that this practice breached data protection rules.ITGaranteGDPR€2,000
15 Sept 2022Comune di ThieneComune di Thiene was fined EUR 3,000 by the Garante for violating data protection principles. The authority found that personal data related to a disciplinary dismissal case was improperly disclosed online.ITGaranteGDPR€3,000
15 Sept 2022HOTEL VILLA SORO, S.L.The company was fined by the AEPD EUR 1,000 for installing surveillance cameras that could capture public areas without proper signage. The authority considered this a breach of data protection rules.ESAEPDGDPR€1,000
15 Sept 2022ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined by the AEPD for obstructing the data protection authority’s inspection. The conduct breached Article 58(1) GDPR.ESAEPDGDPR€3,000
15 Sept 2022EDITORIAL RIBADEO S.L.EDITORIAL RIBADEO S.L. was fined EUR 1,000 by the AEPD for failing to meet the information obligations under Articles 12 and 13 of the GDPR. The authority also noted non-compliance with previous data protection decisions.ESAEPDGDPR€1,000
16 Sept 2022B.B.B.B.B.B. was fined EUR 300 by the AEPD for installing a surveillance camera. The authority found that the device may have recorded images of a neighboring property without consent, potentially breaching data protection rules.ESAEPDGDPR€300
16 Sept 2022D.A.S. DEFENSA DEL AUTOMOVILISTA Y DE SINIESTROS-INTERNACIONAL, S.A. DE SEGUROS Y REASEGUROSD.A.S. Seguros was fined by the AEPD 50,000 EUR for breaching data protection principles. The company improperly disclosed personal and financial data related to an insurance policy to a third party.ESAEPDGDPR€50,000
16 Sept 2022SUPER 24H LOS ROSALES, S.L.The company was fined EUR 300 by the AEPD for operating an external surveillance camera without visible signage. It also failed to provide information on the data controller and data subject rights required under GDPR.ESAEPDGDPR€300
19 Sept 2022Banca Comercială Română SAThe supervisory authority completed an investigation into Banca Comercială Română SA and found a breach of data processing security requirements. The issue was caused by a technical error in the operator’s IT application, which led to improper data processing.ROANSPDCPGDPR€2,000
19 Sept 2022Vodafone România SAVodafone România SA was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
21 Sept 2022Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32.CYCyDPCGDPR€5,000
21 Sept 2022Curtea Veche Publishing SRLCurtea Veche Publishing SRL was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
21 Sept 2022GUUDJOB WORLDWIDE S.L.GUUDJOB WORLDWIDE S.L. failed to delete personal data after a data subject request, breaching GDPR Articles 12 and 17. The AEPD imposed a fine of EUR 1,000, reduced to EUR 800 for early payment.ESAEPDGDPR€1,000
21 Sept 2022LISMARTSA, S.L.LISMARTSA, S.L. was fined EUR 1,200 by the AEPD for sending emails to multiple recipients without using BCC. This exposed personal email addresses and breached data protection and security requirements.ESAEPDGDPR€1,200
22 Sept 2022Bitfactor SRLBitfactor SRL was fined EUR 2,000 by ANSPDCP after a data security incident caused by a malfunctioning application. The application sent marketing communications, resulting in a breach of personal data confidentiality affecting 1,757 users.ROANSPDCPGDPR€2,000
22 Sept 2022Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police.GRHDPAGDPR€3,000
26 Sept 2022FONTANORTE, S.L.FONTANORTE, S.L. was fined 2,000 EUR by the AEPD for breaching Article 32 GDPR. The company improperly disposed of documents containing personal data in public waste containers, making them accessible to third parties.ESAEPDGDPR€2,000
26 Sept 2022B.B.B.B.B.B. was fined EUR 300 by the AEPD for failing to provide adequate information about a video surveillance system. The camera captured a public area without proper notice to affected individuals, breaching Article 13 GDPR.ESAEPDGDPR€300