Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 May 2021Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data.ITGaranteGDPR€100,000
13 May 2021Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity.ITGaranteGDPR€20,000
13 May 2021ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection.ITGaranteGDPR€20,000
13 May 2021Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register.ITGaranteGDPR€2,856,000
13 May 2021Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects.ITGaranteGDPR€80,000
12 May 2021A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications.GRHDPAGDPR€5,000
12 May 2021Anonymisé (CNPD decision-17-fr-2021)The CNPD found that the company breached GDPR principles by failing to comply with data minimization and retention limits in its video surveillance practices. A fine of EUR 1,900 was imposed.LUCNPDGDPR€1,900
12 May 2021Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved.NLAPGDPR€525,000
12 May 2021xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure.HRAZOPGDPR€30,553
12 May 2021E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use.ESAEPDGDPR€3,100,000
12 May 2021Anonymisé (CNPD decision-14-fr-2021)The company was fined by the CNPD in the amount of 2,600 EUR for breaching GDPR requirements on data minimization, data retention, and information obligations. The case concerned non-compliant personal data processing and a failure to provide the required information to data subjects.LUCNPDGDPR€2,600
12 May 2021KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued.GRHDPAGDPR€5,000
12 May 2021Anonymisé (CNPD decision-16-fr-2021)The company was fined for failing to comply with the data minimization principle and for not providing adequate information to data subjects under GDPR Articles 5(1)(c) and 13. The CNPD decision indicates deficiencies in the company’s processing practices and privacy disclosures.LUCNPDGDPR€1,000
12 May 2021Anonymisé (CNPD decision-15-fr-2021)The CNPD imposed a EUR 2,900 fine for breaching the data minimization principle in connection with video surveillance. The camera’s field of view covered areas that were not necessary for the processing purpose, contrary to Article 5(1)(c) GDPR.LUCNPDGDPR€2,900
11 May 2021Érintetti jog és tájékoztatási kötelezettség megsértéseThe case concerned unlawful processing of personal data in connection with debt collection. The entity failed to respond to data subject requests and unlawfully transferred personal data.HUNAIHGDPR€1,395
11 May 2021Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident.NLAPGDPR€7,500
11 May 2021Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days.NODatatilsynetGDPR€124,000
10 May 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for processing personal data without proper consent, in breach of Article 6(1) GDPR. The penalty was set at EUR 70,000, with reductions available for early payment and acknowledgment of responsibility.ESAEPDGDPR€70,000
07 May 2021B.B.B.The entity was fined for improperly directing surveillance cameras toward public transit areas and the complainant's home entrance. This conduct breached data protection rules.ESAEPDGDPR€1,500
06 May 2021Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA.NODatatilsynetGDPR€497,000