Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Nov 2022GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity was fined for sending unsolicited commercial emails despite the recipient's explicit objection. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
15 Nov 2022Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000.HUNAIHGDPR€4,940
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 3,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and the handling of security events.ROANSPDCPGDPR€3,000
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 5,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and required remedial action by the bank.ROANSPDCPGDPR€5,000
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined by ANSPDCP EUR 20,000 for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and security requirements. The decision highlights the need for effective technical and organizational controls.ROANSPDCPGDPR€20,000
17 Nov 2022NUEVAS TECNOLOGIAS MEDITERRANEO, S.L.NUEVAS TECNOLOGIAS MEDITERRANEO, S.L. was fined by the AEPD EUR 800 for sending unsolicited advertising emails without prior consent. The case concerned a breach of Article 21 of the LSSI and unlawful direct marketing.ESAEPDePrivacy€800
18 Nov 2022Asociația de Proprietari Bld. Pipera 1-2EThe association was fined for failing to provide requested information within the legal deadline. The case concerns a breach of the duty to cooperate with the supervisory authority.ROANSPDCPGDPR€300
21 Nov 2022ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller.ROANSPDCPGDPR€20,000
23 Nov 2022Linee Stampalibera Società Cooperativa S.r.l.Linee Stampalibera Società Cooperativa S.r.l. was fined 1,000 EUR by the Garante for publishing personal data on its website without consent. The case also involved the full text of a property purchase contract, which breached data protection rules.ITGaranteGDPR€1,000
24 Nov 2022Azienda per la tutela della salute - ATS SardegnaATS Sardegna was fined by the Garante for breaching data protection principles in its handling of personal data relating to an employee's vaccination status. The authority found violations of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
24 Nov 2022Dello Russo Giulio ditta individualeThe company was fined for using a biometric fingerprint system to record employee attendance without a valid legal basis. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€1,000
24 Nov 2022Società Lombarda Sport s.r.l.Società Lombarda Sport s.r.l. was fined by the Garante 4,000 EUR for processing personal data without an adequate legal basis. The authority also found failures to ensure data integrity and confidentiality in connection with the issuance of medical certificates for non-competitive sports activities.ITGaranteGDPR€4,000
24 Nov 2022STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€1,000
24 Nov 2022SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICESCNIL imposed a fine of 600,000 EUR on SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICES. The available record indicates an administrative penalty issued by the French data protection authority.FRCNILGDPR€600,000
24 Nov 2022D. B.B.B.The entity was fined EUR 300 by the AEPD for installing surveillance cameras on a building facade facing public areas without prior administrative authorization. The authority found this to be a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€300
24 Nov 2022CARROZADOS TECAI, S.L.CARROZADOS TECAI, S.L. was fined by the AEPD EUR 300 for installing a surveillance camera that could capture public areas without proper authorization. The authority also found inadequate informational signage for affected individuals, in breach of Article 13 GDPR.ESAEPDGDPR€300
24 Nov 2022Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure.ITGaranteGDPR€1,000,000
24 Nov 2022dott.ssa Emilia ColosimoThe Garante imposed a EUR 1,000 fine on dott.ssa Emilia Colosimo for breaches of the principles of lawful, fair and transparent processing of personal data, data minimization, and data security. The authority also cited insufficient safeguards against unauthorized or unlawful processing.ITGaranteGDPR€1,000
24 Nov 2022Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data.ROANSPDCPGDPR€1,000
24 Nov 2022Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di CagliariOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari was fined €3,000 by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data related to an individual's employment.ITGaranteGDPR€3,000