Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Nov 2022Meta DatasetThe Irish DPC fined Meta Dataset EUR 265,000,000 in inquiry IN-21-4-2. The matter is currently pending appeal.IEDPCGDPR€265,000,000
25 Nov 2022OTP LEASING ROMANIA IFN SAOTP LEASING ROMANIA IFN SA was fined by ANSPDCP for breaching data security provisions. The penalty followed a data breach notification indicating that personal data had not been adequately protected.ROANSPDCPGDPR€3,000
28 Nov 2022GAVANOVA DE IMMOBLES, S.L.GAVANOVA DE IMMOBLES, S.L. was fined by the AEPD 2,000 EUR for failing to provide an adequate privacy policy on its website. The authority also found that personal data was shared with a cleaning company without the data subjects’ consent.ESAEPDGDPR€2,000
29 Nov 2022B.B.B.The entity was fined by the AEPD EUR 300 for installing surveillance cameras that recorded images and sound in public and communal areas without the required authorization. This constituted a breach of data protection rules.ESAEPDGDPR€300
29 Nov 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for failing to comply with a data subject access request. The case concerned the company’s failure to provide a requested recording of a contract concluded by telephone.ESAEPDGDPR€70,000
30 Nov 2022CBHNOS S.L.CBHNOS S.L. was fined 500 EUR by the AEPD for installing a video surveillance system that could capture images of public areas. The authority considered this a breach of data protection rules.ESAEPDGDPR€500
30 Nov 2022SIA "W&G"A fine of EUR 500 was imposed on SIA "W&G" by the DVI. The decision is final and has entered into force.LVDVIGDPR€500
30 Nov 2022INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD 1,000 EUR for failing to comply with data protection authority resolutions. The breach concerned the obligation to inform data subjects under Article 13 of the GDPR.ESAEPDGDPR€1,000
30 Nov 2022Dane anonimowe (N. B. oraz T. M., wspólników spółki cywilnej Kancelaria)UODO imposed an administrative fine on N. B. and T. M., partners in the civil-law partnership Kancelaria. The authority found that they processed personal data of clients and prospective clients without a legal basis.PLUODOGDPR€9,799
30 Nov 2022OPERATEUR DE TELECOMMUNICATION FIXECNIL imposed a fine of EUR 300,000 on OPERATEUR DE TELECOMMUNICATION FIXE and issued an injunction subject to penalty payments. The case concerns a compliance breach in the area of data protection.FRCNILGDPR€300,000
01 Dec 2022Regione CampaniaRegione Campania was fined by the Garante in the amount of EUR 10,000 for unauthorized access to personal data. The case concerned breaches of GDPR requirements on data protection and security measures.ITGaranteGDPR€10,000
01 Dec 2022Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules.ITGaranteGDPR€8,000
01 Dec 2022Regione LazioThe Garante fined Regione Lazio EUR 100,000 for unlawfully collecting metadata from employees' emails without a proper legal basis. The authority found that the processing did not meet the legal requirements for monitoring employee communications.ITGaranteGDPR€100,000
01 Dec 2022A.R.N.A.S. CivicoA.R.N.A.S. Civico was fined EUR 6,000 by the Italian authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€6,000
01 Dec 2022WoolenWoolen was fined EUR 3,000 by the Garante for a video surveillance system that did not meet transparency requirements. The authority cited a breach of GDPR Article 13 and Article 114 of the Italian Privacy Code.ITGaranteGDPR€3,000
01 Dec 2022Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€20,000
02 Dec 2022IK "Rigas Komunal Service"A fine of 500 EUR was imposed by the DVI. The decision was appealed.LVDVIGDPR€500
08 Dec 2022Danske Shoppingcentre P/SDanske Shoppingcentre P/S was fined by Datatilsynet for unlawful CCTV surveillance of a toilet area in City2. The authority found a breach of the GDPR data minimization principle.DKDatatilsynetGDPR€47,054
09 Dec 2022Casa Rusu S.R.L.The company was fined for a data security breach on its online payment section. An unauthorized form was introduced there and collected customers’ card data.ROANSPDCPGDPR€2,000
13 Dec 2022Anonymisé (CNPD decision-23-fr-2022)The company failed to meet the transparency obligations under Article 12(1) GDPR by not providing the required information in a concise, transparent, and easily accessible manner. CNPD treated this as a breach of the information duties owed to data subjects.LUCNPDGDPR€1,300