Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Dec 2022Scuola Statale Secondaria di I^ grado “Bianco-Pascoli”, di Fasano (BR)The school was fined by the Garante 3,000 EUR for violations in the processing of personal data, including minors' health information. The authority found that the processing lacked a proper legal basis and sufficient transparency.ITGaranteGDPR€3,000
15 Dec 2022BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects.ESAEPDGDPR€2,500
15 Dec 2022B.B.B.The entity was fined for operating surveillance cameras directed at public areas without the required authorization or signage. The authority found this to be a breach of data protection rules.ESAEPDGDPR€3,000
15 Dec 2022Comune di VicchioComune di Vicchio was fined by the Garante 8,000 EUR for using fingerprints to monitor employee attendance without appropriate legal basis and safeguards. The authority found that the biometric processing breached GDPR requirements.ITGaranteGDPR€8,000
15 Dec 2022Comune di BorgiaComune di Borgia was fined by the Garante 5,000 EUR for processing employees’ biometric data for attendance tracking without appropriate legislative measures and specific safeguards. The authority found this to be a breach of GDPR rules on special-category data.ITGaranteGDPR€5,000
15 Dec 2022Eurosanità S.P.A.Eurosanità S.P.A. was fined by the Garante in the amount of 30,000 EUR for violations related to the processing of health data. The authority cited inadequate personal data protection measures.ITGaranteGDPR€30,000
16 Dec 2022INTER PARTNER ASSISTANCE SERVICIOS ESPAÑA, S.A.INTER PARTNER ASSISTANCE SERVICIOS ESPAÑA, S.A. was fined by the AEPD 30,000 EUR for potentially transferring personal data internationally without proper disclosure. This was contrary to the company’s stated privacy policies.ESAEPDGDPR€30,000
16 Dec 2022NORDETIA CLINICS IBERIA, S.L.NORDETIA CLINICS IBERIA, S.L. was fined 3,000 EUR by the AEPD. The authority found that the company obstructed an inspection by failing to provide access required under Article 58(1) GDPR.ESAEPDGDPR€3,000
19 Dec 2022SOCIETE DE VENTE DE SYSTEMES D’EXPLOITATION, DE LOGICIELS APPLICATIFS, DE MATERIELS ET DE SERVICES DERIVESThe CNIL imposed a EUR 60 million fine on SOCIETE DE VENTE DE SYSTEMES D’EXPLOITATION, DE LOGICIELS APPLICATIFS, DE MATERIELS ET DE SERVICES DERIVES and issued an injunction subject to a penalty payment. The case concerned identified compliance breaches requiring corrective action and enforcement measures.FRCNILGDPR€60,000,000
20 Dec 2022Webáruház adatkezelése és törlési jog sérelmeThe authority found breaches of several GDPR provisions concerning information to data subjects, obtaining consent for marketing, and handling deletion requests. A fine of HUF 500,000 was imposed.HUNAIHGDPR€1,240
20 Dec 2022HAYS PERSONNEL SERVICE ESPAÑA, S.A.HAYS PERSONNEL SERVICE ESPAÑA, S.A. was fined by the AEPD 5,000 EUR for sending marketing emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for such communications.ESAEPDePrivacy€5,000
20 Dec 2022Tájékoztatás ügyfélszolgálati telefonhívások rögzítésérőlThe entity did not provide adequate prior information about the recording of customer service phone calls. The authority found this to be a breach of GDPR Articles 12 and 13.HUNAIHGDPR€12,400
20 Dec 2022Autoritatea Națională pentru Restituirea Proprietăților (ANRP)The National Authority for Property Restitution (ANRP) was fined 13,000 RON by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,646
20 Dec 2022Virtue Integrated Elder Care LtdThe Irish DPC imposed a fine of EUR 100,000 on Virtue Integrated Elder Care Ltd in inquiry IN-21-2-5. The penalty has been collected.IEDPCGDPR€100,000
21 Dec 2022Politie NederlandThe Dutch Data Protection Authority fined the police chief for failing to carry out a data protection impact assessment before using mobile camera cars in Rotterdam. The measure created a high risk to individuals' rights and freedoms.NLAPGDPR€50,000
21 Dec 2022Szálláshelyen kamerás megfigyelőrendszer üzemeltetéseThe authority found that the controller unlawfully processed personal data through a camera system, breaching several GDPR provisions. The decision highlighted improper data storage and a lack of transparent information provided to data subjects.HUNAIHGDPR€7,440
22 Dec 2022SUDREZIDENȚIAL Broker S.R.L.The company was fined for failing to inform data subjects about a personal data breach. The authority found a violation of Article 34 of the GDPR.ROANSPDCPGDPR€10,000
24 Dec 2022EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.The entity was fined by the AEPD for breaching data protection rules. Its surveillance cameras were positioned to capture public areas without proper legal authorization.ESAEPDGDPR€500
27 Dec 2022Kaufland România SCSKaufland România SCS was fined by ANSPDCP EUR 3,000 for GDPR violations. The investigation was completed in November 2022.ROANSPDCPGDPR€3,000
29 Dec 2022Dane anonimowe (S. Sp. z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 36,558 on the company. The sanction concerned failure to cooperate with the authority and failure to provide information necessary for the performance of its tasks.PLUODOGDPR€7,802