Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jan 2023KENAI MEDIA, S.L.KENAI MEDIA, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case concerned the publication of a video featuring the complainant without proper consent.ESAEPDGDPR€10,000
11 Jan 2023Società Europea di Edizioni S.p.a.The Garante fined Società Europea di Edizioni S.p.a. EUR 10,000 for publishing non-anonymized personal data concerning an individual's health status in an article. This constituted a breach of data protection rules.ITGaranteGDPR€10,000
11 Jan 2023Reweb s.r.l.Reweb s.r.l. was fined 5,000 EUR by the Garante. The company kept a former employee’s email account active and accessed it after the employment relationship ended, in breach of GDPR requirements.ITGaranteGDPR€5,000
12 Jan 2023ORANGEORANGE was fined EUR 1,000,000 by the AEPD for breaching data protection principles. The authority found failures to implement privacy by design and privacy by default in connection with SIM swapping incidents.ESAEPDGDPR€1,000,000
12 Jan 2023WhatsApp Ireland Ltd.The Irish DPC fined WhatsApp Ireland Ltd. EUR 5,500,000 in case IN-18-5-6. The decision is currently under appeal.IEDPCGDPR€5,500,000
12 Jan 2023ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD EUR 5,000 for including personal data in a credit file without prior notice. The company also failed to respond to access requests, which constitutes a breach of GDPR Article 15.ESAEPDGDPR€5,000
12 Jan 2023BRISTOL LOGISTICS SABRISTOL LOGISTICS SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€2,000
13 Jan 2023Intellexa A.E.Intellexa A.E. was fined EUR 50,000 by the HDPA. The authority found that the company failed to cooperate with the supervisory authority as required under Article 31 of the GDPR.GRHDPAGDPR€50,000
13 Jan 2023CORREDURÍA DE SEGUROS DE MADRID, S.L.CORREDURÍA DE SEGUROS DE MADRID, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company linked the complainant’s bank account to insurance policies they had not taken out, resulting in unauthorized charges.ESAEPDGDPR€10,000
13 Jan 2023Követelésérvényesítési célú adatkezelés és ahhoz kapcsolódó érdekmérlegelés, továbbá adattovábbítások jogszerűségének kérdéseThe authority found unlawful data processing related to credit account management and debt collection. A fine was imposed on the controller for breaching GDPR requirements.HUNAIHGDPR€2,520
16 Jan 2023Kildare County CouncilThe Irish DPC imposed a fine of EUR 50,000 on Kildare County Council in inquiry 05/SIU/2018. The fine has been collected.IEDPCGDPR€50,000
16 Jan 2023Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€10,000
17 Jan 2023B.B.B.The entity installed surveillance cameras in the common areas of a residential community without proper authorization or the required informational signage. AEPD found a breach of GDPR Articles 6 and 13 and imposed a EUR 1,500 fine.ESAEPDGDPR€1,500
17 Jan 2023Fusiona Soluciones Energéticas, S.A.Fusiona Soluciones Energéticas, S.A. was fined by the AEPD for unlawfully processing personal data. The company included an individual's data in a credit information system without a lawful basis.ESAEPDGDPR€50,000
17 Jan 2023ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without valid consent. The case concerned a contract entered into in the name of a deceased person without authorization.ESAEPDGDPR€70,000
17 Jan 2023Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR.SEIMYGDPRkr 200,000
18 Jan 2023Dante Internațional SAIn December 2022, ANSPDCP completed an investigation into Dante Internațional SA and found violations of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.ROANSPDCPGDPR€1,000
18 Jan 2023CONSEJERÍA DE CULTURA DE LA RIOJACONSEJERÍA DE CULTURA DE LA RIOJA was fined for failing to implement corrective measures after the unauthorized recording and dissemination of surveillance footage from the Museo de La Rioja. The authority found a breach of Article 32 GDPR concerning appropriate security measures.ESAEPDGDPR€3,000
19 Jan 2023Sąd Rejonowy Szczecin-Centrum z siedzibą w Szczecinie przy ul.The UODO imposed an administrative fine of PLN 30,000 on the Szczecin-Centrum District Court. The authority found that appropriate technical and organizational measures were not implemented to match the risk of processing data using portable storage devices.PLUODOGDPR€6,374
19 Jan 2023TRC TRUCKS 2020, S.L.TRC TRUCKS 2020, S.L. was fined EUR 1,000 by the AEPD for failing to respond to a data subject’s request for erasure. The case concerns non-compliance with GDPR obligations relating to the exercise of data subject rights.ESAEPDGDPR€1,000