Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Jan 2023ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal and banking data without consent. The conduct occurred in connection with a contract renewal offer presented as if it came from the complainant's electricity supplier.ESAEPDGDPR€10,000
19 Jan 2023A startup football clubThe Belgian data protection authority, GBA, imposed an EUR 8,000 fine on a startup football club. The case involved failure to respond to a data subject access request, as well as additional GDPR breaches concerning transparency and processor-contract requirements.BEGegevensbeschermingsautoriteit (GBA)GDPR€8,000
20 Jan 2023DELSA ALQUILERES, S.L.DELSA ALQUILERES, S.L. installed a surveillance camera covering common areas without a valid legal basis and without adequate informational signage. The AEPD found this to breach GDPR Articles 6 and 13.ESAEPDGDPR€1,000
20 Jan 2023Egészségi állapotra vonatkozó dokumentumok kiadásának megtagadásaThe controller did not comply with the data subject's access request and failed to provide adequate information about data processing. The conduct breached several GDPR provisions, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,530
23 Jan 2023SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a EUR 5,000 fine on SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The authority also issued an injunction to remedy the identified non-compliance.FRCNILGDPR€5,000
23 Jan 2023FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined EUR 5,000 by the AEPD for failing to provide a cookie notice on its website. The authority also found that non-essential cookies were used without prior user consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
23 Jan 2023ENFOKA SISTEMAS GLOBALES, S.L.ENFOKA SISTEMAS GLOBALES, S.L. was fined by the AEPD 30,000 EUR for processing personal data without consent. The company signed an energy supply contract in the complainant's name without their knowledge, which breaches Article 6(1) of the GDPR.ESAEPDGDPR€30,000
25 Jan 2023FUNDACIÓN GOODJOBFUNDACIÓN GOODJOB was fined EUR 2,000 by the AEPD. The authority found that the organization collected unnecessary health data related to disability without a proper legal basis, breaching data minimization principles.ESAEPDGDPR€2,000
25 Jan 2023Dane anonimowe (E. Spółka z o.o. z siedzibą we W. przy ul.)The President of UODO imposed a fine of 22,848 PLN on E. Spółka z o.o. The penalty was issued for failing to comply with an order contained in an earlier decision by the President of UODO.PLUODOGDPR€4,845
25 Jan 2023Dane anonimowe (S. Sp. z o.o. z siedzibą w R. przy ul.)The President of UODO imposed an administrative fine of PLN 18,279 on the company. The sanction was issued for failing to cooperate with the authority and for not providing information necessary for the performance of its duties.PLUODOGDPR€3,876
26 Jan 2023SIA “Business magazine”A fine of 1,900 EUR was imposed on SIA “Business magazine” by the DVI. The decision became final on 2023-01-26.LVDVIGDPR€1,900
26 Jan 2023Политическа партия ******The political party unlawfully processed personal data by including individuals in a list supporting its election registration without their consent. The authority found breaches of GDPR Articles 5, 6, and 24.BGCPDPGDPR€7,823
30 Jan 2023COMUNIDAD DE PROPIETARIOS RÍO CANARIOThe entity did not provide the requested information to the Spanish Data Protection Agency (AEPD). The conduct breached Article 58(1) of the GDPR and resulted in a 500 EUR fine.ESAEPDGDPR€500
30 Jan 2023BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD in the amount of 1,000 EUR for not adequately handling a data subject access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€1,000
31 Jan 2023Dent Estet Clinic SADent Estet Clinic SA was fined by ANSPDCP EUR 1,000 for breaches of the transparency obligations under GDPR Articles 12–14. The case concerned inadequate compliance with information duties toward data subjects.ROANSPDCPGDPR€1,000
31 Jan 2023Dent Estet Clinic SADent Estet Clinic SA was fined EUR 1,000 by ANSPDCP for failing to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. The incident involved unauthorized disclosure of health data, which required prompt reporting under GDPR rules.ROANSPDCPGDPR€1,000
31 Jan 2023PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules.ESAEPDGDPR€3,000
01 Feb 2023Tensa Art Design SAANSPDCP completed an investigation in January 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined EUR 1,000.ROANSPDCPGDPR€1,000
02 Feb 2023LEADDESK, S.L.LEADDESK, S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information to the authority, which constitutes a breach of Article 58.1 of the GDPR.ESAEPDGDPR€500
02 Feb 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without the complainant's consent. The incident led to attempts to gain unauthorized access to the complainant's bank accounts.ESAEPDGDPR€70,000