Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Feb 2023TRACTAMENT D'AIGUES TEIA, S.L.TRACTAMENT D'AIGUES TEIA, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a data subject's request to delete personal data. The case indicates non-compliance with GDPR obligations regarding the exercise of individual rights.ESAEPDGDPR€1,000
02 Feb 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for changing a customer's contract ownership and activating services without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
03 Feb 2023Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls.CYCyDPCGDPR€3,250
06 Feb 2023VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 200,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for breaching Article 6(1) GDPR. The case involved unauthorized SIM card duplication that enabled fraudulent bank charges.ESAEPDGDPR€200,000
06 Feb 2023ONEY SERVICIOS FINANCIEROS E.F.C., S.A.ONEY SERVICIOS FINANCIEROS E.F.C., S.A. was fined by the AEPD 50,000 EUR for inaccurately processing personal data. The company included incorrect debt information in credit information systems, breaching data protection principles.ESAEPDGDPR€50,000
06 Feb 2023I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes.HUNAIHGDPR€76,800
06 Feb 2023ROMBOC COMUNICACIONESROMBOC COMUNICACIONES was fined by the AEPD in the amount of 2,000 EUR for making misleading advertising calls without explicit consent from recipients. The case indicates a breach of data protection and direct marketing rules.ESAEPDGDPR€2,000
07 Feb 2023Dane anonimowe (Wspólnotę Mieszkaniową „)UODO imposed an administrative fine on a housing community for entrusting personal data processing to an external provider without a written agreement and without verifying adequate technical and organizational safeguards. The authority also cited the failure to notify affected individuals without undue delay about the personal data breach.PLUODOGDPR€327
08 Feb 2023SatsThe Norwegian DPA, Datatilsynet, fined Sats 10,000,000 NOK for breaches of GDPR requirements. The case concerned data subjects' rights to information, access, and erasure, as well as the lack of a legal basis for processing certain personal data.NODatatilsynetGDPR€906,000
08 Feb 2023Medijobs Platform SRLMedijobs Platform SRL was fined EUR 5,000 by ANSPDCP after unauthorized access to its IT infrastructure. The incident led to the downloading and deletion of certain personal data.ROANSPDCPGDPR€5,000
08 Feb 2023COMMUNE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on COMMUNE under a simplified procedure and issued an injunction. The case concerned a confirmed breach requiring corrective action.FRCNILGDPR€5,000
08 Feb 2023DKN.5131.50.2021StatusprawomocnaTytuUODO imposed a PLN 33,012 fine on the controller and the processor for failing to implement appropriate technical and organizational measures to secure personal data. The authority also found that the controller did not verify whether the processor provided sufficient guarantees of GDPR compliance and protection of data subjects' rights.PLUODOGDPR€6,967
08 Feb 2023SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE (procédure simplifiée)CNIL imposed a fine of 10,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
08 Feb 2023VODAFONE SERVICIOS, S.L.U.VODAFONE SERVICIOS, S.L.U. was fined by the AEPD 70,000 EUR for a SIM card duplication incident. The incident resulted in identity theft and unauthorized access to a bank account, indicating a breach of data protection rules.ESAEPDGDPR€70,000
08 Feb 2023MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on MEDECIN GENERALISTE under a simplified procedure. The authority also issued an injunction to remedy the identified deficiencies.FRCNILGDPR€3,000
09 Feb 2023Anonymizováno (ÚOOÚ UOOU-04020/22-13)The entity was fined for repeatedly sending unsolicited commercial communications by electronic means without recipients' consent. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€1,688
10 Feb 2023SIA "SOAAR"SIA "SOAAR" was fined EUR 800 by the DVI. The decision entered into force on 10.02.2023.LVDVIGDPR€800
13 Feb 2023B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 2,000 for breaching Article 6 of the GDPR. The case concerned the unauthorized dissemination of a video on social media platforms, including Twitter.ESAEPDGDPR€2,000
13 Feb 2023FUNDACIÓN PRIVADA UNIVERSITARIA EADAThe entity used a participant’s image in a promotional activity without obtaining consent. This constituted a breach of data protection rules and resulted in a fine imposed by the AEPD.ESAEPDGDPR€2,000
14 Feb 2023MENZIES AVIATION SPAIN S.L.MENZIES AVIATION SPAIN S.L. was fined by the AEPD 2,000 EUR for sending emails to multiple recipients without using BCC. This exposed employees’ personal data to other recipients.ESAEPDGDPR€2,000