Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Feb 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for processing personal data without consent. The case concerned a mobile line contracted in the complainant’s name without proper identity verification.ESAEPDGDPR€70,000
28 Feb 2023PELAYO MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJAPelayo Mutua de Seguros y Reaseguros A Prima Fija was fined 70,000 EUR by the AEPD. The authority found that the company disclosed personal data to a third party without consent, breaching GDPR confidentiality and security obligations.ESAEPDGDPR€70,000
01 Mar 2023Spółdzielnie Mieszkaniową „UODO imposed an administrative fine of PLN 51,876 on the controller for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected data subject was not informed about the breach.PLUODOGDPR€11,098
01 Mar 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial communications by text messages and phone calls. The conduct continued despite the recipient’s request to stop contacting them and not to share their phone number for commercial purposes.ESAEPDGDPR€20,000
01 Mar 2023ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing.ESAEPDGDPR€3,000
02 Mar 2023H&M Hennes & Mauritz s.r.l.H&M Hennes & Mauritz s.r.l. was fined EUR 50,000 by the Garante for violations related to installing surveillance systems without the required authorization. Employees were informed about the systems, but this did not cure the underlying compliance breach.ITGaranteGDPR€50,000
02 Mar 2023Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality.ITGaranteGDPR€50,000
02 Mar 2023WILLOUGHBY COLLEGE, S.A.WILLOUGHBY COLLEGE, S.A. failed to provide requested information to the Spanish Data Protection Agency, which constituted a breach of Article 58.1 of the GDPR. A fine was imposed and reduced due to early payment and acknowledgment of responsibility.ESAEPDGDPR€1,500
02 Mar 2023Il Fatto Quotidiano S.p.A.The Garante fined Il Fatto Quotidiano S.p.A. EUR 20,000 for the unlawful dissemination of personal data linked to a judicial case involving the complainants' father. The authority found that the publication breached personal data protection rules.ITGaranteGDPR€20,000
02 Mar 2023Razmataz Live S.r.l.Razmataz Live S.r.l. was fined by the Garante 1,000 EUR for failing to take measures to mitigate or eliminate the consequences of a data protection breach linked to promotional activities. The authority also noted that informed consent for commercial communications was not ensured.ITGaranteGDPR€1,000
02 Mar 2023Flowers R di Malalan MitjaMalalan Mitja was fined by the Garante in the amount of 5,000 EUR for sending unsolicited promotional emails. The messages were sent to randomly generated email addresses, which constituted a breach of GDPR requirements.ITGaranteGDPR€5,000
03 Mar 2023SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE (procédure simplifiée)The CNIL imposed a EUR 15,000 fine on SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE under a simplified procedure. The case concerns a breach of personal data protection rules.FRCNILGDPR€15,000
06 Mar 2023B.B.B.The entity was fined by the AEPD €5,000 for publishing radio amateurs’ personal data on a Telegram channel. The breach involved linking call signs to personal information, which violated data protection rules.ESAEPDGDPR€5,000
06 Mar 2023Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€3,000
06 Mar 2023Finopro IFN SAFinopro IFN SA was fined by ANSPDCP EUR 2,250 for a data security breach caused by a ransomware attack. The incident led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€2,250
07 Mar 2023SIA "Euronics Latvia"The DVI imposed a fine of EUR 20,000 on SIA "Euronics Latvia". The decision entered into force on 7 March 2023.LVDVIGDPR€20,000
08 Mar 2023RING RING CLIN S.L.RING RING CLIN S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR.ESAEPDGDPR€500
08 Mar 2023ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)The organization published a court ruling on its blog without anonymizing the personal data of the individuals involved. The AEPD found a breach of the data minimization principle and imposed a 500 EUR fine.ESAEPDGDPR€500
09 Mar 2023EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€10,000
09 Mar 2023B.B.B.A camera was installed in a community garage without prior authorization and without proper signage. The AEPD found this to be a breach of Article 13 GDPR and imposed a EUR 300 fine.ESAEPDGDPR€300