Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Mar 2023INTERURBANA DE AUTOBUSES, S.A.INTERURBANA DE AUTOBUSES, S.A. was fined by the AEPD 70,000 EUR for publishing employees’ personal data without consent. The breach involved exposing unnecessary information on notice boards accessible to others, contrary to data minimization requirements.ESAEPDGDPR€70,000
09 Mar 2023Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12.ITGaranteGDPR€10,000
09 Mar 2023B.B.B.B.B.B. was fined by the AEPD EUR 600 for failing to implement corrective measures regarding improperly oriented surveillance cameras. The authority also found a failure to provide the required information under the GDPR.ESAEPDGDPR€600
09 Mar 2023Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data.ITGaranteGDPR€3,000
09 Mar 2023Stefano MolenaThe Garante imposed a EUR 3,000 fine on Stefano Molena for operating a surveillance camera without the required informational signage. The breach concerned privacy rules and the duty to properly inform individuals subject to monitoring.ITGaranteGDPR€3,000
09 Mar 2023Deca s.r.l.Deca s.r.l. was fined EUR 1,600 by the Garante. The authority found that the company failed to respond to requests for access to personal data relating to work attendance and unlawfully processed data through an incomplete video surveillance system.ITGaranteGDPR€1,600
09 Mar 2023Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data.ITGaranteGDPR€2,000
10 Mar 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security.ESAEPDGDPR€200,000
13 Mar 2023JUNTA MAYOR DE COFRADÍAS Y HERMANDADES DE LA SEMANA SANTA DE ELCHEThe organization did not inform participants about the processing of their personal data during the “Gymkhana Cofrade” event, which constitutes a breach of Article 13 GDPR. The AEPD imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
13 Mar 2023Modaone SRLModaone SRL was fined by ANSPDCP EUR 2,000 for sending commercial emails to a data subject after the person had objected. The authority found a breach of the GDPR right to object.ROANSPDCPGDPR€2,000
14 Mar 2023Tinmar Energy SATinmar Energy SA was fined EUR 3,000 by ANSPDCP after unauthorized access to its email server. The incident resulted in a personal data breach.ROANSPDCPGDPR€3,000
14 Mar 2023DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined 2,000 EUR by the AEPD for failing to remove an ex-employee’s image from its YouTube channel despite repeated requests. The authority found a breach of GDPR Article 6(1) regarding the lawful basis for processing personal data.ESAEPDGDPR€2,000
14 Mar 2023Dane anonimowe (Prokuraturę Rejonową w G. z siedzibą w G. przy ul.)UODO imposed an administrative fine of PLN 20,000 on the District Prosecutor's Office in G. The authority found that the entity failed to notify the supervisory authority of a personal data breach without undue delay and did not inform the affected individuals without undue delay.PLUODOGDPR€4,266
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
15 Mar 2023Partidul Uniunea Salvați RomâniaThe fine was imposed for a data security breach involving the loss of confidentiality and integrity of data stored on a server. The incident resulted from a phishing attack that compromised the system.ROANSPDCPGDPR€4,000
15 Mar 2023Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements.ROANSPDCPGDPR€10,000
16 Mar 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts.ESAEPDGDPR€200,000
16 Mar 2023Argon Medical DevicesArgon Medical Devices was fined NOK 2.5 million by the Norwegian Data Protection Authority, Datatilsynet. The company failed to report a personal data breach involving European employees within the 72-hour deadline required by GDPR Article 33.NODatatilsynetGDPR€218,000
16 Mar 2023PRODALVIN, S.L.PRODALVIN, S.L. was fined by the AEPD in the amount of 500 EUR for failing to properly inform individuals about the data controller and the address for exercising data subject rights in its video surveillance system. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€500
16 Mar 2023Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for unauthorized disclosure and access to personal data. The case concerned data confidentiality and breaches of GDPR obligations.ROANSPDCPGDPR€1,000