Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Nov 2022Doctolib SrlDoctolib Srl was fined EUR 40,000 by the Italian Garante for violations linked to insufficient transparency in the online information provided to patients. The case concerned, in particular, how consent for processing health data was obtained.ITGaranteGDPR€40,000
01 Jan 2023D. ***NIF.1The entity operating https://www.dmerka.com was fined EUR 600 by the AEPD. The authority found that the controller was not identified and that required information on personal data processing was not provided, in breach of Article 13 GDPR.ESAEPDGDPR€600
01 Jan 2021Dña. B.B.B.The entity was fined for publishing personal images and contact numbers on a dating website without proper consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€2,000
24 Apr 2024Dly S.r.l.Dly S.r.l. was fined by the Garante EUR 5,000 for deploying a non-compliant video surveillance system. The system recorded both customers and employees, in breach of data protection rules.ITGaranteGDPR€5,000
05 Jan 2021DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach.PLUODOGDPR€5,498
09 Dec 2020DKN.5131.5.2020StatusprawomocnaTytuA monetary penalty was imposed for failing to report a personal data breach to the President of UODO and for failing to notify the affected individuals. The case concerns non-compliance with breach notification obligations after a data security incident.PLUODOGDPR€19,344
31 May 2022DKN.5131.51.2021StatusuchylonaTytuUODO imposed an administrative fine of PLN 10,000 for a breach involving the recording and storage of sound in a monitoring system. The case concerned improper use of CCTV monitoring with audio capture.PLUODOGDPR€2,183
08 Feb 2023DKN.5131.50.2021StatusprawomocnaTytuUODO imposed a PLN 33,012 fine on the controller and the processor for failing to implement appropriate technical and organizational measures to secure personal data. The authority also found that the controller did not verify whether the processor provided sufficient guarantees of GDPR compliance and protection of data subjects' rights.PLUODOGDPR€6,967
21 Jun 2021DKN.5131.3.2021StatusprawomocnaTytuUODO imposed an administrative fine of PLN 159,176 on an insurance company. The authority found that the company failed to notify the President of UODO of a personal data breach within the required timeframe.PLUODOGDPR€35,116
12 Mar 2024DKN.5131.28.2023StatusprawomocnaTytuUODO imposed an administrative fine of PLN 78,575.4 for failing to report a personal data breach without undue delay. The incident was not notified to the supervisory authority within 72 hours of becoming aware of the breach.PLUODOGDPR€18,331
03 Nov 2022DKN.5131.18.2022StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 250,000 on the company. The authority found that the company failed to notify the supervisory authority within 24 hours of detecting the personal data breach and did not promptly inform the affected data subject.PLUODOGDPR€53,090
08 Jun 2021DKN.5131.10.2020StatusnieprawomocnaTytuThe President of UODO imposed a fine of PLN 100,000 for failing to notify data breaches within the required deadline. The case concerns the obligation to report personal data breaches to the supervisory authority on time.PLUODOGDPR€22,372
22 Apr 2021DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider.PLUODOGDPR€249,000
04 Feb 2016DIVULGACION DINAMICA, S.L.DIVULGACION DINAMICA, S.L. was fined by the AEPD EUR 600 for sending commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
01 Jan 2015DIVINITEL, S.L.DIVINITEL, S.L. was fined by the AEPD EUR 2,000 for sending unsolicited commercial messages without recipient consent. This constituted a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€2,000
01 Jan 2014DIVER KARTING, S.L.DIVER KARTING, S.L. was fined by the AEPD in the amount of EUR 2,300 for continuing to send commercial communications after the individual exercised the right to object and requested to unsubscribe. The case concerns failure to respect a valid opt-out from direct marketing.ESAEPDePrivacy€2,300
21 Mar 2018Ditta individuale Smile di Remmert OriettaThe company was fined for processing the personal data of 36 individuals without consent in connection with training enrollments. It also submitted false documents to the Province of Turin to account for courses that were never conducted.ITGaranteGDPR€40,000
09 May 2018Ditta individuale “La Scuola della Salute di Francesco Parisi”The Garante imposed a 15,000 EUR fine on Ditta individuale “La Scuola della Salute di Francesco Parisi” for providing inadequate privacy information to clients and for related consent issues. The conduct was found to violate provisions of the privacy code.ITGaranteGDPR€15,000
21 Apr 2016Ditta individuale Fang WeiweiDitta individuale Fang Weiwei was fined 2,400 EUR by the Garante. The authority found that the video surveillance system was used without providing the information required under privacy rules.ITGaranteGDPR€2,400
27 Apr 2021Diszpécseri munkakört betöltő munkavállalóval folytatott telefonhívás rögzítéseThe decision concerned the unlawful recording and use of phone calls without a proper legal basis and without adequate transparency. The authority found breaches of GDPR accountability, lawful processing, and transparency principles.HUNAIHGDPR€1,380