Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Mar 2023Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements.ITGaranteGDPR€4,000
24 Mar 2023NATURGESTYGAS, S.L.NATURGESTYGAS, S.L. was fined EUR 10,000 by the AEPD for processing personal data without a legal basis. The company charged a customer despite having no contract or consent, which breached the legality requirement for processing.ESAEPDGDPR€10,000
24 Mar 2023A.A.A.A.A.A. was fined EUR 300 by the AEPD for failing to provide adequate information about data processing in a video surveillance system. The authority found a breach of Article 13 GDPR because data subjects did not receive the required information.ESAEPDGDPR€300
24 Mar 2023B.B.B.The entity installed surveillance cameras without the required informational signage. AEPD treated this as a breach of data protection rules.ESAEPDGDPR€300
24 Mar 2023COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The homeowners’ association was fined 500 EUR by the AEPD for installing surveillance cameras aimed at public areas without prior administrative authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€500
27 Mar 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the Spanish data protection authority, AEPD. The company failed to provide requested information, obstructing the authority’s investigative powers under Article 58(1) GDPR.ESAEPDGDPR€20,000
27 Mar 2023persoană fizicăAn individual was fined EUR 450 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules.ROANSPDCPGDPR€450
28 Mar 2023SOCIETE DE PROGRAMMATION INFORMATIQUE (procédure simplifiée)The CNIL imposed a EUR 20,000 fine on SOCIETE DE PROGRAMMATION INFORMATIQUE under a simplified procedure. The record only indicates the financial sanction and does not provide further details on the underlying breach.FRCNILGDPR€20,000
28 Mar 2023DENTAL REY-GAR, S.L.DENTAL REY-GAR, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a resolution concerning the right of access to personal data. The authority found a breach of Article 58(2) of the GDPR.ESAEPDGDPR€1,000
28 Mar 2023SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a fine of EUR 10,000 on SOCIETE DE MARKETING and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
28 Mar 2023Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns.ITGarante per la protezione dei dati personaliGDPR€842,000
29 Mar 2023SOLAR PROGRESS, S.L.SOLAR PROGRESS, S.L. was fined 5,000 EUR by the AEPD for displaying an employee’s personal data on a company WhatsApp profile. The authority found a breach of data protection rules.ESAEPDGDPR€5,000
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation.GRHDPAGDPR€10,000
30 Mar 2023XCOM DIGITAL LAB, S.L.XCOM DIGITAL LAB, S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The company failed to comply with Article 21 of the LSSI despite repeated requests from the recipient to unsubscribe.ESAEPDePrivacy€800
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator.GRHDPAGDPR€40,000
31 Mar 2023LODEJU, S.L.LODEJU, S.L. was fined by the AEPD EUR 3,000 for improperly directing surveillance cameras toward public spaces without authorization. The authority also found inadequate informational signage, in breach of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
31 Mar 2023APOLLONIA TOPCO, S.L.APOLLONIA TOPCO, S.L. was fined by the AEPD EUR 30,000 for improperly requesting copies of clients’ ID documents. The authority also noted a failure to respond to a data protection complaint, in breach of data minimization and purpose limitation principles.ESAEPDGDPR€30,000
01 Apr 2023TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully.GBInformation Commissioner's OfficeGDPR€14,444,000
03 Apr 2023HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards.ESAEPDGDPR€200,000
03 Apr 2023Banca Transilvania SABanca Transilvania SA was fined EUR 2,000 by ANSPDCP for a GDPR breach. The case concerned improperly restricting access to an account in the mobile banking application despite the client's explicit request.ROANSPDCPGDPR€2,000