Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Apr 2023Tensa Art Design SAThe National Supervisory Authority completed an investigation in March 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined 1,000 EUR.ROANSPDCPGDPR€1,000
26 Apr 2023CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights.ESAEPDGDPR€220,000
26 Apr 2023Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures.SEIMYGDPR€17,566
27 Apr 2023ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its investigative functions.ESAEPDGDPR€6,000
27 Apr 2023Ministero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di LecceMinistero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce was fined 15,000 EUR by the Garante for publishing personal data on its website. The case concerns a breach of data protection rules through unauthorized disclosure of information.ITGaranteGDPR€15,000
27 Apr 2023Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data.ITGaranteGDPR€239,000
27 Apr 2023Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach.ITGaranteGDPR€176,000
27 Apr 2023Provvedimento del 27 aprile 2023 [9896468]A fine of EUR 400 was imposed for improper use of a video surveillance system that captured images of a public street without the required authorization. The case concerned a breach of personal data processing rules in the context of video monitoring.ITGaranteGDPR€400
27 Apr 2023Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements.ITGaranteGDPR€2,000
27 Apr 2023B.B.B.The entity installed a surveillance camera without informing tenants or obtaining their consent. The camera captured shared areas, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
27 Apr 2023Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements.ITGaranteGDPR€40,000
27 Apr 2023Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed.ITGaranteGDPR€8,000
27 Apr 2023Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification.ITGaranteGDPR€240,000
27 Apr 2023Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
27 Apr 2023Tiziana Life Science LimitedTiziana Life Science Limited was fined by the Italian Garante in the amount of EUR 30,000. The case concerned failure to provide information and obtain consent for processing personal and genetic data acquired from the bankrupt company Shar.Dna S.p.A. for scientific research purposes.ITGaranteGDPR€30,000
27 Apr 2023B.B.B.The entity was fined by the AEPD in the amount of EUR 1,000 for installing surveillance cameras without proper signage and justification. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,000
02 May 2023KópavogsbærKópavogsbær was fined 4,000,000 ISK by Persónuvernd for using the Seesaw student system in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which requires a lawful basis and appropriate safeguards.ISPersónuverndGDPR€26,720
02 May 2023InternetThe company was fined for failing to implement adequate security measures for personal data processing. The deficiency led to a data breach involving user accounts, including accounts protected by weak passwords.CZUOOUGDPR€63,600
03 May 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined EUR 20,000 by the AEPD for irregularities in the cookie policy on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€20,000
03 May 2023B.B.B.A small hospitality establishment was fined 500 EUR by the AEPD for installing a surveillance camera that excessively recorded public areas. The authority found a breach of data protection rules.ESAEPDGDPR€500