Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 May 2023M.S.M. Immobiliare s.r.l.M.S.M. Immobiliare s.r.l. was fined €1,000 by the Garante for a video surveillance system that captured areas beyond its property. The authority also found that proper informational signage was missing, in breach of data protection rules.ITGaranteGDPR€1,000
17 May 2023Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights.ITGaranteGDPR€40,000
17 May 2023Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32.ITGaranteGDPR€10,000
17 May 2023Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications.ITGaranteGDPR€10,000
17 May 2023Anonymizováno (ÚOOÚ UOOU-03562/22-14)The entity was fined for repeatedly sending commercial communications without prior consent from recipients. The messages were not clearly marked as advertising, did not identify the sender, and did not provide a valid address for opting out.CZUOOUePrivacy€2,539
17 May 2023La Gazzetta di Parma S.r.l.La Gazzetta di Parma S.r.l. was fined by the Garante EUR 10,000 for publishing an image of a presumed murderer in breach of privacy rules. The person was shown in a state of physical restraint without proper anonymization.ITGaranteGDPR€10,000
17 May 2023Breikot Management LtdBreikot Management Ltd was fined EUR 3,000 by the CyDPC for publishing personal data, including names and photos. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€3,000
18 May 2023AUTOMOBILE BAVARIA SRLThe fine was imposed for the unauthorized disclosure of personal data of 290 clients and potential clients, which were publicly accessible on the operator's website. The case concerns a breach of data protection rules through disclosure without an appropriate legal basis or safeguards.ROANSPDCPGDPR€18,000
19 May 2023B.B.B.The entity was fined by the AEPD for installing a video surveillance system that captured public areas without authorization. The footage was then used for dissemination via WhatsApp, which breached Article 5(1)(c) GDPR.ESAEPDGDPR€300
19 May 2023MADRID TOURISTIC CAPITAL, S.L.MADRID TOURISTIC CAPITAL, S.L. was fined by the AEPD €1,200 for failing to provide proper signage and information about its video surveillance system. The case concerns a breach of data protection transparency and notice requirements.ESAEPDGDPR€1,200
23 May 2023Global Baby Brands SRLIn May 2023, the Romanian supervisory authority ANSPDCP completed an investigation into Global Baby Brands SRL. It found a GDPR violation and imposed a fine of EUR 1,000.ROANSPDCPGDPR€1,000
24 May 2023PARTIDO LOCAL DE VILLANUEVA DEL PARDILLOPartido Local de Villanueva del Pardillo was fined EUR 500 by the AEPD for publishing an image on Facebook without the data subject's consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€500
26 May 2023B.B.B.The entity was fined EUR 300 by the AEPD for operating a video surveillance system that captured public areas without proper informational signage. The authority treated this as a breach of data protection rules.ESAEPDGDPR€300
26 May 2023B.B.B.B.B.B. was fined EUR 300 by the AEPD for installing a video surveillance system that captured public areas and a private path without authorization. The authority found a breach of the data minimization principle under GDPR Article 5(1)(c).ESAEPDGDPR€300
29 May 2023B.B.B.The entity was fined by the AEPD for failing to remove a viral video from Twitter that breached data protection rules. The case indicates a lack of timely action in response to content processing personal data without a lawful basis.ESAEPDGDPR€2,000
29 May 2023NOVA TELECOMMUNICATIONS & MEDIA MONOPROSOPI A.E.The company was fined for repeatedly sending unsolicited electronic communications for marketing purposes despite the complainant’s objections. The authority also found failures to comply with requests for access, objection, and restriction of processing.GRHDPAePrivacy€50,000
29 May 2023SERVICIOS E INTERVENCIONES EN EDIFICACION DEL MEDITERRÁNEO, S.L.The company published an image on its website without the individual's express consent. The authority treated the case as a repeat infringement because the company had previously been sanctioned for the same conduct.ESAEPDGDPR€2,000
29 May 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 70,000 EUR for processing call and SMS diversion without the customer's consent. The conduct was linked to a bank fraud incident, indicating a serious failure in data protection and service authorization controls.ESAEPDGDPR€70,000
30 May 2023B.B.B.The entity was fined for keeping an operational surveillance camera inside a rented apartment without informing the tenants. The authority found this to be a breach of data protection rules.ESAEPDGDPR€6,000
31 May 2023B.B.B.B.B.B. was fined EUR 500 by the AEPD for failing to properly sign a video surveillance system in a laundry establishment. The authority found a breach of Article 13 GDPR regarding the duty to inform individuals being recorded.ESAEPDGDPR€500