Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Jun 2023Maxen Power Supply LimitedMaxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses. The conduct breached regulations 21 and 24 of PECR, and the ICO imposed a fine of 120,000 GBP and issued an enforcement notice.GBICOePrivacy€139,000
08 Jun 2023Mirva s.r.l.Mirva s.r.l. was fined by the Garante 5,000 EUR for installing a video surveillance system without proper informational signage. The system also captured areas not pertaining to the company, which breached data protection rules.ITGaranteGDPR€5,000
08 Jun 2023Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints.GBICOGDPR€150,000
08 Jun 2023L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential.ITGaranteGDPR€30,000
08 Jun 2023Liguria News S.r.l.Liguria News S.r.l. was fined by Garante EUR 10,000 for publishing an article that breached privacy rules. The article disclosed personal and sensitive information about individuals involved in the reported incident, including a minor.ITGaranteGDPR€10,000
08 Jun 2023SOCIÉTÉ DE VOYANCECNIL imposed a fine of EUR 150,000 on SOCIÉTÉ DE VOYANCE. The case concerns a regulatory breach, with no further details provided on the specific nature of the violation.FRCNILGDPR€150,000
08 Jun 2023Marcozzi Brand s.r.l.Marcozzi Brand s.r.l. was fined €8,400 by the Garante. The case concerned the failure to provide the complainant with the name of the occupational physician and the specific reasons for a negative fitness-for-work assessment, breaching GDPR transparency and access rights.ITGaranteGDPR€8,400
08 Jun 2023ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)ALTERNATIVA CORELLANA INDEPENDIENTE (ACI) was fined by the AEPD for failing to respond to information requests. The authority treated this as a breach of Article 58.1 of the GDPR.ESAEPDGDPR€4,000
09 Jun 2023UNIÓN DE RADIOS LIBRES Y COMUNITARIAS DE MADRIDThe entity did not comply with a data protection authority resolution concerning the right to erasure. As a result, AEPD imposed a fine for breaching Article 58.2 of the GDPR.ESAEPDGDPR€1,000
12 Jun 2023Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language.SEIMYGDPR€4,992,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default.GRHDPAGDPR€100,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access.GRHDPAGDPR€10,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA EUR 100,000 for processing personal data without a legal basis. The breach affected a large number of data subjects, which increases its compliance significance.GRHDPAGDPR€100,000
13 Jun 2023JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SATThe entity was fined by the AEPD for installing a video surveillance system with inadequate signage. The notices did not identify the data controller or provide contact details for exercising data subject rights, breaching Article 13 GDPR.ESAEPDGDPR€500
14 Jun 2023B.B.B.The entity was fined EUR 300 by the AEPD for installing a camera on the exterior facade of a building, aimed at public space, without the required administrative authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€300
15 Jun 2023Artima S.A.Artima S.A. was fined EUR 8,000 by ANSPDCP for a data breach. The incident exposed personal images, vehicle registration numbers, and vehicle details, indicating a breach of internal procedures and data confidentiality.ROANSPDCPGDPR€8,000
15 Jun 2023SOCIÉTÉ SPÉCIALISÉE DANS L'AFFICHAGE DE PUBLICITÉS CIBLÉES SUR LE WEBThe CNIL imposed a fine of 40 million euros on the company. The decision concerns identified breaches of rules under the authority's supervision.FRCNILGDPR€40,000,000
16 Jun 2023Department of HealthThe Irish DPC fined Department of Health €22,500 in inquiry IN-21-3-2. The fine has been collected.IEDPCGDPR€22,500
16 Jun 2023Anonymisiert (DSB 2023-0.404.421)An individual processed personal data without a legal basis by storing contact details on a private phone for political advertising. The DSB imposed a EUR 1,000 fine for breaching GDPR lawfulness requirements.ATDSBGDPR€1,000
16 Jun 2023B.B.B.The entity was fined for installing a surveillance camera in a rented property without informing the tenant. The authority treated this as a breach of data protection rules.ESAEPDGDPR€5,300