Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Jun 2023BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 5,000 by the AEPD for repeatedly sending commercial emails to a client despite requests to unsubscribe. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€5,000
26 Jun 2023Hozzáférési kérelem nem teljesítéseThe controller did not properly handle the data subject’s requests for access and deletion of personal data. NAIH imposed a fine of HUF 500,000 for violating Article 15 GDPR.HUNAIHGDPR€1,355
26 Jun 2023Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes.SEIMYGDPR€1,112,000
26 Jun 2023B.B.B.B.B.B. was fined by the AEPD 10,000 EUR for uploading sexual and personal content of an ex-partner to YouTube and ForoCoches without consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€10,000
27 Jun 2023OPTIME 2016 SLOPTIME 2016 SL was fined EUR 500 by the AEPD for failing to provide requested information. The authority treated this as a breach of Article 58(1) GDPR.ESAEPDGDPR€500
27 Jun 2023Farmacia Ardealul SRLFarmacia Ardealul SRL was fined by ANSPDCP EUR 2,500 for a data security breach on its website. Unauthorized malware installation led to the compromise of personal data confidentiality, including banking data, of a significant number of clients.ROANSPDCPGDPR€2,500
27 Jun 2023A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration.ISPersónuverndGDPR€23,520
27 Jun 2023Creditinfo Lánstraust hf.Creditinfo Lánstraust hf. was fined by Persónuvernd for recording loan default information without meeting the required registration conditions. The authority found breaches of GDPR transparency and lawfulness requirements in the processing of personal data.ISPersónuverndGDPR€254,000
27 Jun 2023embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards.ISPersónuverndGDPR€80,640
27 Jun 2023eCommerce 2020 ApSeCommerce 2020 ApS was fined by Persónuvernd in the amount of 7,500,000 ISK for registering loan defaults with Creditinfo Lánstrausti hf. without meeting the required conditions. The authority noted, among other issues, that claims below the minimum threshold were registered. The case concerns improper handling of debt-related personal data.ISPersónuverndGDPR€50,400
28 Jun 2023FESTINA LOTUS S.A.FESTINA LOTUS S.A. did not respond to requests to delete a user's account and personal data. The authority found a breach of Article 17 GDPR and imposed a fine of EUR 1,000.ESAEPDGDPR€1,000
28 Jun 2023Fortis Insolvency LimitedFortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent, of which 527,481 were received by subscribers between 26 July 2020 and 26 July 2021. This breached regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice.GBICOePrivacy€34,713
29 Jun 2023FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR.ESAEPDGDPR€2,000
29 Jun 2023Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€10,000
29 Jun 2023FUNDACIÓN VEDRUNA EDUCACIÓN COLEGIOA teacher publicly disclosed the content of an email concerning a student's issues, breaching the duty of confidentiality. The AEPD found a violation of data protection rules and imposed a 15,000 EUR fine.ESAEPDGDPR€15,000
03 Jul 2023ENDESAENDESA was fined by the AEPD EUR 2,500,000 for failing to ensure the integrity and confidentiality of personal data and for inadequate security measures. The authority found breaches of GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,500,000
03 Jul 2023LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 5,000 EUR for attempting to install cookies on users' devices without proper consent. The conduct breached data protection rules and electronic commerce requirements.ESAEPDePrivacy€5,000
04 Jul 2023BALLESPE, S.LBALLESPE, S.L was fined by the AEPD in the amount of 500 EUR for installing surveillance cameras that captured public areas without proper signage. The case concerns a breach of data protection rules and the duty to inform individuals being recorded.ESAEPDGDPR€500
05 Jul 2023Anonymisé (CNPD decision-06-fr-2023)The company failed to implement appropriate technical and organizational measures to ensure data security. It also did not cooperate with the supervisory authority, breaching Articles 31 and 32 of the GDPR.LUCNPDGDPR€5,330
05 Jul 20234T OCIO Y CAFÉ 2009, S.L.The company was fined EUR 500 by the AEPD for installing surveillance cameras without the express consent of the property owners. The authority found this to be a breach of Article 6 of the GDPR.ESAEPDGDPR€500