Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Jul 2023Anonymisé (CNPD decision-05-fr-2023)The company did not inform data subjects about the recipients of their personal data. It also failed to implement appropriate technical and organizational measures required under the GDPR, breaching Articles 13 and 24.LUCNPDGDPR€1,500
05 Jul 2023UPMOBILE SOLUTIONS, S.L.UPMOBILE SOLUTIONS, S.L. was fined EUR 500 by the AEPD for failing to provide access during the investigation. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its supervisory function.ESAEPDGDPR€500
05 Jul 2023BILBAO AD INFINITUM, S.L.BILBAO AD INFINITUM, S.L. was fined by the AEPD EUR 500 for installing surveillance cameras directed at a public square without prior administrative authorization. The authority found that this conduct breached GDPR requirements on lawful processing.ESAEPDGDPR€500
06 Jul 2023AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15.ITGaranteGDPR€10,000
06 Jul 2023Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements.ITGaranteGDPR€10,000
06 Jul 2023Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles.ITGaranteGDPR€3,000
06 Jul 2023SUROVI (Surovi Ristorante indiano e kebab di Chowdhury Monika)The Garante fined SUROVI restaurant EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found this to be a breach of Article 13 of the GDPR.ITGaranteGDPR€1,000
06 Jul 2023Ristorante Francesco s.r.l.Ristorante Francesco s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating surveillance cameras without the required notices to affected individuals. The authority treated this as a breach of privacy rules.ITGaranteGDPR€5,000
06 Jul 2023Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection.ITGaranteGDPR€2,000
06 Jul 2023Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€7,000
06 Jul 2023Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data.ITGaranteGDPR€15,000
07 Jul 2023THE COMAKING SPACE, S.L.U.THE COMAKING SPACE, S.L.U. was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without recipient consent. The conduct breached the LSSI rules on electronic marketing communications.ESAEPDePrivacy€2,000
07 Jul 2023Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles.HUNAIHGDPR€2,580
09 Jul 2023PROSULTING, S.L.N.E.PROSULTING, S.L.N.E. was fined by the AEPD in the amount of 1,000 EUR for failing to provide data subjects with the information required under Article 13 GDPR. The case concerned a lack of proper notice about the processing of personal data.ESAEPDGDPR€1,000
10 Jul 2023C.C.C.The entity was fined for operating a video surveillance system that captured public areas and neighboring properties without the required authorization. Required informational signage was also not displayed.ESAEPDGDPR€600
10 Jul 2023B.B.B.The AEPD imposed a 300 EUR fine on B.B.B. after a surveillance camera was directed toward the complainant's property. The authority found a breach of data protection rules due to unauthorized processing of image data.ESAEPDGDPR€300
12 Jul 2023Dane anonimowe (Panią K.W. prowadzącą działalność gospodarczą pod nazwą W. z miejscem wykonywania działalności w O. przy ul.)UODO imposed an administrative fine on the business for failing to report a personal data breach to the supervisory authority within 72 hours. The authority also found that the affected individuals were not notified without undue delay.PLUODOGDPR€2,651
12 Jul 2023B.B.B.The entity installed a surveillance camera without authorization and captured images of communal areas. This breached Article 6(1) GDPR.ESAEPDGDPR€300
13 Jul 2023B.B.B.B.B.B. was fined by the AEPD 600 EUR for installing a surveillance camera directed at a public area without prior administrative authorization and without proper signage. The authority found breaches of Articles 5(1)(c) and 13 GDPR.ESAEPDGDPR€600
13 Jul 2023EUROPA PRESS DE CATALUNYA, S.A.EUROPA PRESS DE CATALUNYA, S.A. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found that the company processed excessive personal data in breach of GDPR Article 5(1)(c).ESAEPDGDPR€50,000