Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Aug 2023LORO PARQUE, S.A.LORO PARQUE, S.A. was fined by the AEPD 250,000 EUR for processing biometric data without a proper legal basis. The authority classified this as a very serious breach of Article 9 GDPR.ESAEPDGDPR€250,000
30 Aug 2023Dane anonimowe (A. S.A. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 56,592 on the company. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for its tasks.PLUODOGDPR€12,652
31 Aug 2023GEDI News Network S.p.a.The Garante imposed a EUR 30,000 fine on GEDI News Network S.p.a. for publishing a photo of minors with insufficient pixelation, making them identifiable. The authority found this to be a breach of data protection rules concerning children.ITGaranteGDPR€30,000
31 Aug 2023operator persoană fizicăA EUR 2,000 fine was imposed on an individual operator for photographing or filming a patient in a medical unit without consent. The authority also applied a corrective measure to ensure compliance of data processing operations with the GDPR.ROANSPDCPGDPR€2,000
31 Aug 2023B.B.B.B.B.B. was fined 300 EUR by the AEPD after a complaint about a surveillance camera installed by a neighbor. The authority found that the device could have captured images of a private property and a private street, creating a potential data protection breach.ESAEPDGDPR€300
31 Aug 2023Provvedimento del 31 agosto 2023 [9938463]The decision concerned a breach of rules on the processing of health data by a medical center. Garante imposed a fine of EUR 10,000.ITGaranteGDPR€10,000
31 Aug 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent.ITGaranteGDPR€10,000
31 Aug 2023Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children.ITGaranteGDPR€25,000
31 Aug 2023Ordine degli Avvocati di XXThe Garante fined the Ordine degli Avvocati di XX EUR 8,000 for unlawfully disclosing personal data without a legal basis. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€8,000
01 Sept 2023TikTok Technology Limited (TTL)The Irish DPC imposed a fine of EUR 345,000,000 on TikTok Technology Limited (TTL) following an inquiry. The matter remains ongoing because the decision is under appeal.IEDPCGDPR€345,000,000
04 Sept 2023ASSOCIACIO OASIS CULTURALASSOCIACIO OASIS CULTURAL was fined by the AEPD EUR 10,000 for unlawful processing of personal data. The case concerned the publication on TikTok of a video showing minors performing dances with sexual connotations without a legal basis under Article 6(1) GDPR.ESAEPDGDPR€10,000
06 Sept 2023Simply Connecting LtdSimply Connecting Ltd sent 441,830 direct marketing text messages to individuals in breach of regulation 22 of PECR. The ICO imposed a £40,000 fine and issued an enforcement notice.GBICOePrivacy€46,780
06 Sept 2023Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations.ISPersónuverndGDPR€10,425
07 Sept 2023IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORAIberia was fined by the AEPD EUR 50,000 for a breach related to personal data handling during a flight from Quito to Dublin. Passengers were asked to provide identity documents and marriage certificates to justify travel during COVID-19 restrictions.ESAEPDGDPR€50,000
07 Sept 2023ISRA Center Marketing Research SRLIn August 2023, the Romanian supervisory authority ANSPDCP completed an investigation into ISRA Center Marketing Research SRL. It found a GDPR violation and imposed a fine of EUR 2,000.ROANSPDCPGDPR€2,000
12 Sept 2023LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide access to information required under Article 58(1) of the GDPR. The conduct was treated as an obstruction of the data protection authority’s investigative functions.ESAEPDGDPR€4,000
14 Sept 2023GFB One s.r.l.GFB One s.r.l. was fined EUR 90,000 by the Italian Garante. The case concerned its failure to respond to requests for information relating to the unauthorized activation of SIM cards and the misuse of personal identification documents.ITGaranteGDPR€90,000
14 Sept 2023društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach.HRAZOPGDPR€15,000
14 Sept 2023Azienda Sanitaria dell'Alto Adige - Suedtiroler SanitaetsbetriebThe Garante fined Azienda Sanitaria dell'Alto Adige EUR 10,000 for failing to provide an adequate response to a data subject's rights request. The case also concerned the processing of sensitive data related to vaccination status.ITGaranteGDPR€10,000
14 Sept 2023Comune di San SeveroThe Municipality of San Severo was fined EUR 10,000 by the Garante for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€10,000