Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Sept 2023COMMERCE INTERENTREPRISES DE PRODUITS SURGELES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMERCE INTERENTREPRISES DE PRODUITS SURGELES under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€20,000
28 Sept 2023Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption.ITGaranteGDPR€30,000
28 Sept 2023SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES (procédure simplifiée)The CNIL imposed a fine of EUR 20,000 on SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES under a simplified procedure. The decision concerns a breach of the rules covered by the administrative proceeding.FRCNILGDPR€20,000
28 Sept 2023SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
28 Sept 2023Azienda Usl Toscana centroThe Garante imposed a fine of EUR 50,000 on Azienda Usl Toscana centro for data protection violations related to the former Sanatorio Guido Banti premises. The case concerned irregularities in the processing of personal data in that context.ITGaranteGDPR€50,000
28 Sept 2023Axpo Italia S.p.A.Axpo Italia S.p.A. was fined by the Garante 10,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the conclusion of unsolicited contracts for electricity and gas supply.ITGaranteGDPR€10,000,000
28 Sept 2023Palombaro s.r.l.Palombaro s.r.l. was fined by the Garante in the amount of 3,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward individuals being recorded.ITGaranteGDPR€3,000
28 Sept 2023MCP Online LtdThe ICO fined MCP Online Ltd 55,000 GBP after finding that 20,939 calls were made between 1 January 2022 and 28 September 2022 to numbers registered with the CTPS or TPS. The conduct breached Regulations 21 and 24 of PECR and came to light through Operation Torc, which investigates unsolicited pensions calls.GBICOePrivacy€63,707
01 Oct 2023Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data.GBInformation Commissioner's OfficeGDPR€2,313,000
01 Oct 2023Anonymised (IDPC CDP_COMP_344_2022)The IDPC imposed a EUR 2,500 fine on the anonymised entity for breaches of multiple GDPR provisions. The case concerned, among others, lawfulness and transparency, information duties, and controller accountability.MTIDPCGDPR€2,500
01 Oct 2023TrustpilotThe Italian Competition Authority (AGCM) fined Trustpilot EUR 4,000,000. The authority found that the company misled consumers about the authenticity of reviews and how they were moderated.ITItalian Competition Authority (AGCM)Omnibus€4,000,000
01 Oct 2023Anonymised (IDPC CDP_COMP_259_2022)The IDPC imposed a EUR 5,000 fine on Anonymised (IDPC CDP_COMP_259_2022) for breaches of Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. The case concerned personal data processing that did not comply with the principles of lawfulness, fairness, data minimisation and purpose limitation.MTIDPCGDPR€5,000
01 Oct 2023ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company.NLAutoriteit PersoonsgegevensGDPR€2,700,000
01 Oct 2023wspólnota mieszkaniowaUODO found that the housing community breached GDPR requirements. The case concerned improper processing of personal data and required supervisory intervention.PLUODOGDPR€1,080
02 Oct 2023AVENTURA EN TRAMPOLINES, S.L.Aventura en Trampolines, S.L. was fined by the AEPD EUR 2,000 for breaching GDPR Article 7. The company required consent for image use without allowing users to refuse specific terms, which did not meet data protection requirements.ESAEPDGDPR€2,000
02 Oct 2023COMUNIDAD DE PROPIETARIOS A.A.A.The president of a homeowners' association shared a bank receipt containing personal data in a WhatsApp group. AEPD found a breach of confidentiality principles under GDPR and imposed a EUR 2,000 fine.ESAEPDGDPR€2,000
02 Oct 2023Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities.ROANSPDCPGDPR€1,000
03 Oct 2023ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements.ESAEPDGDPR€1,500
03 Oct 2023MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€1,140,000
03 Oct 2023Digivo Media LimitedBetween 24 March 2021 and 7 September 2021, 415,041 text messages were sent without valid consent, breaching Regulation 22 of PECR. The ICO identified the matter after reviewing debt management complaints submitted via the SPAM reporting tool.GBICOePrivacy€57,620