Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Dec 2023CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The company also failed to respond to a request to stop such communications, which constitutes a breach of the LSSI.ESAEPDePrivacy€1,000
04 Dec 2023GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. was fined by the AEPD 5,000 EUR for failing to delete a customer's personal data within the legal timeframe. The case concerns a breach of data protection rules and the controller's obligation to comply with a deletion request.ESAEPDePrivacy€5,000
06 Dec 2023ReykjanesbærReykjanesbær was fined by Persónuvernd 2,500,000 ISK for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited the failure to carry out timely data protection impact assessments and to define processing purposes clearly.ISPersónuverndGDPR€16,650
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€2,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€20,000
07 Dec 2023Sirio S.p.A.Sirio S.p.A. was fined EUR 1,000 by the Garante for violating data protection rules. The case concerned the improper handling of an employee’s personal data in connection with issuing a new bank card.ITGaranteGDPR€1,000
07 Dec 2023Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency.ITGaranteGDPR€40,000
07 Dec 2023Mushtaq RubinaThe Garante fined Mushtaq Rubina 2,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward recorded individuals.ITGaranteGDPR€2,000
07 Dec 2023ASESORÍA Y PROGRAMACIÓN PROFESIONAL, S.L.The entity was fined for continuing to send advertising emails despite the recipient's attempts to unsubscribe. This conduct breached Article 21 of the LSSI and resulted in a EUR 5,000 penalty.ESAEPDePrivacy€5,000
07 Dec 2023Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data.CYCyDPCGDPR€1,500
07 Dec 2023Nirvam S.r.l.Nirvam S.r.l., an online dating platform, was fined 200,000 EUR by the Garante. The authority found inadequate personal data protection measures and GDPR breaches related to data processing and security.ITGaranteGDPR€200,000
07 Dec 2023Dane anonimowe (N. Sp. z o.o. z siedzibą w W. przy ul.)The President of UODO imposed a PLN 11,790 administrative fine on N. Sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to personal data and information necessary for those duties.PLUODOGDPR€2,722
07 Dec 2023B.B.B.The educational institution did not inform parents about data processing on Chromebooks used by students. It also failed to have a contract with the data processor, which breaches GDPR Articles 13 and 28.ESAEPDGDPR€5,000
07 Dec 2023N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR.ATDSBGDPR€20,000
07 Dec 2023Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures.ITGaranteGDPR€8,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€2,000
07 Dec 2023H**** Gemeinnützige Wohnungs AGThe entity was fined for failing to cooperate with the Data Protection Authority during a complaint procedure. It did not respond to requests for statements, which constitutes a breach of Article 31 GDPR.ATDSBGDPR€10,000
11 Dec 2023PERSONNALITE POLITIQUE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on PERSONNALITE POLITIQUE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
11 Dec 2023Veranda Obor S.A.The National Supervisory Authority for Personal Data Processing imposed a fine on Veranda Obor S.A. for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
11 Dec 2023C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information.ATDSBGDPR€9,500