Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Dec 2023B*** GmbHB*** GmbH was fined by the DSB EUR 5,900 for failing to timely report a data breach to the supervisory authority and for not providing sufficient information required under GDPR. The company also did not cooperate with the authority’s further requests for information.ATDSBGDPR€5,900
12 Dec 2023COMMUNECNIL imposed a EUR 5,000 fine on COMMUNE and issued an injunction. The case concerns a regulatory breach requiring corrective action.FRCNILGDPR€5,000
13 Dec 2023Dane anonimowe (M. Sp. z o.o. z siedzibą w D. przy ul.)The President of UODO imposed a PLN 23,580 administrative fine on M. Sp. z o.o. The penalty was issued for failing to comply with two administrative decisions issued by the data protection authority.PLUODOGDPR€5,451
15 Dec 2023O nouă amendă - operator persoană fizicăA fine was imposed on an individual operator for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules.ROANSPDCPGDPR€200
15 Dec 2023TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined by the AEPD in the amount of 5,000 EUR for breaching data protection rules. The company failed to honor a request to delete personal data and later sent commercial information to the complainant.ESAEPDGDPR€5,000
15 Dec 2023TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined EUR 5,000 by the AEPD for sending commercial information by email after confirming the deletion of personal data. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
18 Dec 2023MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them.ESAEPDePrivacy€5,000
18 Dec 2023Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles.HUNAIHGDPR€1,295
19 Dec 2023HIPERBAZAR YONGFA 2018 SLHIPERBAZAR YONGFA 2018 SL was fined by the AEPD 5,000 EUR for breaching data protection rules. The case involved the improper sharing of surveillance footage, which was later posted on Facebook, undermining confidentiality and data security requirements.ESAEPDGDPR€5,000
19 Dec 2023Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals.PLUODOGDPR€2,306
20 Dec 2023Educational Development Informatikai Zrt.The company failed to implement adequate data security measures and did not report a data breach without undue delay. The authority found breaches of GDPR Articles 32 and 33.HUNAIHGDPR€286,000
20 Dec 2023Ministra ZdrowiaThe President of the Personal Data Protection Office imposed an administrative fine of 100,000 PLN on Ministra Zdrowia. The authority found unlawful processing of personal data, including special-category data without a legal basis, and a failure to implement technical and organizational measures appropriate to the processing risk. The affected individual was also not provided with the information required under Article 33(3)(c) and (d) of the GDPR.PLUODOGDPR€23,035
20 Dec 2023Dane anonimowe (Wójta Gminy P.)UODO imposed a PLN 50,000 administrative fine on the controller for failing to implement appropriate technical and organizational measures proportionate to the risk of processing. The authority found insufficient safeguards for confidentiality, integrity, availability, and resilience of systems, as well as inadequate recovery capability after an incident.PLUODOGDPR€11,518
21 Dec 2023Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules.ITGaranteGDPR€18,000
21 Dec 2023Gestioni Aziendali s.r.l.Gestioni Aziendali s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating a video surveillance system at Hotel della Vittoria without appropriate informational signage. The authority found this to be a breach of GDPR transparency requirements toward monitored individuals.ITGaranteGDPR€5,000
21 Dec 2023Dane anonimowe (K. sp. z o.o. sp. k. z siedzibą w W. przy ul.)The President of UODO imposed a fine of PLN 18,864 on the company for failing to cooperate in the performance of the authority’s duties. The company also did not provide access to personal data and information necessary for the regulator’s tasks.PLUODOGDPR€4,346
21 Dec 2023MediafondMediafond was fined EUR 10,000 by the Garante for continuing to use a former employee’s email account after the employment ended. The company also forwarded emails without proper notice, which breached GDPR requirements.ITGaranteGDPR€10,000
21 Dec 2023Impresa individuale Macelleria Salumeria HalalThe Garante fined the owner of Impresa individuale Macelleria Salumeria Halal EUR 2,000 for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency and data processing requirements.ITGaranteGDPR€2,000
22 Dec 2023HISPAPOST, S.A.HISPAPOST, S.A. was fined EUR 60,000 by the AEPD for failing to properly safeguard and handle personal data. The incident resulted in the abandonment of 1,404 letters containing personal information, indicating inadequate data protection procedures.ESAEPDGDPR€60,000
27 Dec 2023MEDECIN PEDIATRE (procédure simplifiée)The CNIL imposed a 1,000 EUR fine on MEDECIN PEDIATRE under a simplified procedure. The case concerns a regulatory breach, with no further details provided in the record.FRCNILGDPR€1,000