Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jan 202420 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined 45,000 EUR by the AEPD for publicly exposing the image of a victim of an alleged crime. The authority found that this constituted a breach of data protection rules.ESAEPDGDPR€45,000
09 Jan 2024Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals.DKDatatilsynetGDPR€33,523
11 Jan 2024Provincia di SassariThe Garante imposed a fine of 2,000 EUR on Provincia di Sassari for breaches of data protection obligations under Article 37 GDPR. The case concerned failure to comply with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000
11 Jan 2024Comune di SiracusaThe Garante fined Comune di Siracusa €5,000 for breaches of data protection obligations under Article 37 GDPR. The case concerned failures related to the appointment and management of the data protection officer requirement.ITGaranteGDPR€5,000
11 Jan 2024Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights.ITGaranteGDPR€10,000
11 Jan 2024Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities.ITGaranteGDPR€50,000
11 Jan 2024DESPACHO TORRENTE, S.L.P.DESPACHO TORRENTE, S.L.P. was fined by the AEPD 10,000 EUR for improperly disclosing personal data, including sensitive information, in a letter concerning damage at public facilities. The authority found a breach of data protection principles.ESAEPDGDPR€10,000
11 Jan 2024Euro Servizi per i Notai S.r.l.Euro Servizi per i Notai S.r.l. was fined 5,000 EUR by the Garante for processing personal data without a valid legal basis and without adequate transparency. The violations concerned reporting services provided to banks through the PIGNA portal.ITGaranteGDPR€5,000
11 Jan 2024dott. BagnatoA doctor was fined by the Garante for breaching privacy rules. The case involved improper handling of medical prescriptions outside the office, which could expose sensitive personal data.ITGaranteGDPR€20,000
11 Jan 2024Findomestic Banca S.p.A.Findomestic Banca S.p.A. was fined by the Garante 100,000 EUR for sending unsolicited promotional communications by phone and mail. The authority found that these contacts were made without obtaining proper consent from the data subject.ITGaranteGDPR€100,000
11 Jan 2024Libero Consorzio comunale di CaltanissettaLibero Consorzio comunale di Caltanissetta was fined by the Garante EUR 2,000 for breaching Article 37(7) of the GDPR. The decision also orders publication of the sanction on the authority’s website.ITGaranteGDPR€2,000
11 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 150,000 for processing personal data without proper authorization. The case involved a fraudulent contract created using the complainant’s identity, and the authority found that the company did not adequately verify the identity of the person entering into the contract.ESAEPDGDPR€150,000
11 Jan 2024Provincia di CatanzaroThe Garante fined Provincia di Catanzaro EUR 2,000 for violations of data protection obligations under Article 37 GDPR. The case concerned non-compliance with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000
11 Jan 2024Società David S.r.l.The Garante imposed an €8,000 fine on Società David S.r.l. for posting on Instagram a video of a patient undergoing a cosmetic procedure without a lawful basis. The authority found breaches of the GDPR principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€8,000
12 Jan 2024Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions.GBICOGDPR€162,000
12 Jan 2024Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations.ROANSPDCPGDPR€17,000
15 Jan 2024TECHNINK LEB SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data on its website. The exposed information included IDs, addresses, names, email addresses, and sales information.ROANSPDCPGDPR€3,000
15 Jan 2024AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on AVOCAT (procédure simplifiée). The case concerned a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€5,000
15 Jan 2024CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects.ESAEPDGDPR€3,000
16 Jan 2024Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements.GBICOePrivacy€174,000