Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jan 2024CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.CAJA RURAL NTRA MADRE DEL SOL S.C.A.C. was fined by the AEPD for a data breach that enabled unauthorized access to personal data. The authority found a violation of the confidentiality and integrity principles for personal data.ESAEPDGDPR€250,000
23 Jan 2024CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.CAJA RURAL DE BAENA was fined by the AEPD 10,000 EUR for breaching data protection principles. The case involved failures in confidentiality and integrity of personal data, which led to unauthorized access by third parties.ESAEPDGDPR€10,000
23 Jan 2024CAJA RURAL DE SALAMANCA, S.C.C.CAJA RURAL DE SALAMANCA, S.C.C. was fined by the AEPD 250,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€250,000
23 Jan 2024BANCO COOPERATIVO ESPAÑOL, S.A.Banco Cooperativo Español, S.A. was fined by the AEPD for a personal data breach. The incident allowed unauthorized access to personal data and breached the principles of confidentiality and integrity.ESAEPDGDPR€15,000
23 Jan 2024CAJA RURAL DE BURGOS, FUENTEPELAYO, SEGOVIA Y CASTELLDANS, S.C.C.CAJABURGOS was fined by the AEPD for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€15,000
24 Jan 2024CAIXA RURAL LA VALL SAN ISIDRO, S.C.C.CAIXA RURAL LA VALL SAN ISIDRO was fined by the AEPD 15,000 EUR for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data.ESAEPDGDPR€15,000
24 Jan 2024CAJA RURAL DE ONDA, S.C.C.CAJA RURAL DE ONDA, S.C.C. was fined by the AEPD 15,000 EUR for violating data protection principles, including confidentiality and integrity. The breach resulted in unauthorized access to personal data.ESAEPDGDPR€15,000
24 Jan 2024CAJA RURAL DEL SUR, S.C.C.CAJA RURAL DEL SUR, S.C.C. was fined EUR 20,000 by the AEPD for breaching data protection principles. The authority found that confidentiality and integrity of personal data were not adequately ensured, resulting in unauthorized access by third parties.ESAEPDGDPR€20,000
24 Jan 2024ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES. The case was handled under a simplified procedure.FRCNILGDPR€20,000
24 Jan 2024CAJA RURAL DE GIJÓN, S.C.A.C.CAJA RURAL DE GIJÓN was fined by the AEPD 95,000 EUR for breaching data protection principles, specifically confidentiality and integrity. The incident resulted in unauthorized access to personal data and indicates a significant compliance failure.ESAEPDGDPR€95,000
24 Jan 2024CAJA RURAL DE ASTURIAS, S.C.C.CAJA RURAL DE ASTURIAS was fined by the AEPD EUR 250,000 for breaching the confidentiality and integrity principles of personal data. The incident allowed unauthorized access to personal data, indicating a failure to protect data appropriately.ESAEPDGDPR€250,000
24 Jan 2024CAIXA RURAL D'ALGEMESÍ, S.C.V.CCAIXA RURAL D'ALGEMESÍ, S.C.V.C. was fined by the AEPD 15,000 EUR for breaching data protection principles, including confidentiality and integrity. The breach led to unauthorized access to personal data.ESAEPDGDPR€15,000
25 Jan 2024ASSOCIATION A CARACTERE POLITIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ASSOCIATION A CARACTERE POLITIQUE. The case was handled under a simplified procedure.FRCNILGDPR€20,000
26 Jan 2024Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people.EEAndmekaitse InspektsioonGDPR€3,000,000
29 Jan 2024IDFINANCE SPAIN, S.A.U.The AEPD fined IDFINANCE SPAIN, S.A.U. 70,000 EUR for including personal data in credit information systems in connection with a disputed debt. The authority found that the processing breached Article 6 GDPR.ESAEPDGDPR€70,000
29 Jan 2024JAÉN, SENTIDO Y COMÚNThe entity was fined by the AEPD for failing to comply with a data protection authority resolution. The breach concerned sending emails to multiple recipients without using BCC, contrary to Article 58(2) GDPR.ESAEPDGDPR€1,000
30 Jan 2024Könnycsepp Nélkül a Beteg Gyermekekért AlapítványThe NAIH imposed a 1,000,000 HUF fine on the foundation for GDPR breaches related to personal data processing during phone calls. The authority found that data subjects were not adequately informed and that the processing lacked a valid legal basis.HUNAIHGDPR€2,580
30 Jan 2024HUELLAS AVENTURA, S.L.The company was fined by the AEPD for tying consent for a school trip service to acceptance of data protection policies and commercial communications. The authority also found that users were not given an option to object to the processing of minors' images.ESAEPDGDPR€10,000
31 Jan 2024EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICESCNIL imposed an administrative fine of EUR 100,000 on EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICES. The case concerns identified breaches of rules supervised by the CNIL.FRCNILGDPR€100,000
31 Jan 2024Sectorul 1 al Municipiului BucureștiThe National Supervisory Authority for Personal Data Processing fined Sectorul 1 of Bucharest Municipality for GDPR violations. The entity failed to demonstrate compliance with a remediation measure, which formed the basis for the sanction.ROANSPDCPGDPR€2,010