Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Feb 2024DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined by the AEPD 1,000 EUR for operating a video surveillance system without the required signage. The authority found that the lack of notice breached the information obligations under GDPR Article 13.ESAEPDGDPR€1,000
13 Feb 2024FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD 6,000 EUR for processing personal data without a legal basis, in breach of Article 6(1) GDPR. The company failed to communicate the termination of a gas contract and improperly shared personal data with other companies.ESAEPDGDPR€6,000
13 Feb 2024LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD €10,000 for installing non-essential cookies on its website without obtaining valid user consent. The authority found this to be a breach of the LSSI.ESAEPDePrivacy€10,000
14 Feb 2024ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined by the AEPD €5,000 for continuing to send commercial emails despite repeated requests to unsubscribe. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
14 Feb 2024PRENSA IBÉRICA MEDIA S.L.PRENSA IBÉRICA MEDIA S.L. was fined by the AEPD in the amount of 5,000 EUR for failing to obtain proper user consent for cookies on its website. The authority found that this practice breached the LSSI requirements on cookies.ESAEPDePrivacy€5,000
15 Feb 2024Fiziska personaA monetary fine of 100 EUR was imposed by DVI on a natural person. The decision is final and has entered into force.LVDVIGDPR€100
15 Feb 2024Dr TelemarketingBetween 11 February 2021 and 24 January 2022, 80,240 connected unsolicited marketing calls were made to subscribers registered with the TPS who had not consented to receive them. Two complaints were received, and the calls related to the Irish Lottery. The company stopped engaging with the Commissioner during the investigation and did not provide a satisfactory explanation for the Lotto Express calls.GBICOGDPR€116,000
16 Feb 2024Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee.GRHDPAGDPR€2,000
19 Feb 2024DHL PARCEL IBERIA, S.L.U.DHL Parcel Iberia, S.L.U. was fined by the AEPD 5,000 EUR for failing to implement appropriate technical and organizational measures to ensure security appropriate to the risk, as required by Article 32 GDPR. As a result, personal data, including phone numbers, were exposed on shipping labels.ESAEPDGDPR€5,000
19 Feb 2024XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 200,000 by the AEPD for processing personal data without a legal basis. The case concerned a phone number portability carried out without the user's consent, which breached the requirement for lawful processing.ESAEPDGDPR€200,000
20 Feb 2024SPORT & SPA GEST, S.L.SPORT & SPA GEST, S.L. was fined by the AEPD 20,000 EUR for breaches of GDPR Articles 6(1), 13, 9, and 35. The case concerned improper data processing and insufficient information provided to users.ESAEPDGDPR€20,000
21 Feb 2024SOCIEDAD CONJUNTA PARA LA EMISIÓN Y GESTIÓN DE MEDIOS DE PAGO EFC SAIberia Cards was fined by the AEPD for failing to properly delete customer data after confirming cancellation. This caused issues when a former customer reapplied for a card.ESAEPDGDPR€20,000
21 Feb 2024DIBEA ESTETIC, S.L.DIBEA ESTETIC, S.L. was fined EUR 7,000 by the AEPD for transferring personal data without the data subject’s consent. The authority found this conduct to be contrary to Article 6(1) of the GDPR.ESAEPDGDPR€7,000
22 Feb 2024Ossitocina24 di Patrono AntonellaOssitocina24 di Patrono Antonella was fined 5,000 EUR by the Italian Garante. The case concerned the failure to delete personal data from its website after a contract termination request, which breached GDPR data processing requirements.ITGaranteGDPR€5,000
22 Feb 2024Azienda Usl Valle d’AostaThe Garante imposed a EUR 75,000 fine on Azienda Usl Valle d’Aosta for unauthorized access to patient health records. Healthcare professionals who were not involved in the patients’ care accessed the data, breaching GDPR data protection requirements.ITGaranteGDPR€75,000
22 Feb 2024Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC.ITGaranteGDPR€100,000
22 Feb 2024S.A.T.E. (Servizi Ambiente Territorio Energia)The Garante fined S.A.T.E. 6,000 EUR for breaches of data protection principles, including lawfulness, integrity, and confidentiality. The authority found that inadequate security measures led to unauthorized access to data.ITGaranteGDPR€6,000
22 Feb 2024Blue Work s.r.l.Blue Work s.r.l. was fined EUR 6,000 by the Garante for unlawful processing of biometric data using facial recognition for employee attendance tracking. The authority found that the same purpose could have been achieved through less intrusive means.ITGaranteGDPR€6,000
22 Feb 2024Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5.ITGaranteGDPR€90,000
22 Feb 2024Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned.ITGaranteGDPR€2,000