Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Apr 2024ALPHA BANK ROMANIA SAALPHA BANK ROMANIA SA was fined by ANSPDCP for a data security breach caused by improper management of a record system by an employee. This led to unauthorized disclosure and access to the personal data of certain clients.ROANSPDCPGDPR€2,000
23 Apr 2024Odsherred KommuneOdsherred Kommune was fined by Datatilsynet for failing to implement adequate security measures, including encryption of laptops containing sensitive personal data. The deficiency resulted in a data breach.DKDatatilsynetGDPR€13,404
24 Apr 2024C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates.ITGaranteGDPR€10,000
24 Apr 2024Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data.ITGaranteGDPR€30,000
24 Apr 2024I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
24 Apr 2024Dane anonimowe (Komitet Inicjatywy Ustawodawczej W. na rzecz ustawy o zmianie ustawy z dn. 24 lipca 2015 r. Prawo o zgromadzeniach oraz niektórych innych ustaw)UODO imposed an administrative fine on the entity responsible for a list of citizens supporting a legislative initiative. The authority found inadequate technical and organisational measures for the risk, a failure to regularly test security controls, and delays in reporting and notifying the personal data breach.PLUODOGDPR€2,527
24 Apr 2024Dly S.r.l.Dly S.r.l. was fined by the Garante EUR 5,000 for deploying a non-compliant video surveillance system. The system recorded both customers and employees, in breach of data protection rules.ITGaranteGDPR€5,000
24 Apr 2024Gestore Dei Servizi Energetici - Gse S.p.A.The Garante fined Gestore Dei Servizi Energetici - Gse S.p.A. 30,000 EUR for failing to respond to a data subject access request. The request concerned the individual's personal performance evaluation records for 2019 and 2020.ITGaranteGDPR€30,000
25 Apr 2024SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT. The case was handled under a simplified procedure.FRCNILGDPR€15,000
25 Apr 2024ALL IN DIGITAL MARKETING, S.L.ALL IN DIGITAL MARKETING, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct to be in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,000
25 Apr 2024REVUE LITTERAIRE FRANCAISE (procédure simplifiée)The CNIL imposed a EUR 3,000 penalty on REVUE LITTERAIRE FRANCAISE under a simplified procedure. The case concerns the liquidation of an astreinte, meaning enforcement of a previously ordered monetary obligation.FRCNILGDPR€3,000
25 Apr 2024ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 16,000 on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES. The authority also issued an injunction requiring corrective action.FRCNILGDPR€16,000
26 Apr 2024Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began.DKDatatilsynetGDPR€6,705
26 Apr 2024SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data.ESAEPDGDPR€50,000
29 Apr 2024Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13.HUNAIHGDPR€12,750
29 Apr 2024Dane anonimowe (A. Sp. k. z siedzibą w T.)UODO imposed a PLN 238,345 administrative fine on A. Sp. k. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing, including the use of external storage media. The authority also found a lack of regular testing, measurement, and evaluation of the effectiveness of the security measures in place.PLUODOGDPR€55,103
30 Apr 2024Dane anonimowe (Stowarzyszenie F. z siedzibą w X. przy ul.)UODO imposed an administrative fine on Association F. for failing to notify the supervisory authority of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to report data security incidents within the required timeframe.PLUODOGDPR€212
03 May 2024D.D.D.The entity published images of a minor on its Telegram channel without consent, breaching data protection rules. AEPD imposed a fine of EUR 5,000.ESAEPDGDPR€5,000
06 May 2024DQG NORTE A.I.E.DQG NORTE A.I.E. was fined by the AEPD for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€5,000
07 May 2024PINKGREEN BARCELONA, S.L.PINKGREEN BARCELONA, S.L. was fined by the AEPD 4,000 EUR for disclosing personal data of individuals in responses to negative Google reviews. The authority found that the processing breached Articles 6 and 9 of the GDPR.ESAEPDGDPR€4,000