Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 May 2024Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose.GRHDPAGDPR€5,000
27 May 2024KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 10,000 EUR for requiring a customer to provide a photo with their ID to cancel a loan. The authority found that this processing breached GDPR principles of data minimisation and proportionality.ESAEPDGDPR€10,000
28 May 2024B.B.B.B.B.B., a councilor, unlawfully published the personal data of a complainant and their spouse in a municipal meeting note. The information was shared with a group of about 400 people, causing reputational harm.ESAEPDGDPR€1,000
28 May 2024CUI ZSQ FOOD, S.L.CUI ZSQ FOOD, S.L. was fined by the AEPD 70,000 EUR for using a video surveillance system to intimidate employees. The company shared footage of an employee’s absence in a work chat, which breached data protection rules.ESAEPDGDPR€70,000
30 May 2024Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
30 May 2024Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€1,000
31 May 2024CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle.ESAEPDGDPR€7,500
31 May 2024MEDIOS DE PREVENCIÓN EXTERNOS, S.L.MEDIOS DE PREVENCIÓN EXTERNOS, S.L. was fined by the AEPD for leaving medical documentation of police and civil guard agents in a public place. The authority found this to be a breach of data protection rules.ESAEPDGDPR€100,000
31 May 2024MAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.AMAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.A was fined EUR 300,000 by the AEPD. The authority found that the company carried out unauthorized investment transactions using personal data without consent, in breach of data protection rules.ESAEPDGDPR€300,000
31 May 2024LABORATORIO PEDRO PERALES, S.L.P.LABORATORIO PEDRO PERALES, S.L.P. was fined by the AEPD 5,000 EUR for failing to comply with data protection rules in relation to cookie management on its website. The case concerned deficiencies in how users were informed and how consent was handled.ESAEPDePrivacy€5,000
05 Jun 2024Ambitious People Group B.V.Ambitious People Group B.V. was fined by the AP EUR 6,000 for failing to handle data erasure requests submitted by three individuals within the required timeframe. The breach concerned GDPR Articles 17 and 12.NLAPGDPR€6,000
06 Jun 2024Cappello Giovanni & figli s.r.l.Cappello Giovanni & figli s.r.l. was fined by Garante for unlawful processing of employee personal data using Infinity DMS software and X.-Face 380 hardware. The authority found that the company's practices breached GDPR principles.ITGaranteGDPR€120,000
06 Jun 2024WORLD 2 MEET, S.L.WORLD 2 MEET, S.L. was fined EUR 70,000 by the AEPD for requesting excessive personal data from guests during traveler registration. The company required full copies of identity documents, which breached the data minimization principle.ESAEPDGDPR€70,000
06 Jun 2024FCA Bank S.p.A.FCA Bank S.p.A. was fined EUR 1,000,000 by the Italian supervisory authority Garante for data protection violations. The case concerned the use of blacklists in car rental services, raising compliance concerns about personal data processing.ITGaranteGDPR€1,000,000
06 Jun 2024MÁRMOLES Y GRANITOS MEJIAS, S. L.The entity was fined by the AEPD for operating a video surveillance system with cameras directed toward public areas without the required administrative authorization. It also failed to provide legally compliant informational signage.ESAEPDGDPR€1,000
06 Jun 2024Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules.ITGaranteGDPR€6,419,000
06 Jun 2024Drivalia Leasys Rent S.p.A.Drivalia Leasys Rent S.p.A. was fined by Garante 250,000 EUR for denying a car rental voucher to a customer listed on a blacklist. The authority found insufficient transparency in data processing and a lack of proper legal basis and consent under GDPR.ITGaranteGDPR€250,000
06 Jun 2024Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance.ITGaranteGDPR€24,000
07 Jun 2024Club Balonmano GijónClub Balonmano Gijón was fined EUR 1,000 by the AEPD for unlawfully processing personal data by publishing images of minors on its website without a legal basis. The case indicates a breach of the lawfulness principle and the protection of children's image rights.ESAEPDGDPR€1,000
07 Jun 2024AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A.AXA Real Estate Investment Managers Iberica S.A. was fined by the AEPD for failing to implement adequate security measures. The deficiency resulted in a data breach involving personal data stored on an encrypted USB drive.ESAEPDGDPR€100,000