Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2024KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined by the AEPD EUR 2,000 for sending an email to more than 400 recipients without using BCC. This exposed other recipients’ email addresses and breached GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,000
10 Jun 2024SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
10 Jun 2024BOULANGERIE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on BOULANGERIE under a simplified procedure. The record does not provide further details on the underlying infringement.FRCNILGDPR€5,000
10 Jun 2024SIA "Moshmans"A fine of EUR 500 was imposed by the DVI. The decision has entered into force.LVDVIGDPR€500
10 Jun 2024MEDECIN GENERALISTE (procédure simplifiée)CNIL imposed an administrative fine of EUR 4,000 on MEDECIN GENERALISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€4,000
11 Jun 2024APARTAMENTOS BUENAVISTA HOMEAPARTAMENTOS BUENAVISTA HOME was fined EUR 1,000 by the AEPD for requesting guests to submit electronic images of their ID documents. The authority found that this practice breached the GDPR data minimization principle.ESAEPDGDPR€1,000
11 Jun 2024A.A.A.The municipality accessed and disclosed personal data without a legal basis, including full name, ID number, address, and financial details. The authority found a breach of Article 6 GDPR and imposed a EUR 500 fine.ESAEPDGDPR€500
11 Jun 2024DIGITAL FLOW, S.L.DIGITAL FLOW, S.L. was fined EUR 2,000 by the AEPD for sending emails without an unsubscribe option. The authority also found that the company failed to provide a valid contact for exercising data deletion rights.ESAEPDePrivacy€2,000
13 Jun 2024Samodzielny Publiczny Zespół Opieki Zdrowotnej z siedzibą w P., za naruszenie art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1, art. 32 ust. 1 i 2 oraz art. 34 ust. 1 rozporządzenia 2016/679The Polish DPA (UODO) imposed an administrative fine of PLN 40,000 on the Samodzielny Publiczny Zespół Opieki Zdrowotnej based in P. The decision concerns breaches of Article 5(1)(f) and (2), Article 25(1), Article 32(1) and (2), and Article 34(1) of Regulation (EU) 2016/679.PLUODOGDPR€9,201
13 Jun 2024RETSINNAL GROUP, S.L.U.RETSINNAL GROUP, S.L.U. was fined by the AEPD in the amount of 10,000 EUR for failing to comply with cookie management rules on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
14 Jun 2024GESCONSULT, S.A. S.G.I.I.C.GESCONSULT, S.A. S.G.I.I.C. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case involved recording a meeting and sharing the recording without proper consent.ESAEPDGDPR€5,000
17 Jun 2024FÚTBOL CLUB BARCELONAFútbol Club Barcelona was fined by the AEPD for processing biometric data without explicit consent during a mandatory member census update. The authority found breaches of GDPR Articles 9 and 35, relating to special-category data processing and data protection impact assessment requirements.ESAEPDGDPR€6,000,000
18 Jun 2024FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYAThe organization changed the bank account for a community water bill to its own account without authorization. The AEPD found this breached the lawfulness of processing under GDPR Article 6(1).ESAEPDGDPR€8,000
20 Jun 2024Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante EUR 1,000,000 for carrying out telemarketing activities without obtaining proper consent from the contacted individuals. The authority found a breach of fairness and transparency principles in the processing of personal data.ITGaranteGDPR€1,000,000
20 Jun 2024Rețele Electrice Dobrogea SARețele Electrice Dobrogea SA was fined by ANSPDCP in the amount of EUR 1,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
20 Jun 2024Grafiche E.The Garante imposed a fine of EUR 12,000 on Grafiche E. for violations of data protection rules. The case concerned non-compliance with regulatory requirements for the processing of personal data.ITGaranteGDPR€12,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings.ITGaranteGDPR€4,000
20 Jun 2024Rețele Electrice Muntenia SARețele Electrice Muntenia SA was fined by ANSPDCP in the amount of 3,000 EUR for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules.ITGaranteGDPR€10,000
20 Jun 2024Comune di ForlìThe Municipality of Forlì was fined EUR 15,000 by the Garante for failing to embed data protection principles in the design of its video surveillance system. The authority found breaches of transparency and accountability requirements.ITGaranteGDPR€15,000