Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jun 2024Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations.ITGaranteGDPR€5,000
20 Jun 2024TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€10,000
21 Jun 2024ADMINISTRACIONES BENIPON, S.L.ADMINISTRACIONES BENIPON, S.L. was fined 2,200 EUR by the AEPD for failing to provide access to information as required under Article 58(1) GDPR. The case concerns non-compliance with the supervisory authority’s information access requirements.ESAEPDGDPR€2,200
24 Jun 2024WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.The entity sent postal advertising to an individual without any prior commercial relationship, using data from the Official Industrial Property Bulletin. The authority found this to be a breach of data protection rules.ESAEPDGDPR€500
25 Jun 2024LOS NIÑOS DE MONTESSORI, S.L.The entity was fined for failing to provide information or obtain consent for the use of cookies on its website. This conduct breached the LSSI.ESAEPDePrivacy€5,000
25 Jun 2024AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta.SEIMYGDPR€1,336,000
25 Jun 2024COMUNIDAD.1The community of property owners disclosed a resident’s personal data, including their DNI, in meeting minutes. AEPD found this breached confidentiality principles and imposed a 300 EUR fine.ESAEPDGDPR€300
25 Jun 2024RIVENDELL TECHNOLOGY, S.L.RIVENDELL TECHNOLOGY, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The company was fined for not complying with the data protection authority's resolution.ESAEPDGDPR€900
27 Jun 2024METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure.GRHDPAGDPR€20,000
27 Jun 2024SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 12,000 on SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES under a simplified procedure. The case concerned a breach of rules supervised by the CNIL.FRCNILGDPR€12,000
01 Jul 2024Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000.MTIDPCGDPR€15,000
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságALDI Magyarország was fined by the NAIH 80,000,000 HUF for failing to ensure transparency in data processing related to the purchase of alcoholic beverages. The authority found breaches of GDPR transparency and data minimization principles.HUNAIHGDPR€202,000
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságNAIH imposed a HUF 95,000,000 fine on ALDI Magyarország for GDPR violations linked to data processing during alcohol purchases. The authority cited improper age verification and insufficient personal data protection measures.HUNAIHGDPR€240,000
04 Jul 2024Provvedimento del 4 luglio 2024 [10068075]The Garante imposed a EUR 400 fine on an individual for improperly installing a surveillance system. The cameras captured public street areas, which breached privacy rules.ITGaranteGDPR€400
04 Jul 2024Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles.ITGaranteGDPR€10,000
04 Jul 2024Lapis SasThe Garante fined Lapis Sas EUR 1,500 for incorrectly presenting itself as the data controller. This created public confusion and constituted a prolonged breach of GDPR requirements.ITGaranteGDPR€1,500
04 Jul 2024Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities.ITGaranteGDPR€7,000
04 Jul 2024Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web.ITGaranteGDPR€900,000
04 Jul 2024Comune di VillasimiusComune di Villasimius was fined for failing to respond to a request to remove personal data from its website and for unlawfully publishing personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
05 Jul 2024PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9.ESAEPDGDPR€10,000