Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Jul 2024COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR.ESAEPDGDPR€20,000
08 Jul 2024CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
10 Jul 2024Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks.PLUODOGDPR€5,129
11 Jul 2024EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history.HRAZOPGDPR€5,470,000
12 Jul 2024CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients.ESAEPDGDPR€3,000
15 Jul 2024ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations.ESAEPDGDPR€200,000
16 Jul 2024A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6.NLAPGDPR€600,000
16 Jul 2024AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules.NLAutoriteit PersoonsgegevensGDPR€600,000
17 Jul 2024Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 50,000 by the Garante for sending promotional emails without obtaining proper customer consent. The authority found this conduct to be a breach of GDPR rules on electronic marketing.ITGaranteGDPR€50,000
17 Jul 2024IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient.ITGaranteGDPR€10,000
17 Jul 2024Provvedimento del 17 luglio 2024 [10070330]The Garante imposed a fine of EUR 4,000 for violations related to the processing of health data. The case highlights the need to comply with data protection principles when handling special category data.ITGaranteGDPR€4,000
17 Jul 2024Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data.ITGaranteGDPR€22,000
17 Jul 2024Selectra S.p.A.Selectra S.p.A. was fined EUR 80,000 by the Garante for unlawfully accessing and retaining a former employee's email account after the end of the collaboration. The authority found that the company's conduct breached data protection rules.ITGaranteGDPR€80,000
17 Jul 2024Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures.ITGaranteGDPR€5,000,000
17 Jul 2024Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations.ITGaranteGDPR€5,000
18 Jul 2024SIA "Doner King"A fine of EUR 500 was imposed on SIA "Doner King" by the DVI. The decision is final and has entered into force.LVDVIGDPR€500
22 Jul 2024COMMUNECNIL imposed EUR 6,900 on COMMUNE as an astreinte liquidation. The case concerns enforcement of a prior obligation subject to supervisory authority action.FRCNILGDPR€6,900
23 Jul 2024SIA "Piesēst"A fine of EUR 500 was imposed on SIA "Piesēst" by the DVI. The decision is final and has entered into force.LVDVIGDPR€500
23 Jul 2024VOLTIUM CONSULTORES 2020, S.L.VOLTIUM CONSULTORES 2020, S.L. was fined by the AEPD in the amount of EUR 600 for failing to provide access to information under Article 58(1) of the GDPR. The case concerns a breach of cooperation and transparency obligations toward the supervisory authority.ESAEPDGDPR€600
24 Jul 2024MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial SMS messages without recipient consent. The case concerned Article 21 of the LSSI, which requires prior consent for electronic marketing communications.ESAEPDePrivacy€5,000