Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Sept 2024GESTIÓN DE VENTAS IBERIA S.L.GESTIÓN DE VENTAS IBERIA S.L. was fined 4,000 EUR by the AEPD for failing to provide access as required under Article 58.1 of the GDPR. The case concerns non-compliance with a supervisory authority request.ESAEPDGDPR€4,000
10 Sept 2024Fundația Pro Economica – Pro Economica AlapítványThe foundation was fined EUR 1,000 by ANSPDCP after a data security incident caused by a cyberattack. The attack led to the deletion of personal data from its server, affecting data availability.ROANSPDCPGDPR€1,000
10 Sept 2024Okmánymásolat feltöltését is előíró regisztrációs folyamattal és regisztrációs adatbázissal kapcsolatos jogellenes adatkezelésThe authority imposed a fine for negligent GDPR violations between December 2021 and November 2023. The breaches concerned transparency and data processing principles in connection with the registration process and the registration database.HUNAIHGDPR€189,000
10 Sept 2024HWM PSI, S.L.HWM PSI, S.L. was fined by the AEPD 100 EUR for sending an email to multiple recipients without using BCC. This exposed recipients’ personal email addresses and breached data protection rules.ESAEPDGDPR€100
11 Sept 2024KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerned non-compliance with Article 58.1 of the GDPR.ESAEPDGDPR€1,200
11 Sept 2024NEGOCIOS R&R 2020 S.L.NEGOCIOS R&R 2020 S.L. was fined by the AEPD 12,000 EUR for failing to provide access under Article 58(1) of the GDPR. The authority treated this as a serious breach of data protection obligations.ESAEPDGDPR€12,000
11 Sept 2024Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals.NODatatilsynetGDPR€12,566
12 Sept 2024Medic4All Italia S.r.l.Medic4All Italia S.r.l. was fined by the Garante 15,000 EUR for failing to respond to a data subject access request. The conduct breached Article 15 GDPR, which requires controllers to provide access to personal data upon request.ITGaranteGDPR€15,000
12 Sept 2024Top Quality Corporation S.r.l.s.Top Quality Corporation S.r.l.s. was fined by the Garante 5,000 EUR for failing to respond to a data subject’s request to access personal data related to employment. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
12 Sept 2024Ordine delle Professioni Infermieristiche di UdineOrdine delle Professioni Infermieristiche di Udine was fined 8,000 EUR by the Garante for breaches of data protection rules. The authority found improper disclosure of data to third parties and a failure to provide proper information to data subjects.ITGaranteGDPR€8,000
12 Sept 2024SOCIETE EXPLOITANT UN CASINO ET UN HOTEL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 12,000 on SOCIETE EXPLOITANT UN CASINO ET UN HOTEL under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€12,000
12 Sept 2024Ordine delle Professioni Infermieristiche di GoriziaThe Garante imposed a fine of EUR 5,000 on the Ordine delle Professioni Infermieristiche di Gorizia for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data.ITGaranteGDPR€5,000
12 Sept 2024Provvedimento del 12 settembre 2024 [10065894]The Garante imposed a EUR 400 fine for the improper installation of surveillance cameras oriented toward private residences. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€400
12 Sept 2024Ordine delle Professioni Infermieristiche di TriesteThe Garante fined the Ordine delle Professioni Infermieristiche di Trieste EUR 4,000 for breaches of data protection rules. The case involved improper disclosure of data to third parties and a failure to provide adequate information to data subjects.ITGaranteGDPR€4,000
12 Sept 2024B.B.B.B.B.B. was fined by the AEPD €4,000 for failing to properly inform individuals about the presence of surveillance cameras. The authority also found the surveillance system disproportionate because it recorded audio and retained images longer than permitted.ESAEPDGDPR€4,000
12 Sept 2024Ordine delle Professioni Infermieristiche di PordenoneOrdine delle Professioni Infermieristiche di Pordenone was fined 6,000 EUR by the Garante for breaching data protection rules. The authority found that the organization mishandled a data subject request and failed to respect privacy rights.ITGaranteGDPR€6,000
12 Sept 2024Sky Italia S.r.l.Sky Italia S.r.l. was fined EUR 842,062 by the Garante for telemarketing violations. The authority found that the company contacted individuals without proper consent and failed to consult the Public Register of Objections before promotional campaigns.ITGaranteGDPR€842,000
13 Sept 2024DIGITAL PHOTO IMAGE, S.A.DIGITAL PHOTO IMAGE, S.A. was fined EUR 20,000 by the AEPD for breaching the LSSI. The company sent emails without providing recipients with a valid means to exercise their right to stop receiving such communications.ESAEPDePrivacy€20,000
13 Sept 2024COMMUNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMUNE (procédure simplifiée) and issued an injunction. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€20,000
13 Sept 2024ARES CAPITAL, S.A.ARES CAPITAL, S.A. was fined by the AEPD for requiring employees to use personal phones for work together with continuous monitoring apps. The authority found that the company did not provide sufficient information about data collection, breaching GDPR rules on lawful basis, transparency, and data processing principles.ESAEPDGDPR€200,000