Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Jul 2018BUTALI S.P.A.BUTALI S.P.A. was fined €16,000 by the Garante for activating a SIM card without providing the required privacy information and obtaining the customer’s specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
11 Jul 2018BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules.ITGaranteGDPR€10,000
08 May 2013Business Services s.r.lBusiness Services s.r.l was fined EUR 6,400 by the Garante. The case concerned the sending of promotional faxes without the required information and without obtaining explicit consent from recipients.ITGaranteGDPR€6,400
01 Jan 2015BUSCANDO SUERTE S.L.BUSCANDO SUERTE S.L. was fined by the AEPD €2,300 for sending unsolicited SMS messages. The messages misled recipients into replying and caused charges without any legitimate purpose.ESAEPDePrivacy€2,300
09 Jul 2020Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent.ITGaranteGDPR€20,000
07 May 2015Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification.GRHDPAGDPR€3,000
06 Jul 2020Bureau Krediet Registratie (BKR)Bureau Krediet Registratie (BKR) was fined EUR 830,000 by the AP for not providing free electronic access to personal data. The authority found this practice breached the GDPR right of access.NLAPGDPR€830,000
19 Oct 2010BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U.BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U. was fined by the AEPD for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent.ESAEPDePrivacy€1,200
03 Dec 2021Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR.HUNAIHGDPR€825
11 Jan 2024Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights.ITGaranteGDPR€10,000
21 Mar 2024Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.).HUNAIHGDPR€762
25 Jun 2019Budapesti Rendőr-főkapitányságBudapesti Rendőr-főkapitányság was fined by NAIH 5,000,000 HUF for failing to report a personal data breach within the 72-hour deadline. The incident involved the loss of a pendrive containing personal data, in breach of GDPR Article 33.HUNAIHGDPR€15,400
10 Dec 2020Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds.HUNAIHGDPR€22,480
05 Apr 2019Budapesti Műszaki és Gazdaságtudományi EgyetemBudapest University of Technology and Economics was fined 600,000 HUF by NAIH. The authority found that the university failed to comply with a data subject's request for access to personal data.HUNAIHGDPR€1,872
25 Apr 2022Budapest Főváros XVIII. kerület Pestszentlőrinc - Pestszentimre ÖnkormányzataThe authority fined the municipality for failing to provide adequate information to data subjects about the collection and use of their personal data. It also found processing of personal and health data without a valid legal basis or proper consent.HUNAIHGDPR€8,010
24 Mar 2021Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals.HUNAIHGDPR€27,400
08 Feb 2022Budapest Bank Zrt.Budapest Bank Zrt. was fined by NAIH for improper personal data processing related to the analysis of recorded phone conversations. The authority found violations of several GDPR provisions.HUNAIHGDPR€707,000
21 Mar 2025Bucharest Down Town Hotel SRLThe National Supervisory Authority for Personal Data Processing fined Bucharest Down Town Hotel SRL for GDPR violations following a complaint. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€1,000
05 Jun 2020BUBO MEDIA, S.L.BUBO MEDIA, S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS messages to individuals without their consent. The conduct breached data protection and electronic communications rules.ESAEPDePrivacy€1,500
06 Sept 2012BT Italia s.p.a.BT Italia s.p.a. was fined by the Garante EUR 75,000 for sending unsolicited promotional faxes without recipient consent. The conduct breached data protection and direct marketing rules.ITGaranteGDPR€75,000