Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Sept 2024SC Class IT Outsourcing SRLSC Class IT Outsourcing SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
16 Sept 2024Vodafone România SAVodafone România SA was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to respond to a request to exercise the GDPR rights of access and erasure.ROANSPDCPGDPR€3,000
17 Sept 2024Constanța South Container Terminal SRLConstanța South Container Terminal SRL was fined by ANSPDCP EUR 3,000 after a third party gained unauthorized access to employees’ personal data. The breach resulted from inadequate security measures on a publicly accessible file management platform.ROANSPDCPGDPR€3,000
18 Sept 2024Paula Stradiņa klīniskā universitātes slimnīcaA fine of EUR 2,000 was imposed. The decision has entered into force.LVDVIGDPR€2,000
19 Sept 2024GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.GACM Seguros was fined 8,000 EUR by the AEPD for improperly sharing personal data related to an insurance claim with another insured party. The authority found a breach of data protection rules.ESAEPDGDPR€8,000
19 Sept 2024ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN. The case was handled under a simplified procedure.FRCNILGDPR€20,000
19 Sept 2024CRIDOLMA BARCELONA S.L.CRIDOLMA BARCELONA S.L. was fined €9,000 by the AEPD for failing to properly handle a data subject access request. The case concerned a breach of Article 15 GDPR and non-compliance with a data protection authority resolution.ESAEPDGDPR€9,000
23 Sept 2024PPC ENERGIE MUNTENIA S.A.In September 2024, ANSPDCP completed an investigation into PPC ENERGIE MUNTENIA S.A. and found violations of GDPR provisions. The company was fined EUR 2,000.ROANSPDCPGDPR€2,000
24 Sept 2024SIA "ĀRES J & T"A fine of 500 EUR was imposed on SIA "ĀRES J & T" by the DVI. The decision has entered into force.LVDVIGDPR€500
26 Sept 2024SOCIETE PROPOSANT DES SERVICES DE CONSEIL EN SYSTÈMES ET LOGICIELS INFORMATIQUES, L'EDITION ET LA REALISATION DE LOGICIELS (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€15,000
26 Sept 2024Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status.ITGaranteGDPR€17,000
26 Sept 2024Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules.ITGaranteGDPR€50,000
26 Sept 2024Meta Platforms Ireland Limited (MPIL)The Irish DPC imposed a fine of 91,000,000 EUR on Meta Platforms Ireland Limited. The case relates to an inquiry and is currently pending appeal.IEDPCGDPR€91,000,000
26 Sept 2024SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a EUR 3,000 penalty on SOCIETE DE MARKETING under a simplified procedure. The case concerns liquidation astreinte, meaning enforcement of a previously imposed monetary obligation.FRCNILGDPR€3,000
26 Sept 2024ORGANISME DE FORMATION DESTINE AUX PROFESSIONNELS DE SANTE (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR on ORGANISME DE FORMATION DESTINE AUX PROFESSIONNELS DE SANTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€15,000
26 Sept 2024Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements.ITGaranteGDPR€10,000
26 Sept 2024CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records.ITGaranteGDPR€4,000
26 Sept 2024SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRECNIL imposed an administrative fine of EUR 250,000 on SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRE. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€250,000
26 Sept 2024SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUESCNIL imposed an administrative fine of EUR 150,000 on SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUES. The decision was issued on 26 September 2024.FRCNILGDPR€150,000
30 Sept 2024ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE. The case concerns a breach of personal data protection rules under a simplified procedure.FRCNILGDPR€3,000