Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Oct 2024TRIVE CREDIT SPAIN, S.L.TRIVE CREDIT SPAIN, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine for non-compliance with a prior resolution.ESAEPDGDPR€450,000
01 Oct 2024IBERCAJA BANCO, S.A.Ibercaja Banco, S.A. accessed personal data in the BADEXCUG EXPERIAN file 47 times without consent after the contractual relationship ended. The AEPD found this to be a breach of data protection rules and imposed a 300,000 EUR fine.ESAEPDGDPR€300,000
01 Oct 2024SERVACE, S.L.SERVACE, S.L. was fined by the AEPD EUR 1,400 for using an employee’s personal email address for work purposes without consent. The authority found this breached GDPR Articles 6(1) and 5(1)(f).ESAEPDGDPR€1,400
01 Oct 2024CONSULTORIA INTEGRAL DE ENERGÍA ECOLÓGICA, S.L.The company was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising messages to a complainant. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
02 Oct 2024Global Ports’s Services S.R.L.The company was fined for processing personal data without a legal basis, which breaches Article 6 of the GDPR. The case concerned unlawful processing by the controller.ROANSPDCPGDPR€2,000
03 Oct 2024ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined EUR 5,000 by the AEPD for continuing to send marketing emails despite the recipient's unsubscribe requests. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
03 Oct 2024Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards.GBICOGDPR€890,000
04 Oct 2024DIAMOND FERVA, S.L.DIAMOND FERVA, S.L. was fined by the AEPD 1,000 EUR for installing a surveillance camera without properly informing data subjects and without the required authorization. The authority treated this as a breach of the information obligations under GDPR Article 13.ESAEPDGDPR€1,000
07 Oct 2024B*** GmbHB*** GmbH was fined EUR 600 by the Austrian Data Protection Authority (DSB). The penalty concerned a failure to cooperate in a data breach procedure, which breached Article 31 GDPR.ATDSBGDPR€600
07 Oct 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing.ESAEPDGDPR€200,000
08 Oct 2024SEAT, S.A.SEAT, S.A. was fined by the AEPD €20,000 for using cookies on its website without obtaining user consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€20,000
09 Oct 2024Pana AB, prowadzącego działalność gospodarczą pod firmą X, ul.The Polish DPA (UODO) imposed a fine of PLN 353,589 on Pana AB, operating under the name X, for breaches of the GDPR. The authority also ordered the company to bring its processing operations into compliance with Regulation (EU) 2016/679.PLUODOGDPR€82,273
10 Oct 2024Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice.GBICOePrivacy€47,796
10 Oct 2024Dane anonimowe (X w K.)The UODO imposed an administrative fine of PLN 15,000 on the entity identified as Anonymous data (X in K.). The authority found breaches of data protection principles, including integrity and confidentiality, accountability, data protection by design, processor obligations, and security measures.PLUODOGDPR€3,485
10 Oct 2024FEDERAL NAJANAJANA, S.L.FEDERAL NAJANAJANA, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial messages via WhatsApp without the recipient’s explicit consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
10 Oct 2024SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIEThe CNIL imposed an administrative fine of EUR 750,000 on SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIE. The record indicates a regulatory breach, but no further details are provided.FRCNILGDPR€750,000
10 Oct 2024WerepairUK LtdWerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The ICO fined the company 80,000 GBP and issued an enforcement notice.GBICOePrivacy€95,592
11 Oct 2024ORTHOPHONISTE (procédure simplifiée)The CNIL imposed a 4,000 EUR penalty on ORTHOPHONISTE (procédure simplifiée) in connection with the liquidation of an astreinte. The case concerns compliance with a prior obligation under the data protection authority’s supervision.FRCNILGDPR€4,000
14 Oct 2024ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD EUR 50,000 for publishing a video containing violent content and the voices of the aggressors and the victim. The authority found a breach of data protection rules.ESAEPDGDPR€50,000
14 Oct 2024National Debt Advice LimitedNational Debt Advice Limited sent 129,902 unsolicited direct marketing text messages, breaching regulation 22 of PECR. The activity generated more than 4,000 complaints to the 7726 spam reporting service. The ICO imposed a £30,000 fine and issued an enforcement notice.GBICOePrivacy€35,856