Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Nov 2024CLUB ESPORTIU VILA OLÍMPICAThe club pressured a parent to obtain consent for collecting images of a minor child. AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,000
20 Nov 2024Anonymisé (CNPD decision-03-fr-2024)The company was fined for installing surveillance cameras without a legal basis. The authority found breaches of GDPR principles of lawfulness, transparency, and security.LUCNPDGDPR€14,288
20 Nov 2024Raiffeisen Bank S.A.Raiffeisen Bank S.A. was fined EUR 20,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€20,000
20 Nov 2024B.B.B.B.B.B. was fined by the AEPD EUR 300 for sending a marketing email to multiple recipients without using BCC. This exposed recipients’ email addresses to each other and breached data protection principles.ESAEPDGDPR€300
22 Nov 2024CLUB BALONCESTO TELDEClub Baloncesto Telde was fined for publishing images of a minor on social media without obtaining the required consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€1,000
22 Nov 2024MAXPOWER FITNESS NUTRITION, S.L.MAXPOWER FITNESS NUTRITION, S.L. was fined by the AEPD in the amount of 2,000 EUR for deficiencies in its cookie policy. The breach concerned the information and consent requirements under the LSSI.ESAEPDePrivacy€2,000
22 Nov 2024Maynooth UniversityThe Irish DPC imposed a fine of EUR 40,000 on Maynooth University in inquiry IN-19-9-3. The penalty has been collected.IEDPCGDPR€40,000
25 Nov 2024XFERA CONSUMER FINANCE ESTABLECIMIENTO FINANCIERO DE CRÉDITO, S.A.The AEPD fined XFERA Consumer Finance 5,000 EUR for sending a customer unsolicited advertising SMS messages. The messages were sent after the customer had asked to stop receiving such communications, indicating a breach of marketing communication rules.ESAEPDePrivacy€5,000
26 Nov 2024ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES (procédure simplifiée)CNIL imposed an administrative fine of 10,000 EUR on ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES. The case was handled under a simplified procedure.FRCNILGDPR€10,000
26 Nov 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited advertising emails. The messages were sent despite the recipient's unsubscribe request and inclusion on the Robinson list, breaching the LSSI.ESAEPDePrivacy€10,000
26 Nov 2024Dane anonimowe (X. ul.)UODO imposed an administrative fine of PLN 29,684.04 on Dane anonimowe (X. ul.) for breaching Article 33(1) and Article 34(1) and (2) of the GDPR. The authority also ordered the controller to notify the affected data subject about the personal data breach.PLUODOGDPR€6,886
26 Nov 2024SOCIETE DE GESTION D'INSTALLATIONS INFORMATIQUES (procédure simplifiée)CNIL imposed an administrative fine of EUR 15,000 on SOCIETE DE GESTION D'INSTALLATIONS INFORMATIQUES. The case was handled under a simplified procedure.FRCNILGDPR€15,000
26 Nov 2024NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests.NLAutoriteit PersoonsgegevensGDPR€4,750,000
27 Nov 2024Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended.DKDatatilsynetGDPR€53,632
27 Nov 2024Comune di TorrenovaThe Garante fined Comune di Torrenova 4,000 EUR for breaches of GDPR principles, including lawfulness, fairness, and transparency in data processing. The case indicates failures to meet basic data protection requirements in the public authority's processing activities.ITGaranteGDPR€4,000
27 Nov 2024E.ON Energia S.p.A.E.ON Energia S.p.A. was fined EUR 892,738 by the Garante for telemarketing-related violations. The authority cited repeated contact attempts and numerous communications sent without proper consent.ITGaranteGDPR€892,000
27 Nov 2024Faro di RomaFaro di Roma was fined 15,000 EUR by the Garante for failing to comply with data protection rules. The case concerned the failure to honor requests for erasure and rectification of personal data linked to a judicial matter.ITGaranteGDPR€15,000
27 Nov 2024Istituto Comprensivo Statale "Corso Matteotti" di AlfonsineIstituto Comprensivo Statale “Corso Matteotti” di Alfonsine was fined by the Garante EUR 1,000 for violations related to the processing of personal data. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€1,000
27 Nov 2024Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data.ITGaranteGDPR€10,000
27 Nov 2024Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data.ITGaranteGDPR€10,000