Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Nov 2024Molise dati S.p.A.Molise dati S.p.A. was fined EUR 10,000 by the Garante for a data breach involving the regional health portal. A system vulnerability allowed unauthorized access to personal data of citizens in the Molise Regional Registry.ITGaranteGDPR€10,000
27 Nov 2024Maximum International Corp. S.r.l.Maximum International Corp. S.r.l. was fined by the Garante 10,000 EUR for persistent promotional calls despite objections and for failing to respond to data subject requests. The authority found breaches of GDPR rules on consent and information obligations.ITGaranteGDPR€10,000
27 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code.ITGaranteGDPR€20,000
28 Nov 2024COMUNIDAD DE PROPIETARIOS A.A.A.The community of property owners was fined by the AEPD for publicly displaying personal data, including names and debt information. The authority found a breach of the confidentiality principle under GDPR.ESAEPDGDPR€1,000
01 Dec 2024Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€40,000
03 Dec 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a customer who had opted out. The authority also found that there was no effective mechanism to revoke consent.ESAEPDePrivacy€20,000
03 Dec 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization.ESAEPDGDPR€200,000
03 Dec 2024Fiziska personaA fine of EUR 500 was imposed by the DVI. The decision has entered into force.LVDVIGDPR€500
05 Dec 2024ESL Consultancy Services Ltd Between 15 September 2022 and 5 December 2023, 37,977 complaints were received about direct marketing messages sent at the instigation of ESL Consultancy Services Ltd. The ICO fined the company GBP 200,000 and issued an enforcement notice.GBICOGDPR€241,000
05 Dec 2024SOCIETE VENDANT DES PRODUITS COSMETIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE VENDANT DES PRODUITS COSMETIQUES. The case was handled under a simplified procedure.FRCNILGDPR€3,000
05 Dec 2024CLINIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on CLINIQUE (procédure simplifiée). The case concerns a regulatory breach that resulted in an administrative sanction.FRCNILGDPR€15,000
05 Dec 2024SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEURThe CNIL imposed an administrative fine of EUR 240,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEUR and issued an injunction. The case concerns identified regulatory breaches.FRCNILGDPR€240,000
05 Dec 2024SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
05 Dec 2024TMETME was fined EUR 200,000 by the AEPD for changing the ownership of a mobile line without consent and for issuing a duplicate SIM card without a valid legal basis. The authority found that these actions failed to meet the requirements for lawful processing and proper authorization of subscriber account changes.ESAEPDGDPR€200,000
05 Dec 2024KASPRThe CNIL imposed an administrative fine of EUR 200,000 on KASPR on 5 December 2024. The authority found GDPR breaches relating to lawful basis, retention, transparency, information, and access rights in connection with KASPR's data scraping activities.FRCNILGDPR€200,000
05 Dec 2024SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES under a simplified procedure. The case concerns a data protection breach identified by the authority.FRCNILGDPR€20,000
05 Dec 2024KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights.FRCNILGDPR€240,000
09 Dec 2024SOBLADA RESTAURACIÓN, S.L.SOBLADA RESTAURACIÓN, S.L. was fined by the AEPD EUR 4,500 for installing a video surveillance system without proper signage. The company also failed to inform employees about the system and its purposes, breaching GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€4,500
10 Dec 2024un operatorANSPDCP imposed a fine of 10,000 RON on un operator for non-compliance with the law. A warning was also issued.ROANSPDCPGDPR€2,012
11 Dec 2024INSTITUTO RAIMON GAJA, S.L.INSTITUTO RAIMON GAJA, S.L. was fined by the AEPD 2,000 EUR for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI, despite the recipient’s request to stop receiving such messages.ESAEPDePrivacy€2,000