Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Dec 2024BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€20,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT. The case was handled under a simplified procedure.FRCNILGDPR€20,000
12 Dec 2024Comune di PorticiThe Garante fined Comune di Portici EUR 6,000 for breaches of data protection principles, including lawfulness, fairness, and transparency. The authority also found that the municipality failed to carry out a data protection impact assessment before processing personal data through video surveillance.ITGaranteGDPR€6,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT under a simplified procedure. The decision dates from 12 December 2024.FRCNILGDPR€10,000
12 Dec 2024SOCIETE DE VENTE AU DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE DE VENTE AU DETAIL under a simplified procedure. The decision concerns a breach of rules within the CNIL's remit.FRCNILGDPR€18,000
12 Dec 2024AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€6,000
17 Dec 2024ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN was fined EUR 750 by the AEPD for failing to comply with a data protection authority resolution. The case concerns Article 58(2) of the GDPR.ESAEPDGDPR€750
17 Dec 2024Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security.FITSVGDPR€950,000
17 Dec 2024Geanonimiseerd (APD 166/2024)The hospital was fined by the APD for failing to carry out a data protection impact assessment and for lacking effective information security policies. These deficiencies contributed to a ransomware incident affecting up to 300,000 individuals.BEAPDGDPR€50,000
17 Dec 2024UNICREDIT CONSUMER FINANCING IFN S.A.UNICREDIT CONSUMER FINANCING IFN S.A. was fined EUR 5,000 by ANSPDCP for processing former employees’ personal data without a legal basis. The authority found breaches of legality, security, and protection against unauthorized or unlawful processing arising from operational errors.ROANSPDCPGDPR€5,000
18 Dec 2024Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations.PLPresident of the Personal Data Protection Office (UODO)GDPR€132,000
18 Dec 2024Netflix International B.V.Netflix International B.V. was fined EUR 4,750,000 by the Dutch data protection authority AP. The authority found that the company did not provide sufficient information to customers in its privacy statement and in responses to data access requests, breaching GDPR transparency and information requirements.NLAPGDPR€4,750,000
18 Dec 2024GAOLANIA SERVICIOS, S.L.GAOLANIA SERVICIOS, S.L. was fined EUR 30,000 by the AEPD for breaching the GDPR data accuracy principle under Article 5(1)(d). The authority found a lack of diligence in handling data errors.ESAEPDGDPR€30,000
18 Dec 2024Dane anonimowe (C. S.A. z siedzibą w D. przy ul.)UODO imposed an administrative fine of PLN 261,918 on C. S.A. for breaches of GDPR obligations. The case concerned, among others, Article 38(3), Article 30(1), and Article 35(1) and (7) of Regulation 2016/679.PLUODOGDPR€61,514
18 Dec 2024Electrica Furnizare S.A.The National Supervisory Authority for Personal Data Processing completed an investigation in November 2024 at Electrica Furnizare S.A. and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed.ROANSPDCPGDPR€3,000
19 Dec 2024Altroconsumo Edizioni S.r.l.Altroconsumo Edizioni S.r.l. was fined by the Garante EUR 60,000 for sending unsolicited marketing emails despite unsubscribe requests. The authority also found deficiencies in obtaining valid consent and in the handling of personal data by third-party affiliates involved in the campaign.ITGaranteGDPR€60,000
19 Dec 2024SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed an administrative fine of EUR 8,000 on SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the source data.FRCNILGDPR€8,000
19 Dec 2024CENTRE D'APPEL (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on CENTRE D'APPEL under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€20,000
19 Dec 2024Comune di LevantoThe Garante fined Comune di Levanto 4,000 EUR for data protection breaches linked to video surveillance systems. The authority found violations of the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
19 Dec 2024Studio Riabilitazione Creditizia s.r.l.s.The Garante fined Studio Riabilitazione Creditizia s.r.l.s. €70,000 for improperly accessing financial data from the Central Credit Register without proper authorization. The authority found this conduct breached data protection principles.ITGaranteGDPR€70,000