Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Sept 2017Little Kook - K. Tzortzis – I. Thanos I.K.EThe company was fined EUR 7,000 by the HDPA for operating a video surveillance system without proper notification to the authority. It also monitored employee workspaces, which breached privacy requirements.GRHDPAGDPR€7,000
12 May 2017Strategy MentorThe fine was imposed for sending unsolicited marketing emails to a large number of recipients without prior consent. This conduct breached ePrivacy rules governing electronic marketing communications.GRHDPAePrivacy€75,000
26 Feb 2015Anonymised (HDPA 26/2015)The company was fined for unlawful collection and processing of personal data, and for sending unsolicited marketing emails without recipients’ consent. The case concerns breaches of core data protection principles and the requirement to obtain prior consent for marketing communications.GRHDPAePrivacy€1,000
22 Jun 2017Bolos & SynergatesThe law firm Bolos & Synergates was fined EUR 1,000 by the HDPA for unlawfully collecting and using personal data for direct marketing. The violation involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€1,000
06 Sept 2013Groupon Greece Monoprosopi Etaireia Periorismenis EfthynisGroupon Greece was fined by the HDPA for failing to inform customers that their credit card data was stored by a third party. The authority found this to be a breach of data protection law.GRHDPAePrivacy€1,500
14 Jul 2021Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules.GRHDPAGDPR€2,000
11 Jul 2025NN HellasNN Hellas was fined EUR 20,000 for failing to satisfy the complainant’s access request concerning recorded telephone conversations. The authority found a violation of Article 15 GDPR.GRHDPAGDPR€20,000
26 May 2014General Hospital PapageorgiouGeneral Hospital Papageorgiou was fined EUR 1,000 by the HDPA for transferring sensitive health data without prior authorization. The hospital also failed to inform the data subject, breaching Greek data protection law.GRHDPAGDPR€1,000
09 Oct 2018Vodafone-PanafonVodafone-Panafon was fined by the HDPA for making unsolicited marketing calls to subscribers who had opted out of such contact. The authority found that the conduct breached privacy and data protection rules.GRHDPAePrivacy€12,000
08 Jan 2015OTEThe Hellenic Data Protection Authority fined OTE EUR 60,000 for failing to implement adequate security measures. The deficiency led to a data breach involving personal data of a large number of subscribers.GRHDPAePrivacy€60,000
07 Jul 2015OLYMPION XENODOXEION AEThe company was fined by the HDPA EUR 5,000 for failing to implement appropriate organizational and technical security measures. The deficiency led to a data breach involving credit card information.GRHDPAGDPR€5,000
07 Apr 2021Ignatiadis Nikolaos and SIA E.E.The company was fined for unlawfully using a surveillance camera to monitor employees. The authority found a breach of data protection principles and an absence of a valid legal basis for processing.GRHDPAGDPR€2,000
08 Aug 2014PARAMOUNT A.E.The company was fined EUR 5,000 by the HDPA for processing publicly available personal data without consent. The authority found a breach of the principles of lawful data collection and proportionality.GRHDPAGDPR€5,000
13 Jun 2025Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage.GRHDPAGDPR€1,000
11 Jul 2025MEDIADENTMEDIADENT was fined for failing to cooperate with the supervisory authority. The case concerned Article 31 GDPR, which requires controllers and processors to cooperate with the authority during its work.GRHDPAGDPR€2,000
04 Aug 2017VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing.GRHDPAGDPR€10,000
21 Aug 2018Alpha BankAlpha Bank was fined by the HDPA for failing to maintain and process accurate data of its debtors. The authority found that the bank’s conduct breached data protection requirements.GRHDPAGDPR€10,000
19 May 2011Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications.GRHDPAePrivacy€2,000
07 Apr 2021MZN HELLAS A.E.The company was fined for sending unsolicited marketing SMS messages to a customer who had explicitly objected to such communications. The authority found this to be a breach of GDPR rules on data subject rights and data protection by design.GRHDPAGDPR€20,000
08 Aug 2014Compass ExpoCompass Expo was fined EUR 10,000 by the HDPA for sending unsolicited electronic communications without recipients' consent. The authority found a breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€10,000