Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Sept 2022Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police.GRHDPAGDPR€3,000
09 Sept 2022Anonymised (HDPA 48/2022)The mayor of a municipality was fined for sending unsolicited emails without the recipients’ consent. The authority found breaches of GDPR transparency and purpose limitation principles.GRHDPAGDPR€2,000
14 Jul 2021Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules.GRHDPAGDPR€2,000
16 Jun 2010Anonymised (HDPA 29/2010)The company was fined EUR 3,000 by the HDPA for sending unsolicited marketing emails and faxes without subscriber consent. This conduct breached ePrivacy rules on electronic marketing communications.GRHDPAePrivacy€3,000
16 Jun 2010Anonymised (HDPA 29/2010)The company was fined 3,000 EUR by the HDPA for unlawfully processing email addresses without prior consent. This conduct breached Greek data protection law.GRHDPAGDPR€3,000
24 May 2022Anonymised (HDPA 26/2022)A fine of EUR 2,000 was imposed for sending unsolicited political communication by SMS without the recipient's prior consent. The authority treated this as a breach of data protection and electronic communications rules.GRHDPAePrivacy€2,000
26 Feb 2015Anonymised (HDPA 26/2015)The company was fined for unlawful collection and processing of personal data, and for sending unsolicited marketing emails without recipients’ consent. The case concerns breaches of core data protection principles and the requirement to obtain prior consent for marketing communications.GRHDPAePrivacy€1,000
20 Jun 2022Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights.GRHDPAGDPR€2,000
13 Jun 2025Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage.GRHDPAGDPR€1,000
13 Jun 2025Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring.GRHDPAGDPR€2,000
27 Sept 2022Anonymised (HDPA 18/2022)A fine was imposed for sending unsolicited political communication via SMS without prior consent. The case concerns a breach of consent requirements for political and marketing communications.GRHDPAePrivacy€2,000
24 Mar 2022Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
18 Dec 2013Anonymised (HDPA 154/2013)The HDPA imposed a fine of EUR 3,000 on the company for unlawfully collecting an individual's creditworthiness data. The case concerned processing without a valid legal basis, which breaches data protection rules.GRHDPAGDPR€3,000
04 Apr 2022Anonymised (HDPA 15/2022)The former mayor disclosed a municipal employee’s personal data without consent or a lawful basis. The authority found this to be a breach of GDPR principles of lawfulness and purpose limitation.GRHDPAGDPR€5,000
29 Dec 2017Anonymised (HDPA 151/2017)The controller of the blog dexiextrem.blogspot.gr was fined EUR 2,000 for failing to comply with the data subject’s right to object to the processing of personal data. The authority found a breach of Article 13 of Law 2472/1997 in connection with the publication of personal data.GRHDPAGDPR€2,000
03 Sept 2014Anonymised (HDPA 119/2014)A fine was imposed for the unlawful collection and processing of personal data, including email addresses, and for sending unsolicited marketing emails without subscriber consent. The case concerns breaches of lawful processing requirements and the need for prior consent for marketing communications.GRHDPAePrivacy€4,000
08 Aug 2014Anonymised (HDPA 115/2014)The controller was fined for processing personal data without consent and for sending unsolicited marketing messages. The case indicates breaches of core data protection and marketing communication obligations.GRHDPAePrivacy€1,500
08 Aug 2014Anonymised (HDPA 112/2014)The controller sent unsolicited marketing SMS messages without recipients' consent, breaching data protection rules. The case concerned the use of contact data for marketing without a valid legal basis.GRHDPAePrivacy€1,000
08 Aug 2014Anonymised (HDPA 104/2014)The supervisory authority found that the controller processed personal data without the data subjects' consent. The breach concerned the principles governing data processing under Greek law.GRHDPAGDPR€6,000
31 Mar 2022Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31.CYCyDPCGDPR€1,500