Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Dec 2023Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data.CYCyDPCGDPR€1,500
12 Sept 2019Anonymised (CyDPC ΑΝΩΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ ΔΗΜΟΠΡ)A complaint was filed against an individual for using personal data without consent to contact the complainant about a property sale. The Commissioner found a breach of Article 6 GDPR and imposed a fine of EUR 2,000.CYCyDPCGDPR€2,000
06 Sept 2019Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data.CYCyDPCGDPR€14,000
15 Dec 2021Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR.LUCNPDGDPR€11,600
09 Nov 2021Anonymisé (CNPD decision-44-fr-2021)The company failed to meet the GDPR information obligations under Article 13 and the data minimization principle under Article 5(1)(c), particularly in connection with video surveillance. CNPD imposed a fine of 1,500 EUR.LUCNPDGDPR€1,500
27 Oct 2021Anonymisé (CNPD decision-41-fr-2021)The CNPD imposed a fine of 18,700 EUR on Anonymisé for improper implementation of Data Protection Officer obligations. The company did not publish the DPO’s contact details, did not involve the DPO in all data protection matters, did not ensure the DPO’s autonomy, and did not assign monitoring of GDPR compliance.LUCNPDGDPR€18,700
13 Oct 2021Anonymisé (CNPD decision-36-fr-2021)The company did not involve the Data Protection Officer in all matters related to personal data protection. CNPD found this breached GDPR Articles 38(1) and 39(1) and imposed a EUR 23,400 fine.LUCNPDGDPR€23,400
06 Oct 2021Anonymisé (CNPD decision-35-fr-2021)The company was fined by the CNPD in the amount of 5,300 EUR for breaching GDPR requirements. The authority found that it failed to provide adequate information to data subjects and did not comply with the data minimization principle.LUCNPDGDPR€5,300
05 Aug 2021Anonymisé (CNPD decision-31-fr-2021)The company sent emails containing sensitive medical data to incorrect recipients. The authority also found a breach of data protection duties due to improper documentation of the incidents.LUCNPDGDPR€275,000
04 Aug 2021Anonymisé (CNPD decision-30-fr-2021)The public establishment failed to communicate the DPO’s contact details to the supervisory authority and did not provide the DPO with the resources needed to perform the role effectively. CNPD found breaches of GDPR Articles 37(7), 38(2), and 39(1)(b) and imposed a fine of 6,600 EUR.LUCNPDGDPR€6,600
04 Aug 2021Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39.LUCNPDGDPR€17,700
15 Jul 2021Anonymisé (CNPD decision-27-fr-2021)The company did not meet GDPR requirements to inform individuals about data processing, especially in relation to video surveillance and employee notices. CNPD treated this as a breach of the information obligations owed to data subjects.LUCNPDGDPR€3,500
13 Dec 2022Anonymisé (CNPD decision-24-fr-2022)The entity failed to meet GDPR transparency obligations, particularly regarding the accessibility and comprehensibility of information provided to data subjects. CNPD imposed a fine of EUR 3,700.LUCNPDGDPR€3,700
29 Jun 2021Anonymisé (CNPD decision-24-fr-2021)The company was fined EUR 17,000 by the CNPD for breaching the data minimization principle and for failing to provide adequate information to data subjects. The deficiencies concerned employees and third parties in relation to processing activities.LUCNPDGDPR€17,000
13 Dec 2022Anonymisé (CNPD decision-23-fr-2022)The company failed to meet the transparency obligations under Article 12(1) GDPR by not providing the required information in a concise, transparent, and easily accessible manner. CNPD treated this as a breach of the information duties owed to data subjects.LUCNPDGDPR€1,300
13 Dec 2022Anonymisé (CNPD decision-22-fr-2022)The CNPD found that the entity breached GDPR transparency obligations by failing to provide information in a concise, transparent, and easily accessible manner. The infringement concerned Articles 12 and 13 of the GDPR.LUCNPDGDPR€1,700
11 Jun 2021Anonymisé (CNPD decision-22-fr-2021)The company failed to comply with GDPR requirements on data minimization and transparency. It also did not adequately inform individuals about video surveillance and geolocation systems, breaching Articles 5(1)(c), 5(1)(e), 13, and 32(1) of the GDPR.LUCNPDGDPR€7,200
13 Dec 2022Anonymisé (CNPD decision-21-fr-2022)The company was fined EUR 3,700 by the CNPD for breaching the transparency obligations under Article 12(1) of the GDPR. The authority found that information was not sufficiently accessible to users.LUCNPDGDPR€3,700
11 Jun 2021Anonymisé (CNPD decision-21-fr-2021)The company did not comply with the data minimization principle and failed to adequately inform employees and third parties about data processing activities. CNPD found these practices to breach GDPR Articles 5(1)(c) and 13.LUCNPDGDPR€7,600
13 Dec 2022Anonymisé (CNPD decision-20-fr-2022)The entity failed to meet GDPR transparency obligations, particularly by not providing information in a clear and accessible manner. CNPD imposed a fine of 4,200 EUR.LUCNPDGDPR€4,200