Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Mar 2022Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31.CYCyDPCGDPR€1,500
03 Feb 2022Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent.CYCyDPCGDPR€2,000
07 Dec 2023Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data.CYCyDPCGDPR€1,500
03 Feb 2023Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls.CYCyDPCGDPR€3,250
17 Sept 2021Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR.CYCyDPCGDPR€10,000
16 Jan 2023Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€10,000
06 Sept 2019Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data.CYCyDPCGDPR€14,000
16 Jun 2025Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards.CYΕπίτροπος Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
17 May 2023Breikot Management LtdBreikot Management Ltd was fined EUR 3,000 by the CyDPC for publishing personal data, including names and photos. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€3,000
06 Apr 2023К. Л. НK. L. N was fined for unlawfully processing voters' personal data. The case involved forwarding an email containing scanned voting lists to a personal email address, in breach of GDPR Article 6.BGCPDPGDPR€767
26 Feb 2019телекомуникационен операторThe telecommunications operator was fined BGN 53,000 by the CPDP for processing personal data without consent. The case involved changing a subscription plan to a prepaid service without the data subject's knowledge or agreement.BGCPDPGDPR€27,099
18 Oct 2019National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach.BGCommission for Personal Data ProtectionGDPR€2,607,000
26 Mar 2019А.Р. ЕООДThe CPDP imposed a 10,000 BGN fine on А.Р. ЕООД for processing personal data without consent. The case also involved registering an employment contract for an imprisoned individual, which breached Article 6 GDPR.BGCPDPGDPR€5,113
24 Jul 2019НОИThe National Social Security Institute (НОИ) was fined for failing to implement adequate technical and organizational measures to prevent employees from accessing personal data without authorization. The authority found this to be a breach of GDPR Article 25.BGCPDPGDPR€2,557
26 Jan 2023Политическа партия ******The political party unlawfully processed personal data by including individuals in a list supporting its election registration without their consent. The authority found breaches of GDPR Articles 5, 6, and 24.BGCPDPGDPR€7,823
06 Jan 2020дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR.BGCPDPGDPR€5,113
12 Feb 2018Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing.BGCPDPGDPR€5,113
26 Oct 2021ЧСИ2The Commission fined the private bailiff ЧСИ2 for unlawfully processing personal data by accessing bank account information after the enforcement proceeding had ended. The authority found a breach of the purpose limitation principle under Article 5 GDPR.BGCPDPGDPR€383
08 Oct 2019Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure.BGCPDPGDPR€5,113
07 Oct 2019Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-657-08-0)The Bulgarian data protection authority, CPDP, fined an individual, V.M., BGN 1,000. The sanction concerned failure to provide access to information requested by the authority in connection with a complaint about unlawful dissemination of personal data.BGCPDPGDPR€511