Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Aug 2017VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing.GRHDPAGDPR€10,000
21 Aug 2018Alpha BankAlpha Bank was fined by the HDPA for failing to maintain and process accurate data of its debtors. The authority found that the bank’s conduct breached data protection requirements.GRHDPAGDPR€10,000
19 May 2011Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications.GRHDPAePrivacy€2,000
07 Apr 2021MZN HELLAS A.E.The company was fined for sending unsolicited marketing SMS messages to a customer who had explicitly objected to such communications. The authority found this to be a breach of GDPR rules on data subject rights and data protection by design.GRHDPAGDPR€20,000
08 Aug 2014Compass ExpoCompass Expo was fined EUR 10,000 by the HDPA for sending unsolicited electronic communications without recipients' consent. The authority found a breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€10,000
05 Jul 2022Global Greece MEPEThe company was fined for sending unsolicited marketing emails without obtaining the recipients’ prior explicit consent. The authority found this conduct to be in breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
20 Jun 2022Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights.GRHDPAGDPR€2,000
30 May 2018Alpha BankAlpha Bank was fined by the HDPA for failing to respond to a data subject access request within the prescribed timeframe. The case concerned Article 12 of Law 2472/1997 and the bank’s obligations to facilitate data subject rights.GRHDPAGDPR€10,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 4,000 EUR for failing to notify the data breach to the supervisory authority and the affected data subjects in a timely manner. The case indicates non-compliance with the statutory notification deadlines following a security incident.GRHDPAGDPR€4,000
20 Nov 2006Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject.GRHDPAGDPR€3,000
11 Nov 2011Galineio Melathro Private ClinicThe clinic unlawfully disclosed sensitive personal data without the required authorization from the HDPA. The breach involved special-category personal data and resulted in a 2,000 EUR fine.GRHDPAGDPR€2,000
08 Aug 2014L & J ELLAS ANONYMOUS VIOMICHANIKI KAI EMPORIKI ETAIREIA AUTOKINITON-EPISIMOS EISAGOGEAS OCHIMATON LANCIA & JEEPThe company was fined by the HDPA 1,000 EUR for processing publicly available personal data without consent. The authority also found that it lacked a written data processing agreement with a third party.GRHDPAGDPR€1,000
13 Jan 2023Intellexa A.E.Intellexa A.E. was fined EUR 50,000 by the HDPA. The authority found that the company failed to cooperate with the supervisory authority as required under Article 31 of the GDPR.GRHDPAGDPR€50,000
08 Jan 2015CHRYSOS ODIGOS ENTYPH & HLEKTRONIKI PLHROFORISI A.E.The company was fined by the HDPA EUR 10,000 for processing personal data without consent. The authority also found that it failed to respond to data subjects' requests for access and objection.GRHDPAGDPR€10,000
20 Mar 2015IANO OIKONOMIKE EKDOSEIS AEIANO OIKONOMIKE EKDOSEIS AE was fined EUR 30,000 by the HDPA for sending unsolicited electronic communications. The company collected a large number of email addresses without consent, breaching data protection rules.GRHDPAePrivacy€30,000
16 May 2019ANANEOSI MONOPROSOPI E.P.E.The company was fined for making unsolicited marketing calls to subscribers registered on the opt-out list. It also failed to properly identify itself during the calls, which hindered data subjects’ ability to exercise their rights.GRHDPAePrivacy€5,000
30 Jul 2013GLOBAL GREECE M.E.P.EThe company was fined for sending marketing emails without obtaining subscribers' consent. The authority found a breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€5,000
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information.GRHDPAGDPR€7,500
24 May 2022Anonymised (HDPA 26/2022)A fine of EUR 2,000 was imposed for sending unsolicited political communication by SMS without the recipient's prior consent. The authority treated this as a breach of data protection and electronic communications rules.GRHDPAePrivacy€2,000
08 Mar 2017Elliniki Etaireia Systimikon MeletonThe company was fined by the HDPA for illegally collecting and using personal data for direct marketing purposes. The infringement involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€3,000