Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jun 2020NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations.GRHDPAGDPR€5,000
12 May 2021KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued.GRHDPAGDPR€5,000
15 Jan 2018Alkis Alqi Zarbala ZarballaA fine was imposed for operating a video surveillance system without the required notification and for monitoring employee workspaces. These actions breached data protection rules.GRHDPAGDPR€1,000
09 Oct 2018OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact.GRHDPAePrivacy€150,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000.GRHDPAGDPR€3,000
13 Jun 2025Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring.GRHDPAGDPR€2,000
20 Nov 2006Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data.GRHDPAGDPR€15,000
04 Sept 2024Agrotikos Elaiourgikos Synetairismos StylidasAgrotikos Elaiourgikos Synetairismos Stylidas was fined EUR 2,000 by the HDPA. The authority found breaches of data minimization and transparency principles, as well as inadequate technical and organizational measures in its video surveillance system.GRHDPAGDPR€2,000
29 Apr 2022Fire Brigade HeadquartersA fine of EUR 5,000 was imposed for failing to respond to a data access request. The breach concerned access rights under the GDPR and national law.GRHDPAGDPR€5,000
08 Aug 2014Anonymised (HDPA 104/2014)The supervisory authority found that the controller processed personal data without the data subjects' consent. The breach concerned the principles governing data processing under Greek law.GRHDPAGDPR€6,000
25 Sept 2023OASAThe Athens Urban Transport Organization (OASA) was fined for failing to timely conduct a Data Protection Impact Assessment (DPIA) for its Automatic Fare Collection System. The authority found this to be a breach of data protection principles in connection with the system's processing activities.GRHDPAGDPR€20,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default.GRHDPAGDPR€2,000
24 Mar 2022Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
22 Jun 2017Vodafone-PanafonVodafone-Panafon was fined EUR 10,000 by the HDPA for a significant delay in responding to a data subject access request. The authority found a breach of Article 12 of Law L.2472/1997.GRHDPAGDPR€10,000
21 Oct 2014ACDACD was fined by the HDPA 1,000 EUR for sending unsolicited marketing emails without the recipients’ consent. This breached Article 11 of Law 3471/2006.GRHDPAePrivacy€1,000
24 Jun 2025I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements.GRHDPAGDPR€1,000
21 Aug 2018National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations.GRHDPAGDPR€5,000
27 May 2024Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose.GRHDPAGDPR€5,000
27 Dec 2012Euro-Catering O.E.The company was fined for failing to comply with a prior decision by the authority. It was noted that it no longer operated the stores concerned and that its financial situation was difficult.GRHDPAGDPR€10,000
25 Jul 2013Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements.GRHDPAGDPR€1,000