Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Dec 2024Anonymisiert (DSB 2024-0.796.258)The individual unlawfully processed intimate photos by transferring and storing them without the data subject’s consent. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€2,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT under a simplified procedure. The case concerns a breach of rules addressed by the supervisory authority.FRCNILGDPR€5,000
12 Dec 2024Start To Fly S.r.l.Start To Fly S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited emails and SMS messages to a complainant. The complainant was unable to unsubscribe from the mailing list despite multiple attempts.ITGaranteGDPR€10,000
12 Dec 2024Comune di Corte FrancaComune di Corte Franca was fined EUR 6,000 for publishing personal data online without a proper legal basis. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€6,000
12 Dec 2024Provvedimento del 12 dicembre 2024 [10095836]A doctor was fined EUR 20,000 for breaching core data protection principles. The authority cited failures relating to lawfulness, fairness, transparency, purpose limitation, data minimization, and integrity and confidentiality.ITGaranteGDPR€20,000
12 Dec 2024Istituto Comprensivo Statale CalenzanoIstituto Comprensivo Statale Calenzano was fined EUR 1,000 by the Garante for breaching data protection principles. The case concerned the processing of personal data without meeting the requirements of lawfulness, fairness, and transparency.ITGaranteGDPR€1,000
12 Dec 2024BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€20,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT. The case was handled under a simplified procedure.FRCNILGDPR€20,000
12 Dec 2024Comune di PorticiThe Garante fined Comune di Portici EUR 6,000 for breaches of data protection principles, including lawfulness, fairness, and transparency. The authority also found that the municipality failed to carry out a data protection impact assessment before processing personal data through video surveillance.ITGaranteGDPR€6,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT under a simplified procedure. The decision dates from 12 December 2024.FRCNILGDPR€10,000
12 Dec 2024SOCIETE DE VENTE AU DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE DE VENTE AU DETAIL under a simplified procedure. The decision concerns a breach of rules within the CNIL's remit.FRCNILGDPR€18,000
12 Dec 2024AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€6,000
11 Dec 2024INSTITUTO RAIMON GAJA, S.L.INSTITUTO RAIMON GAJA, S.L. was fined by the AEPD 2,000 EUR for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI, despite the recipient’s request to stop receiving such messages.ESAEPDePrivacy€2,000
11 Dec 2024Granit Bostad Beritsholm ABGranit Bostad Beritsholm AB was fined by IMY for conducting video surveillance without a lawful basis. The authority also found that required information was not provided to affected individuals, constituting a GDPR breach.SEIMYGDPR€17,366
10 Dec 2024un operatorANSPDCP imposed a fine of 10,000 RON on un operator for non-compliance with the law. A warning was also issued.ROANSPDCPGDPR€2,012
09 Dec 2024SOBLADA RESTAURACIÓN, S.L.SOBLADA RESTAURACIÓN, S.L. was fined by the AEPD EUR 4,500 for installing a video surveillance system without proper signage. The company also failed to inform employees about the system and its purposes, breaching GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€4,500
05 Dec 2024ESL Consultancy Services Ltd Between 15 September 2022 and 5 December 2023, 37,977 complaints were received about direct marketing messages sent at the instigation of ESL Consultancy Services Ltd. The ICO fined the company GBP 200,000 and issued an enforcement notice.GBICOGDPR€241,000
05 Dec 2024SOCIETE VENDANT DES PRODUITS COSMETIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE VENDANT DES PRODUITS COSMETIQUES. The case was handled under a simplified procedure.FRCNILGDPR€3,000
05 Dec 2024CLINIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on CLINIQUE (procédure simplifiée). The case concerns a regulatory breach that resulted in an administrative sanction.FRCNILGDPR€15,000
05 Dec 2024SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEURThe CNIL imposed an administrative fine of EUR 240,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEUR and issued an injunction. The case concerns identified regulatory breaches.FRCNILGDPR€240,000