Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Apr 2022Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization.BGCPDPGDPR€1,534
23 Jul 2019община К.The Municipality of K. unlawfully processed the complainant’s personal data by sharing it with third parties without consent. The authority found a GDPR breach and imposed a 500 BGN fine.BGCPDPGDPR€256
03 Sept 2019А.Т.The CPDP imposed a fine of 23,000 BGN on A.T. for processing personal data without consent, in breach of Article 6 GDPR. The case concerned the creation of financial obligations for the complainant without a valid contract.BGCPDPGDPR€11,760
17 Jan 2019Учебно заведениеThe school was fined 1,000 BGN by the CPDP for unlawfully processing students' personal data. It shared the data with a financial institution without proper consent, which breached GDPR requirements.BGCPDPGDPR€511
12 Sept 2019Anonymised (CyDPC ΑΝΩΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ ΔΗΜΟΠΡ)A complaint was filed against an individual for using personal data without consent to contact the complainant about a property sale. The Commissioner found a breach of Article 6 GDPR and imposed a fine of EUR 2,000.CYCyDPCGDPR€2,000
10 Mar 2025Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements.CYCyDPCGDPR€10,000
21 Sept 2022Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32.CYCyDPCGDPR€5,000
31 Mar 2022Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31.CYCyDPCGDPR€1,500
03 Feb 2022Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent.CYCyDPCGDPR€2,000
07 Dec 2023Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data.CYCyDPCGDPR€1,500
03 Feb 2023Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls.CYCyDPCGDPR€3,250
17 Sept 2021Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR.CYCyDPCGDPR€10,000
16 Jan 2023Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€10,000
06 Sept 2019Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data.CYCyDPCGDPR€14,000
16 Jun 2025Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards.CYΕπίτροπος Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
17 May 2023Breikot Management LtdBreikot Management Ltd was fined EUR 3,000 by the CyDPC for publishing personal data, including names and photos. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€3,000
24 Jul 2018Anonymizováno (ÚOOÚ UOOU-00078/17-47)The entity was fined CZK 400,000 by the UOOU for processing customers' personal data without their consent. The authority found this conduct to be in breach of the Czech Data Protection Act.CZUOOUGDPR€15,528
25 Oct 2021Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services.CZUOOUePrivacy€1,166
07 Apr 2021Anonymizováno (ÚOOÚ UOOU-03058/20-30)The entity did not respond to a data subject's request to delete personal data from a publicly accessible auction notice. The authority found this to be a breach of GDPR rights and imposed a monetary penalty.CZUOOUGDPR€386
11 May 2018Česká republika – Ministerstvo vnitraThe Ministry of the Interior was fined by UOOU for processing sensitive personal data, including DNA profiles, without explicit consent. The authority found this to be a breach of data protection law.CZUOOUGDPR€25,487