Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Oct 2024Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000.ROANSPDCPGDPR€10,000
30 Oct 2024Untold SRLUntold SRL was fined EUR 5,000 by ANSPDCP for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
30 Oct 2024COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35.ESAEPDGDPR€10,000
29 Oct 2024AUTOMOCIÓN 1972, S.L.AUTOMOCIÓN 1972, S.L. was fined by the AEPD in the amount of 2,000 EUR for failing to comply with a data access request. The authority found a breach of GDPR obligations.ESAEPDGDPR€2,000
29 Oct 2024TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for allowing a SIM card to be duplicated without the customer's consent. The incident led to fraudulent activity on the customer's bank account, indicating serious weaknesses in identity verification and security controls.ESAEPDGDPR€200,000
29 Oct 2024Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security.NODatatilsynetGDPR€21,113
28 Oct 2024Vodafone România S.A.Vodafone România S.A. was fined by ANSPDCP EUR 5,000 for the unauthorized disclosure of email addresses. The breach resulted from failing to use the “BCC” option, which exposed recipients’ data and violated GDPR obligations.ROANSPDCPGDPR€5,000
28 Oct 2024HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD for failing to comply with data protection rules. The authority cited non-compliance with measures required under Article 58(2) GDPR.ESAEPDGDPR€15,000
25 Oct 2024IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€1,000
25 Oct 2024IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
23 Oct 2024SNOW INK SIERRA NEVADA, S.L.SNOW INK SIERRA NEVADA, S.L. was fined by the AEPD 4,000 EUR for using surveillance cameras that captured public areas, which breached data protection principles. Privacy masks were implemented during the sanctioning process.ESAEPDGDPR€4,000
23 Oct 2024ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)CNIL imposed a EUR 4,000 penalty on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES under a simplified procedure. The case concerns liquidation of an astreinte, indicating that a prior obligation was not fulfilled on time.FRCNILGDPR€4,000
23 Oct 2024Profi Rom Food SrlProfi Rom Food Srl was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€10,000
22 Oct 2024LinkedInThe Irish DPC fined LinkedIn EUR 310,000,000. The case concerns data processing violations and is currently under appeal.IEDPCGDPR€310,000,000
22 Oct 2024political partyThe Hellenic Data Protection Authority imposed a 10,000 EUR fine on a political party for unlawful processing of the personal data of overseas voters. The case concerns data protection breaches in the handling of electoral information.GRHellenic Data Protection AuthorityGDPR€10,000
18 Oct 2024X, ul.UODO imposed an administrative fine of PLN 25,000 on X, ul. for breaching Article 37(1)(a) and Article 37(7) of Regulation 2016/679. The authority also ordered the processing operations to be brought into compliance with GDPR requirements.PLUODOGDPR€5,803
17 Oct 2024SIA HERA fine of EUR 500 was imposed on SIA HER by the DVI. The decision entered into force on 17.10.2024.LVDVIGDPR€500
17 Oct 2024Giancarlo FranciniThe Garante imposed a EUR 6,500 fine on Giancarlo Francini for breaches related to the processing of health data. The authority found failures to meet transparency obligations and noted that data subject requests were answered only after a complaint was filed.ITGaranteGDPR€6,500
17 Oct 2024OK MOBILITY ESPAÑA, S.L.OK MOBILITY ESPAÑA, S.L. was fined by the AEPD in the amount of 100,000 EUR for failing to respond to a data access request. The authority cited breaches of GDPR Articles 5(1)(e), 13, and 15.ESAEPDGDPR€100,000
17 Oct 2024SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES). The case was handled under a simplified procedure.FRCNILGDPR€20,000