Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Oct 2024Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules.ITGaranteGDPR€60,000
17 Oct 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on CHIRURGIEN DENTISTE under a simplified procedure. The authority also issued an injunction, indicating that remedial action is required.FRCNILGDPR€3,000
17 Oct 2024AziendaThe company was fined for failing to implement adequate security measures, which led to a data breach affecting a large number of individuals. The case indicates insufficient protection of personal data and elevated risk to data subjects.ITGaranteGDPR€25,000
17 Oct 2024la SocietàThe company was fined EUR 7,000 by the Garante for violations related to security measures in handling online medical reports and data. The case concerned insufficient safeguards for processed medical information.ITGaranteGDPR€7,000
17 Oct 2024Ente di Supporto Tecnico Amministrativo Regionale DirezionaleEnte di Supporto Tecnico Amministrativo Regionale Direzionale was fined 5,000 EUR by the Garante for improper handling of personal data during a public selection process. The issue concerned the transmission of files with incorrect names, even though the content was correct.ITGaranteGDPR€5,000
17 Oct 2024Immobiliare Pianezza S.r.l.s.Immobiliare Pianezza S.r.l.s. was fined €5,000 by the Garante for making unsolicited marketing calls without consent. The authority also noted a failure to respond to requests for deletion of personal data.ITGaranteGDPR€5,000
17 Oct 2024ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency.ITGaranteGDPR€8,000
16 Oct 2024D**** GmbHThe company appointed its managing director as the data protection officer, creating a conflict of interest. The DSB found this breached Article 38(6) GDPR and imposed a fine of EUR 5,000.ATDSBGDPR€5,000
16 Oct 2024Your Consulting SRLThe national supervisory authority completed an investigation into Your Consulting SRL and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed.ROANSPDCPGDPR€3,000
15 Oct 2024CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD in the amount of EUR 6,000 for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR and Article 58.2 of the GDPR.ESAEPDGDPR€6,000
15 Oct 2024Quick Tax Claims LimitedThe ICO found that Quick Tax Claims Limited sent 7,863,547 unlawful text messages over one month, generating 66,793 complaints. In 93% of complaints, recipients said there was no opt-out option, and the company had bought personal data from suppliers without valid consent.GBICOGDPR€143,000
15 Oct 2024TERRA, BRASA Y MAR, S.L.TERRA, BRASA Y MAR, S.L. was fined 500 EUR by the AEPD for adding the complainant's phone number to a WhatsApp group without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€500
15 Oct 2024AFP GESTION DEL COLOR, S.L.AFP GESTION DEL COLOR, S.L. was fined by the AEPD in the amount of €1,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€1,000
14 Oct 2024ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD EUR 50,000 for publishing a video containing violent content and the voices of the aggressors and the victim. The authority found a breach of data protection rules.ESAEPDGDPR€50,000
14 Oct 2024National Debt Advice LimitedNational Debt Advice Limited sent 129,902 unsolicited direct marketing text messages, breaching regulation 22 of PECR. The activity generated more than 4,000 complaints to the 7726 spam reporting service. The ICO imposed a £30,000 fine and issued an enforcement notice.GBICOePrivacy€35,856
11 Oct 2024ORTHOPHONISTE (procédure simplifiée)The CNIL imposed a 4,000 EUR penalty on ORTHOPHONISTE (procédure simplifiée) in connection with the liquidation of an astreinte. The case concerns compliance with a prior obligation under the data protection authority’s supervision.FRCNILGDPR€4,000
10 Oct 2024Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice.GBICOePrivacy€47,796
10 Oct 2024Dane anonimowe (X w K.)The UODO imposed an administrative fine of PLN 15,000 on the entity identified as Anonymous data (X in K.). The authority found breaches of data protection principles, including integrity and confidentiality, accountability, data protection by design, processor obligations, and security measures.PLUODOGDPR€3,485
10 Oct 2024FEDERAL NAJANAJANA, S.L.FEDERAL NAJANAJANA, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial messages via WhatsApp without the recipient’s explicit consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
10 Oct 2024SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIEThe CNIL imposed an administrative fine of EUR 750,000 on SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIE. The record indicates a regulatory breach, but no further details are provided.FRCNILGDPR€750,000