Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Oct 2024WerepairUK LtdWerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The ICO fined the company 80,000 GBP and issued an enforcement notice.GBICOePrivacy€95,592
09 Oct 2024Pana AB, prowadzącego działalność gospodarczą pod firmą X, ul.The Polish DPA (UODO) imposed a fine of PLN 353,589 on Pana AB, operating under the name X, for breaches of the GDPR. The authority also ordered the company to bring its processing operations into compliance with Regulation (EU) 2016/679.PLUODOGDPR€82,273
08 Oct 2024SEAT, S.A.SEAT, S.A. was fined by the AEPD €20,000 for using cookies on its website without obtaining user consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€20,000
07 Oct 2024B*** GmbHB*** GmbH was fined EUR 600 by the Austrian Data Protection Authority (DSB). The penalty concerned a failure to cooperate in a data breach procedure, which breached Article 31 GDPR.ATDSBGDPR€600
07 Oct 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing.ESAEPDGDPR€200,000
04 Oct 2024DIAMOND FERVA, S.L.DIAMOND FERVA, S.L. was fined by the AEPD 1,000 EUR for installing a surveillance camera without properly informing data subjects and without the required authorization. The authority treated this as a breach of the information obligations under GDPR Article 13.ESAEPDGDPR€1,000
03 Oct 2024ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined EUR 5,000 by the AEPD for continuing to send marketing emails despite the recipient's unsubscribe requests. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
03 Oct 2024Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards.GBICOGDPR€890,000
02 Oct 2024Global Ports’s Services S.R.L.The company was fined for processing personal data without a legal basis, which breaches Article 6 of the GDPR. The case concerned unlawful processing by the controller.ROANSPDCPGDPR€2,000
01 Oct 2024TRIVE CREDIT SPAIN, S.L.TRIVE CREDIT SPAIN, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine for non-compliance with a prior resolution.ESAEPDGDPR€450,000
01 Oct 2024IBERCAJA BANCO, S.A.Ibercaja Banco, S.A. accessed personal data in the BADEXCUG EXPERIAN file 47 times without consent after the contractual relationship ended. The AEPD found this to be a breach of data protection rules and imposed a 300,000 EUR fine.ESAEPDGDPR€300,000
01 Oct 2024SERVACE, S.L.SERVACE, S.L. was fined by the AEPD EUR 1,400 for using an employee’s personal email address for work purposes without consent. The authority found this breached GDPR Articles 6(1) and 5(1)(f).ESAEPDGDPR€1,400
01 Oct 2024CONSULTORIA INTEGRAL DE ENERGÍA ECOLÓGICA, S.L.The company was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising messages to a complainant. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
30 Sept 2024ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE. The case concerns a breach of personal data protection rules under a simplified procedure.FRCNILGDPR€3,000
26 Sept 2024SOCIETE PROPOSANT DES SERVICES DE CONSEIL EN SYSTÈMES ET LOGICIELS INFORMATIQUES, L'EDITION ET LA REALISATION DE LOGICIELS (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€15,000
26 Sept 2024Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status.ITGaranteGDPR€17,000
26 Sept 2024Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules.ITGaranteGDPR€50,000
26 Sept 2024Meta Platforms Ireland Limited (MPIL)The Irish DPC imposed a fine of 91,000,000 EUR on Meta Platforms Ireland Limited. The case relates to an inquiry and is currently pending appeal.IEDPCGDPR€91,000,000
26 Sept 2024SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a EUR 3,000 penalty on SOCIETE DE MARKETING under a simplified procedure. The case concerns liquidation astreinte, meaning enforcement of a previously imposed monetary obligation.FRCNILGDPR€3,000
26 Sept 2024ORGANISME DE FORMATION DESTINE AUX PROFESSIONNELS DE SANTE (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR on ORGANISME DE FORMATION DESTINE AUX PROFESSIONNELS DE SANTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€15,000