Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Sept 2024Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements.ITGaranteGDPR€10,000
26 Sept 2024CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records.ITGaranteGDPR€4,000
26 Sept 2024SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRECNIL imposed an administrative fine of EUR 250,000 on SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRE. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€250,000
26 Sept 2024SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUESCNIL imposed an administrative fine of EUR 150,000 on SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUES. The decision was issued on 26 September 2024.FRCNILGDPR€150,000
24 Sept 2024SIA "ĀRES J & T"A fine of 500 EUR was imposed on SIA "ĀRES J & T" by the DVI. The decision has entered into force.LVDVIGDPR€500
23 Sept 2024PPC ENERGIE MUNTENIA S.A.In September 2024, ANSPDCP completed an investigation into PPC ENERGIE MUNTENIA S.A. and found violations of GDPR provisions. The company was fined EUR 2,000.ROANSPDCPGDPR€2,000
19 Sept 2024GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.GACM Seguros was fined 8,000 EUR by the AEPD for improperly sharing personal data related to an insurance claim with another insured party. The authority found a breach of data protection rules.ESAEPDGDPR€8,000
19 Sept 2024ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN. The case was handled under a simplified procedure.FRCNILGDPR€20,000
19 Sept 2024CRIDOLMA BARCELONA S.L.CRIDOLMA BARCELONA S.L. was fined €9,000 by the AEPD for failing to properly handle a data subject access request. The case concerned a breach of Article 15 GDPR and non-compliance with a data protection authority resolution.ESAEPDGDPR€9,000
18 Sept 2024Paula Stradiņa klīniskā universitātes slimnīcaA fine of EUR 2,000 was imposed. The decision has entered into force.LVDVIGDPR€2,000
17 Sept 2024Constanța South Container Terminal SRLConstanța South Container Terminal SRL was fined by ANSPDCP EUR 3,000 after a third party gained unauthorized access to employees’ personal data. The breach resulted from inadequate security measures on a publicly accessible file management platform.ROANSPDCPGDPR€3,000
16 Sept 2024SC Class IT Outsourcing SRLSC Class IT Outsourcing SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
16 Sept 2024Vodafone România SAVodafone România SA was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to respond to a request to exercise the GDPR rights of access and erasure.ROANSPDCPGDPR€3,000
13 Sept 2024DIGITAL PHOTO IMAGE, S.A.DIGITAL PHOTO IMAGE, S.A. was fined EUR 20,000 by the AEPD for breaching the LSSI. The company sent emails without providing recipients with a valid means to exercise their right to stop receiving such communications.ESAEPDePrivacy€20,000
13 Sept 2024COMMUNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMUNE (procédure simplifiée) and issued an injunction. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€20,000
13 Sept 2024ARES CAPITAL, S.A.ARES CAPITAL, S.A. was fined by the AEPD for requiring employees to use personal phones for work together with continuous monitoring apps. The authority found that the company did not provide sufficient information about data collection, breaching GDPR rules on lawful basis, transparency, and data processing principles.ESAEPDGDPR€200,000
12 Sept 2024Medic4All Italia S.r.l.Medic4All Italia S.r.l. was fined by the Garante 15,000 EUR for failing to respond to a data subject access request. The conduct breached Article 15 GDPR, which requires controllers to provide access to personal data upon request.ITGaranteGDPR€15,000
12 Sept 2024Top Quality Corporation S.r.l.s.Top Quality Corporation S.r.l.s. was fined by the Garante 5,000 EUR for failing to respond to a data subject’s request to access personal data related to employment. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
12 Sept 2024Ordine delle Professioni Infermieristiche di UdineOrdine delle Professioni Infermieristiche di Udine was fined 8,000 EUR by the Garante for breaches of data protection rules. The authority found improper disclosure of data to third parties and a failure to provide proper information to data subjects.ITGaranteGDPR€8,000
12 Sept 2024SOCIETE EXPLOITANT UN CASINO ET UN HOTEL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 12,000 on SOCIETE EXPLOITANT UN CASINO ET UN HOTEL under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€12,000