Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Aug 2024EDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTSEDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTS was fined EUR 300,000 by the CNIL. The case concerns a breach of personal data protection rules.FRCNILGDPR€300,000
29 Aug 2024Apoteket AB, gällande Meta-pixelApoteket AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€3,261,000
29 Aug 2024Apohem, gällande Meta-pixelApohem AB was fined by IMY 8,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel analytics tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€705,000
28 Aug 2024SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTEThe CNIL imposed an administrative fine of EUR 200,000 on SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTE. The case concerns a breach of data protection rules supervised by the French authority.FRCNILGDPR€200,000
28 Aug 2024SOCIETE SPECIALISEE DANS LA REALISATION D'ETUDES STATISTIQUES EN MATIERE DE DONNEES DE SANTECNIL imposed an administrative fine of 800,000 EUR on SOCIETE SPECIALISEE DANS LA REALISATION D'ETUDES STATISTIQUES EN MATIERE DE DONNEES DE SANTE. The decision concerns violations related to data processing and should be assessed against applicable data protection obligations.FRCNILGDPR€800,000
27 Aug 2024YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine.BEAPDGDPR€8,000
26 Aug 2024Uber Technologies Inc.Uber Technologies Inc. was fined by the Dutch data protection authority AP in the amount of EUR 290,000,000. The authority found that the company transferred personal data to the United States without appropriate safeguards, in breach of Article 44 GDPR.NLAPGDPR€290,000,000
23 Aug 2024Geanonimiseerd (APD 107/2024)The APD Litigation Chamber imposed a EUR 5,000 fine for responding to a data subject access request after more than 14 months. The authority found a breach of GDPR Articles 12 and 15, which require timely handling of access rights.BEAPDGDPR€5,000
22 Aug 2024Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements.ROANSPDCPGDPR€3,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined EUR 3,000 by ANSPDCP for a data security breach. The case concerns an incident involving personal data protection that resulted in an administrative sanction.ROANSPDCPGDPR€3,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined by ANSPDCP €2,000 for a data security breach. The case concerned an incident affecting data protection and required supervisory authority action.ROANSPDCPGDPR€2,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for a data security breach. The case concerns an incident affecting data protection and resulted in an administrative sanction.ROANSPDCPGDPR€2,000
20 Aug 2024Ana Hotels SRLAna Hotels SRL was fined by ANSPDCP €8,000 after a data security incident caused by a ransomware attack. The incident led to unauthorized disclosure of personal data belonging to a significant number of employees.ROANSPDCPGDPR€8,000
20 Aug 2024Dane anonimowe (X. S.A.)The UODO imposed an administrative fine of PLN 4,053,173 on X. S.A. for breaching Article 34(1) and (2) of the GDPR. The case concerned failure to meet the obligations to notify affected individuals about a personal data breach.PLUODOGDPR€950,000
20 Aug 2024HEBERGEUR DE SITE WEB (procédure simplifiée)The CNIL imposed an administrative fine of 8,000 EUR on HEBERGEUR DE SITE WEB under a simplified procedure. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€8,000
16 Aug 2024D*** Handels Ges.m.b.H.D*** Handels Ges.m.b.H. was fined by the DSB for unlawfully processing personal data through a video surveillance system without a legal basis. The authority also found a breach of the data minimization principle.ATDSBGDPR€1,500,000
15 Aug 2024Coastal Windows & Conservatories (UK) LimitedCoastal Windows & Conservatories (UK) Limited made more than 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people who said they had not consented to the calls or continued to receive them after asking for the calls to stop.GBICOGDPR€46,720
14 Aug 2024GRUPO INMOBILIARIO GONTEGA, S.L.GRUPO INMOBILIARIO GONTEGA, S.L. was fined by the AEPD EUR 450 for failing to properly handle a data access request. The authority found a breach of Article 15 GDPR and non-compliance with its resolution.ESAEPDGDPR€450
14 Aug 2024Vejen KommuneVejen Kommune was fined by Datatilsynet for insufficient security measures after stolen computers containing children's data were found to be unencrypted. The case also revealed up to 300 other unencrypted computers in the municipality.DKDatatilsynetGDPR€26,802
08 Aug 2024ASOCIACIÓN SOCIO CULTURAL Y HUMANITARIA VIRGEN DE COROMOTOThe organization was fined 600 EUR by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerned non-compliance with the authority’s powers under Article 58.1 of the GDPR.ESAEPDGDPR€600