Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Jul 2024Provvedimento del 17 luglio 2024 [10070330]The Garante imposed a fine of EUR 4,000 for violations related to the processing of health data. The case highlights the need to comply with data protection principles when handling special category data.ITGaranteGDPR€4,000
17 Jul 2024Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data.ITGaranteGDPR€22,000
17 Jul 2024Selectra S.p.A.Selectra S.p.A. was fined EUR 80,000 by the Garante for unlawfully accessing and retaining a former employee's email account after the end of the collaboration. The authority found that the company's conduct breached data protection rules.ITGaranteGDPR€80,000
17 Jul 2024Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures.ITGaranteGDPR€5,000,000
17 Jul 2024Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations.ITGaranteGDPR€5,000
16 Jul 2024A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6.NLAPGDPR€600,000
16 Jul 2024AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules.NLAutoriteit PersoonsgegevensGDPR€600,000
15 Jul 2024ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations.ESAEPDGDPR€200,000
12 Jul 2024CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients.ESAEPDGDPR€3,000
11 Jul 2024EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history.HRAZOPGDPR€5,470,000
10 Jul 2024Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks.PLUODOGDPR€5,129
08 Jul 2024COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR.ESAEPDGDPR€20,000
08 Jul 2024CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
05 Jul 2024PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9.ESAEPDGDPR€10,000
04 Jul 2024Provvedimento del 4 luglio 2024 [10068075]The Garante imposed a EUR 400 fine on an individual for improperly installing a surveillance system. The cameras captured public street areas, which breached privacy rules.ITGaranteGDPR€400
04 Jul 2024Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles.ITGaranteGDPR€10,000
04 Jul 2024Lapis SasThe Garante fined Lapis Sas EUR 1,500 for incorrectly presenting itself as the data controller. This created public confusion and constituted a prolonged breach of GDPR requirements.ITGaranteGDPR€1,500
04 Jul 2024Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities.ITGaranteGDPR€7,000
04 Jul 2024Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web.ITGaranteGDPR€900,000
04 Jul 2024Comune di VillasimiusComune di Villasimius was fined for failing to respond to a request to remove personal data from its website and for unlawfully publishing personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000