Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságALDI Magyarország was fined by the NAIH 80,000,000 HUF for failing to ensure transparency in data processing related to the purchase of alcoholic beverages. The authority found breaches of GDPR transparency and data minimization principles.HUNAIHGDPR€202,000
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságNAIH imposed a HUF 95,000,000 fine on ALDI Magyarország for GDPR violations linked to data processing during alcohol purchases. The authority cited improper age verification and insufficient personal data protection measures.HUNAIHGDPR€240,000
01 Jul 2024Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000.MTIDPCGDPR€15,000
27 Jun 2024METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure.GRHDPAGDPR€20,000
27 Jun 2024SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 12,000 on SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES under a simplified procedure. The case concerned a breach of rules supervised by the CNIL.FRCNILGDPR€12,000
25 Jun 2024LOS NIÑOS DE MONTESSORI, S.L.The entity was fined for failing to provide information or obtain consent for the use of cookies on its website. This conduct breached the LSSI.ESAEPDePrivacy€5,000
25 Jun 2024AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta.SEIMYGDPR€1,336,000
25 Jun 2024COMUNIDAD.1The community of property owners disclosed a resident’s personal data, including their DNI, in meeting minutes. AEPD found this breached confidentiality principles and imposed a 300 EUR fine.ESAEPDGDPR€300
25 Jun 2024RIVENDELL TECHNOLOGY, S.L.RIVENDELL TECHNOLOGY, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The company was fined for not complying with the data protection authority's resolution.ESAEPDGDPR€900
24 Jun 2024WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.The entity sent postal advertising to an individual without any prior commercial relationship, using data from the Official Industrial Property Bulletin. The authority found this to be a breach of data protection rules.ESAEPDGDPR€500
21 Jun 2024ADMINISTRACIONES BENIPON, S.L.ADMINISTRACIONES BENIPON, S.L. was fined 2,200 EUR by the AEPD for failing to provide access to information as required under Article 58(1) GDPR. The case concerns non-compliance with the supervisory authority’s information access requirements.ESAEPDGDPR€2,200
20 Jun 2024Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante EUR 1,000,000 for carrying out telemarketing activities without obtaining proper consent from the contacted individuals. The authority found a breach of fairness and transparency principles in the processing of personal data.ITGaranteGDPR€1,000,000
20 Jun 2024Rețele Electrice Dobrogea SARețele Electrice Dobrogea SA was fined by ANSPDCP in the amount of EUR 1,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
20 Jun 2024Grafiche E.The Garante imposed a fine of EUR 12,000 on Grafiche E. for violations of data protection rules. The case concerned non-compliance with regulatory requirements for the processing of personal data.ITGaranteGDPR€12,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings.ITGaranteGDPR€4,000
20 Jun 2024Rețele Electrice Muntenia SARețele Electrice Muntenia SA was fined by ANSPDCP in the amount of 3,000 EUR for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules.ITGaranteGDPR€10,000
20 Jun 2024Comune di ForlìThe Municipality of Forlì was fined EUR 15,000 by the Garante for failing to embed data protection principles in the design of its video surveillance system. The authority found breaches of transparency and accountability requirements.ITGaranteGDPR€15,000
20 Jun 2024Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations.ITGaranteGDPR€5,000
20 Jun 2024TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€10,000