Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 May 2022SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L.The Spanish Data Protection Agency (AEPD) fined SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L. EUR 50,000 for publishing audio of a victim’s court testimony without adequate data protection safeguards. The authority found a breach of GDPR Article 5(1)(c) on data minimization.ESAEPDGDPR€50,000
26 Apr 2024Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began.DKDatatilsynetGDPR€6,705
19 Jan 2024L.A.D.H LimitedL.A.D.H Limited sent 31,329 direct marketing text messages to individuals in breach of regulations 22 and 23 of PECR. The ICO imposed a fine of GBP 50,000 and issued an enforcement notice.GBICOePrivacy€58,260
03 May 2022TITANIA COMPAÑÍA EDITORIAL, S.L.TITANIA COMPAÑÍA EDITORIAL, S.L. was fined by the AEPD 50,000 EUR for publishing an audio recording of a victim’s testimony in a high-profile court case. The authority found that the company processed personal data excessively and breached data protection principles.ESAEPDGDPR€50,000
11 Jan 2024Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities.ITGaranteGDPR€50,000
01 Jan 2023SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L. was fined by the AEPD 50,000 EUR for processing personal data without consent. The case involved formalizing an electricity supply contract and charging the complainant's bank account without authorization.ESAEPDGDPR€50,000
30 Dec 2022SECURITAS DIREC ESPAÑA, S.A.SECURITAS DIREC ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for failing to provide complete access to personal data logs linked to an alarm system. The case concerned an inadequate response to a data subject access request.ESAEPDGDPR€50,000
23 Apr 2021VODAFONE SERVICIOS, S.L.U.Vodafone Servicios, S.L.U. was fined by the AEPD 50,000 EUR for failing to verify a customer's identity. The lapse enabled identity fraud and the unauthorized creation of an account.ESAEPDGDPR€50,000
09 May 2018Sioufas and Partners Law FirmThe law firm was fined for operating a video surveillance system that covered workspaces without proper justification. It also failed to notify the authority in a timely manner and did not inform individuals about the surveillance, breaching several provisions of Greek data protection law.GRHDPAGDPR€50,000
29 Jul 2011INFORMA D&B, SAINFORMA D&B, SA was fined by the AEPD 50,000 EUR for continuing to send commercial emails after the recipient requested unsubscribing and objected to data processing. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€50,000
14 Oct 2024ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD EUR 50,000 for publishing a video containing violent content and the voices of the aggressors and the victim. The authority found a breach of data protection rules.ESAEPDGDPR€50,000
28 Jul 2020Anonymizováno (ÚOOÚ UOOU-05226/19-22)The entity was fined for publishing personal data of court proceeding participants on a website. The authority found this to be a breach of data protection law.CZUOOUGDPR€1,905
22 Jul 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending an SMS to a third party with a link to a customer's purchase summary. This disclosed personal data without proper authorization.ESAEPDGDPR€50,000
01 Jan 2023ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD in the amount of 50,000 EUR for publishing excessive personal data. The case concerned an audio recording of a victim's court statement, which was not necessary for the journalistic purpose.ESAEPDGDPR€50,000
08 Apr 2022SECURITAS DIRECT ESPAÑA, S.A.SECURITAS DIRECT ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for disclosing a customer's personal information to another client via email. The authority found a breach of confidentiality and insufficient security measures under the GDPR.ESAEPDGDPR€50,000
28 Apr 2022DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data. The company published audio of a victim’s testimony without necessity, breaching the data minimisation principle under Article 5(1)(c) GDPR.ESAEPDGDPR€50,000
04 Oct 2011NGI s.p.a.NGI s.p.a. was fined by the Garante 50,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers, did not prepare the required security program document, and improperly retained traffic data.ITGaranteGDPR€50,000
10 May 2022CONECTA5 TELECINCO, S.A.U.CONECTA5 TELECINCO, S.A.U. was fined by the AEPD 50,000 EUR for publishing audio of a victim’s court testimony without voice distortion. The authority found a breach of data protection principles.ESAEPDGDPR€50,000
26 Apr 2022CORPORACIÓN DE RADIO Y TELEVISIÓN ESPAÑOLA S.A.The company published audio of a victim's court statement in a high-profile case. The authority found a breach of the data minimization principle because excessive personal data was processed.ESAEPDGDPR€50,000
20 Sept 2012Casa di cura privata Montevergine s.p.a.The private clinic Montevergine was fined 50,000 EUR by the Garante. The authority found that it processed employees' biometric data for attendance tracking without first notifying the supervisory authority.ITGaranteGDPR€50,000