Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jun 2024Drivalia Leasys Rent S.p.A.Drivalia Leasys Rent S.p.A. was fined by Garante 250,000 EUR for denying a car rental voucher to a customer listed on a blacklist. The authority found insufficient transparency in data processing and a lack of proper legal basis and consent under GDPR.ITGaranteGDPR€250,000
06 Jun 2024Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance.ITGaranteGDPR€24,000
05 Jun 2024Ambitious People Group B.V.Ambitious People Group B.V. was fined by the AP EUR 6,000 for failing to handle data erasure requests submitted by three individuals within the required timeframe. The breach concerned GDPR Articles 17 and 12.NLAPGDPR€6,000
31 May 2024CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle.ESAEPDGDPR€7,500
31 May 2024MEDIOS DE PREVENCIÓN EXTERNOS, S.L.MEDIOS DE PREVENCIÓN EXTERNOS, S.L. was fined by the AEPD for leaving medical documentation of police and civil guard agents in a public place. The authority found this to be a breach of data protection rules.ESAEPDGDPR€100,000
31 May 2024MAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.AMAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.A was fined EUR 300,000 by the AEPD. The authority found that the company carried out unauthorized investment transactions using personal data without consent, in breach of data protection rules.ESAEPDGDPR€300,000
31 May 2024LABORATORIO PEDRO PERALES, S.L.P.LABORATORIO PEDRO PERALES, S.L.P. was fined by the AEPD 5,000 EUR for failing to comply with data protection rules in relation to cookie management on its website. The case concerned deficiencies in how users were informed and how consent was handled.ESAEPDePrivacy€5,000
30 May 2024Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
30 May 2024Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€1,000
28 May 2024B.B.B.B.B.B., a councilor, unlawfully published the personal data of a complainant and their spouse in a municipal meeting note. The information was shared with a group of about 400 people, causing reputational harm.ESAEPDGDPR€1,000
28 May 2024CUI ZSQ FOOD, S.L.CUI ZSQ FOOD, S.L. was fined by the AEPD 70,000 EUR for using a video surveillance system to intimidate employees. The company shared footage of an employee’s absence in a work chat, which breached data protection rules.ESAEPDGDPR€70,000
27 May 2024Urban Home Development S.R.L.Urban Home Development S.R.L. was fined 10,000 RON by ANSPDCP. The sanction was imposed for violating the provisions of Law no. 506/2004.ROANSPDCPePrivacy€2,010
27 May 2024Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose.GRHDPAGDPR€5,000
27 May 2024KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 10,000 EUR for requiring a customer to provide a photo with their ID to cancel a loan. The authority found that this processing breached GDPR principles of data minimisation and proportionality.ESAEPDGDPR€10,000
24 May 2024B.B.B.B.B.B. was fined by the AEPD in the amount of 5,000 EUR for publishing personal data, including images and documents, on a public channel. The authority found a breach of the data minimization principle under GDPR Article 5(1)(c).ESAEPDGDPR€5,000
24 May 2024G&F&S SECURITY GROUP, S.L.G&F&S SECURITY GROUP, S.L. was fined by the AEPD €18,000 for failing to properly handle a data subject access request. The authority found a breach of Article 15 GDPR and non-compliance with a data protection authority resolution.ESAEPDGDPR€18,000
23 May 2024Luigi De BenedictisThe Garante fined Luigi De Benedictis EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR.ITGaranteGDPR€1,000
23 May 2024SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS. The decision was issued under a simplified procedure and concerns a breach of data protection rules.FRCNILGDPR€15,000
23 May 2024SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS. The case was handled under a simplified procedure.FRCNILGDPR€10,000
23 May 2024Radio Marte S.r.l.Radio Marte S.r.l. was fined EUR 5,000 by the Garante for unlawfully disseminating identifying data of a minor during a radio program. The authority found a breach of privacy and personal data protection rules.ITGaranteGDPR€5,000