Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 May 2024ETABLISSEMENT PUBLIC NATIONAL (ENSEIGNEMENT) (procédure simplifiée)CNIL imposed an administrative fine of EUR 6,000 on ETABLISSEMENT PUBLIC NATIONAL (ENSEIGNEMENT) under a simplified procedure. The case concerned a breach identified by the supervisory authority.FRCNILGDPR€6,000
23 May 2024Ordine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di MateraOrdine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di Matera was fined 3,500 EUR by the Garante. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization, in the handling of personal data.ITGaranteGDPR€3,500
23 May 2024Green Land African MinimarketThe Garante fined Green Land African Minimarket EUR 1,000 for improper use of a video surveillance system. The system captured areas beyond the company's premises and recorded employees without meeting the required legal conditions.ITGaranteGDPR€1,000
23 May 2024SOCIETE AYANT POUR ACTIVITE LE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)The CNIL ordered liquidation of a penalty payment of EUR 4,000 against SOCIETE AYANT POUR ACTIVITE LE COMMERCE DE DETAIL OPTIQUE. The measure relates to non-compliance with a prior obligation in simplified proceedings.FRCNILGDPR€4,000
23 May 2024Azienda Socio-sanitaria Territoriale RhodenseAzienda Socio-sanitaria Territoriale Rhodense was fined EUR 4,500 by the Garante for breaching GDPR Article 16. The case concerned data processing in the health sector, where strict compliance controls are required.ITGaranteGDPR€4,500
23 May 202420 AÑOS DE MÚSICA A.I.E.The entity was fined for collecting copies of identity documents and personal data without proper data protection information. The authority found breaches of the data minimization and transparency principles.ESAEPDGDPR€5,000
23 May 2024Associazione Medica Chirone s.c.r.l.The Garante fined Associazione Medica Chirone s.c.r.l. 5,000 EUR for improperly accessing and using an employee's vaccination status data. The authority found that the data were not properly anonymized, resulting in a breach of data protection rules.ITGaranteGDPR€5,000
23 May 2024Provvedimento del 23 maggio 2024 [10043051]The Garante imposed a fine of EUR 400 for the unlawful use of surveillance cameras capturing public areas without a proper legal basis. The conduct breached privacy and data protection requirements.ITGaranteGDPR€400
23 May 2024Azienda USL della RomagnaThe Garante imposed a fine of EUR 8,400 on Azienda USL della Romagna for violations related to data processing operations. The processes were largely manual and dependent on operator diligence, which led to a data breach.ITGaranteGDPR€8,400
22 May 2024TRADING INTERNATIONAL TOURIST, S.L.TRADING INTERNATIONAL TOURIST, S.L. was fined 2,000 EUR by the AEPD for adding the complainant’s phone number to a WhatsApp group with more than 500 members without consent. The authority found a breach of Article 6(1) GDPR, which requires a lawful basis for processing personal data.ESAEPDGDPR€2,000
21 May 2024B.B.B.B.B.B. was fined 2,000 EUR by the AEPD for unlawfully processing personal data. The case concerned the inclusion of data in the ASNEF credit information system without meeting the legal requirements under GDPR.ESAEPDGDPR€2,000
21 May 2024BANCO CETELEM, S.A.Banco Cetelem, S.A. was fined by the AEPD 250,000 EUR for unauthorized processing of personal data. The case included charging the complainant’s bank account for a loan taken out by an unknown third party without consent.ESAEPDGDPR€250,000
20 May 2024Dane anonimowe (A. Spółka Akcyjna z siedzibą w U., ul.)UODO imposed an administrative fine of PLN 1,440,549 on A. Spółka Akcyjna. The authority found breaches of the integrity and confidentiality principle and the obligation to implement appropriate data security measures.PLUODOGDPR€338,000
17 May 2024Nem közszereplő személyes és különleges adatainak online sajtótermékben történő nyilvánosságra hozatalaThe controller published personal data in an online news outlet without a valid legal basis. It also failed to delete unlawfully processed personal data, resulting in breaches of several GDPR provisions.HUNAIHGDPR€25,800
16 May 2024EDITAURI S.L.EDITAURI S.L. was fined by the AEPD EUR 600 for not having a privacy policy on its online store. The authority found a breach of Article 13 GDPR because users were not provided with the required information about data processing.ESAEPDGDPR€600
16 May 2024Fiziska personaA fine of EUR 100 was imposed by DVI. The decision became effective on 2024-05-16.LVDVIGDPR€100
13 May 2024INDEPENDENTS DE VALLROMANESThe political party Independents de Vallromanes was fined by the AEPD €2,000. The case concerned posting images of a court judgment on social media that included the complainant’s first and last name.ESAEPDGDPR€2,000
10 May 2024EUSKALTEL, S.A.EUSKALTEL, S.A. was fined 400,000 EUR by the AEPD for failing to comply with a resolution requiring access to geolocation data. The authority found a breach of Article 58.2 of the GDPR.ESAEPDGDPR€400,000
09 May 2024Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR.ITGaranteGDPR€10,000
09 May 2024Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di MantovaThe Garante imposed a 3,000 EUR fine on the Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di Mantova for breaches of data protection principles. The authority found non-compliance with lawfulness, fairness, transparency, and data minimization. The infringement affected a significant number of data subjects.ITGaranteGDPR€3,000