Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Apr 2024Fiziska personaA fine of EUR 150 was imposed by the DVI. The decision is final and has entered into force.LVDVIGDPR€150
01 Apr 2024Your Consulting SRLANSPDCP imposed a fine on Your Consulting SRL for GDPR violations related to insufficient technical and organizational security measures. The security gap allowed unauthorized access to personal data through one of the company’s applications.ROANSPDCPGDPR€3,000
28 Mar 2024SIA “JK Media group”The DVI imposed a fine of EUR 1,000 on SIA “JK Media group”. The decision is final and has entered into force.LVDVIGDPR€1,000
25 Mar 2024KUR KLINIKUM, S.L.KUR KLINIKUM, S.L. was fined EUR 1,000 by the AEPD for failing to comply with a data protection authority resolution. The case concerned the right of access to personal data.ESAEPDGDPR€1,000
22 Mar 2024NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent.ESAEPDePrivacy€10,000
21 Mar 2024Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls.ITGaranteGDPR€10,000
21 Mar 2024Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.).HUNAIHGDPR€762
21 Mar 2024Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security.ITGaranteGDPR€120,000
21 Mar 2024Imperatori Immobiliari s.r.l.The Garante fined Imperatori Immobiliari s.r.l. 4,000 EUR for operating a surveillance system without the required informational signage. The authority treated this as a breach of data protection rules.ITGaranteGDPR€4,000
21 Mar 2024Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR.ITGaranteGDPR€2,000
21 Mar 2024LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services.ITGaranteGDPR€271,000
20 Mar 2024Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights.ISPersónuverndGDPR€10,095
19 Mar 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
19 Mar 2024LOCAL VERTICALS, S.L.LOCAL VERTICALS, S.L. was fined by the AEPD 10,000 EUR for storing cookies without user consent and for failing to provide a legal notice on its website. The case concerns breaches of data protection rules and website transparency obligations.ESAEPDePrivacy€10,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified.NODatatilsynetGDPR€1,730,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data.NODatatilsynetGDPR€1,730,000
15 Mar 2024LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide information requested by the data protection authority during an investigation. The conduct breached Article 58(1) GDPR and hindered supervisory oversight.ESAEPDGDPR€6,000
12 Mar 2024SARARTE, S.L.SARARTE, S.L. was fined 6,000 EUR by the AEPD for disclosing personal data, including a private mobile number, to 18 people without consent. The case indicates a breach of data protection rules and unauthorized sharing of information.ESAEPDGDPR€6,000
12 Mar 2024DKN.5131.28.2023StatusprawomocnaTytuUODO imposed an administrative fine of PLN 78,575.4 for failing to report a personal data breach without undue delay. The incident was not notified to the supervisory authority within 72 hours of becoming aware of the breach.PLUODOGDPR€18,331
12 Mar 2024Dane anonimowe (U.)An administrative fine was imposed for failing to notify the supervisory authority of a personal data breach within the required 72 hours after detection. The authority also found that the affected individuals were not informed without undue delay.PLUODOGDPR€336,000