Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Mar 2024Fiziska personaA monetary penalty of 150 EUR was imposed by DVI. The decision is final and has entered into force.LVDVIGDPR€150
07 Mar 2024Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access.ITGaranteGDPR€20,000
07 Mar 2024CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent.ESAEPDGDPR€2,000,000
07 Mar 2024BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15.ITGaranteGDPR€10,000
07 Mar 2024Pinnacle Life LimitedBetween 5 May 2021 and 5 May 2022, the company made 47,998 connected unsolicited direct marketing calls to subscribers registered with the TPS who had not consented to receive such calls. Four complaints were submitted, and the ICO imposed a fine of 80,000 GBP.GBICOGDPR€93,624
07 Mar 2024Giuliana VinziThe Garante fined Giuliana Vinzi, owner of Rocky Bar, 2,000 EUR for operating video surveillance without the required notices to data subjects. The authority also found that authorization from the Labor Inspectorate was missing, resulting in a GDPR breach.ITGaranteGDPR€2,000
07 Mar 2024Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees.ITGaranteGDPR€20,000
07 Mar 2024Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification.ITGaranteGDPR€100,000
07 Mar 2024Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate.ITGaranteGDPR€3,000
06 Mar 2024The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand.GBICOGDPR€8,772
06 Mar 2024Sectorul 1 al Municipiului BucureștiSectorul 1 of Bucharest was fined 159,000 RON by ANSPDCP for failing to comply with a remediation measure. The authority had required the requested information to be provided within 10 days, but the obligation was not met.ROANSPDCPGDPR€31,988
05 Mar 2024ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR.ESAEPDGDPR€5,000
05 Mar 2024EURO MINI STORAGE ROMANIA SRLEURO MINI STORAGE ROMANIA SRL was fined by ANSPDCP EUR 5,000 for a data security breach caused by a cyber attack. The incident led to unauthorized access to personal data and affected data availability for several weeks.ROANSPDCPGDPR€5,000
04 Mar 2024EXESRIVAS GESTIÓN PATRIMONIALThe entity sent unsolicited commercial messages via WhatsApp despite the complainant's explicit refusal to receive such communications. AEPD found a breach of Article 21 of the LSSI and imposed a 300 EUR fine.ESAEPDePrivacy€300
03 Mar 2024FUNDACIÓN C.R.E.T.A. CENTRO PARA EL ESTUDIO Y REPRESENTACIÓN DEL TEATRO ANTIGUOThe organization failed to properly handle a data subject access request. AEPD imposed a fine of 1,000 EUR for non-compliance with GDPR obligations.ESAEPDGDPR€1,000
29 Feb 2024WATIUM S.L.WATIUM S.L. was fined by the Spanish Data Protection Agency (AEPD) in the amount of EUR 160,000. The case concerned the failure to provide the required information, which constitutes a breach of Article 58.1 of the GDPR.ESAEPDGDPR€160,000
29 Feb 2024SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE under a simplified procedure. The case concerns a violation identified by the French supervisory authority.FRCNILGDPR€10,000
29 Feb 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on CHIRURGIEN DENTISTE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision.FRCNILGDPR€4,000
28 Feb 2024Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach.GRHDPAGDPR€2,995,000
26 Feb 2024Ministry of DefenceThe UK Ministry of Defence sent emails using the “To” field instead of “BCC”, which disclosed 265 unique email addresses. The ICO found this breached GDPR Article 5(1)(f) and imposed a fine of 350,000 GBP.GBICOGDPR€409,000