Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jan 2024CAJA RURAL DE BURGOS, FUENTEPELAYO, SEGOVIA Y CASTELLDANS, S.C.C.CAJABURGOS was fined by the AEPD for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€15,000
22 Jan 2024ASILO DE ANCIANOS SANTO DOMINGO Y SANTA ELOISAThe organization was fined for repeatedly sending emails with visible recipient addresses. The case involved a breach of data protection principles and a failure to implement adequate security measures.ESAEPDGDPR€1,000
22 Jan 2024AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 500 on AVOCAT (procédure simplifiée). The record indicates a regulatory breach, but no further details are provided.FRCNILGDPR€500
22 Jan 2024Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents.DKDatatilsynetGDPR€26,816
22 Jan 2024CAJASIETE, CAJA RURAL SOCIEDAD COOPERATIVA DE CREDITOCAJASIETE was fined by the AEPD in the amount of 250,000 EUR for a data security incident. The incident compromised the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f).ESAEPDGDPR€250,000
22 Jan 2024CAJA RURAL DE SORIA, S.C.C.CAJA RURAL DE SORIA, S.C.C. was fined by the AEPD 15,000 EUR for breaching personal data protection principles. The case involved a failure to protect confidentiality and integrity, resulting in unauthorized access following a data breach.ESAEPDGDPR€15,000
19 Jan 2024L.A.D.H LimitedL.A.D.H Limited sent 31,329 direct marketing text messages to individuals in breach of regulations 22 and 23 of PECR. The ICO imposed a fine of GBP 50,000 and issued an enforcement notice.GBICOePrivacy€58,260
19 Jan 2024GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill.ESAEPDGDPR€20,000
18 Jan 2024Dane anonimowe (przez Pana B.W. prowadzącego działalność gospodarczą pod firmą: B.)UODO imposed an administrative fine on B. for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected individuals were not informed of the breach without undue delay.PLUODOGDPR€2,251
18 Jan 2024Fiziska personaA fine of EUR 250 was imposed by the DVI. The decision is final and has entered into force.LVDVIGDPR€250
17 Jan 2024Dane anonimowe (V. sp. z o. o. z siedzibą w S. za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 lit. b) i lit. d) i ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 3,819,960 on V. sp. z o.o. for breaches of GDPR rules on data security and confidentiality. The case concerned, among other things, data processing principles, data protection by design, and the implementation of appropriate technical and organizational measures.PLUODOGDPR€868,000
16 Jan 2024Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements.GBICOePrivacy€174,000
16 Jan 2024Skean Homes LtdSkean Homes Ltd was fined by the ICO after it was found to have instigated 614,342 unsolicited direct marketing calls between 2 March 2022 and 31 May 2022. The calls promoted energy grants for resin driveways and generated 31 complaints through the ICO and TPS reporting tools. The ICO found breaches of regulations 21 and 24 of PECR.GBICOePrivacy€116,000
16 Jan 2024International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR.NLAPGDPR€150,000
15 Jan 2024TECHNINK LEB SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data on its website. The exposed information included IDs, addresses, names, email addresses, and sales information.ROANSPDCPGDPR€3,000
15 Jan 2024AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on AVOCAT (procédure simplifiée). The case concerned a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€5,000
15 Jan 2024CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects.ESAEPDGDPR€3,000
12 Jan 2024Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions.GBICOGDPR€162,000
12 Jan 2024Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations.ROANSPDCPGDPR€17,000
11 Jan 2024Provincia di SassariThe Garante imposed a fine of 2,000 EUR on Provincia di Sassari for breaches of data protection obligations under Article 37 GDPR. The case concerned failure to comply with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000