Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jan 2024Comune di SiracusaThe Garante fined Comune di Siracusa €5,000 for breaches of data protection obligations under Article 37 GDPR. The case concerned failures related to the appointment and management of the data protection officer requirement.ITGaranteGDPR€5,000
11 Jan 2024Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights.ITGaranteGDPR€10,000
11 Jan 2024Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities.ITGaranteGDPR€50,000
11 Jan 2024DESPACHO TORRENTE, S.L.P.DESPACHO TORRENTE, S.L.P. was fined by the AEPD 10,000 EUR for improperly disclosing personal data, including sensitive information, in a letter concerning damage at public facilities. The authority found a breach of data protection principles.ESAEPDGDPR€10,000
11 Jan 2024Euro Servizi per i Notai S.r.l.Euro Servizi per i Notai S.r.l. was fined 5,000 EUR by the Garante for processing personal data without a valid legal basis and without adequate transparency. The violations concerned reporting services provided to banks through the PIGNA portal.ITGaranteGDPR€5,000
11 Jan 2024dott. BagnatoA doctor was fined by the Garante for breaching privacy rules. The case involved improper handling of medical prescriptions outside the office, which could expose sensitive personal data.ITGaranteGDPR€20,000
11 Jan 2024Findomestic Banca S.p.A.Findomestic Banca S.p.A. was fined by the Garante 100,000 EUR for sending unsolicited promotional communications by phone and mail. The authority found that these contacts were made without obtaining proper consent from the data subject.ITGaranteGDPR€100,000
11 Jan 2024Libero Consorzio comunale di CaltanissettaLibero Consorzio comunale di Caltanissetta was fined by the Garante EUR 2,000 for breaching Article 37(7) of the GDPR. The decision also orders publication of the sanction on the authority’s website.ITGaranteGDPR€2,000
11 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 150,000 for processing personal data without proper authorization. The case involved a fraudulent contract created using the complainant’s identity, and the authority found that the company did not adequately verify the identity of the person entering into the contract.ESAEPDGDPR€150,000
11 Jan 2024Provincia di CatanzaroThe Garante fined Provincia di Catanzaro EUR 2,000 for violations of data protection obligations under Article 37 GDPR. The case concerned non-compliance with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000
11 Jan 2024Società David S.r.l.The Garante imposed an €8,000 fine on Società David S.r.l. for posting on Instagram a video of a patient undergoing a cosmetic procedure without a lawful basis. The authority found breaches of the GDPR principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€8,000
09 Jan 2024EDITEUR DE SITE WEB - ANNUAIRE INVERSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 1,500 on EDITEUR DE SITE WEB - ANNUAIRE INVERSE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision.FRCNILGDPR€1,500
09 Jan 202420 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined 45,000 EUR by the AEPD for publicly exposing the image of a victim of an alleged crime. The authority found that this constituted a breach of data protection rules.ESAEPDGDPR€45,000
09 Jan 2024Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals.DKDatatilsynetGDPR€33,523
08 Jan 2024VUKMAL TRADE, S.L.VUKMAL TRADE, S.L. was fined by the AEPD €2,000 for requiring an employee to use a personal mobile phone for work purposes without consent. The company also shared the employee’s personal number with other staff, breaching data protection principles.ESAEPDGDPR€2,000
08 Jan 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity sent unsolicited commercial emails to an individual registered on the Robinson List. This breached Article 21 of the LSSI and led to a fine imposed by the AEPD.ESAEPDePrivacy€2,000
08 Jan 2024INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 1,000 EUR by the AEPD for failing to meet its information obligations toward data subjects. The authority found that the required information under Article 13 GDPR was not provided.ESAEPDGDPR€1,000
05 Jan 2024B.B.B.The entity was fined for publishing personal images and phone numbers on Telegram channels without the data subjects’ consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
04 Jan 2024N*** -FußballvereinigungThe football association failed to implement appropriate technical and organizational measures for handling data deletion requests. The authority found breaches of Articles 25 and 17 GDPR and imposed a fine of EUR 11,000.ATDSBGDPR€11,000
02 Jan 2024FEDERACIÓN DE SERVICIOS PÚBLICOS DE LA UGT (FSP-UGT)The entity sent emails that disclosed personal data of multiple recipients. The AEPD found a breach of the confidentiality principle under Article 5(1)(f) GDPR.ESAEPDGDPR€5,000