Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Dec 2023Educational Development Informatikai Zrt.The company failed to implement adequate data security measures and did not report a data breach without undue delay. The authority found breaches of GDPR Articles 32 and 33.HUNAIHGDPR€286,000
20 Dec 2023Ministra ZdrowiaThe President of the Personal Data Protection Office imposed an administrative fine of 100,000 PLN on Ministra Zdrowia. The authority found unlawful processing of personal data, including special-category data without a legal basis, and a failure to implement technical and organizational measures appropriate to the processing risk. The affected individual was also not provided with the information required under Article 33(3)(c) and (d) of the GDPR.PLUODOGDPR€23,035
20 Dec 2023Dane anonimowe (Wójta Gminy P.)UODO imposed a PLN 50,000 administrative fine on the controller for failing to implement appropriate technical and organizational measures proportionate to the risk of processing. The authority found insufficient safeguards for confidentiality, integrity, availability, and resilience of systems, as well as inadequate recovery capability after an incident.PLUODOGDPR€11,518
19 Dec 2023HIPERBAZAR YONGFA 2018 SLHIPERBAZAR YONGFA 2018 SL was fined by the AEPD 5,000 EUR for breaching data protection rules. The case involved the improper sharing of surveillance footage, which was later posted on Facebook, undermining confidentiality and data security requirements.ESAEPDGDPR€5,000
19 Dec 2023Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals.PLUODOGDPR€2,306
18 Dec 2023MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them.ESAEPDePrivacy€5,000
18 Dec 2023Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles.HUNAIHGDPR€1,295
15 Dec 2023O nouă amendă - operator persoană fizicăA fine was imposed on an individual operator for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules.ROANSPDCPGDPR€200
15 Dec 2023TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined by the AEPD in the amount of 5,000 EUR for breaching data protection rules. The company failed to honor a request to delete personal data and later sent commercial information to the complainant.ESAEPDGDPR€5,000
15 Dec 2023TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined EUR 5,000 by the AEPD for sending commercial information by email after confirming the deletion of personal data. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
13 Dec 2023Dane anonimowe (M. Sp. z o.o. z siedzibą w D. przy ul.)The President of UODO imposed a PLN 23,580 administrative fine on M. Sp. z o.o. The penalty was issued for failing to comply with two administrative decisions issued by the data protection authority.PLUODOGDPR€5,451
12 Dec 2023B*** GmbHB*** GmbH was fined by the DSB EUR 5,900 for failing to timely report a data breach to the supervisory authority and for not providing sufficient information required under GDPR. The company also did not cooperate with the authority’s further requests for information.ATDSBGDPR€5,900
12 Dec 2023COMMUNECNIL imposed a EUR 5,000 fine on COMMUNE and issued an injunction. The case concerns a regulatory breach requiring corrective action.FRCNILGDPR€5,000
11 Dec 2023PERSONNALITE POLITIQUE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on PERSONNALITE POLITIQUE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
11 Dec 2023Veranda Obor S.A.The National Supervisory Authority for Personal Data Processing imposed a fine on Veranda Obor S.A. for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
11 Dec 2023C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information.ATDSBGDPR€9,500
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€2,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€20,000
07 Dec 2023Sirio S.p.A.Sirio S.p.A. was fined EUR 1,000 by the Garante for violating data protection rules. The case concerned the improper handling of an employee’s personal data in connection with issuing a new bank card.ITGaranteGDPR€1,000
07 Dec 2023Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency.ITGaranteGDPR€40,000