Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Nov 2023Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures.ROANSPDCPGDPR€110,000
13 Nov 2023RECICLAJES LOGROÑO, S.L.RECICLAJES LOGROÑO, S.L. was fined by the AEPD 10,000 EUR for photocopying a customer's ID without consent and for failing to provide privacy policy information. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€10,000
13 Nov 2023Kerepesi Polgármesteri HivatalKerepesi Polgármesteri Hivatal was fined by NAIH for unlawful data processing linked to the operation of a public surveillance camera system. The authority found violations of several provisions of the Infotv.HUNAIHGDPR€21,200
10 Nov 2023VERNE INFORMATION TECHNOLOGY, S.L.VERNE INFORMATION TECHNOLOGY, S.L. was fined 2,000 EUR by the AEPD. The case concerned sending unsolicited commercial electronic communications without prior consent or an existing contractual relationship.ESAEPDePrivacy€2,000
09 Nov 2023Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS.GBICOePrivacy€172,000
09 Nov 2023DPG Professional Services LtdBetween 3 August 2021 and 3 August 2022, DPG made 74,119 unsolicited calls for direct marketing purposes, breaching Reg 21 of PECR. The activity resulted in 13 complaints and came to the Commissioner’s attention through an operation focused on life insurance and later life planning marketing.GBICOePrivacy€103,000
08 Nov 2023SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA MISE EN OEUVRE DE LOGICIELS DE SURVEILLANCE DES EMPLOYES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company under a simplified procedure. The decision concerns breaches linked to the company's activity in employee monitoring software.FRCNILGDPR€20,000
07 Nov 2023FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information.SEIMYGDPR€42,845
03 Nov 2023OTP BANK ROMANIA SAThe National Supervisory Authority for Personal Data Processing imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
02 Nov 2023ASYMECO, S.A.ASYMECO, S.A. was fined EUR 5,000 by the AEPD for sending clients’ personal data to an employee’s private WhatsApp without proper authorization. The authority found this breached GDPR Articles 6(1) and 32.ESAEPDGDPR€5,000
02 Nov 2023KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List.ESAEPDePrivacy€5,000
30 Oct 2023CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations.ESAEPDGDPR€1,000
27 Oct 2023Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents.HRAZOPGDPR€4,500,000
27 Oct 2023Asociația de Proprietari bloc A1The homeowners association was fined by ANSPDCP for failing to implement measures ordered by the authority and for unlawfully disclosing owners’ names on maintenance lists without consent. The case concerns breaches of personal data protection rules and non-compliance with supervisory instructions.ROANSPDCPGDPR€501
26 Oct 2023Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy.ITGaranteGDPR€20,000
26 Oct 2023Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool.GBICOePrivacy€74,568
26 Oct 2023Regione LombardiaThe Garante fined Regione Lombardia EUR 20,000 for improperly publishing the personal data of numerous workers online. The disclosed information also included health-related data, which breached privacy rules.ITGaranteGDPR€20,000
26 Oct 2023SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL (procédure simplifiée)The CNIL imposed a EUR 2,000 fine on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL under a simplified procedure. The case concerned a breach of personal data protection rules.FRCNILGDPR€2,000
26 Oct 2023Azienda Sanitaria Locale TO3Azienda Sanitaria Locale TO3 was fined by the Garante for a health data breach affecting four individuals. The incident lasted nine days and was deemed negligent.ITGaranteGDPR€6,000
26 Oct 2023Provvedimento del 26 ottobre 2023 [9960920]The Garante imposed a EUR 1,000 fine on a condominium administrator for installing a video surveillance system without a proper legal basis or assembly resolution. The conduct was found to breach GDPR rules on lawful processing.ITGaranteGDPR€1,000