Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Oct 2023A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request.ITGaranteGDPR€10,000
25 Oct 2023SC Spark Car Sharing SRLANSPDCP completed an investigation in October 2023 at SC Spark Car Sharing SRL and found a breach of personal data processing principles. The company received a EUR 1,000 fine and a warning.ROANSPDCPGDPR€1,000
24 Oct 2023Mensajero SRLMensajero SRL was fined EUR 3,000 by ANSPDCP for a data security breach on its website. A link allowed access to downloadable files containing customer invoices and product warranty certificates.ROANSPDCPGDPR€3,000
24 Oct 2023FIBRA ÓPTICA MÁLAGA, S.L.FIBRA ÓPTICA MÁLAGA, S.L. changed a customer's contact email and bank account details without consent. The AEPD found a breach of GDPR Article 6(1) and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000
24 Oct 2023UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose.ESAEPDGDPR€50,000
23 Oct 2023EDITEUR DE BLOG EN LIGNE DEDIE A LA LUTTE CONTRE LA PEDOCRIMINALITE (procédure simplifiée)The CNIL imposed a fine of 2,000 EUR on EDITEUR DE BLOG EN LIGNE DEDIE A LA LUTTE CONTRE LA PEDOCRIMINALITE (procédure simplifiée). The matter was handled under a simplified procedure.FRCNILGDPR€2,000
23 Oct 2023EDITEUR DE SITE WEB DEDIE A LA PRESSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on EDITEUR DE SITE WEB DEDIE A LA PRESSE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€5,000
20 Oct 2023DANTE INTERNAȚIONAL SADANTE INTERNAȚIONAL SA was fined EUR 1,000 by ANSPDCP for processing the complainant's phone number for direct marketing without consent. The case involved sending commercial SMS messages without a valid legal basis.ROANSPDCPGDPR€1,000
20 Oct 2023Outsource Strategies LtdOutsource Strategies Ltd made 1,346,503 unwanted marketing calls between 11 February 2021 and 22 March 2022 to numbers registered with the TPS. The ICO received 74 complaints, including reports of repeated calls despite requests to stop and aggressive caller behaviour.GBICOGDPR€275,000
18 Oct 2023Dane anonimowe (J. Towarzystwo Ubezpieczeń S.A. z siedzibą w N.)UODO imposed an administrative fine of PLN 103,752 on J. Towarzystwo Ubezpieczeń S.A. The authority found that the company failed to notify the supervisory authority of a personal data breach without undue delay.PLUODOGDPR€23,362
17 Oct 2023H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21.SEIMYGDPR€30,356
17 Oct 2023MOBILITY AUTOCENTRO, S.L.MOBILITY AUTOCENTRO, S.L. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached the Spanish LSSI.ESAEPDePrivacy€2,000
17 Oct 2023Íþrótta- og sýningahöllin hf.Íþrótta- og sýningahöllin hf. was fined by Persónuvernd 3,500,000 ISK for unlawful electronic surveillance at Laugardalshöll. The case involved processing sensitive personal data without proper authorization, including data relating to children.ISPersónuverndGDPR€23,905
13 Oct 2023COMUNIDAD DE PROPIETARIOS ***COMUNIDAD.1The entity installed a video surveillance system with cameras directed toward public areas without prior administrative authorization. In addition, unauthorized personnel had access to the system, creating a data protection compliance breach.ESAEPDGDPR€1,000
12 Oct 2023Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data.ITGaranteGDPR€200,000
12 Oct 2023SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTESCNIL imposed a fine of EUR 600,000 on SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTES. The case concerns a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€600,000
12 Oct 2023S.T.A. Società Trattamento Acque s.r.l.S.T.A. Società Trattamento Acque s.r.l. was fined €75,000 by the Garante. The authority found a breach of Article 15 GDPR after the company failed to respond to an employee's request for access to professional training records.ITGaranteGDPR€75,000
12 Oct 2023Scionti Selezioni Superiori S.r.l.Scionti Selezioni Superiori S.r.l. was fined EUR 70,000 by the Garante for failing to implement adequate measures to prevent unauthorized access to customer data. The data was then used for promotional purposes without the individuals' consent.ITGaranteGDPR€70,000
11 Oct 2023CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company was fined by the AEPD 1,000 EUR for not having a privacy policy on its website. The issue arose because it collected personal data through a contact form, triggering the information duties under GDPR Article 13.ESAEPDGDPR€1,000
11 Oct 2023COM. PROP. ***COMUNIDAD.1The entity installed surveillance cameras oriented toward public roads without prior administrative authorization. This breached data protection rules and resulted in a fine by the AEPD.ESAEPDGDPR€1,000