Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Sept 2023Simply Connecting LtdSimply Connecting Ltd sent 441,830 direct marketing text messages to individuals in breach of regulation 22 of PECR. The ICO imposed a £40,000 fine and issued an enforcement notice.GBICOePrivacy€46,780
06 Sept 2023Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations.ISPersónuverndGDPR€10,425
04 Sept 2023ASSOCIACIO OASIS CULTURALASSOCIACIO OASIS CULTURAL was fined by the AEPD EUR 10,000 for unlawful processing of personal data. The case concerned the publication on TikTok of a video showing minors performing dances with sexual connotations without a legal basis under Article 6(1) GDPR.ESAEPDGDPR€10,000
01 Sept 2023TikTok Technology Limited (TTL)The Irish DPC imposed a fine of EUR 345,000,000 on TikTok Technology Limited (TTL) following an inquiry. The matter remains ongoing because the decision is under appeal.IEDPCGDPR€345,000,000
31 Aug 2023GEDI News Network S.p.a.The Garante imposed a EUR 30,000 fine on GEDI News Network S.p.a. for publishing a photo of minors with insufficient pixelation, making them identifiable. The authority found this to be a breach of data protection rules concerning children.ITGaranteGDPR€30,000
31 Aug 2023operator persoană fizicăA EUR 2,000 fine was imposed on an individual operator for photographing or filming a patient in a medical unit without consent. The authority also applied a corrective measure to ensure compliance of data processing operations with the GDPR.ROANSPDCPGDPR€2,000
31 Aug 2023B.B.B.B.B.B. was fined 300 EUR by the AEPD after a complaint about a surveillance camera installed by a neighbor. The authority found that the device could have captured images of a private property and a private street, creating a potential data protection breach.ESAEPDGDPR€300
31 Aug 2023Provvedimento del 31 agosto 2023 [9938463]The decision concerned a breach of rules on the processing of health data by a medical center. Garante imposed a fine of EUR 10,000.ITGaranteGDPR€10,000
31 Aug 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent.ITGaranteGDPR€10,000
31 Aug 2023Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children.ITGaranteGDPR€25,000
31 Aug 2023Ordine degli Avvocati di XXThe Garante fined the Ordine degli Avvocati di XX EUR 8,000 for unlawfully disclosing personal data without a legal basis. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€8,000
30 Aug 2023LORO PARQUE, S.A.LORO PARQUE, S.A. was fined by the AEPD 250,000 EUR for processing biometric data without a proper legal basis. The authority classified this as a very serious breach of Article 9 GDPR.ESAEPDGDPR€250,000
30 Aug 2023Dane anonimowe (A. S.A. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 56,592 on the company. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for its tasks.PLUODOGDPR€12,652
28 Aug 2023Trygg-HansaTrygg-Hansa Försäkring filial was fined by IMY SEK 35,000,000 for failing to implement appropriate technical measures. This allowed unauthorized access to sensitive customer data, breaching GDPR Articles 5(1)(f) and 32(1).SEIMYGDPR€2,941,000
28 Aug 2023VOX ESPAÑAVOX ESPAÑA was fined by the AEPD EUR 1,000 for failing to properly sign its surveillance cameras and for capturing an excessive area of public space. The authority found breaches of GDPR data minimisation and transparency obligations.ESAEPDGDPR€1,000
25 Aug 2023This Is The Big Deal LimitedThis Is The Big Deal Limited sent or instigated 41,417,889 unsolicited direct marketing messages to individuals without consent, breaching regulation 22 of PECR. In addition, 102,132 text messages were sent without the required opt-out information under regulation 23 of PECR. The ICO imposed a fine of 30,000 GBP.GBICOePrivacy€35,028
24 Aug 2023Kamerás adatkezelés szálláshelyenThe entity was fined for failing to provide easily accessible and transparent information about data processing through a camera system. The authority found a breach of GDPR Articles 12 and 13.HUNAIHGDPR€2,600
23 Aug 2023GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined by the AEPD 5,000 EUR for sending commercial emails to a complainant after they had opted out. The authority treated this as a breach of data protection rules.ESAEPDePrivacy€5,000
23 Aug 2023BODY LINE SRLIn July 2023, the Romanian authority ANSPDCP completed an investigation at BODY LINE SRL and found violations of GDPR provisions. The operator was fined 49,322 lei, equivalent to EUR 10,000.ROANSPDCPGDPR€10,000
21 Aug 2023Uipath SRLUipath SRL was fined by ANSPDCP EUR 70,000 for violations related to cross-border data processing. The case concerned compliance issues in the transfer or handling of data across borders.ROANSPDCPGDPR€70,000