Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Jul 2023THE COMAKING SPACE, S.L.U.THE COMAKING SPACE, S.L.U. was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without recipient consent. The conduct breached the LSSI rules on electronic marketing communications.ESAEPDePrivacy€2,000
07 Jul 2023Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles.HUNAIHGDPR€2,580
06 Jul 2023AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15.ITGaranteGDPR€10,000
06 Jul 2023Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements.ITGaranteGDPR€10,000
06 Jul 2023Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles.ITGaranteGDPR€3,000
06 Jul 2023SUROVI (Surovi Ristorante indiano e kebab di Chowdhury Monika)The Garante fined SUROVI restaurant EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found this to be a breach of Article 13 of the GDPR.ITGaranteGDPR€1,000
06 Jul 2023Ristorante Francesco s.r.l.Ristorante Francesco s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating surveillance cameras without the required notices to affected individuals. The authority treated this as a breach of privacy rules.ITGaranteGDPR€5,000
06 Jul 2023Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection.ITGaranteGDPR€2,000
06 Jul 2023Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€7,000
06 Jul 2023Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data.ITGaranteGDPR€15,000
05 Jul 2023Anonymisé (CNPD decision-06-fr-2023)The company failed to implement appropriate technical and organizational measures to ensure data security. It also did not cooperate with the supervisory authority, breaching Articles 31 and 32 of the GDPR.LUCNPDGDPR€5,330
05 Jul 20234T OCIO Y CAFÉ 2009, S.L.The company was fined EUR 500 by the AEPD for installing surveillance cameras without the express consent of the property owners. The authority found this to be a breach of Article 6 of the GDPR.ESAEPDGDPR€500
05 Jul 2023Anonymisé (CNPD decision-05-fr-2023)The company did not inform data subjects about the recipients of their personal data. It also failed to implement appropriate technical and organizational measures required under the GDPR, breaching Articles 13 and 24.LUCNPDGDPR€1,500
05 Jul 2023UPMOBILE SOLUTIONS, S.L.UPMOBILE SOLUTIONS, S.L. was fined EUR 500 by the AEPD for failing to provide access during the investigation. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its supervisory function.ESAEPDGDPR€500
05 Jul 2023BILBAO AD INFINITUM, S.L.BILBAO AD INFINITUM, S.L. was fined by the AEPD EUR 500 for installing surveillance cameras directed at a public square without prior administrative authorization. The authority found that this conduct breached GDPR requirements on lawful processing.ESAEPDGDPR€500
04 Jul 2023BALLESPE, S.LBALLESPE, S.L was fined by the AEPD in the amount of 500 EUR for installing surveillance cameras that captured public areas without proper signage. The case concerns a breach of data protection rules and the duty to inform individuals being recorded.ESAEPDGDPR€500
03 Jul 2023ENDESAENDESA was fined by the AEPD EUR 2,500,000 for failing to ensure the integrity and confidentiality of personal data and for inadequate security measures. The authority found breaches of GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,500,000
03 Jul 2023LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 5,000 EUR for attempting to install cookies on users' devices without proper consent. The conduct breached data protection rules and electronic commerce requirements.ESAEPDePrivacy€5,000
29 Jun 2023FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR.ESAEPDGDPR€2,000
29 Jun 2023Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€10,000