Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Jun 2023Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language.SEIMYGDPR€4,992,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default.GRHDPAGDPR€100,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access.GRHDPAGDPR€10,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA EUR 100,000 for processing personal data without a legal basis. The breach affected a large number of data subjects, which increases its compliance significance.GRHDPAGDPR€100,000
09 Jun 2023UNIÓN DE RADIOS LIBRES Y COMUNITARIAS DE MADRIDThe entity did not comply with a data protection authority resolution concerning the right to erasure. As a result, AEPD imposed a fine for breaching Article 58.2 of the GDPR.ESAEPDGDPR€1,000
08 Jun 2023La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details.ITGaranteGDPR€300,000
08 Jun 2023AziendaThe company was fined for failing to process personal data in a lawful, fair, and transparent manner. The authority also found breaches of data minimization and inadequate security measures.ITGaranteGDPR€5,000
08 Jun 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights.ITGaranteGDPR€40,660
08 Jun 2023Maxen Power Supply LimitedMaxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses. The conduct breached regulations 21 and 24 of PECR, and the ICO imposed a fine of 120,000 GBP and issued an enforcement notice.GBICOePrivacy€139,000
08 Jun 2023Mirva s.r.l.Mirva s.r.l. was fined by the Garante 5,000 EUR for installing a video surveillance system without proper informational signage. The system also captured areas not pertaining to the company, which breached data protection rules.ITGaranteGDPR€5,000
08 Jun 2023Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints.GBICOGDPR€150,000
08 Jun 2023L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential.ITGaranteGDPR€30,000
08 Jun 2023Liguria News S.r.l.Liguria News S.r.l. was fined by Garante EUR 10,000 for publishing an article that breached privacy rules. The article disclosed personal and sensitive information about individuals involved in the reported incident, including a minor.ITGaranteGDPR€10,000
08 Jun 2023SOCIÉTÉ DE VOYANCECNIL imposed a fine of EUR 150,000 on SOCIÉTÉ DE VOYANCE. The case concerns a regulatory breach, with no further details provided on the specific nature of the violation.FRCNILGDPR€150,000
08 Jun 2023Marcozzi Brand s.r.l.Marcozzi Brand s.r.l. was fined €8,400 by the Garante. The case concerned the failure to provide the complainant with the name of the occupational physician and the specific reasons for a negative fitness-for-work assessment, breaching GDPR transparency and access rights.ITGaranteGDPR€8,400
08 Jun 2023ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)ALTERNATIVA CORELLANA INDEPENDIENTE (ACI) was fined by the AEPD for failing to respond to information requests. The authority treated this as a breach of Article 58.1 of the GDPR.ESAEPDGDPR€4,000
07 Jun 2023ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine.ESAEPDGDPR€10,000
06 Jun 2023S.C.In May 2023, ANSPDCP completed an investigation at operator S.C. and found a violation of GDPR provisions. As a result, a fine of EUR 3,000 was imposed.ROANSPDCPGDPR€3,000
05 Jun 2023HIPER STORE, S.L.HIPER STORE, S.L. was fined EUR 500 by the AEPD for not properly signposting its video surveillance system. The authority also found that the company failed to provide customers with the required data protection information under Article 13 GDPR.ESAEPDGDPR€500
05 Jun 2023CHINA CENTER LLEIDACHINA CENTER LLEIDA was fined EUR 700 by the AEPD for failing to properly sign its video surveillance system and for not providing customers with required data protection information. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€700