Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Jun 2023Dane anonimowe (T. sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed a fine of PLN 18,864 on T. sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to information necessary for those duties.PLUODOGDPR€4,194
01 Jun 2023Comune di GuardiagreleComune di Guardiagrele was fined EUR 5,000 by the Garante for failing to provide an adequate response to a data access request. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€5,000
01 Jun 2023Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests.ITGaranteGDPR€20,000
01 Jun 2023Comune di NapoliComune di Napoli was fined for improperly communicating performance evaluation results of former employees. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€3,000
01 Jun 2023Ew Business Machines S.p.A.Ew Business Machines S.p.A. was fined 20,000 EUR by the Garante. The authority found that the company used a surveillance system without proper notice, collected employee fingerprints, and tracked employee locations through mobile apps without adequate transparency.ITGaranteGDPR€20,000
01 Jun 2023Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security.ITGaranteGDPR€10,000
01 Jun 2023Thin SrlThin Srl was fined EUR 15,000 by the Garante for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned processing activities linked to a medical project.ITGaranteGDPR€15,000
01 Jun 2023AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles.ITGaranteGDPR€20,000
01 Jun 2023NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data.ITGaranteGDPR€200,000
31 May 2023B.B.B.B.B.B. was fined EUR 500 by the AEPD for failing to properly sign a video surveillance system in a laundry establishment. The authority found a breach of Article 13 GDPR regarding the duty to inform individuals being recorded.ESAEPDGDPR€500
31 May 2023D.D.D.The entity installed surveillance cameras without authorization, breaching Article 5(1)(c) of the GDPR. The AEPD imposed a fine of EUR 500.ESAEPDGDPR€500
31 May 2023Dane anonimowe (G. Sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed an administrative fine of PLN 14,148 on G. Sp. z o.o. The sanction was issued for failing to cooperate with the authority in the performance of its duties and for not providing access to information necessary for those duties.PLUODOGDPR€3,119
31 May 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for failing to implement adequate security measures. This allowed a third party to impersonate a customer, change contact details, and gain unauthorized access to personal and banking data.ESAEPDGDPR€70,000
31 May 2023Dane anonimowe (P. Sp. z o.o. z siedzibą w W. przy ul.)UODO imposed a PLN 47,160 fine on the anonymous company for failing to implement appropriate technical and organizational measures to secure personal data processing in IT systems. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures, as well as failure to report the personal data breach without undue delay. In addition, the company did not notify affected individuals without undue delay despite a high risk to their rights and freedoms.PLUODOGDPR€10,395
30 May 2023B.B.B.The entity was fined for keeping an operational surveillance camera inside a rented apartment without informing the tenants. The authority found this to be a breach of data protection rules.ESAEPDGDPR€6,000
29 May 2023B.B.B.The entity was fined by the AEPD for failing to remove a viral video from Twitter that breached data protection rules. The case indicates a lack of timely action in response to content processing personal data without a lawful basis.ESAEPDGDPR€2,000
29 May 2023NOVA TELECOMMUNICATIONS & MEDIA MONOPROSOPI A.E.The company was fined for repeatedly sending unsolicited electronic communications for marketing purposes despite the complainant’s objections. The authority also found failures to comply with requests for access, objection, and restriction of processing.GRHDPAePrivacy€50,000
29 May 2023SERVICIOS E INTERVENCIONES EN EDIFICACION DEL MEDITERRÁNEO, S.L.The company published an image on its website without the individual's express consent. The authority treated the case as a repeat infringement because the company had previously been sanctioned for the same conduct.ESAEPDGDPR€2,000
29 May 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 70,000 EUR for processing call and SMS diversion without the customer's consent. The conduct was linked to a bank fraud incident, indicating a serious failure in data protection and service authorization controls.ESAEPDGDPR€70,000
26 May 2023B.B.B.The entity was fined EUR 300 by the AEPD for operating a video surveillance system that captured public areas without proper informational signage. The authority treated this as a breach of data protection rules.ESAEPDGDPR€300