Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 May 2023COLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRECOLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRE was fined by the AEPD for failing to implement appropriate technical and organizational measures to ensure data security. The deficiency resulted in a breach involving minors’ data stored in cloud services.ESAEPDGDPR€5,000
15 May 2023TikTok Information Technologies UK Limited and TikTok Inc (TikTok)The UK ICO imposed a fine of 12,700,000 GBP on TikTok Information Technologies UK Limited and TikTok Inc for multiple breaches of data protection law. The regulator specifically cited unlawful use of children’s personal data.GBICOGDPR€14,607,000
12 May 2023Noi sancțiuniA company in the insurance sector was fined by ANSPDCP in the amount of 1,500 EUR for violating GDPR Article 5. The case concerned non-compliance with the basic principles for processing personal data.ROANSPDCPGDPR€1,500
12 May 2023CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed a fine of EUR 4,500 on CHIRURGIEN DENTISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€4,500
12 May 2023Noi sancțiuniAn insurance-sector company was fined EUR 1,000 by ANSPDCP for breaching GDPR Article 5. The case concerned non-compliance with the core principles governing personal data processing under data protection law.ROANSPDCPGDPR€1,000
12 May 2023Meta Platforms Ireland Limited (previously known as Facebook Ireland Limited)The Irish DPC imposed a fine of EUR 1,200,000,000 on Meta Platforms Ireland Limited (formerly Facebook Ireland Limited) in case IN-20-8-1. The decision is currently under appeal.IEDPCGDPR€1,200,000,000
12 May 2023CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine.ESAEPDGDPR€4,000
11 May 2023SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRECNIL imposed a fine of 380,000 EUR on SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRE. The case concerns data processing breaches in connection with a health and wellness website.FRCNILGDPR€380,000
11 May 2023Libra Internet Bank SALibra Internet Bank SA was fined EUR 1,000 by ANSPDCP. The sanction relates to a breach of GDPR provisions.ROANSPDCPGDPR€1,000
11 May 2023Libra Internet Bank SALibra Internet Bank SA was fined EUR 10,000 by ANSPDCP for another breach of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€10,000
09 May 2023Dane anonimowe (Burmistrza Miasta i Gminy W.)UODO imposed an administrative fine of PLN 10,000 on the Mayor of the City and Commune of W. for failing to implement organisational measures appropriate to the risk of data processing. The deficiency resulted in an employee unlawfully copying personal data from a work computer to a portable storage device.PLUODOGDPR€2,187
09 May 2023TELEFÓNICA SERVICIOS INTEGRALES DE DISTRIBUCIÓN, S.A.ZELERIS, a Telefónica subsidiary, was fined by the AEPD for delivering a package containing personal data to the wrong address without consent. The case indicates a breach of data protection rules in the handling and delivery of shipments.ESAEPDGDPR€70,000
04 May 2023RENEDO JOHNSEY, S.L.RENEDO JOHNSEY, S.L. was fined by the AEPD €2,000 for not having a privacy policy on its website. The authority treated this as a breach of Article 13 of the GDPR.ESAEPDGDPR€2,000
03 May 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined EUR 20,000 by the AEPD for irregularities in the cookie policy on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€20,000
03 May 2023B.B.B.A small hospitality establishment was fined 500 EUR by the AEPD for installing a surveillance camera that excessively recorded public areas. The authority found a breach of data protection rules.ESAEPDGDPR€500
02 May 2023KópavogsbærKópavogsbær was fined 4,000,000 ISK by Persónuvernd for using the Seesaw student system in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which requires a lawful basis and appropriate safeguards.ISPersónuverndGDPR€26,720
02 May 2023InternetThe company was fined for failing to implement adequate security measures for personal data processing. The deficiency led to a data breach involving user accounts, including accounts protected by weak passwords.CZUOOUGDPR€63,600
27 Apr 2023ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its investigative functions.ESAEPDGDPR€6,000
27 Apr 2023Ministero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di LecceMinistero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce was fined 15,000 EUR by the Garante for publishing personal data on its website. The case concerns a breach of data protection rules through unauthorized disclosure of information.ITGaranteGDPR€15,000
27 Apr 2023Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data.ITGaranteGDPR€239,000