Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Apr 2023Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach.ITGaranteGDPR€176,000
27 Apr 2023Provvedimento del 27 aprile 2023 [9896468]A fine of EUR 400 was imposed for improper use of a video surveillance system that captured images of a public street without the required authorization. The case concerned a breach of personal data processing rules in the context of video monitoring.ITGaranteGDPR€400
27 Apr 2023Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements.ITGaranteGDPR€2,000
27 Apr 2023B.B.B.The entity installed a surveillance camera without informing tenants or obtaining their consent. The camera captured shared areas, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
27 Apr 2023Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements.ITGaranteGDPR€40,000
27 Apr 2023Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed.ITGaranteGDPR€8,000
27 Apr 2023Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification.ITGaranteGDPR€240,000
27 Apr 2023Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
27 Apr 2023Tiziana Life Science LimitedTiziana Life Science Limited was fined by the Italian Garante in the amount of EUR 30,000. The case concerned failure to provide information and obtain consent for processing personal and genetic data acquired from the bankrupt company Shar.Dna S.p.A. for scientific research purposes.ITGaranteGDPR€30,000
27 Apr 2023B.B.B.The entity was fined by the AEPD in the amount of EUR 1,000 for installing surveillance cameras without proper signage and justification. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,000
26 Apr 2023CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights.ESAEPDGDPR€220,000
26 Apr 2023Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures.SEIMYGDPR€17,566
24 Apr 2023B.B.B.B.B.B. published the complainant’s image and name on its website without consent. AEPD found this to be a breach of data protection rules and imposed a EUR 1,000 fine.ESAEPDGDPR€1,000
24 Apr 2023Tensa Art Design SAThe National Supervisory Authority completed an investigation in March 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined 1,000 EUR.ROANSPDCPGDPR€1,000
23 Apr 2023GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. did not delete the complainant’s personal data after a request and continued sending promotional emails. The AEPD found this to be a breach of Article 17 GDPR and imposed a fine of 10,000 EUR.ESAEPDGDPR€10,000
23 Apr 2023COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities.ESAEPDGDPR€2,000
21 Apr 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a SIM card swap without the user's consent. The incident enabled unauthorized access to the customer's bank information and resulted in a fraudulent bank transfer.ESAEPDGDPR€70,000
20 Apr 2023Dane anonimowe (Rzecznika Dyscyplinarnego Izby Adwokackiej w X.)UODO imposed a fine of PLN 23,580 on an anonymous entity for failing to implement appropriate technical and organizational measures. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures in relation to processing data using external storage media.PLUODOGDPR€5,114
20 Apr 2023HOLALUZ-CLIDOM, S.A.HOLALUZ-CLIDOM, S.A. was fined EUR 70,000 by the AEPD for processing personal data without consent. The company registered energy supplies for properties without the owner's consent, which breached Article 6(1) GDPR.ESAEPDGDPR€70,000
19 Apr 2023MULTIGAS ASESORES S.L.MULTIGAS ASESORES S.L. was fined EUR 500 by the AEPD. The company failed to provide access required under Article 58(1) GDPR, obstructing the data protection authority’s inspection function.ESAEPDGDPR€500