Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Apr 2023Partidul Uniunea Salvați RomâniaThe National Supervisory Authority imposed a fine on Partidul Uniunea Salvați România (USR) for publishing personal data of persons with disabilities on its website without a legal basis. The authority found a breach of personal data processing principles.ROANSPDCPGDPR€3,000
18 Apr 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 140,000 EUR for a data protection breach involving incorrect billing information. A customer's mobile line was charged under another person's name, indicating an error in the processing of personal data.ESAEPDGDPR€140,000
18 Apr 2023B.B.B.A neighbor installed a surveillance camera aimed at the public street without authorization. The authority found this breached the data minimization principle under GDPR Article 5(1)(c).ESAEPDGDPR€300
17 Apr 2023SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALECNIL imposed a penalty of EUR 5,200,000 on SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE in connection with the liquidation of astreinte. The case concerns failure to comply with a prior obligation within the required timeframe, resulting in this amount being due.FRCNILGDPR€5,200,000
17 Apr 2023WIZINK BANK, S.A.WIZINK BANK, S.A. was fined 5,000 EUR by the AEPD for sending commercial emails to a complainant who had opted out of receiving such communications. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
17 Apr 2023SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEESCNIL imposed a EUR 10,000 penalty on SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEES in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the sanction for non-compliance.FRCNILGDPR€10,000
17 Apr 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 200,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident led to identity theft and fraudulent bank charges.ESAEPDGDPR€200,000
14 Apr 2023ESTUDIO VILLALBA ANTIQUE, S.L.ESTUDIO VILLALBA ANTIQUE, S.L. was fined by the AEPD for processing personal data without consent. The authority found a breach of the lawfulness principle under Article 6(1) GDPR.ESAEPDGDPR€5,000
14 Apr 2023Sorgenia S.p.a.Sorgenia S.p.a. was fined EUR 676,956 by the Italian data protection authority, Garante. The case concerned failure to respect data deletion and objection rights in connection with unlawful telemarketing practices in the energy sector.ITGaranteGDPR€676,000
14 Apr 2023Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles.ITGaranteGDPR€237,000
14 Apr 2023Join the Triboo LimitedBetween 1 August 2019 and 19 August 2020, Join the Triboo Limited sent a confirmed total of 107 million direct marketing messages, of which 437,324 were received by distinct individuals. On average, each person received 244 emails during the period, and the messages contained direct marketing material without valid subscriber consent.GBICOGDPR€146,000
13 Apr 2023Citynews S.p.A.Citynews S.p.A. was fined EUR 15,000 by the Italian data protection authority, Garante. The case concerned the publication of detailed health information about an individual without consent, in breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€15,000
13 Apr 2023Unione PilotiUnione Piloti was fined by the Garante in the amount of 4,000 EUR for violations related to the processing of personal data. The authority found that the company failed to ensure lawful, fair, and transparent data handling.ITGaranteGDPR€4,000
13 Apr 2023Arnia società cooperativaThe Garante imposed a fine of 800,000 EUR on Arnia società cooperativa for unauthorized data processing and telemarketing activities. The case concerned a breach of GDPR Article 5.ITGaranteGDPR€800,000
13 Apr 2023Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32.NLAPGDPR€150,000
13 Apr 2023SWG S.p.A.SWG S.p.A. was fined EUR 15,000 by the Garante for blocking an employee’s access to email and phone before the agreed termination date. This prevented access to personal data, including sensitive data.ITGaranteGDPR€15,000
13 Apr 2023Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data.ITGaranteGDPR€2,500
13 Apr 2023GMC s.a.p.a.GMC s.a.p.a. was fined EUR 15,000 by the Italian supervisory authority, Garante. The case concerned the publication of detailed health data of an individual without consent, in breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€15,000
13 Apr 2023Ordine degli Avvocati di AnconaThe Garante fined the Ordine degli Avvocati di Ancona 20,000 EUR for violations related to data processing transparency and security. The authority found incorrect privacy notices and non-compliance with GDPR principles.ITGaranteGDPR€20,000
13 Apr 2023Azienda Ospedaliero Universitaria SeneseThe Garante fined Azienda Ospedaliero Universitaria Senese EUR 13,000 for violations related to the processing of personal data in the health sector. The case concerned data minimization and security measures.ITGaranteGDPR€13,000