Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Apr 2023Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€8,000
13 Apr 2023Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data.ITGaranteGDPR€2,500
13 Apr 2023Comune di Cogollo del CengioThe Garante fined Comune di Cogollo del Cengio EUR 3,000 for breaches of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-septies of the Italian Privacy Code. The case concerned the processing of an employee’s personal data without an adequate legal basis and in breach of data protection rules.ITGaranteGDPR€3,000
12 Apr 2023Česká republika – Ministerstvo vnitraThe Czech Ministry of Interior was fined CZK 975,000 by the UOOU for violations of personal data processing rules during COVID-19 measures. The authority found, among other issues, a failure to conduct data protection impact assessments and improper disclosure of processing purposes.CZUOOUGDPR€41,633
11 Apr 2023CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine.ESAEPDGDPR€150,000
11 Apr 2023CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules.ESAEPDGDPR€200,000
11 Apr 2023SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle.ESAEPDGDPR€150,000
10 Apr 2023BIROU GAS, S.L.BIROU GAS, S.L. was fined EUR 60,000 by the AEPD for breaching Article 58(1) of the GDPR. The company did not respond to information requests from the supervisory authority.ESAEPDGDPR€60,000
10 Apr 2023COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent.ESAEPDePrivacy€14,000
06 Apr 2023К. Л. НK. L. N was fined for unlawfully processing voters' personal data. The case involved forwarding an email containing scanned voting lists to a personal email address, in breach of GDPR Article 6.BGCPDPGDPR€767
04 Apr 2023Tensa Art Design SRLThe company was fined for sending commercial messages to individuals by phone and email despite their requests to stop contact. The case concerned failure to respect opt-out requests against further marketing communication.ROANSPDCPGDPR€3,000
04 Apr 2023B.B.B.A neighbor installed a digital peephole with video recording capabilities without the consent of the homeowners' association. AEPD found that personal data were processed without a lawful basis, in breach of Article 6(1) GDPR.ESAEPDGDPR€300
03 Apr 2023HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards.ESAEPDGDPR€200,000
03 Apr 2023Banca Transilvania SABanca Transilvania SA was fined EUR 2,000 by ANSPDCP for a GDPR breach. The case concerned improperly restricting access to an account in the mobile banking application despite the client's explicit request.ROANSPDCPGDPR€2,000
03 Apr 2023CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR.ESAEPDGDPR€200,000
01 Apr 2023TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully.GBInformation Commissioner's OfficeGDPR€14,444,000
31 Mar 2023LODEJU, S.L.LODEJU, S.L. was fined by the AEPD EUR 3,000 for improperly directing surveillance cameras toward public spaces without authorization. The authority also found inadequate informational signage, in breach of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
31 Mar 2023APOLLONIA TOPCO, S.L.APOLLONIA TOPCO, S.L. was fined by the AEPD EUR 30,000 for improperly requesting copies of clients’ ID documents. The authority also noted a failure to respond to a data protection complaint, in breach of data minimization and purpose limitation principles.ESAEPDGDPR€30,000
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation.GRHDPAGDPR€10,000
30 Mar 2023XCOM DIGITAL LAB, S.L.XCOM DIGITAL LAB, S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The company failed to comply with Article 21 of the LSSI despite repeated requests from the recipient to unsubscribe.ESAEPDePrivacy€800