Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator.GRHDPAGDPR€40,000
29 Mar 2023SOLAR PROGRESS, S.L.SOLAR PROGRESS, S.L. was fined 5,000 EUR by the AEPD for displaying an employee’s personal data on a company WhatsApp profile. The authority found a breach of data protection rules.ESAEPDGDPR€5,000
28 Mar 2023SOCIETE DE PROGRAMMATION INFORMATIQUE (procédure simplifiée)The CNIL imposed a EUR 20,000 fine on SOCIETE DE PROGRAMMATION INFORMATIQUE under a simplified procedure. The record only indicates the financial sanction and does not provide further details on the underlying breach.FRCNILGDPR€20,000
28 Mar 2023DENTAL REY-GAR, S.L.DENTAL REY-GAR, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a resolution concerning the right of access to personal data. The authority found a breach of Article 58(2) of the GDPR.ESAEPDGDPR€1,000
28 Mar 2023SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a fine of EUR 10,000 on SOCIETE DE MARKETING and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
28 Mar 2023Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns.ITGarante per la protezione dei dati personaliGDPR€842,000
27 Mar 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the Spanish data protection authority, AEPD. The company failed to provide requested information, obstructing the authority’s investigative powers under Article 58(1) GDPR.ESAEPDGDPR€20,000
27 Mar 2023persoană fizicăAn individual was fined EUR 450 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules.ROANSPDCPGDPR€450
24 Mar 2023NATURGESTYGAS, S.L.NATURGESTYGAS, S.L. was fined EUR 10,000 by the AEPD for processing personal data without a legal basis. The company charged a customer despite having no contract or consent, which breached the legality requirement for processing.ESAEPDGDPR€10,000
24 Mar 2023A.A.A.A.A.A. was fined EUR 300 by the AEPD for failing to provide adequate information about data processing in a video surveillance system. The authority found a breach of Article 13 GDPR because data subjects did not receive the required information.ESAEPDGDPR€300
24 Mar 2023B.B.B.The entity installed surveillance cameras without the required informational signage. AEPD treated this as a breach of data protection rules.ESAEPDGDPR€300
24 Mar 2023COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The homeowners’ association was fined 500 EUR by the AEPD for installing surveillance cameras aimed at public areas without prior administrative authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€500
23 Mar 2023B.B.B.B.B.B. was fined 300 EUR by the AEPD for installing surveillance cameras that could capture images of a neighboring property without prior authorization. The authority found this to be a breach of the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€300
23 Mar 2023Dedalus Italia S.p.a.Dedalus Italia S.p.a. was fined EUR 15,000 by the Garante for failing to implement adequate measures to protect personal data. The authority found a breach of Article 32 GDPR on security of processing.ITGaranteGDPR€15,000
23 Mar 2023Consiglio Nazionale dell'Ordine degli Assistenti SocialiConsiglio Nazionale dell'Ordine degli Assistenti Sociali was fined EUR 3,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data during a recruitment process, including disclosure of information about a candidate's exclusion.ITGaranteGDPR€3,000
23 Mar 2023Tehnoplus Industry SRLTehnoplus Industry SRL was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
23 Mar 2023Comune di PulsanoComune di Pulsano was fined by the Garante for unlawfully publishing personal data related to an employee’s disciplinary proceedings on its institutional website. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€3,000
23 Mar 2023Tehnoplus Industry SRLANSPDCP imposed a fine of EUR 3,000 on Tehnoplus Industry SRL for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
23 Mar 2023Paolo MeloniThe condominium administrator, Paolo Meloni, was fined for disclosing to all residents that a family had tested positive for COVID-19. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,000
23 Mar 2023Azienda 1 di SassariThe Garante imposed a fine of 4,000 EUR on Azienda 1 di Sassari for violations related to the processing of personal data, including health data. The authority found that adequate security measures were not in place for this processing.ITGaranteGDPR€4,000