Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Mar 2023B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails after a request for data deletion. The conduct breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€2,000
23 Mar 2023La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security.ITGaranteGDPR€40,000
23 Mar 2023CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data.ITGaranteGDPR€30,000
23 Mar 2023Gruppo SAE S.p.A.The Garante fined Gruppo SAE S.p.A. 10,000 EUR for publishing sensitive personal data, including medical information, in an article without proper consent. The case concerns unlawful processing of special-category personal data.ITGaranteGDPR€10,000
23 Mar 2023Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements.ITGaranteGDPR€4,000
22 Mar 2023GRUPO MASSIMO DUTTI, S.A.The AEPD fined GRUPO MASSIMO DUTTI, S.A. EUR 5,000 for failing to provide sufficient information and adequate options regarding cookie consent on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
18 Mar 2023TOTALENERGIES CLIENTES, S.A.TOTALENERGIES CLIENTES, S.A. was fined EUR 200,000 by the AEPD for linking a customer’s personal data to a third party during gas supply service registration. The authority found this breached data protection principles.ESAEPDGDPR€200,000
17 Mar 2023ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions.ESAEPDGDPR€70,000
17 Mar 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.The AEPD fined TELEFÓNICA MÓVILES ESPAÑA, S.A. 70,000 EUR for changing a customer's mobile tariff without consent. The authority found that the action breached Article 6(1) GDPR because there was no valid legal basis for the change.ESAEPDGDPR€70,000
17 Mar 2023PLAY FUL KIDS, S.L.PLAY FUL KIDS, S.L. was fined by the AEPD EUR 3,000 for breaching Article 6(1) of the GDPR, which requires a lawful basis for processing personal data. The infringement was classified as very serious.ESAEPDGDPR€3,000
16 Mar 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts.ESAEPDGDPR€200,000
16 Mar 2023Argon Medical DevicesArgon Medical Devices was fined NOK 2.5 million by the Norwegian Data Protection Authority, Datatilsynet. The company failed to report a personal data breach involving European employees within the 72-hour deadline required by GDPR Article 33.NODatatilsynetGDPR€218,000
16 Mar 2023PRODALVIN, S.L.PRODALVIN, S.L. was fined by the AEPD in the amount of 500 EUR for failing to properly inform individuals about the data controller and the address for exercising data subject rights in its video surveillance system. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€500
16 Mar 2023Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for unauthorized disclosure and access to personal data. The case concerned data confidentiality and breaches of GDPR obligations.ROANSPDCPGDPR€1,000
16 Mar 2023B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for failing to provide adequate information about video surveillance. The authority found a breach of Article 13 GDPR because the affected individuals did not receive the required information.ESAEPDGDPR€300
16 Mar 2023SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICEThe CNIL imposed a fine of EUR 125,000 on SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICE. The case concerns a confirmed breach of rules supervised by the data protection authority.FRCNILGDPR€125,000
16 Mar 2023Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for failing to implement adequate security measures, which led to unauthorized access to personal data. The case indicates a breach of data protection obligations under the GDPR.ROANSPDCPGDPR€3,000
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
15 Mar 2023Partidul Uniunea Salvați RomâniaThe fine was imposed for a data security breach involving the loss of confidentiality and integrity of data stored on a server. The incident resulted from a phishing attack that compromised the system.ROANSPDCPGDPR€4,000
15 Mar 2023Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements.ROANSPDCPGDPR€10,000