Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Mar 2023Tinmar Energy SATinmar Energy SA was fined EUR 3,000 by ANSPDCP after unauthorized access to its email server. The incident resulted in a personal data breach.ROANSPDCPGDPR€3,000
14 Mar 2023DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined 2,000 EUR by the AEPD for failing to remove an ex-employee’s image from its YouTube channel despite repeated requests. The authority found a breach of GDPR Article 6(1) regarding the lawful basis for processing personal data.ESAEPDGDPR€2,000
14 Mar 2023Dane anonimowe (Prokuraturę Rejonową w G. z siedzibą w G. przy ul.)UODO imposed an administrative fine of PLN 20,000 on the District Prosecutor's Office in G. The authority found that the entity failed to notify the supervisory authority of a personal data breach without undue delay and did not inform the affected individuals without undue delay.PLUODOGDPR€4,266
13 Mar 2023JUNTA MAYOR DE COFRADÍAS Y HERMANDADES DE LA SEMANA SANTA DE ELCHEThe organization did not inform participants about the processing of their personal data during the “Gymkhana Cofrade” event, which constitutes a breach of Article 13 GDPR. The AEPD imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
13 Mar 2023Modaone SRLModaone SRL was fined by ANSPDCP EUR 2,000 for sending commercial emails to a data subject after the person had objected. The authority found a breach of the GDPR right to object.ROANSPDCPGDPR€2,000
10 Mar 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security.ESAEPDGDPR€200,000
09 Mar 2023EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€10,000
09 Mar 2023B.B.B.A camera was installed in a community garage without prior authorization and without proper signage. The AEPD found this to be a breach of Article 13 GDPR and imposed a EUR 300 fine.ESAEPDGDPR€300
09 Mar 2023INTERURBANA DE AUTOBUSES, S.A.INTERURBANA DE AUTOBUSES, S.A. was fined by the AEPD 70,000 EUR for publishing employees’ personal data without consent. The breach involved exposing unnecessary information on notice boards accessible to others, contrary to data minimization requirements.ESAEPDGDPR€70,000
09 Mar 2023Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12.ITGaranteGDPR€10,000
09 Mar 2023B.B.B.B.B.B. was fined by the AEPD EUR 600 for failing to implement corrective measures regarding improperly oriented surveillance cameras. The authority also found a failure to provide the required information under the GDPR.ESAEPDGDPR€600
09 Mar 2023Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data.ITGaranteGDPR€3,000
09 Mar 2023Stefano MolenaThe Garante imposed a EUR 3,000 fine on Stefano Molena for operating a surveillance camera without the required informational signage. The breach concerned privacy rules and the duty to properly inform individuals subject to monitoring.ITGaranteGDPR€3,000
09 Mar 2023Deca s.r.l.Deca s.r.l. was fined EUR 1,600 by the Garante. The authority found that the company failed to respond to requests for access to personal data relating to work attendance and unlawfully processed data through an incomplete video surveillance system.ITGaranteGDPR€1,600
09 Mar 2023Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data.ITGaranteGDPR€2,000
08 Mar 2023RING RING CLIN S.L.RING RING CLIN S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR.ESAEPDGDPR€500
08 Mar 2023ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)The organization published a court ruling on its blog without anonymizing the personal data of the individuals involved. The AEPD found a breach of the data minimization principle and imposed a 500 EUR fine.ESAEPDGDPR€500
07 Mar 2023SIA "Euronics Latvia"The DVI imposed a fine of EUR 20,000 on SIA "Euronics Latvia". The decision entered into force on 7 March 2023.LVDVIGDPR€20,000
06 Mar 2023B.B.B.The entity was fined by the AEPD €5,000 for publishing radio amateurs’ personal data on a Telegram channel. The breach involved linking call signs to personal information, which violated data protection rules.ESAEPDGDPR€5,000
06 Mar 2023Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€3,000