Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Apr 2025Ente di Patrocinio ed Assistenza per i Cittadini e l’Agricoltura (EPACA)EPACA was fined EUR 5,000 by the Italian Garante. The authority found that the organization retained personal data beyond the legally permitted period and accessed the INPS database without a valid mandate.ITGaranteGDPR€5,000
03 Jul 2025WALLAPOP, S.L.WALLAPOP, S.L. was fined by the AEPD in the amount of 5,000 EUR for using cookies without properly informing users or obtaining their consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€5,000
11 Jan 2024Euro Servizi per i Notai S.r.l.Euro Servizi per i Notai S.r.l. was fined 5,000 EUR by the Garante for processing personal data without a valid legal basis and without adequate transparency. The violations concerned reporting services provided to banks through the PIGNA portal.ITGaranteGDPR€5,000
22 Jun 2023More News società cooperativa a r.l.The Garante fined More News società cooperativa a r.l. 5,000 EUR for publishing a minor’s personal data without proper anonymization. The disclosure allowed acquaintances to identify the child and caused embarrassment.ITGaranteGDPR€5,000
28 Sept 2023Ministero dell'Ambiente e della Sicurezza EnergeticaThe Ministry of Environment and Energy Security was fined EUR 5,000 by the Garante for the online publication of personal data relating to numerous workers. The disclosure also included health-related data for some individuals.ITGaranteGDPR€5,000
02 Jul 2020Istituto Nazionale della Previdenza Sociale-Direzione Provinciale di BresciaThe Italian Data Protection Authority fined the INPS Brescia Provincial Directorate for failing to respond to a request for access to personal health data. The authority found a breach of data protection rules.ITGaranteGDPR€5,000
04 Dec 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 5,000 EUR for failing to provide the requested information. The case concerned a breach of obligations under data protection rules.ESAEPDGDPR€5,000
08 May 2024CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures.ROANSPDCPGDPR€5,000
21 Feb 2026VERTI ASEGURADORA, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.VERTI Aseguradora was fined by the AEPD €5,000 for sending promotional emails without providing a simple and free way for recipients to opt out. The authority found this to be a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2014CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD 5,000 EUR for sending unauthorized commercial emails. The conduct occurred after the complainant had exercised the right to object to the use of their data for advertising purposes.ESAEPDePrivacy€5,000
17 Jul 2015VUELING AIRLINES, S.A.VUELING AIRLINES, S.A. was fined by the AEPD 5,000 EUR for sending unsolicited commercial emails to a user who had previously unsubscribed. The authority found this breached article 21.1 of the LSSI.ESAEPDePrivacy€5,000
23 Aug 2023GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined by the AEPD 5,000 EUR for sending commercial emails to a complainant after they had opted out. The authority treated this as a breach of data protection rules.ESAEPDePrivacy€5,000
14 Jul 2017BARCLAYS BANK PLC Sucursal en EspañaBARCLAYS BANK PLC Sucursal en España was fined by the AEPD 5,000 EUR for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The breach occurred despite the recipient's request to cancel their personal data.ESAEPDePrivacy€5,000
22 Mar 2023GRUPO MASSIMO DUTTI, S.A.The AEPD fined GRUPO MASSIMO DUTTI, S.A. EUR 5,000 for failing to provide sufficient information and adequate options regarding cookie consent on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
11 Jan 2023Associazione Nazionale MagistratiAssociazione Nazionale Magistrati was fined by the Garante for improper handling of personal data. An official email address was used instead of a personal one to notify a disciplinary proceeding, which breached confidentiality requirements.ITGaranteGDPR€5,000
23 Jan 2025Softtehnica S.R.LIn December 2024, ANSPDCP completed an investigation at Softtehnica S.R.L. The authority found a GDPR violation and imposed a fine of EUR 5,000.ROANSPDCPGDPR€5,000
01 Jan 2017WEWI MOBILE, S.L.WEWI MOBILE, S.L. was fined by the AEPD in the amount of €5,000 for sending unsolicited commercial messages to individuals without their prior consent. This conduct breached the LSSI rules on marketing communications.ESAEPDePrivacy€5,000
18 May 2022SERVICIOS INTEGRALES DEL HOGAR TENERIFE, S.L.The company was fined by the AEPD for unlawfully processing personal data. The breach involved sending a wage garnishment notice via WhatsApp without proper authorization or legal basis.ESAEPDGDPR€5,000
21 Aug 2018Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements.GRHDPAGDPR€5,000
21 Sept 2022Curtea Veche Publishing SRLCurtea Veche Publishing SRL was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000