Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Apr 2019Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
31 Jan 2019Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system.ITGaranteGDPR€16,000
20 Jun 2013Terme di Agnano s.p.a.Terme di Agnano s.p.a. was fined EUR 16,000 by the Garante for processing personal and sensitive data of individuals undergoing thermal treatments without the required notice and consent. The authority also found that personal data of job applicants were processed without providing the mandatory information notice.ITGaranteGDPR€16,000
14 Feb 2019Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
04 May 2017Starweb s.r.l.Starweb s.r.l. was fined €16,000 by the Garante for making unsolicited promotional calls. The authority found that the company failed to provide the required information notice and did not obtain consent from the contacted individuals.ITGaranteGDPR€16,000
06 Jun 2022Dane anonimowe (C.)UODO imposed an administrative fine of PLN 15,994 on Anonymous Data (C.). The case concerned the failure to report a personal data breach involving the loss of an employee’s employment certificate.PLUODOGDPR€3,491
26 Jan 2023Политическа партия ******The political party unlawfully processed personal data by including individuals in a list supporting its election registration without their consent. The authority found breaches of GDPR Articles 5, 6, and 24.BGCPDPGDPR€7,823
11 Sept 2025ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities.ITGaranteGDPR€15,000
19 May 2021CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing.NLAPGDPR€15,000
13 Apr 2023Citynews S.p.A.Citynews S.p.A. was fined EUR 15,000 by the Italian data protection authority, Garante. The case concerned the publication of detailed health information about an individual without consent, in breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€15,000
25 Apr 2024SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT. The case was handled under a simplified procedure.FRCNILGDPR€15,000
20 Dec 2019GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f).ESAEPDGDPR€15,000
24 Jan 2024CAIXA RURAL LA VALL SAN ISIDRO, S.C.C.CAIXA RURAL LA VALL SAN ISIDRO was fined by the AEPD 15,000 EUR for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data.ESAEPDGDPR€15,000
26 Sept 2024SOCIETE PROPOSANT DES SERVICES DE CONSEIL EN SYSTÈMES ET LOGICIELS INFORMATIQUES, L'EDITION ET LA REALISATION DE LOGICIELS (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€15,000
20 Jan 2025Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 15,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€15,000
23 Mar 2023Dedalus Italia S.p.a.Dedalus Italia S.p.a. was fined EUR 15,000 by the Garante for failing to implement adequate measures to protect personal data. The authority found a breach of Article 32 GDPR on security of processing.ITGaranteGDPR€15,000
10 Oct 2024Dane anonimowe (X w K.)The UODO imposed an administrative fine of PLN 15,000 on the entity identified as Anonymous data (X in K.). The authority found breaches of data protection principles, including integrity and confidentiality, accountability, data protection by design, processor obligations, and security measures.PLUODOGDPR€3,485
05 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated attempts to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€15,000
12 Sept 2024Medic4All Italia S.r.l.Medic4All Italia S.r.l. was fined by the Garante 15,000 EUR for failing to respond to a data subject access request. The conduct breached Article 15 GDPR, which requires controllers to provide access to personal data upon request.ITGaranteGDPR€15,000
23 Jan 2024CAJA RURAL GRANADA, S.C.C.CAJA RURAL GRANADA was fined by the AEPD EUR 15,000 for breaching data protection principles. The authority found that unauthorized access to personal data occurred due to a security incident, affecting confidentiality and integrity.ESAEPDGDPR€15,000