Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The conduct breached Article 58(1) of the GDPR and hindered the authority’s supervisory powers.ESAEPDGDPR€5,000
12 Feb 2026Unleadmited S.r.l.Unleadmited S.r.l. was fined EUR 5,000 by the Garante for violations linked to aggressive telemarketing practices. The authority found non-compliance with data protection requirements.ITGaranteGDPR€5,000
03 Apr 2025Banca Transilvania S.A.Banca Transilvania S.A. was fined EUR 5,000 by ANSPDCP for processing personal data without a legal basis. The authority found a breach of the GDPR principle of lawfulness, fairness, and transparency.ROANSPDCPGDPR€5,000
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure.FRCNILGDPR€5,000
15 Apr 2021HAZTEOIR.ORGThe association HazteOir.Org was fined EUR 5,000 by the AEPD for including images and names of individuals in a pamphlet without their consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default.ITGaranteGDPR€5,000
23 Aug 2024Geanonimiseerd (APD 107/2024)The APD Litigation Chamber imposed a EUR 5,000 fine for responding to a data subject access request after more than 14 months. The authority found a breach of GDPR Articles 12 and 15, which require timely handling of access rights.BEAPDGDPR€5,000
15 Apr 2021Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly.ITGaranteGDPR€5,000
12 Mar 2025Automobilus International S.R.L.The company was fined for failing to implement appropriate technical and organizational measures to ensure an adequate level of security. The authority found this to be a breach of Article 32 of the GDPR.ROANSPDCPGDPR€5,000
25 Jul 2021CYNGASA, S.L.CYNGASA, S.L. was fined by the AEPD EUR 5,000 for transferring an employee’s personal data to another company without consent. The authority found this conduct to be a breach of Article 6 of the GDPR.ESAEPDGDPR€5,000
12 Jan 2023ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD EUR 5,000 for including personal data in a credit file without prior notice. The company also failed to respond to access requests, which constitutes a breach of GDPR Article 15.ESAEPDGDPR€5,000
11 Sept 2025SOCIETE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE under a simplified procedure. The case concerns an administrative decision by the French supervisory authority.FRCNILGDPR€5,000
08 May 2024CREMA GAMES, S.L.CREMA GAMES, S.L. was fined EUR 5,000 by the AEPD for breaching Article 15 of the GDPR. The company obstructed the complainant’s exercise of the right of access to their personal data.ESAEPDGDPR€5,000
11 Aug 2020FEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓNFEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓN was fined by the AEPD 5,000 EUR for the unauthorized disclosure of personal data. The data included names, DNI numbers, and signatures, which were published in a newspaper and on social media.ESAEPDGDPR€5,000
20 Dec 2019TECSIBLE, S.L.TECSIBLE, S.L. was fined by the AEPD 5,000 EUR for a data protection breach. The case involved unsolicited contact and messages sent to an individual on the Robinson list through a third-party call center.ESAEPDGDPR€5,000
19 Nov 2018VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 5,000 EUR for breaching data quality principles. The company incorrectly included personal data in a creditworthiness file despite a prior order to correct billing errors.ESAEPDGDPR€5,000
07 Jul 2015OLYMPION XENODOXEION AEThe company was fined by the HDPA EUR 5,000 for failing to implement appropriate organizational and technical security measures. The deficiency led to a data breach involving credit card information.GRHDPAGDPR€5,000
08 Aug 2014PARAMOUNT A.E.The company was fined EUR 5,000 by the HDPA for processing publicly available personal data without consent. The authority found a breach of the principles of lawful data collection and proportionality.GRHDPAGDPR€5,000
21 May 2025Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 5,000 by ANSPDCP. The authority found that the company did not provide complainants with complete information when they exercised their right of access to personal data.ROANSPDCPGDPR€5,000
07 Dec 2023ASESORÍA Y PROGRAMACIÓN PROFESIONAL, S.L.The entity was fined for continuing to send advertising emails despite the recipient's attempts to unsubscribe. This conduct breached Article 21 of the LSSI and resulted in a EUR 5,000 penalty.ESAEPDePrivacy€5,000