Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Mar 2022PRODESSPA DECORATIUS I PINTURES, S.L.PRODESSPA DECORATIUS I PINTURES, S.L. was fined by the AEPD 15,000 EUR for unlawfully processing personal data. The company included a former employee’s data in a credit information system without proper legal justification.ESAEPDGDPR€15,000
14 Sept 2023društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach.HRAZOPGDPR€15,000
28 Feb 2025DYNAMIC EXPRESS COURIER S.LDYNAMIC EXPRESS COURIER S.L was fined 15,000 EUR by the AEPD for subcontracting without prior authorization and for failing to put proper contracts in place with subcontractors. The authority found this conduct breached GDPR Article 28 on processor arrangements.ESAEPDGDPR€15,000
02 Jul 2020Mapei S.p.A.Mapei S.p.A. was fined EUR 15,000 by the Italian authority Garante. The case concerned the failure to respond to a request for access to email communications and the failure to delete an email account after employment ended, in breach of GDPR principles.ITGaranteGDPR€15,000
29 May 2020Dane anonimowe (R. Sp. z o.o. z siedzibą w D. przy ul.)UODO imposed a fine of PLN 15,000 on R. Sp. z o.o. The sanction concerned the failure to provide information required by the authority.PLUODOGDPR€3,371
29 Dec 2022SOCIETE DEVELOPPANT DES LOGICIELS DE GESTION ET LA COMMERCIALISATION DE LOGICIELS A DESTINATION DES COLLECTIVITES TERRITORIALES (procédure simplifiée)The CNIL imposed a fine of EUR 15,000 on SOCIETE DEVELOPPANT DES LOGICIELS DE GESTION ET LA COMMERCIALISATION DE LOGICIELS A DESTINATION DES COLLECTIVITES TERRITORIALES under a simplified procedure. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€15,000
01 Jul 2024Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000.MTIDPCGDPR€15,000
23 Aug 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD for failing to comply with a resolution concerning the right of access. The authority cited a breach of Article 83(6) GDPR.ESAEPDGDPR€15,000
11 Mar 2021Mediacom s.r.l.Mediacom s.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The authority found that this conduct breached GDPR rules on the processing of personal data for marketing purposes.ITGaranteGDPR€15,000
09 Jan 2025SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE (procédure simplifiée)The CNIL imposed an administrative fine of 15,000 EUR on SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE and issued an injunction. The case was handled under simplified proceedings.FRCNILGDPR€15,000
13 Dec 2012Azienda sanitaria regionale MoliseThe Regional Health Company of Molise was fined for failing to designate data processing officers for each employee. The authority also found that minimum security measures for electronic processing were not implemented, including weak password policies and insufficient protection against unauthorized external access.ITGaranteGDPR€15,000
26 Feb 2026Ministero delle Imprese e del Made in ItalyMinistero delle Imprese e del Made in Italy was fined by the Garante €15,000 for unlawfully publishing personal data in a ranking list. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€15,000
30 Jun 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 15,000 EUR for incorrectly listing a customer's ex-spouse as the account holder, even though the customer's data appeared on invoices. The company acknowledged responsibility and paid the reduced fine.ESAEPDGDPR€15,000
23 May 2024SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS. The decision was issued under a simplified procedure and concerns a breach of data protection rules.FRCNILGDPR€15,000
24 Jan 2024CAJA RURAL DE ONDA, S.C.C.CAJA RURAL DE ONDA, S.C.C. was fined by the AEPD 15,000 EUR for violating data protection principles, including confidentiality and integrity. The breach resulted in unauthorized access to personal data.ESAEPDGDPR€15,000
07 Feb 2022JIMBO NETWORKS, S.L.JIMBO NETWORKS, S.L. was fined by the AEPD for unlawful processing of personal data obtained from emails and for cookie policy violations on its website. The authority found that users were not properly informed and that valid consent was not obtained where required.ESAEPDGDPR€15,000
03 Mar 2023SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE (procédure simplifiée)The CNIL imposed a EUR 15,000 fine on SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE under a simplified procedure. The case concerns a breach of personal data protection rules.FRCNILGDPR€15,000
25 Sept 2025Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards.ITGaranteGDPR€15,000
23 Oct 2025Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization.ITGaranteGDPR€15,000
06 Oct 2022Servizio Idrico Integrato S.c.p.a.Servizio Idrico Integrato S.c.p.a. was fined by the Garante EUR 15,000 for failing to implement adequate security measures to protect the personal data of users registered on its website. The case concerned insufficient safeguards for data processed online.ITGaranteGDPR€15,000