Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 5,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and required remedial action by the bank.ROANSPDCPGDPR€5,000
22 Jun 2023Maviglia Assicurazioni snc di Gherardo Maviglia & c.Maviglia Assicurazioni was fined 5,000 EUR by the Garante for failing to deactivate former employees' email accounts. This allowed unauthorized access to data and breached data protection rules.ITGaranteGDPR€5,000
11 May 2026Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights.BEAPDGDPR€5,000
11 Feb 2021Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website.ITGaranteGDPR€5,000
18 Dec 2023MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them.ESAEPDePrivacy€5,000
23 May 2024Radio Marte S.r.l.Radio Marte S.r.l. was fined EUR 5,000 by the Garante for unlawfully disseminating identifying data of a minor during a radio program. The authority found a breach of privacy and personal data protection rules.ITGaranteGDPR€5,000
15 Dec 2022Azienda Sanitaria provinciale di CataniaAzienda Sanitaria provinciale di Catania was fined 5,000 EUR by the Garante for unlawfully publishing personal data on its website concerning an employee's disciplinary and criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€5,000
01 Jan 2019CENTRO DE ESTUDIOS DIRIGIDOS DELTA, S.L.The entity sent a document via WhatsApp containing personal data of three individuals without their consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€5,000
15 Dec 2022Societatea Energetică Electrica S.A.In November 2022, ANSPDCP completed an investigation at Societatea Energetică Electrica S.A. and found a GDPR violation. The operator was fined 5,000 EUR and advised to take all necessary measures to comply with the rules.ROANSPDCPGDPR€5,000
05 Aug 2021HUBSIDE IBÉRICA S.L.HUBSIDE IBÉRICA S.L. was fined by the AEPD for charging a customer for services that were not contracted. Personal and bank account data were collected during a purchase, and the penalty was reduced due to early payment.ESAEPDGDPR€5,000
10 Apr 2025Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose.ITGaranteGDPR€5,000
16 May 2023Compania Națională Poșta Română S.A.Compania Națională Poșta Română S.A. was fined EUR 5,000 by ANSPDCP for GDPR violations related to the completion of Form 230. The case arose from complaints, and the authority instructed the company to ensure personal data processing complies with processing principles.ROANSPDCPGDPR€5,000
09 Oct 2025AD Media S.r.l.AD Media S.r.l. was fined EUR 5,000 by the Garante for sending promotional emails without proper consent. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€5,000
06 Dec 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules.ESAEPDGDPR€5,000
19 Dec 2024ACCES AUX SOINS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on ACCES AUX SOINS under a simplified procedure. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€5,000
11 Jan 2017WIZINK BANK, S.A.WIZINK BANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
11 Dec 2025UPGYMS IBERIA, S.L.UPGYMS IBERIA, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages without obtaining recipient consent. The conduct breached the LSSI rules on marketing communications.ESAEPDePrivacy€5,000
26 Jan 2022ESTUDIO INMOBILIARIO SAN ISIDRO, S.L.UESTUDIO INMOBILIARIO SAN ISIDRO, S.L.U was fined by the AEPD EUR 5,000 for unlawfully obtaining personal data and visiting the complainant's home to promote real estate services without proper consent. The case concerns unlawful processing and improper direct marketing contact.ESAEPDGDPR€5,000
25 May 2025ENTIDAD DE CONSERVACION TORREMIRONAThe entity was fined by the AEPD for operating a video surveillance system that excessively covered public areas. This infringed the privacy of residents and passersby.ESAEPDGDPR€5,000
01 Jul 2021UNIVERSIDAD A DISTANCIA DE MADRID, S.A.UNIVERSIDAD A DISTANCIA DE MADRID, S.A. was fined by the AEPD for failing to comply with a request to delete personal data. As a result, the individual received unsolicited marketing emails, indicating a breach of data protection obligations.ESAEPDGDPR€5,000