Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Apr 2023WIZINK BANK, S.A.WIZINK BANK, S.A. was fined 5,000 EUR by the AEPD for sending commercial emails to a complainant who had opted out of receiving such communications. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2022UNIQUEDESIGN & DECOR, S.L.UNIQUEDESIGN & DECOR, S.L. was fined by the AEPD 5,000 EUR for not having an accessible privacy policy on its website. The authority found a breach of Article 13 GDPR because users were not properly provided with the required information.ESAEPDGDPR€5,000
14 Feb 2024ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined by the AEPD €5,000 for continuing to send commercial emails despite repeated requests to unsubscribe. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2016AUTOCLUB MUTUA MADRILEÑA S.L.AUTOCLUB MUTUA MADRILEÑA S.L. was fined by the AEPD 5,000 EUR for sending an unsolicited commercial SMS without prior consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
03 May 2024D.D.D.The entity published images of a minor on its Telegram channel without consent, breaching data protection rules. AEPD imposed a fine of EUR 5,000.ESAEPDGDPR€5,000
24 Jun 2023BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 5,000 by the AEPD for repeatedly sending commercial emails to a client despite requests to unsubscribe. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€5,000
11 Jan 2023AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once.ESAEPDePrivacy€5,000
20 Dec 2025KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case concerned debt collection related to a loan that the complainant had neither consented to nor requested.ESAEPDGDPR€5,000
15 Jan 2024AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on AVOCAT (procédure simplifiée). The case concerned a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€5,000
11 Mar 2021Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing.ITGaranteGDPR€5,000
16 Jun 2025SC Kashto Concept SRLANSPDCP completed an investigation at SC Kashto Concept SRL and found a breach of the GDPR. The operator was fined 5,000 RON.ROANSPDCPGDPR€995
16 May 2019ANANEOSI MONOPROSOPI E.P.E.The company was fined for making unsolicited marketing calls to subscribers registered on the opt-out list. It also failed to properly identify itself during the calls, which hindered data subjects’ ability to exercise their rights.GRHDPAePrivacy€5,000
30 Jul 2013GLOBAL GREECE M.E.P.EThe company was fined for sending marketing emails without obtaining subscribers' consent. The authority found a breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€5,000
27 Sept 2021Сиела Норма АДThe CPDP found that Сиела Норма АД violated the GDPR by inaccurately processing personal data. The error led to an individual being misidentified as a liquidator of companies, and a fine of 5,000 BGN was imposed.BGCPDPGDPR€2,557
20 Jun 2024Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations.ITGaranteGDPR€5,000
01 Jan 2024ACTIVOS INTELIGENTES, S.L.ACTIVOS INTELIGENTES, S.L. was fined by the AEPD 5,000 EUR for requiring guests to submit selfies with their ID cards during check-in. The authority found the data collection excessive and not properly justified or explained in terms of processing purposes.ESAEPDGDPR€5,000
01 Jan 2021JUBASER DE CONTROL, S.L.JUBASER DE CONTROL, S.L. was fined by the AEPD 5,000 EUR for unlawful processing of personal data. The case concerned improper handling of a customer's ID and personal information, which later appeared on an adult contact website.ESAEPDGDPR€5,000
10 Jun 2024BOULANGERIE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on BOULANGERIE under a simplified procedure. The record does not provide further details on the underlying infringement.FRCNILGDPR€5,000
16 Sept 2021Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information.ITGaranteGDPR€5,000
31 Dec 2024PARTICULIERS (procédure simplifiée)An administrative fine of EUR 5,000 was imposed by the CNIL. The case was handled under a simplified procedure.FRCNILGDPR€5,000