Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jan 2020COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images.ESAEPDGDPR€5,000
27 Apr 2023B.B.B.The entity installed a surveillance camera without informing tenants or obtaining their consent. The camera captured shared areas, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
26 Mar 2026PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice.ITGaranteGDPR€5,000
31 Mar 2022FUNDACIÓ ESCOLA PRIVADA DE GESTIÓThe entity was fined by the AEPD 5,000 EUR for failing to implement adequate security measures under Article 32 of the GDPR. This deficiency led to a personal data breach.ESAEPDGDPR€5,000
16 Oct 2024D**** GmbHThe company appointed its managing director as the data protection officer, creating a conflict of interest. The DSB found this breached Article 38(6) GDPR and imposed a fine of EUR 5,000.ATDSBGDPR€5,000
28 Nov 2021INCOPROSOL, S.L.INCOPROSOL, S.L. was fined EUR 5,000 by the AEPD for recording a customer's phone conversation without informing them. The authority treated this as a breach of data protection principles.ESAEPDGDPR€5,000
03 Oct 2024ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined EUR 5,000 by the AEPD for continuing to send marketing emails despite the recipient's unsubscribe requests. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
11 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'ARTS DU SPECTACLE VIVANT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE EXERCANT UNE ACTIVITE D'ARTS DU SPECTACLE VIVANT and issued an injunction. The case concerns a breach of regulatory obligations under the data protection authority's supervision.FRCNILGDPR€5,000
16 Sept 2021Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data.ITGaranteGDPR€5,000
20 Dec 2022HAYS PERSONNEL SERVICE ESPAÑA, S.A.HAYS PERSONNEL SERVICE ESPAÑA, S.A. was fined by the AEPD 5,000 EUR for sending marketing emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for such communications.ESAEPDePrivacy€5,000
23 Jan 2023SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a EUR 5,000 fine on SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The authority also issued an injunction to remedy the identified non-compliance.FRCNILGDPR€5,000
25 Jan 2021PATIO ANCESTRAL, S.L.PATIO ANCESTRAL, S.L. was fined by the AEPD in the amount of EUR 5,000 for sending a letter containing personal data to the complainant's workplace. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
09 Nov 2021Cyrana España General S.L.Cyrana España General S.L. was fined by the AEPD in the amount of 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account.ESAEPDGDPR€5,000
29 Apr 2022Fire Brigade HeadquartersFire Brigade Headquarters was fined EUR 5,000 by the HDPA. The authority found a failure to fulfill data protection officer duties required under national law.GRHDPAGDPR€5,000
29 Apr 2026dottoressa GuzzoThe Garante imposed a fine of EUR 5,000 on dottoressa Guzzo for unlawfully processing personal data by publishing images of a deceased minor without consent. The authority found that this breached core data protection principles.ITGaranteGDPR€5,000
18 Jul 2023Ermeslink di Giovanni Di StefanoThe Garante imposed a fine of EUR 5,000 on Ermeslink di Giovanni Di Stefano for improperly handling video surveillance data. The breach concerned data protection rules and could have affected all residents and non-residents of the Municipality of Modica.ITGaranteGDPR€5,000
14 Nov 2024D’Anna Assicurazioni S.r.l.D’Anna Assicurazioni S.r.l. was fined by the Garante 5,000 EUR for sending unsolicited promotional emails despite the recipient’s objection. The authority found this breached GDPR rules on data subject rights and transparency.ITGaranteGDPR€5,000
01 Jan 2014TELEFÓNICA MÓVILES ESPAÑA S.A.U.TELEFÓNICA MÓVILES ESPAÑA S.A.U. was fined by the AEPD in the amount of 5,000 EUR. The case concerned unsolicited commercial communications sent via SMS in breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
16 Sept 2021Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€5,000
31 Dec 2024SOCIETE GERANT UN ROBOT CONVERSATIONNEL UTILISANT L'INTELLIGENCE ARTIFICELLE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company operating an AI-based conversational robot. The case was handled under a simplified procedure.FRCNILGDPR€5,000