Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Dec 2024SOCIETE EDITANT UN SITE DE JEUX DEMATERIALISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EDITANT UN SITE DE JEUX DEMATERIALISES. The decision was issued under a simplified procedure.FRCNILGDPR€15,000
26 Feb 2026Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals.ITGaranteGDPR€15,000
18 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE (GESTIONS LOCATIVE ET DE COPROPRIETE) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE and issued an injunction. The case concerned a breach of personal data protection obligations.FRCNILGDPR€15,000
11 Aug 2025FUNDACIÓN PARA EL DESARROLLO DE LA ENFERMERÍA y SINDICATO DE ENFERMERÍA, SATSESATSE and FUDEN were fined by the AEPD EUR 15,000 after a ransomware incident affected personal data. The authority also found that the parties had not properly formalized a joint controllership agreement under the GDPR.ESAEPDGDPR€15,000
14 May 2026Azienda ospedaliera dei colli Monaldi-Cotugno-CTO di NapoliAzienda ospedaliera dei colli Monaldi-Cotugno-CTO di Napoli was fined EUR 15,000 by the Garante. The authority found that the entity provided false statements and interrupted the performance of its tasks. The case concerns breaches of data protection rules.ITGaranteGDPR€15,000
20 Nov 2006Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data.GRHDPAGDPR€15,000
18 Jul 2023Dane anonimowe (K. za naruszenie przepisów art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679)UODO imposed a fine on the controller for failing to implement appropriate technical and organizational measures when employees used portable company laptops. The authority also found a lack of regular testing, measuring, and evaluation of security measures, which breached the principles of integrity, confidentiality, and accountability.PLUODOGDPR€3,374
29 Jun 2023FUNDACIÓN VEDRUNA EDUCACIÓN COLEGIOA teacher publicly disclosed the content of an email concerning a student's issues, breaching the duty of confidentiality. The AEPD found a violation of data protection rules and imposed a 15,000 EUR fine.ESAEPDGDPR€15,000
22 Jun 2023COLEGIO VIRGEN DE EUROPA, S.L.The school processed and published images of a 3-year-old child on Facebook and WhatsApp without parental consent. This disregarded the parents’ explicit refusal and led to a fine imposed by the AEPD.ESAEPDGDPR€15,000
13 Feb 2025MDE – Movimento Diritti Europei s.r.l.s.MDE – Movimento Diritti Europei s.r.l.s. was fined 15,000 EUR by the Garante. The authority found that the company failed to provide shareholders with the information required under GDPR Article 14 and instead referred them to a website that did not contain sufficient details.ITGaranteGDPR€15,000
28 Jul 2025KINYO, S.L.KINYO, S.L. was fined by the AEPD in the amount of 15,000 EUR for sending unsolicited commercial emails. The authority also found that recipients were not provided with an effective mechanism to opt out of future communications.ESAEPDePrivacy€15,000
06 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 15,000 for failing to honor unsubscribe requests from commercial newsletters. The case concerned a breach of Article 21.1 of the LSSI and indicates inadequate handling of marketing opt-out requests.ESAEPDePrivacy€15,000
23 Jan 2024BANCO COOPERATIVO ESPAÑOL, S.A.Banco Cooperativo Español, S.A. was fined by the AEPD for a personal data breach. The incident allowed unauthorized access to personal data and breached the principles of confidentiality and integrity.ESAEPDGDPR€15,000
06 Jul 2023Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data.ITGaranteGDPR€15,000
24 Jun 2021Ospedale Pediatrico Bambino GesùOspedale Pediatrico Bambino Gesù was fined by the Garante 15,000 EUR for breaches involving a data incident and improper handling of patient health data. The authority cited violations of GDPR Articles 5 and 32 on lawful processing and security of personal data.ITGaranteGDPR€15,000
02 Apr 2015Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€15,000
12 Feb 2026Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5.ITGaranteGDPR€15,000
01 Jan 2023GLOVOGLOVO was fined EUR 15,000 by the AEPD for failing to properly handle a data access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€15,000
23 Jan 2024CAJA RURAL DE BURGOS, FUENTEPELAYO, SEGOVIA Y CASTELLDANS, S.C.C.CAJABURGOS was fined by the AEPD for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€15,000
24 Jan 2024CAIXA RURAL D'ALGEMESÍ, S.C.V.CCAIXA RURAL D'ALGEMESÍ, S.C.V.C. was fined by the AEPD 15,000 EUR for breaching data protection principles, including confidentiality and integrity. The breach led to unauthorized access to personal data.ESAEPDGDPR€15,000