Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Nov 2024Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended.DKDatatilsynetGDPR€53,632
02 Jul 2015Lycamobile s.r.l.Lycamobile s.r.l. was fined EUR 102,000 by the Garante for failing to provide requested information on the retention of telephone and telematic traffic data. The case concerned a breach of data protection rules.ITGaranteGDPR€102,000
05 May 2022LYCAMOBILE S.L.U.LYCAMOBILE S.L.U. was fined by the AEPD 56,000 EUR for processing personal data without consent. The case involved unauthorized phone number portability, which could create a risk of identity theft.ESAEPDGDPR€56,000
01 Jan 2020Lycamobile, S.L.Lycamobile, S.L. was fined by the AEPD 60,000 EUR for falsifying the personal data of prepaid card users. The case concerns a breach of data protection rules.ESAEPDGDPR€60,000
15 Apr 2025LVMH IBERIA, S.L.LVMH IBERIA, S.L. was fined by the AEPD 70,000 EUR for adding an employee’s personal phone number to a WhatsApp group without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€70,000
27 Apr 2016Luziotti Auto s.r.l.Luziotti Auto s.r.l. was fined by the Garante 2,400 EUR for collecting personal data through its website without providing users with the required information notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
18 Jul 2025LUXURY ANGELS, S.L.LUXURY ANGELS, S.L. was fined EUR 500 by the AEPD for sending a client a form that contained a third party’s personal data. The authority treated this as a breach of data protection principles.ESAEPDGDPR€500
10 Apr 2025Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR.ITGarante per la protezione dei dati personaliGDPR€5,000,000
02 Jul 2015Lu JiruiLu Jirui was fined EUR 2,400 by the Garante for processing personal data through a video surveillance system without providing the required information to data subjects. The breach concerned Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
02 Jul 2015Lu JiruLu Jiru was fined EUR 2,400 by the Garante. The authority found that personal data were processed through a video surveillance system without providing the required information to data subjects, in breach of the Italian Privacy Code.ITGaranteGDPR€2,400
22 May 2018Luigi PagnanelliLuigi Pagnanelli, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
28 Jun 2018Luigi Di CesareLuigi Di Cesare was fined EUR 10,000 by the Garante for failing to implement minimum security measures. The breach led to the unauthorized disclosure of medical reports to a third party.ITGaranteGDPR€10,000
23 May 2024Luigi De BenedictisThe Garante fined Luigi De Benedictis EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR.ITGaranteGDPR€1,000
23 Feb 2017Lucini & Lucini Communication LtdLucini & Lucini Communication Ltd was fined EUR 72,000 by the Garante. The authority found that the company collected personal data through its websites and sent promotional emails without proper consent.ITGaranteGDPR€72,000
07 May 2015Lucchese FrancoLucchese Franco was fined by the Garante EUR 12,000 for retaining surveillance footage beyond the legally prescribed period. The case concerned non-compliance with data protection retention rules.ITGaranteGDPR€12,000
18 Dec 2025LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
24 Nov 2020LSS-boendeGnosjö kommun - Socialutskottet was fined by IMY for unlawful video surveillance in an LSS residence. The authority found processing of personal and sensitive data without a legal basis and no data protection impact assessment.SEIMYGDPR€19,600
29 Jan 2019LOS SEIS MAESTROS S.L.LOS SEIS MAESTROS S.L. was fined by the AEPD EUR 3,000 for processing personal data without consent. The breach involved sending an email offering a discount for an event, contrary to Article 6.1 of the LOPD.ESAEPDePrivacy€3,000
25 Jun 2024LOS NIÑOS DE MONTESSORI, S.L.The entity was fined for failing to provide information or obtain consent for the use of cookies on its website. This conduct breached the LSSI.ESAEPDePrivacy€5,000
22 Nov 2023LOS NIÑOS DE MONTESSORI, S.L.The company was fined by the AEPD for failing to publish a privacy policy on its website and for installing non-exempt cookies without informing users or obtaining consent. The case reflects deficiencies in basic transparency and consent requirements under data protection rules.ESAEPDGDPR€4,000