Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2022BANQUETES SANTA ANA, S.L.BANQUETES SANTA ANA, S.L. was fined EUR 5,000 by the AEPD for collecting personal data, including DNI numbers, from wedding guests without providing information about data processing. The authority found a breach of data minimization and transparency obligations.ESAEPDGDPR€5,000
23 Jan 2023FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined EUR 5,000 by the AEPD for failing to provide a cookie notice on its website. The authority also found that non-essential cookies were used without prior user consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
13 Nov 2025SOCIETE EXERCANT L'ACTIVITE DE "PORTAILS INTERNET" PERMETTANT D'ACCEDER AUX INFORMATIONS LEGALES ET FINANCIERES DES ENTREPRISES (procédure simplifiée)CNIL imposed an administrative fine of 5,000 EUR on SOCIETE EXERCANT L'ACTIVITE DE "PORTAILS INTERNET". The case was handled under a simplified procedure.FRCNILGDPR€5,000
01 Jan 2019QUESERIA ARTESANAL AMECO S.L.QUESERIA ARTESANAL AMECO S.L. was fined by the AEPD 5,000 EUR for processing personal data without consent. Customers were unaware of how their data had been obtained, indicating a breach of transparency and lawful processing requirements.ESAEPDGDPR€5,000
18 Dec 2013Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database.GRHDPAGDPR€5,000
09 May 2025ROUMASPORT SRLIn April 2025, Romania’s data protection authority ANSPDCP completed an investigation at ROUMASPORT SRL. The authority found GDPR violations and imposed a fine of 5,000 EUR.ROANSPDCPGDPR€5,000
18 Jul 2023Maximum International Corp. S.r.l.The Garante fined Maximum International Corp. S.r.l. 5,000 EUR for making promotional calls without consent and for failing to respond to data access and deletion requests. The case concerns breaches of personal data processing rules and data subject rights.ITGaranteGDPR€5,000
11 Dec 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide the requested information. The case concerned a breach of obligations under data protection rules.ESAEPDGDPR€5,000
29 Mar 2023SOLAR PROGRESS, S.L.SOLAR PROGRESS, S.L. was fined 5,000 EUR by the AEPD for displaying an employee’s personal data on a company WhatsApp profile. The authority found a breach of data protection rules.ESAEPDGDPR€5,000
11 Feb 2021Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da PietrelcinaThe foundation was fined by the Garante 5,000 EUR for processing personal data in breach of the principles of lawfulness, fairness, transparency, integrity, and confidentiality. The case concerned in particular the handling of health data.ITGaranteGDPR€5,000
15 Dec 2023TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined by the AEPD in the amount of 5,000 EUR for breaching data protection rules. The company failed to honor a request to delete personal data and later sent commercial information to the complainant.ESAEPDGDPR€5,000
06 Jul 2023Ristorante Francesco s.r.l.Ristorante Francesco s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating surveillance cameras without the required notices to affected individuals. The authority treated this as a breach of privacy rules.ITGaranteGDPR€5,000
03 Nov 2022FINCAS MARTIN 2, S.L.FINCAS MARTIN 2, S.L. was fined by the AEPD 5,000 EUR for failing to provide the information required under Article 13 GDPR when collecting personal data through a website contact form. The authority found that users were not properly informed about the processing of their data at the time of collection.ESAEPDGDPR€5,000
04 Dec 2023GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. was fined by the AEPD 5,000 EUR for failing to delete a customer's personal data within the legal timeframe. The case concerns a breach of data protection rules and the controller's obligation to comply with a deletion request.ESAEPDePrivacy€5,000
24 Apr 2024Dly S.r.l.Dly S.r.l. was fined by the Garante EUR 5,000 for deploying a non-compliant video surveillance system. The system recorded both customers and employees, in breach of data protection rules.ITGaranteGDPR€5,000
04 Feb 2026E-RETAIL ADVERTISING, S.L.E-RETAIL ADVERTISING, S.L. was fined by the AEPD in the amount of 5,000 EUR for installing non-exempt cookies on its website without prior user consent. The case concerns non-compliance with cookie consent requirements and user privacy obligations.ESAEPDePrivacy€5,000
15 Dec 2023TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined EUR 5,000 by the AEPD for sending commercial information by email after confirming the deletion of personal data. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed on Eurobank Ergasias AE for unlawful processing of the complainant’s personal data. The case concerned a breach of data protection rules by the bank.GRHDPAGDPR€5,000
29 Jun 2020NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations.GRHDPAGDPR€5,000
16 Sept 2021Ordine Provinciale di Roma dei Medici Chirurghi e degli OdontoiatriOrdine Provinciale di Roma dei Medici Chirurghi e degli Odontoiatri was fined by the Garante €5,000 for failing to adequately respond to a data subject’s request for access to personal data. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000