Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 May 2021KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued.GRHDPAGDPR€5,000
16 May 2023COLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRECOLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRE was fined by the AEPD for failing to implement appropriate technical and organizational measures to ensure data security. The deficiency resulted in a breach involving minors’ data stored in cloud services.ESAEPDGDPR€5,000
18 May 2015ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 5,000 EUR for sending commercial emails to a recipient who had requested to unsubscribe. The case concerns a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request.ESAEPDePrivacy€5,000
10 Apr 2025Vogliocasa Holding & Servizi S.r.l.Vogliocasa Holding & Servizi S.r.l. was fined by the Garante EUR 5,000 for making unsolicited telemarketing calls promoting real estate brokerage services without valid consent. The company also failed to respond to the authority's information requests, which hindered the supervisory process.ITGaranteGDPR€5,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT under a simplified procedure. The case concerns a breach of rules addressed by the supervisory authority.FRCNILGDPR€5,000
10 Nov 2022Comune di Cisterna di LatinaComune di Cisterna di Latina was fined 5,000 EUR by the Garante for violating data protection principles, including data minimization. Improper handling of personal data led to unauthorized access by third parties.ITGaranteGDPR€5,000
31 Jan 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CHIRURGIEN DENTISTE. The case was handled under a simplified procedure.FRCNILGDPR€5,000
31 May 2022B.B.B.The entity was fined for using a surveillance camera with audio to monitor an employee without prior notice. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
12 Nov 2021EUSKALTEL, S.A.EUSKALTEL, S.A. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without the required consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€5,000
26 Jan 2022Slane Credit UnionThe Irish DPC imposed a fine of EUR 5,000 on Slane Credit Union in inquiry IN-19-7-5. The penalty has been collected.IEDPCGDPR€5,000
03 Jul 2023LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 5,000 EUR for attempting to install cookies on users' devices without proper consent. The conduct breached data protection rules and electronic commerce requirements.ESAEPDePrivacy€5,000
23 Oct 2019SHOP MACOYN, S.L. (YBL ABOGADOS)SHOP MACOYN, S.L. was fined EUR 5,000 by the AEPD for disclosing email addresses in promotional emails. The case concerned a breach of data protection principles and the confidentiality of recipients’ personal data.ESAEPDGDPR€5,000
22 Feb 2024Ordine dei Medici Veterinari della Provincia di LatinaOrdine dei Medici Veterinari della Provincia di Latina was fined by the Garante 5,000 EUR for breaches of data protection principles. The case involved the unlawful communication of personal data to its members.ITGaranteGDPR€5,000
06 Jun 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages continued despite requests to stop such communications.ESAEPDePrivacy€5,000
30 Mar 2026Κέντρο Εκπαίδευσης και Αποκατάστασης Τυφλών (ΚΕΑΤ)The Greek Data Protection Authority fined ΚΕΑΤ EUR 5,000 for an untimely and improper response to an employee’s request for access to CCTV footage. The case involved edited footage, missing material, and inadequate technical and organizational measures to support compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
30 Jun 2022Federazione Italiana Sommelier, Albergatori e RistoratoriFederazione Italiana Sommelier, Albergatori e Ristoratori was fined by the Garante 5,000 EUR for unlawful processing of personal data. The breach involved the improper communication of one member’s data to all associates.ITGaranteGDPR€5,000
11 Feb 2021Liceo Pepe CalamoLiceo Pepe Calamo was fined EUR 5,000 by the Garante for publishing teachers' personal data in public rankings on its institutional website. The authority found a breach of data minimization and transparency principles.ITGaranteGDPR€5,000
01 Jan 2017ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior recipient consent.ESAEPDePrivacy€5,000
06 Mar 2020IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD in the amount of EUR 5,000 for failing to provide requested information to the data protection authority. The conduct breached Article 58(1) of the GDPR.ESAEPDGDPR€5,000
14 Oct 2025CORAL TRAVEL & TOURISM SERVICES S.R.L.The operator was fined for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€982