Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 May 2025Maravet S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Maravet S.R.L. and found a violation of GDPR provisions. The operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
26 May 2022Azienda sanitaria universitaria Friuli OccidentaleAzienda sanitaria universitaria Friuli Occidentale was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the electronic health dossier. The authority found non-compliance with GDPR requirements.ITGaranteGDPR€5,000
12 Mar 2026SOCIÉTÉ EXERÇANT UNE ACTIVITÉ DE VENTE À DISTANCE SUR CATALOGUE SPECIALISÉE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on Société exerçant une activité de vente à distance sur catalogue spécialisée. The case was handled under a simplified procedure.FRCNILGDPR€5,000
19 Dec 2023HIPERBAZAR YONGFA 2018 SLHIPERBAZAR YONGFA 2018 SL was fined by the AEPD 5,000 EUR for breaching data protection rules. The case involved the improper sharing of surveillance footage, which was later posted on Facebook, undermining confidentiality and data security requirements.ESAEPDGDPR€5,000
17 Apr 2026Associazione Movimento Cinque Stelle SiciliaThe Garante fined Associazione Movimento Cinque Stelle Sicilia 5,000 EUR for failing to adopt adequate technical and organizational measures to facilitate the exercise of data protection rights. The authority also found that requests were not addressed without undue delay.ITGaranteGDPR€5,000
29 Sept 2021K-city srlK-city srl was fined by the Italian Garante in the amount of 5,000 EUR for breaching data protection principles. The case concerned the management of a paid parking service for the Municipality of Formia, where compliance with lawfulness, fairness, and transparency was not ensured.ITGaranteGDPR€5,000
23 Oct 2023EDITEUR DE SITE WEB DEDIE A LA PRESSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on EDITEUR DE SITE WEB DEDIE A LA PRESSE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€5,000
27 Nov 2025Logika Group s.r.l.Logika Group s.r.l. was fined EUR 5,000 by the Italian supervisory authority, Garante. The authority found that the company sent unsolicited commercial communications and failed to respond to a data access request, in breach of GDPR requirements.ITGaranteGDPR€5,000
16 May 2025ACCOUNTING & AUDIT CONSULTING SRLACCOUNTING & AUDIT CONSULTING SRL was fined by ANSPDCP €5,000 for GDPR violations. The investigation was completed in April 2025, and the decision was issued on 16 May 2025.ROANSPDCPGDPR€5,000
25 Feb 2021Mistore Canarias, S.L.U.Mistore Canarias, S.L.U. was fined by the AEPD 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account.ESAEPDGDPR€5,000
17 Oct 2024Ente di Supporto Tecnico Amministrativo Regionale DirezionaleEnte di Supporto Tecnico Amministrativo Regionale Direzionale was fined 5,000 EUR by the Garante for improper handling of personal data during a public selection process. The issue concerned the transmission of files with incorrect names, even though the content was correct.ITGaranteGDPR€5,000
13 Oct 2025Vellea Home SRLIn September 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Vellea Home SRL and found violations of GDPR provisions. The operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
29 Apr 2022Fire Brigade HeadquartersA fine of EUR 5,000 was imposed for failing to respond to a data access request. The breach concerned access rights under the GDPR and national law.GRHDPAGDPR€5,000
18 May 2022Kredyt Inkaso Investments RO S.A.The company unlawfully processed personal data by disclosing it excessively, including health data. The authority found a breach of personal data processing principles.ROANSPDCPGDPR€5,000
27 Nov 2020CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR.ESAEPDGDPR€5,000
04 Oct 2021SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
21 Sept 2020AVATA HISPANIA, S.L.AVATA HISPANIA, S.L. was fined by the AEPD 5,000 EUR for using personal data after the contract had ended. The company acted as a data processor, and continued use of the data was inconsistent with its obligations in that role.ESAEPDGDPR€5,000
17 Jul 2024Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations.ITGaranteGDPR€5,000
30 Mar 2021PROMOTECH DIGITAL, S.L.PROMOTECH DIGITAL, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited SMS messages without recipient consent. The authority also found that the company did not provide an easy opt-out mechanism, in breach of data protection rules.ESAEPDGDPR€5,000
02 Jun 2021TENTEA ENERGY, S.L.TENTEA ENERGY, S.L. was fined by the AEPD EUR 5,000 for using personal data and a signature without consent in connection with energy service contracts. The authority also found a refusal to provide access to personal data in relation to a cancellation request.ESAEPDGDPR€5,000