Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Dec 2022MEDECIN (procédure simplifiée)The CNIL imposed a EUR 5,000 fine on MEDECIN under a simplified procedure. The authority also issued an injunction subject to a penalty payment, indicating the need for prompt remediation.FRCNILGDPR€5,000
05 Mar 2024EURO MINI STORAGE ROMANIA SRLEURO MINI STORAGE ROMANIA SRL was fined by ANSPDCP EUR 5,000 for a data security breach caused by a cyber attack. The incident led to unauthorized access to personal data and affected data availability for several weeks.ROANSPDCPGDPR€5,000
22 Feb 2024Ordine dei Medici Chirurghi e Odontoiatri di PadovaOrdine dei Medici Chirurghi e Odontoiatri di Padova was fined 5,000 EUR by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data.ITGaranteGDPR€5,000
23 May 202420 AÑOS DE MÚSICA A.I.E.The entity was fined for collecting copies of identity documents and personal data without proper data protection information. The authority found breaches of the data minimization and transparency principles.ESAEPDGDPR€5,000
15 Nov 2024AXARQUIA VELEZ DENTAL, S.L.AXARQUIA VELEZ DENTAL, S.L. was fined by the AEPD 5,000 EUR for failing to properly signpost the video surveillance system inside its premises. The authority found a breach of GDPR transparency requirements.ESAEPDGDPR€5,000
20 Apr 2021EB CREATIVE LABEB CREATIVE LAB was fined by the AEPD EUR 5,000 for failing to provide information or obtain consent for cookies on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
19 Jun 2019VF JEANSWEAR ESPAÑA S.L.VF Jeanswear España S.L. was fined by the AEPD 5,000 EUR for using cookies on its website without obtaining user consent. The case concerns a breach of data protection rules and consent requirements for cookies.ESAEPDePrivacy€5,000
05 Jan 2022CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing.ESAEPDePrivacy€5,000
09 Sept 2025Unita Turism Holding S.A.In August 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Unita Turism Holding S.A. and found violations of GDPR provisions. As a result, the operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
19 Dec 2024SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES PORTAILS INTERNET (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES PORTAILS INTERNET under a simplified procedure. The decision concerns a data protection breach identified by the authority.FRCNILGDPR€5,000
21 Aug 2018National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations.GRHDPAGDPR€5,000
02 Dec 2021Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation.ITGaranteGDPR€5,000
27 May 2024Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose.GRHDPAGDPR€5,000
23 May 2024Associazione Medica Chirone s.c.r.l.The Garante fined Associazione Medica Chirone s.c.r.l. 5,000 EUR for improperly accessing and using an employee's vaccination status data. The authority found that the data were not properly anonymized, resulting in a breach of data protection rules.ITGaranteGDPR€5,000
17 Dec 2024UNICREDIT CONSUMER FINANCING IFN S.A.UNICREDIT CONSUMER FINANCING IFN S.A. was fined EUR 5,000 by ANSPDCP for processing former employees’ personal data without a legal basis. The authority found breaches of legality, security, and protection against unauthorized or unlawful processing arising from operational errors.ROANSPDCPGDPR€5,000
29 Sept 2020Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation.BEAPDGDPR€5,000
15 Dec 2022Comune di BorgiaComune di Borgia was fined by the Garante 5,000 EUR for processing employees’ biometric data for attendance tracking without appropriate legislative measures and specific safeguards. The authority found this to be a breach of GDPR rules on special-category data.ITGaranteGDPR€5,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent.ESAEPDePrivacy€5,000
01 Oct 2023Anonymised (IDPC CDP_COMP_259_2022)The IDPC imposed a EUR 5,000 fine on Anonymised (IDPC CDP_COMP_259_2022) for breaches of Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. The case concerned personal data processing that did not comply with the principles of lawfulness, fairness, data minimisation and purpose limitation.MTIDPCGDPR€5,000
01 Oct 2024CONSULTORIA INTEGRAL DE ENERGÍA ECOLÓGICA, S.L.The company was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising messages to a complainant. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000