Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2012LET’s BONUS, S.L.LET’s BONUS, S.L. was fined EUR 34,001 by the AEPD for sending unsolicited commercial emails to a user. The conduct continued despite multiple requests to stop, which breached Article 21 of the LSSI.ESAEPDePrivacy€34,001
13 Jan 2015LEROY MERLIN ESPAÑA S.L.U.LEROY MERLIN ESPAÑA S.L.U. was fined by the AEPD EUR 3,900 for sending unsolicited commercial SMS messages without recipient consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,900
29 Apr 2026Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing.ITGaranteGDPR€100,000
05 Sept 2013Leon d'oro Shi e Shi di Shi Deshao e C. S.n.cThe company was fined by the Garante 2,400 EUR for operating a video surveillance system without the required privacy notice. This breached the Italian Privacy Code because individuals under surveillance were not properly informed.ITGaranteGDPR€2,400
12 May 2016Leonardo SestaLeonardo Sesta, a lawyer, was fined by the Italian data protection authority, Garante. The violation concerned transmitting personal data by email instead of registered mail, contrary to data protection rules.ITGaranteGDPR€4,000
26 Mar 2010Lenzi automobili s.p.a.Lenzi automobili s.p.a. was fined by the Garante for using a biometric system to verify employee attendance without the required authorization. This constituted a breach of data protection rules.ITGaranteGDPR€10,000
Lensa.roLensa.ro, operated by Tensa Art Design, was fined EUR 20,000 by Romania’s data protection authority, ANSPDCP. The case involved cookie-based tracking and behavioral advertising without clear user consent, as well as failure to respond to the authority’s official information requests.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
11 Sept 2025Lenjeria Magică SRLLenjeria Magică SRL was fined by ANSPDCP in the amount of 15,000 RON for violating the national ePrivacy law. The breach concerned articles a)-l), n), o) and q).ROANSPDCPePrivacy€2,958
30 Jun 2020Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors.DKDatatilsynetGDPR€6,709
18 Jul 2025LEIVA BUS, S.L.LEIVA BUS, S.L. was fined by the AEPD 3,000 EUR for disclosing the personal data of a claimant and a third party in a damage assessment document. The case concerned a breach of data protection rules and unauthorized disclosure of information.ESAEPDGDPR€3,000
29 Jul 2015LEIPZIG COMUNICACIONES, S.L.LEIPZIG COMUNICACIONES, S.L. was fined by the AEPD for sending six unsolicited advertising SMS messages without prior consent. The authority also found that no opt-out mechanism was provided, which breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
21 Nov 2018Legea s.p.a.Legea s.p.a. was fined for processing personal data through forms on its website without providing the required information notice to data subjects. The case concerned a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
07 Sept 2022LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €1,000 for sending unsolicited commercial communications. The conduct occurred after the complainant had exercised the right to data deletion.ESAEPDePrivacy€1,000
12 Jul 2022LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €6,000 for sending commercial emails without the recipients’ consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing activity.ESAEPDePrivacy€6,000
28 Oct 2013LEGALITAS ASISTENCIA LEGAL, S.L.LEGALITAS ASISTENCIA LEGAL, S.L. was fined by the AEPD 33,000 EUR for sending unsolicited commercial communications. The conduct continued despite requests for data cancellation, which breached Article 21 of the LSSI.ESAEPDePrivacy€33,000
08 Jun 2023L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential.ITGaranteGDPR€30,000
04 Aug 2022LEASE PLAN SERVICIOS, S.A.U.LEASE PLAN SERVICIOS, S.A.U. was fined by the AEPD EUR 1,500 for failing to properly handle a request to restrict the processing of personal data. This led to unauthorized commercial communications being sent.ESAEPDePrivacy€1,500
06 Nov 2025Lead Pronto LtdLead Pronto Ltd received an MPN and an EN from the ICO for sending unsolicited SMS messages promoting Government funded boiler grants. The case indicates a breach of direct marketing rules and consent requirements.GBICOGDPR€34,065
15 Mar 2024LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide information requested by the data protection authority during an investigation. The conduct breached Article 58(1) GDPR and hindered supervisory oversight.ESAEPDGDPR€6,000
12 Sept 2023LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide access to information required under Article 58(1) of the GDPR. The conduct was treated as an obstruction of the data protection authority’s investigative functions.ESAEPDGDPR€4,000