BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Nov 2017 | AMAT PALERMO S.P.A.AMAT PALERMO S.P.A. was fined by the Garante 20,000 EUR for failing to properly notify the use of a geolocation system to track vehicles. The authority found a breach of the Italian data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Oct 2023 | Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements. | LU | CNPD | GDPR | €746,000,000 | ↗ |
| 01 Dec 2022 | Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Nov 2023 | Amazon Italia Transport s.r.l.Amazon Italia Transport s.r.l. was fined €40,000 by the Garante for failing to respond to a former employee’s request for access to personal data. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 Oct 2021 | AMAZON ROAD TRANSPORT SPAIN, S.LAmazon Road Transport Spain, S.L was fined 3,300,000 EUR by the AEPD for requiring job candidates to provide a criminal record certificate and consent for data transfers outside the EEA. The authority found that these practices breached GDPR and LOPDGDD rules on lawful processing and data transfer safeguards. | ES | AEPD | GDPR | €3,300,000 | ↗ |
| 12 Dec 2024 | Ambiente 2000 S.r.l.Ambiente 2000 S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company required employees to disclose passwords to their work email and files containing personal data, in breach of the GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Jun 2024 | Ambitious People Group B.V.Ambitious People Group B.V. was fined by the AP EUR 6,000 for failing to handle data erasure requests submitted by three individuals within the required timeframe. The breach concerned GDPR Articles 17 and 12. | NL | AP | GDPR | €6,000 | ↗ |
| 25 Aug 2021 | Amendă în aplicarea Legii nr. 190/2018The operator was fined for failing to respond to the authority's requests during an investigation. The case concerns non-cooperation with ANSPDCP in the course of supervisory proceedings. | RO | ANSPDCP | GDPR | €2,029 | ↗ |
| 08 Jan 2026 | Amendă pentru încălcarea Legii nr. 506/2004 și a RGPDA fine of EUR 2,000 was imposed for violations of certain provisions of Law No. 506/2004 and the GDPR. The case concerns non-compliant personal data processing and privacy protection obligations. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 30 Jul 2021 | Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual for violating GDPR requirements. The case was handled by the Romanian supervisory authority ANSPDCP. | RO | ANSPDCP | GDPR | €100 | ↗ |
| 30 Jul 2021 | Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual by ANSPDCP for violating GDPR requirements. The case concerned a confirmed breach of personal data protection obligations. | RO | ANSPDCP | GDPR | €100 | ↗ |
| 10 Oct 2023 | American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 27 Nov 2025 | AMERICAN EXPRESS CARTE FRANCEOn 27 November 2025, CNIL fined AMERICAN EXPRESS CARTE FRANCE EUR 1.5 million for breaches of cookie and tracker rules. The authority found that trackers were placed without consent, despite refusal, and continued to be read after consent was withdrawn. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 04 Oct 2012 | American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Feb 2013 | American Express Services Europe LimitedAmerican Express Services Europe Limited was fined EUR 60,000 by the Garante. The authority found that the security program document was not updated in line with the technical rules on minimum security measures. | IT | Garante | GDPR | €60,000 | ↗ |
| 16 Feb 2012 | Amiat s.p.a.Amiat s.p.a. was fined EUR 30,000 by the Garante for failing to designate Allsystems s.p.a. as a data processor and for not providing the necessary instructions. The authority found that the company did not adopt the minimum security measures required for data processing. | IT | Garante | GDPR | €30,000 | ↗ |
| 21 Sept 2017 | AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 28 Apr 2022 | Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 May 2018 | Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 Oct 2015 | Amministrazione provinciale di PordenoneAmministrazione provinciale di Pordenone was fined 4,000 EUR by the Garante. The authority found that the annual Security Programmatic Document was not updated by the required deadline, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |