Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Feb 2023LEADDESK, S.L.LEADDESK, S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information to the authority, which constitutes a breach of Article 58.1 of the GDPR.ESAEPDGDPR€500
31 May 2017LEAD CONVERSIÓN, S.L.LEAD CONVERSIÓN, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial emails. The conduct breached rules on electronic communications and recipient consent.ESAEPDePrivacy€2,000
26 Jun 2017LEAD CONVERSION S.L.LEAD CONVERSION S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without prior recipient consent. The conduct breached electronic communications rules and marketing consent requirements.ESAEPDePrivacy€2,500
21 Mar 2024LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services.ITGaranteGDPR€271,000
24 Sept 2015Layla SerenelliLayla Serenelli was fined 2,400 EUR by the Italian data protection authority, Garante. The case concerned inadequate simplified information about video surveillance, which breached data protection rules.ITGaranteGDPR€2,400
22 Nov 2012La Villa s.p.a.La Villa s.p.a. was fined EUR 16,000 by the Garante. The company failed to update its notification of data processing activities after changing its registered office address, which breached privacy rules.ITGaranteGDPR€16,000
11 May 2022LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found excessive processing of personal data and a breach of data protection rules.ESAEPDGDPR€50,000
03 Jul 2023LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 5,000 EUR for attempting to install cookies on users' devices without proper consent. The conduct breached data protection rules and electronic commerce requirements.ESAEPDePrivacy€5,000
13 Feb 2024LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD €10,000 for installing non-essential cookies on its website without obtaining valid user consent. The authority found this to be a breach of the LSSI.ESAEPDePrivacy€10,000
04 Oct 2021LA ÚLTIMA HORA NOTICIAS, S.L.LA ÚLTIMA HORA NOTICIAS, S.L. was fined by the AEPD EUR 2,000 for installing cookies on users’ devices without prior consent. The authority also found that the website did not provide adequate information about the cookies used.ESAEPDePrivacy€2,000
01 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeGDPR€1,361,000
20 Nov 2025LastPass UK LtdThe ICO imposed a GBP 1,228,283 penalty on LastPass UK Ltd for breaches of Article 5(1)(f) and Article 32(1)(f) UK GDPR. Failure to implement appropriate technical and organisational measures allowed a threat actor to exfiltrate personal data relating to about 1.6 million UK customers from a backup database. The most sensitive data in customer password vaults remained encrypted because of LastPass' zero-knowledge system.GBICOGDPR€1,393,000
01 Jan 2015LASTMINUTE NETWORK S.L.LASTMINUTE NETWORK S.L. was fined by the AEPD in the amount of €1,500 for sending unsolicited commercial emails to a complainant who had previously requested that such communications stop. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,500
17 Oct 2024la SocietàThe company was fined EUR 7,000 by the Garante for violations related to security measures in handling online medical reports and data. The case concerned insufficient safeguards for processed medical information.ITGaranteGDPR€7,000
11 Mar 2025LÁSER METALPRINT 3D, S.L.LÁSER METALPRINT 3D, S.L. was fined by the AEPD 10,000 EUR for deploying a video surveillance system without proper data processing agreements. The authority found a breach of GDPR Article 28.ESAEPDGDPR€10,000
02 Sept 2019LA SALA 2015 S.L.U.LA SALA 2015 S.L.U. was fined by the AEPD 1,500 EUR for improper processing of personal data through a video surveillance system. The cameras captured images disproportionately from public sidewalks without the required legal basis.ESAEPDGDPR€1,500
29 Apr 2021LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD €1,000 for sending commercial emails to an individual whose email address was included in the Robinson List. The conduct breached Spanish data protection rules governing unsolicited marketing communications.ESAEPDePrivacy€1,000
01 Jan 2019LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without proper consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€2,500
23 Mar 2023La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security.ITGaranteGDPR€40,000
08 Jun 2023La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details.ITGaranteGDPR€300,000