Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Nov 2022SC Prestige Media PHG SRLSC Prestige Media PHG SRL was fined by ANSPDCP in the amount of 5,000 EUR for breaching the data processing principles under Article 5 of the GDPR. The case concerned unlawful processing of personal data.ROANSPDCPGDPR€5,000
06 Jun 2020GLOBAL BUSINESS TRAVEL SPAIN S.L.U.An employee of GLOBAL BUSINESS TRAVEL SPAIN S.L.U. improperly accessed and disclosed an individual's health data. The AEPD found this to be a breach of the integrity and confidentiality principles under data protection law.ESAEPDGDPR€5,000
08 Jul 2024CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
01 Sept 2020B.B.B.The entity was fined by the AEPD €5,000 for using a webcam to record video and audio without justification. The conduct infringed privacy by monitoring private conversations and activities inside a rented residence.ESAEPDGDPR€5,000
22 Jun 2020PARTIT DELS SOCIALISTES DE CATALUNYA (PSC-PSOE)PSC-PSOE was fined by the AEPD 5,000 EUR for using personal data obtained in a doctor-patient relationship to send requests for political support. The authority found this breached purpose limitation rules for data processing.ESAEPDGDPR€5,000
05 Mar 2026ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX(procédure simplifiée)CNIL imposed a EUR 5,100 penalty on ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX in connection with the liquidation of astreinte. The matter concerns enforcement of a prior obligation, with the amount arising from non-compliance.FRCNILGDPR€5,100
13 Jul 2006Comune di LatinaThe Municipality of Latina was fined by the Garante for failing to notify the processing of students’ personal data obtained from public records. The authority found a breach of the obligations under the data protection code.ITGaranteGDPR€5,164
06 Jul 2006Ced di Demartis CarloThe sole proprietorship Ced di Demartis Carlo was fined by the Garante for failing to notify the processing of personal data. This constituted a breach of Article 7 of Law 675/1996.ITGaranteGDPR€5,164
06 Jul 2006Comune di AugustaThe Municipality of Augusta was fined by the Garante for failing to make a required notification under data protection law. The breach concerned Article 163 of the Codice Privacy.ITGaranteGDPR€5,164
06 Oct 2021Anonymisé (CNPD decision-35-fr-2021)The company was fined by the CNPD in the amount of 5,300 EUR for breaching GDPR requirements. The authority found that it failed to provide adequate information to data subjects and did not comply with the data minimization principle.LUCNPDGDPR€5,300
16 Jun 2023B.B.B.The entity was fined for installing a surveillance camera in a rented property without informing the tenant. The authority treated this as a breach of data protection rules.ESAEPDGDPR€5,300
05 Jul 2023Anonymisé (CNPD decision-06-fr-2023)The company failed to implement appropriate technical and organizational measures to ensure data security. It also did not cooperate with the supervisory authority, breaching Articles 31 and 32 of the GDPR.LUCNPDGDPR€5,330
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure.FRCNILGDPR€5,500
22 Jul 2019SANTI 3000, S.L.SANTI 3000, S.L. was fined by the AEPD for using video surveillance footage without informing employees. The authority treated this as a breach of data protection principles.ESAEPDGDPR€5,500
30 Jun 2022Anonymisé (CNPD decision-13-fr-2022)The company breached GDPR by failing to respect data retention limits and by not providing employees with adequate information about the vehicle geolocation system. The CNPD imposed a fine of EUR 5,600.LUCNPDGDPR€5,600
25 Jul 2025Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract.SIIP-RSGDPR€5,610
01 Jan 2018IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia 5,700 EUR for sending unsolicited commercial emails to a complainant. The company had previously confirmed the cancellation of the complainant’s personal data, yet it continued marketing communications, breaching Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
03 Jan 2017EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined by the AEPD in the amount of EUR 5,700 for continuing to send marketing emails to a complainant despite requests to stop. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
25 Oct 2016CEPSA COMERCIAL PETROLEO, SAUCEPSA COMERCIAL PETROLEO, SAU was fined by the AEPD in the amount of 5,700 EUR. The sanction concerned the sending of unauthorized commercial emails in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
16 Mar 2021SIA "“fit People”A fine of EUR 5,836 was imposed. The decision has entered into force.LVDVIGDPR€5,836