Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Aug 2012Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules.ITGaranteGDPR€10,400
13 Apr 2026Dane anonimowe (Pana L. A. prowadzącego działalność gospodarczą pod nazwą: A.)UODO issued a reprimand to the controller, two agents and a sub-agent, and imposed an administrative fine on the sub-agent. The case concerned GDPR breaches related to processing security, verification of processors, and the principles of confidentiality and accountability.PLUODOGDPR€2,385
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request.ITGaranteGDPR€10,000
30 Oct 2024Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000.ROANSPDCPGDPR€10,000
21 Mar 2024Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls.ITGaranteGDPR€10,000
23 Jun 2023LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications.ESAEPDePrivacy€10,000
09 Mar 2023EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€10,000
24 Oct 2013Comune di Torre CajetaniComune di Torre Cajetani was fined by the Garante for unlawfully publishing an individual's health data on a public notice board. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
14 Sept 2006Asl n. 8 di Asolo (TV)Asl n. 8 di Asolo was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The notification was required under the Italian Privacy Code.ITGaranteGDPR€10,000
26 Nov 2020Reti Televisive Italiane S.p.a.Reti Televisive Italiane S.p.a. was fined EUR 10,000 by the Garante for broadcasting a segment on “Le Iene” that included footage of an individual recorded without consent. The person was identifiable, which constituted a breach of data protection rules.ITGaranteGDPR€10,000
01 Jan 2019IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
06 Jul 2022Uniwersyteckie CentrumThe Polish DPA (UODO) imposed an administrative fine of PLN 10,000 on Uniwersyteckie Centrum Kliniczne Uniwersytetu Medycznego. The authority found that the entity failed to report the personal data breach without undue delay and did not notify the affected individuals without undue delay.PLUODOGDPR€2,096
01 Mar 2017CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily.ESAEPDePrivacy€10,000
26 May 2022Comune di AfragolaComune di Afragola was fined EUR 10,000 by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The authority found that personal data had been handled improperly.ITGaranteGDPR€10,000
28 Jul 2016IMPACTING EMAIL MARKETING SOLUTIONS, S.L.IMPACTING EMAIL MARKETING SOLUTIONS, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited commercial communications by SMS without recipient consent. The case concerns a breach of data protection and direct marketing rules.ESAEPDePrivacy€10,000
13 Mar 2025IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s.IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s. was fined by the Garante EUR 10,000 for making unsolicited marketing calls without proper consent. The authority found a breach of GDPR rules on data processing and consent.ITGaranteGDPR€10,000
27 May 2021Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante 10,000 EUR for unlawfully communicating a customer's financial data related to a Postepay card to an unauthorized third party. The case concerns a breach of personal data protection and financial confidentiality requirements.ITGaranteGDPR€10,000
01 Jan 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company impersonated another energy provider and used personal data without consent.ESAEPDGDPR€10,000
12 Dec 2024SOCIETE EXERCANT UNE ACTIVITE DE COMPARATEUR D'AUTO-ECOLES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMPARATEUR D'AUTO-ECOLES. The case was handled under a simplified procedure.FRCNILGDPR€10,000
10 Apr 2025Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 10,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements.ROANSPDCPGDPR€10,000