Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 May 2011Jnternet srlJnternet srl was fined by the Italian data protection authority, Garante, in the amount of EUR 10,000. The case concerned the failure to respond to requests for information about compliance with data protection obligations in connection with promotional emails sent without proper consent.ITGaranteGDPR€10,000
11 Jul 2018Comune di VollaComune di Volla was fined by the Garante EUR 10,000 for allowing all employees access to sensitive and judicial personal data through its electronic protocol system. The authority found that this setup failed to meet required data protection safeguards.ITGaranteGDPR€10,000
27 Jan 2021Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance.ITGaranteGDPR€10,000
22 May 2014Tenacta Group s.p.a.Tenacta Group s.p.a. was fined €10,000 by the Garante for making an unsolicited promotional phone call. The conduct breached the complainant’s right to object, as recorded in the public opt-out list.ITGaranteGDPR€10,000
12 Feb 2015Comune di Castelvetrano SelinunteComune di Castelvetrano Selinunte was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The case involved a breach of data protection rules and the confidentiality of sensitive information.ITGaranteGDPR€10,000
13 Jul 2021Dane anonimowe (Prezesa Sądu Rejonowego w M. za naruszenie art. 5 ust. 1 lit. f), art. 25 ust. 1, art. 32 ust. 1 lit. b) i d) oraz art. 32 ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 10,000 on the President of the District Court for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing data using portable external storage devices.PLUODOGDPR€2,189
21 Mar 2022RESTAURANTCNIL imposed a fine of EUR 10,000 on RESTAURANT. The case concerned a regulatory breach, with no further details provided.FRCNILGDPR€10,000
12 Mar 2015Comune di Alì TermeComune di Alì Terme was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy rules and the protection of sensitive personal data.ITGaranteGDPR€10,000
25 Jul 2023EDICIONES PERIÓDICAS DEL NOROESTE, S.L.The entity published a private video on Twitter without the data subject’s consent. The authority found a breach of data minimization because excessive data were processed beyond what was necessary for the intended purpose.ESAEPDGDPR€10,000
12 Dec 2024BREOGAN AUTOLUX, S.L.BREOGAN AUTOLUX, S.L. was fined EUR 10,000 by the AEPD for sending unsolicited SMS advertisements without prior consent from recipients. The authority also found that the messages did not provide an opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€10,000
23 Jan 2024CAIXA RURAL BENICARLÓ, S.C.C.VCAIXA RURAL BENICARLÓ was fined by the AEPD 10,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€10,000
19 Apr 2022INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR.ESAEPDGDPR€10,000
21 Apr 2011Azienda Trasporti per l'Area Metropolitana S.p.A.Azienda Trasporti per l'Area Metropolitana S.p.A. was fined by the Garante €10,000 for failing to provide adequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€10,000
26 Mar 2019А.Р. ЕООДThe CPDP imposed a 10,000 BGN fine on А.Р. ЕООД for processing personal data without consent. The case also involved registering an employment contract for an imprisoned individual, which breached Article 6 GDPR.BGCPDPGDPR€5,113
10 Jun 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages were sent despite the recipient’s request not to receive such communications.ESAEPDePrivacy€10,000
12 Mar 2015Comune di BasicòComune di Basicò was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of data protection rules and the confidentiality of sensitive data.ITGaranteGDPR€10,000
25 Feb 2016Decatel s.r.l.Decatel s.r.l. was fined €10,000 by the Italian Garante. The case concerned the processing and retention of telephone traffic data without the required safeguards, including biometric recognition and strong authentication.ITGaranteGDPR€10,000
15 Jan 2015Comune di SidernoComune di Siderno was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The conduct breached privacy and data protection rules.ITGaranteGDPR€10,000
06 Jan 2020дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR.BGCPDPGDPR€5,113
17 Jul 2025Federazione Italiana Sport EquestriThe Italian Data Protection Authority imposed a EUR 10,000 fine on Federazione Italiana Sport Equestri for publishing a disciplinary decision involving a minor on its website without anonymizing personal data. The breach concerned data protection rules and the disclosure of information that could identify the minor.ITGaranteGDPR€10,000