Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2024KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined by the AEPD EUR 2,000 for sending an email to more than 400 recipients without using BCC. This exposed other recipients’ email addresses and breached GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,000
01 Jan 2015JYCTEL ESPAÑA SLJYCTEL ESPAÑA SL was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited SMS and WhatsApp messages. The company did not provide information on how to exercise the right to object, which breaches Article 21 of the LSSI.ESAEPDePrivacy€3,000
01 Jan 2020JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2.ESAEPDePrivacy€3,000
28 Jul 2016Jurica PavicJurica Pavic was fined by the Garante for failing to provide adequate information to data subjects about video surveillance. The authority found this to be a breach of privacy regulations.ITGaranteGDPR€2,400
13 Mar 2023JUNTA MAYOR DE COFRADÍAS Y HERMANDADES DE LA SEMANA SANTA DE ELCHEThe organization did not inform participants about the processing of their personal data during the “Gymkhana Cofrade” event, which constitutes a breach of Article 13 GDPR. The AEPD imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
13 Jun 2023JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SATThe entity was fined by the AEPD for installing a video surveillance system with inadequate signage. The notices did not identify the data controller or provide contact details for exercising data subject rights, breaching Article 13 GDPR.ESAEPDGDPR€500
15 Mar 2022JUNTA ADMINISTRADORA A.A.A.The entity was fined for displaying complainants’ personal data on a public notice board. This breached data protection rules and created a risk of unauthorized disclosure of personal information.ESAEPDGDPR€2,000
17 Jul 2025Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements.ITGaranteGDPR€25,000
13 Sept 2017Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller.ITGaranteGDPR€14,800
01 Jan 2021JUBASER DE CONTROL, S.L.JUBASER DE CONTROL, S.L. was fined by the AEPD 5,000 EUR for unlawful processing of personal data. The case concerned improper handling of a customer's ID and personal information, which later appeared on an adult contact website.ESAEPDGDPR€5,000
18 Mar 2025JRSY Laser LimitedThe Jersey Data Protection Authority fined JRSY Laser Limited 500 GBP following an investigation opened on 27 March 2024. The case concerned a breach of data protection requirements by the data controller.JEJOICGDPR€594
05 May 2022JOYPAZAR, S.A.JOYPAZAR, S.A. was fined by the AEPD for reinstalling a surveillance camera that captured images of a public children's park. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,000
20 Dec 2025JOMAFRAN 2013, S. LJOMAFRAN 2013, S. L was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,400
09 Sept 2022JOLY DIGITAL, S.L.U.JOLY DIGITAL, S.L.U. was fined by the AEPD EUR 20,000 for publishing the complainant’s private Instagram photo without consent. The authority found a breach of Article 6 GDPR because there was no lawful basis for processing the personal data.ESAEPDGDPR€20,000
29 Oct 2019JOKER PREMIUM INVEX, S.L.JOKER PREMIUM INVEX, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited commercial communications. The company used personal data taken from public sources without the individuals’ consent.ESAEPDGDPR€10,000
14 Apr 2023Join the Triboo LimitedBetween 1 August 2019 and 19 August 2020, Join the Triboo Limited sent a confirmed total of 107 million direct marketing messages, of which 437,324 were received by distinct individuals. On average, each person received 244 emails during the period, and the messages contained direct marketing material without valid subscriber consent.GBICOGDPR€146,000
07 Apr 2021Jogellenes adatkezelés, adattakarékosság és megfelelő tájékoztatási kötelezettség megsértéseThe authority found that the controller unlawfully processed personal data related to debt collection. It held that the principles of data minimization and transparency were breached, together with the duty to provide proper information to data subjects.HUNAIHGDPR€2,780
20 Mar 2026Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations.HUNAIHGDPR€1,275
22 Oct 2020Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access.HUNAIHGDPR€5,480
15 May 2020JobTeam A/SJobTeam A/S was reported to the police, and Datatilsynet recommended a fine of 50,000 DKK for breaching GDPR principles. The company deleted personal data after a data subject access request, which hindered the exercise of the individual's rights.DKDatatilsynetGDPR€6,705