Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Sept 2024SOCIETE SPECIALISEE DANS LAFABRICATION ET POSE DE CLOTURES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE SPECIALISEE DANS LAFABRICATION ET POSE DE CLOTURES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
17 May 2023Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15.ITGaranteGDPR€10,000
30 Jan 2025Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks.ITGaranteGDPR€10,000
30 Oct 2024COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35.ESAEPDGDPR€10,000
12 Feb 2018Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing.BGCPDPGDPR€5,113
24 Apr 2025Dante International SAIn April 2025, ANSPDCP completed an investigation into Dante International SA and found violations of GDPR provisions. As a result, a fine of 10,000 EUR was imposed.ROANSPDCPGDPR€10,000
01 Jan 2024EMPRENDEDORES ONLINE, LLCEMPRENDEDORES ONLINE, LLC was fined by the AEPD 10,000 EUR for recording and sharing course participants’ personal data without consent. The authority found a breach of GDPR Articles 5(1)(f) and 6(1), indicating unlawful processing and insufficient legal basis.ESAEPDGDPR€10,000
01 Jan 2019EL PERIODICO DE CATALUNYA, S.L.EL PERIODICO DE CATALUNYA, S.L. was fined by the AEPD 10,000 EUR for sending a commercial email after a data deletion request. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€10,000
05 Apr 2018Comune di Magliano SabinaThe Municipality of Magliano Sabina was fined 10,000 EUR by the Garante for unlawfully disclosing personal data to a private educational institution without a valid legal basis. The authority found that this conduct breached the Italian Privacy Code.ITGaranteGDPR€10,000
06 Apr 2017Effepì Credit s.r.l.Effepì Credit s.r.l. was fined by the Garante in the amount of EUR 10,000 for inadequate security measures. The authority cited weak and outdated passwords as a breach of data protection rules.ITGaranteGDPR€10,000
19 Jul 2018Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules.CZUOOUGDPR€386
11 Mar 2021Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data.ITGaranteGDPR€10,000
26 Jun 2026Artmark Holding SRLArtmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements.ROANSPDCPePrivacy€1,908
08 Oct 2019Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure.BGCPDPGDPR€5,113
13 Feb 2025Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing.ITGaranteGDPR€10,000
24 Nov 2016Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules.ITGaranteGDPR€10,000
16 May 2018Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
01 May 2025CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.CURENERGÍA was fined EUR 10,000 by the AEPD for sharing personal data with IBERDROLA without the data subject’s consent. The disclosure led to a contract offer at a higher price than requested.ESAEPDGDPR€10,000
25 Sept 2023UAT Comuna AlbeniANSPDCP imposed a 10,000 RON fine on UAT Comuna Albeni for failing to implement measures previously ordered by the authority. The entity also did not respond to the authority’s requests.ROANSPDCPGDPR€2,013
10 Nov 2016Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined by the Garante for making an unsolicited promotional call to a number listed in the public opposition registry. The conduct breached data protection rules.ITGaranteGDPR€10,000