Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Mar 2012Ammiro Partners s.r.l.Ammiro Partners s.r.l. was fined for violations related to the processing of personal data. The authority cited failure to comply with a prior injunction and failure to respond to requests from the Garante.ITGaranteGDPR€250,000
11 Aug 2022AMPLIFON Magyarország Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságAMPLIFON Magyarország was fined by the NAIH 80,000,000 HUF for processing personal data for market research without proper notice to data subjects, without a specific and legitimate purpose, and without a valid legal basis. The authority found that the company’s conduct breached core GDPR principles.HUNAIHGDPRFt 80,000,000
20 Aug 2024Ana Hotels SRLAna Hotels SRL was fined by ANSPDCP €8,000 after a data security incident caused by a ransomware attack. The incident led to unauthorized disclosure of personal data belonging to a significant number of employees.ROANSPDCPGDPR€8,000
16 May 2019ANANEOSI MONOPROSOPI E.P.E.The company was fined for making unsolicited marketing calls to subscribers registered on the opt-out list. It also failed to properly identify itself during the calls, which hindered data subjects’ ability to exercise their rights.GRHDPAePrivacy€5,000
18 Apr 2018Anas S.p.A.Anas S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to designate employees as data processors and for not issuing instructions on the proper use of surveillance and geolocation systems. The authority found that these omissions breached data protection rules.ITGaranteGDPR€20,000
18 Oct 2022a natural personA natural person was fined EUR 150 by ANSPDCP for violating the General Data Protection Regulation. The case concerned a breach of GDPR requirements.ROANSPDCPGDPR€150
12 Feb 2026Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR.ITGaranteGDPR€2,500
19 Feb 2015Andrea AngeloniAndrea Angeloni was fined by the Garante for sending unsolicited promotional letters. The entity also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
20 Nov 2014Andrea Romualdo CerriAndrea Romualdo Cerri was fined €2,400 by the Garante. The violation concerned failing to provide the required information to data subjects when collecting personal data through a web form on the company website.ITGaranteGDPR€2,400
28 Oct 2021Anfiteatro Flavio s.r.l.Anfiteatro Flavio s.r.l. was fined EUR 2,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR.ITGaranteGDPR€2,000
09 Jun 2016Angela BellavitaAngela Bellavita was fined EUR 2,400 by the Italian Garante. The case concerned the collection of personal data, including name, surname, and email address, through a website contact form without providing users with adequate information.ITGaranteGDPR€2,400
14 Apr 2021ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined by the AEPD EUR 2,000 for not having a GDPR-compliant privacy policy on its website. In particular, it failed to provide contact details for exercising data subject rights.ESAEPDGDPR€2,000
01 Jan 2022ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined €2,000 by the AEPD. The authority found that the website did not provide adequate contact information for individuals to exercise their data protection rights.ESAEPDGDPR€2,000
01 Jul 2020ANMAVAS 61, S.L. (LA CUEVA SEX CLUB)ANMAVAS 61, S.L. did not respond to a data subject’s request for erasure. The AEPD imposed a fine of EUR 2,000 for breaching GDPR obligations.ESAEPDGDPR€2,000
17 Oct 2013Annamaria FazziniAnnamaria Fazzini was fined EUR 2,400 by the Garante for failing to provide the required privacy notice for a video surveillance system at her business. The case concerns non-compliance with the obligation to inform individuals about the processing of their personal data.ITGaranteGDPR€2,400
27 May 2024Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose.GRHDPAGDPR€5,000
23 May 2022ANOIXISThe fine was imposed for sending unsolicited SMS messages for direct marketing without prior consent. The company also failed to provide a valid opt-out address, affecting data subjects’ rights of access and objection.GRHDPAePrivacy€54,000
22 Jul 2025Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements.SIIP-RSGDPR€2,000
26 Nov 2025Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR.SIIP-RSGDPR€6,000
08 Dec 2025Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR.SIIP-RSGDPR€4,800