Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jul 2025dottoressa Monica Maria FerrariThe doctor was fined for recording conversations with a patient during a specialist visit without proper consent. The authority also found a failure to provide required information, breaching transparency and information obligations.ITGaranteGDPR€7,000
25 Oct 2016CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI.ESAEPDePrivacy€7,000
29 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 7,000 on SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€7,000
16 Jun 2021MARBELLA RESORTS, S.L.MARBELLA RESORTS, S.L. was fined EUR 7,000 by the AEPD for non-compliance with data protection rules. The breaches concerned the handling of personal data and the website cookie policy.ESAEPDePrivacy€7,000
14 Mar 2017GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€7,100
11 Jun 2021Anonymisé (CNPD decision-22-fr-2021)The company failed to comply with GDPR requirements on data minimization and transparency. It also did not adequately inform individuals about video surveillance and geolocation systems, breaching Articles 5(1)(c), 5(1)(e), 13, and 32(1) of the GDPR.LUCNPDGDPR€7,200
11 Jul 2018General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met.ITGaranteGDPR€7,200
16 Dec 2025Anonymisé (CNPD decision-05-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. The record lacked or contained incomplete information on data categories and transfers to third countries.LUCNPDGDPR€7,341
07 Nov 2014MASTOCADOS S.L.MASTOCADOS S.L. was fined by the AEPD 7,400 EUR for sending unauthorized commercial emails to individuals without a prior contractual relationship. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€7,400
01 Jan 2015JAZZ TELECOM, SAUJAZZ TELECOM, SAU was fined by the AEPD in the amount of 7,400 EUR for sending unsolicited commercial emails to a complainant. The conduct occurred after the cancellation of the complainant’s personal data had been confirmed and breached Article 21.1 of the LSSI.ESAEPDePrivacy€7,400
13 Jan 2022Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13.ITGaranteGDPR€7,500
31 May 2024CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle.ESAEPDGDPR€7,500
08 Aug 2014INFOASSIST A.E.INFOASSIST A.E. was fined by the HDPA 7,500 EUR for processing personal data without consent. The authority found breaches of legality and data minimization principles.GRHDPAGDPR€7,500
08 Aug 2014Hummingbird EPEHummingbird EPE was fined by the HDPA for processing publicly available personal data without the consent of the data subjects. The authority found a breach of the principles of data relevance and proportionality.GRHDPAGDPR€7,500
06 Mar 2024The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand.GBICOGDPR€8,772
11 May 2021Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident.NLAPGDPR€7,500
17 Jul 2025Perla Odontoiatria Veneta S.r.l.The Garante fined Perla Odontoiatria Veneta S.r.l. EUR 7,500 for failing to meet information and transparency obligations in the processing of health data. The authority cited breaches of GDPR Articles 5, 9, and 15.ITGaranteGDPR€7,500
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information.GRHDPAGDPR€7,500
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data.GRHDPAGDPR€7,500
02 Apr 2026SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,500 on SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES under a simplified procedure. The case concerns a breach of rules covered by the authority’s decision.FRCNILGDPR€7,500