Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 May 2023InternetThe company was fined for failing to implement adequate security measures for personal data processing. The deficiency led to a data breach involving user accounts, including accounts protected by weak passwords.CZUOOUGDPR€63,600
16 Jan 2024International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR.NLAPGDPR€150,000
24 Jul 2014Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000
13 Mar 2025Interflora Italia S.p.A.Interflora Italia S.p.A. was fined EUR 40,000 by the Garante for sending promotional SMS messages without providing an opt-out option. The case indicates a breach of GDPR requirements for marketing communications and data subject rights.ITGaranteGDPR€40,000
16 Nov 2023Intelling LtdBetween 1 January 2021 and 11 November 2021, Intelling sent 1,164,877 direct marketing messages in breach of Regulation 22 of PECR. The Commissioner opened the case after receiving 1,103 complaints via the 7726 Spam Reporting Service.GBICOePrivacy€79,982
13 Jan 2023Intellexa A.E.Intellexa A.E. was fined EUR 50,000 by the HDPA. The authority found that the company failed to cooperate with the supervisory authority as required under Article 31 of the GDPR.GRHDPAGDPR€50,000
03 Oct 2025INTEGRAL DE VIGILANCIA Y CONTROL, S.L.INTEGRAL DE VIGILANCIA Y CONTROL, S.L. was fined by the AEPD 5,000 EUR for sending emails to a personal email address without a proper legal basis. The authority treated this as a breach of data protection rules.ESAEPDGDPR€5,000
06 Mar 2023Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€3,000
12 Apr 2018Insurances Global Services S.r.l.Insurances Global Services S.r.l. was fined by the Garante EUR 20,000 for violations involving access to and handling of client data from credit risk databases without proper authorization. The case concerned the unauthorized use of personal data in the context of credit risk assessment.ITGaranteGDPR€20,000
07 Mar 2012INSTITUTO TECNOLOGICO AUTESEL SLINSTITUTO TECNOLOGICO AUTESEL SL was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€600
01 Jan 2015INSTITUTO SUPERIOR DE ESTUDIOS EMPRESARIALES CAMBRIDGE S.A.The entity was fined by the AEPD 1,500 EUR for sending commercial messages without providing recipients a way to oppose further communications. The authority treated this as a breach of the right to data cancellation and control over continued contact.ESAEPDePrivacy€1,500
01 Jan 2014INSTITUTO SUPERIOR DE EDUCACIÓN, ADMINISTRACIÓN Y DESARROLLO S.L.The entity sent unsolicited commercial emails without prior recipient consent. This breached Article 21.1 of the LSSI and resulted in an EUR 800 fine imposed by the AEPD.ESAEPDePrivacy€800
11 Dec 2024INSTITUTO RAIMON GAJA, S.L.INSTITUTO RAIMON GAJA, S.L. was fined by the AEPD 2,000 EUR for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI, despite the recipient’s request to stop receiving such messages.ESAEPDePrivacy€2,000
01 Jan 2023INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR.ESAEPDGDPR€7,000
02 Oct 2020INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine.ESAEPDePrivacy€3,000
21 Feb 2014INSTITUCIÓN EUROAMERICANA DE FORMACIÓN E.I.R.L.The entity was fined by the AEPD in the amount of 39,000 EUR for sending unsolicited commercial emails without prior recipient consent. This constituted a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€39,000
12 Apr 2021INSTAPACK, S.L.INSTAPACK, S.L. was fined by the AEPD for sending unsolicited SMS messages without valid consent. The authority also found that the company failed to respond to a deletion request, constituting a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
09 Aug 2018InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000.NLAPGDPR€48,000
20 Dec 2021INSEKT FOOD S.L.INSEKT FOOD S.L. was fined by the AEPD EUR 4,000 for sharing an individual's personal data in WhatsApp group chats without consent. The authority found that the processing lacked a lawful basis under Article 6 of the GDPR.ESAEPDGDPR€4,000
12 Mar 2026INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles.ITGaranteGDPR€40,000