Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Apr 2021INPSThe Italian Data Protection Authority fined INPS €12,000 for failing to provide a data subject with access to their personal data and for unlawfully communicating personal data to third parties. The authority found breaches of lawfulness, fairness, and transparency.ITGaranteGDPR€12,000
24 Apr 2024I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
15 Feb 2018Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data.ITGaranteGDPR€22,400
04 Jan 2021Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing.NODatatilsynetGDPR€95,750
11 Apr 2024Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack.ITGaranteGDPR€25,000
08 Jun 2022INMUR JOYEROS, S.L.INMUR JOYEROS, S.L. was fined by the AEPD 300 EUR for failing to properly inform individuals about the video surveillance system in its premises. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€300
09 Jun 2021INMOPISO ZARAGOZA, S.L.INMOPISO ZARAGOZA, S.L. was fined EUR 2,000 by the AEPD for failing to provide data protection information to a customer who made a deposit for a property purchase. The case concerns a breach of the transparency and information duty owed to the data subject.ESAEPDGDPR€2,000
01 Jan 2022INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR.ESAEPDGDPR€40,000
01 Jan 2021INMARÁN ASESORES, S.L.INMARÁN ASESORES, S.L. was fined 2,000 EUR by the AEPD for recording telephone conversations without informing the data subject or obtaining consent. The authority found this to be a breach of the GDPR information obligations.ESAEPDGDPR€2,000
30 Nov 2022INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD 1,000 EUR for failing to comply with data protection authority resolutions. The breach concerned the obligation to inform data subjects under Article 13 of the GDPR.ESAEPDGDPR€1,000
01 Jan 2023INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD in the amount of 2,000 EUR for failing to comply with a data protection authority resolution. The company did not implement the required measures to inform data subjects under Article 13 GDPR.ESAEPDGDPR€2,000
27 Apr 2011Iniziative immobiliari s.p.a.Iniziative immobiliari s.p.a. was fined 20,000 EUR by the Garante. The authority found that the company collected personal data through a website form without providing adequate information and failed to appoint data processing personnel or implement minimum security measures.ITGaranteGDPR€20,000
05 Sept 2013Iniziative Commerciali S.r.l.Iniziative Commerciali S.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This breached the Italian Data Protection Code.ITGaranteGDPR€4,800
16 Nov 2010INGORA SERAI S.L.INGORA SERAI S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications.ESAEPDePrivacy€600
19 Apr 2022INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR.ESAEPDGDPR€10,000
27 Mar 2014ING DIRECT NV SUCURSAL EN ESPAÑAING Direct Spain was fined by the AEPD for sending commercial emails to a user after consent had been revoked. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
05 Jun 2014Ing. Claudio ZiniThe individual enterprise of Ing. Claudio Zini was fined for sending unsolicited promotional emails. The authority also found that the required information notice under Article 13 of the Italian Privacy Code was not provided.ITGaranteGDPR€2,400
23 Jul 2025ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR.PLPresident of the Personal Data Protection OfficeGDPR€4,375,000
23 Mar 2026ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement.ROANSPDCPGDPR€4,000
18 Jul 2023ING BANK NV Amsterdam Sucursala BucureștiING Bank NV Amsterdam Sucursala București received a fine from ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000