Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 May 2018Ierardi TeresaIerardi Teresa, a general practitioner, was fined by the Garante for failing to adopt minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
19 Jul 2018Idroservice Italia s.r.l.Idroservice Italia s.r.l. was fined by the Garante for failing to respond to a request for information. The authority treated this as a breach of data protection rules.ITGaranteGDPR€20,000
05 May 2011Idrablu SpaIdrablu Spa was fined by the Garante in the amount of EUR 20,000 for failing to respond to requests for information about the transfer of personal data to another company. The authority treated this as a breach of data protection rules.ITGaranteGDPR€20,000
14 Jan 2021IDFINANCE SPAIN, S.L.IDFINANCE SPAIN, S.L. was fined by the AEPD EUR 5,000 after an incident in which a user could access another customer's personal data and loan information through a faulty email link. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€5,000
29 Jan 2024IDFINANCE SPAIN, S.A.U.The AEPD fined IDFINANCE SPAIN, S.A.U. 70,000 EUR for including personal data in credit information systems in connection with a disputed debt. The authority found that the processing breached Article 6 GDPR.ESAEPDGDPR€70,000
24 Jul 2020I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.UI-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U was fined by the AEPD EUR 200,000 for sending letters to customers without a legal basis. The authority found that this breached the principles of data minimization and purpose limitation.ESAEPDGDPR€200,000
31 May 2018IDEASORRISO S.R.L.IDEASORRISO S.R.L. was fined by the Garante EUR 86,000 for making unsolicited promotional calls without the recipients’ consent. The case concerned data protection rules applicable to telemarketing activities.ITGaranteGDPR€86,000
10 Nov 2011Idea Service S.r.l.Idea Service S.r.l. was fined EUR 20,000 by the Garante for failing to provide information about an unwanted switch of telephone service provider. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€20,000
01 Jan 2012IDEAS CREATIVAS DE OPERACION S.L.IDEAS CREATIVAS DE OPERACION S.L. was fined EUR 33,001 by the AEPD for sending unsolicited commercial emails despite requests for data cancellation. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€33,001
01 Jan 2012IDEAS CREATIVAS DE OPERACIONES, S.L.IDEAS CREATIVAS DE OPERACIONES, S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The authority also found that the company failed to provide a functional opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€30,001
17 Oct 2013Ideal Service srlIdeal Service srl was fined by the Garante EUR 2,400 for sending promotional emails without the required privacy information. The authority found this to be a breach of Article 161 of the Italian Data Protection Code.ITGaranteGDPR€2,400
03 Jun 2010ICTS Italia s.r.l.ICTS Italia s.r.l. was fined by the Garante for using a biometric system for employee access control and attendance without adequate notice, consent, or minimum security measures. The company also failed to notify the Garante.ITGaranteGDPR€18,400
06 Jul 2006I.C. Recruiting di Aldo Corradi & C. s.n.c.The company was fined EUR 258 by the Garante for failing to provide adequate information to data subjects in job advertisements. This constituted a breach of Article 13 of the Italian Codice Privacy.ITGaranteGDPR€258
16 May 2023Ice Telecommunications LtdIce Telecommunications Ltd made 72,682 unsolicited marketing calls to businesses registered with the CTPS or TPS between 13 September 2021 and 31 January 2022. The ICO imposed a fine of £80,000 for breaching direct marketing rules.GBICOGDPR€92,016
02 Dec 2021Ica s.r.l.Ica s.r.l. was fined by the Garante EUR 30,000 for failing to implement adequate security measures in its online traffic-fine payment service. The weakness allowed unauthorized access to the personal data of fined citizens.ITGaranteGDPR€30,000
17 Oct 2013ICA Foods S.p.a.ICA Foods S.p.a. was fined by the Garante for installing a video surveillance system without providing employees with adequate information. The conduct breached privacy rules and the information obligations applicable to monitored persons.ITGaranteGDPR€2,400
03 Feb 2025IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274IBERMUTUA was fined EUR 1,000,000 by the AEPD for a data breach. Due to a computer error, personal data, including health information, was mistakenly sent to various companies.ESAEPDGDPR€1,000,000
29 Jul 2024IBERINFORMIBERINFORM was fined by the AEPD €1,000,000 for processing personal data of self-employed individuals without a proper legal basis. The authority also found that the data were used beyond professional relationships, including for marketing and online exposure.ESAEPDGDPR€1,000,000
01 Jan 2013IBÉRICA SECTORIAL DE ANÁLISIS, S.L.U.IBÉRICA SECTORIAL DE ANÁLISIS, S.L.U. was fined by the AEPD 1,400 EUR for sending unsolicited commercial emails. The authority found that the messages lacked a valid opt-out address, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,400
01 Jan 2013IBERIA LÍNEAS AÉREAS DE ESPAÑA, SOCIEDAD ANÓNIMA OPERADORA, Sociedad UnipersonalIberia was fined by the AEPD EUR 1,200 for sending commercial emails without providing recipients with a simple and free way to opt out of further messages. The authority found a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€1,200