Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Jun 2025SUNERIS, S.A.SUNERIS, S.A. was fined by the AEPD in the amount of 9,000 EUR for improper handling of personal data. The case involved copying a guest’s information without consent and leaving a master key card accessible, which breached data protection principles.ESAEPDGDPR€9,000
11 Mar 2010Teleservizi s.r.l.Teleservizi s.r.l. was fined EUR 9,000 by the Garante for processing personal data without providing the required information to data subjects. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
03 Feb 2011Able Tech s.r.l.Able Tech s.r.l. was fined EUR 9,000 by the Garante for failing to provide timely information to the data subject. The breach concerned the obligation under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
10 Apr 2025Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€9,000
22 May 2014COMERCIAL POLINDUS 21, S.L.COMERCIAL POLINDUS 21, S.L. was fined by the AEPD 9,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached Article 21 of the LSSI.ESAEPDePrivacy€9,000
16 Feb 2011Bioacqua s.r.l.Bioacqua s.r.l. was fined EUR 9,000 by the Garante for using phone numbers for commercial communications without explicit consent and without providing the required information notice. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
06 Aug 2025YUNEXPRESS SPAIN, S.L.YUNEXPRESS SPAIN, S.L. was fined EUR 9,000 by the AEPD for failing to formalize a data processing agreement and for inaccuracies in data handling. The authority found breaches of GDPR Articles 28(3) and 5(1)(d).ESAEPDGDPR€9,000
22 Oct 2025εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€9,000
19 Sept 2024CRIDOLMA BARCELONA S.L.CRIDOLMA BARCELONA S.L. was fined €9,000 by the AEPD for failing to properly handle a data subject access request. The case concerned a breach of Article 15 GDPR and non-compliance with a data protection authority resolution.ESAEPDGDPR€9,000
15 Jun 2011Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
05 Oct 2022Dane anonimowe (D. sp. z o.o. sp. k. z siedzibą w P. przy ul.)The President of UODO imposed a fine of PLN 9,139 on the company. The sanction was issued because the company failed to comply with an order contained in an administrative decision of the data protection authority.PLUODOGDPR€1,907
11 Dec 2023C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information.ATDSBGDPR€9,500
19 Jan 2017D’Agostino Domenico FedeleD’Agostino Domenico Fedele was fined EUR 9,600 by the Garante for failing to provide individuals with the required data protection information. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,600
04 Sept 2025Owner of the studentenkotenThe Belgian Data Protection Authority (GBA) imposed a total fine of EUR 9,700 on the owner of a student house. The case concerned the unlawful use of surveillance cameras inside and around the property to monitor students.BEGegevensbeschermingsautoriteit (GBA)GDPR€9,700
18 Jan 2024Dane anonimowe (przez Pana B.W. prowadzącego działalność gospodarczą pod firmą: B.)UODO imposed an administrative fine on B. for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected individuals were not informed of the breach without undue delay.PLUODOGDPR€2,251
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request.ITGaranteGDPR€10,000
30 Oct 2024Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000.ROANSPDCPGDPR€10,000
21 Mar 2024Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls.ITGaranteGDPR€10,000
23 Jun 2023LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications.ESAEPDePrivacy€10,000
09 Mar 2023EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€10,000