Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Oct 2022Codess Sociale, Soc. Coop. socialeCodess Sociale, Soc. Coop. sociale was fined EUR 10,000 by the Garante. The authority found that the company failed to respond to a data subject's request to exercise GDPR rights.ITGaranteGDPR€10,000
18 May 2017Brennercom s.p.a.Brennercom s.p.a. was fined 10,000 EUR by the Garante for inadequate password security measures. The authority found that the company's practices breached data protection rules.ITGaranteGDPR€10,000
11 Aug 2025APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR.ESAEPDGDPR€10,000
07 Apr 2021Anonymizováno (ÚOOÚ UOOU-03058/20-30)The entity did not respond to a data subject's request to delete personal data from a publicly accessible auction notice. The authority found this to be a breach of GDPR rights and imposed a monetary penalty.CZUOOUGDPR€386
03 Apr 2025SOCIETE DE COURTAGE EN TRAVAUX, CONSULTING EN BATIMENT ET TRAVAUX PUBLICS, ACHAT ET REVENTE DE MATERIEL, TRANSACTION IMMOBILIERE ET MAITRISE D'ŒUVRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
20 Oct 2022Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse.ITGaranteGDPR€10,000
26 Mar 2015Comune di SortinoComune di Sortino was fined for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the improper disclosure of sensitive data.ITGaranteGDPR€10,000
27 Jan 2016Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules.ITGaranteGDPR€10,000
10 Mar 2025Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements.CYCyDPCGDPR€10,000
31 Jan 2024Sectorul 1 al Municipiului BucureștiThe National Supervisory Authority for Personal Data Processing fined Sectorul 1 of Bucharest Municipality for GDPR violations. The entity failed to demonstrate compliance with a remediation measure, which formed the basis for the sanction.ROANSPDCPGDPR€2,010
18 May 2017Terrecablate reti e servizi s.r.l.Terrecablate reti e servizi s.r.l. was fined by the Garante €10,000 for inadequate security measures. The violation concerned weak password authentication on servers storing telephone traffic data.ITGaranteGDPR€10,000
07 May 2015Pelamatti GiacomoPelamatti Giacomo was fined by the Garante EUR 10,000 for activating phone cards in the names of individuals without their knowledge. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,000
09 May 2024Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR.ITGaranteGDPR€10,000
16 May 2018Bolignari PietroBolignari Pietro, a general practitioner, was fined for failing to implement minimum security measures for personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 Mar 2024NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent.ESAEPDePrivacy€10,000
30 May 2022ASOCIACIÓN CONTRA LA CORRUPCION Y EN DEFENSA DE LA ACCIÓN PÚBLICAACODAP was fined EUR 10,000 by the AEPD for publishing complainants’ personal data on its website without anonymization. The authority found this conduct to be contrary to GDPR Article 5(1)(b).ESAEPDGDPR€10,000
26 Oct 2020***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information.ESAEPDGDPR€10,000
31 Oct 2022B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization.GRHDPAGDPR€10,000
16 Nov 2017Terre Etrusche e di Maremma Credito CooperativoThe Garante fined Terre Etrusche e di Maremma Credito Cooperativo EUR 10,000 for inadequate password security measures. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€10,000
04 Feb 2026GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances.ROANSPDCPGDPR€10,000