Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Mar 2015Comune di Alì TermeComune di Alì Terme was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy rules and the protection of sensitive personal data.ITGaranteGDPR€10,000
25 Jul 2023EDICIONES PERIÓDICAS DEL NOROESTE, S.L.The entity published a private video on Twitter without the data subject’s consent. The authority found a breach of data minimization because excessive data were processed beyond what was necessary for the intended purpose.ESAEPDGDPR€10,000
12 Dec 2024BREOGAN AUTOLUX, S.L.BREOGAN AUTOLUX, S.L. was fined EUR 10,000 by the AEPD for sending unsolicited SMS advertisements without prior consent from recipients. The authority also found that the messages did not provide an opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€10,000
23 Jan 2024CAIXA RURAL BENICARLÓ, S.C.C.VCAIXA RURAL BENICARLÓ was fined by the AEPD 10,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€10,000
19 Apr 2022INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR.ESAEPDGDPR€10,000
21 Apr 2011Azienda Trasporti per l'Area Metropolitana S.p.A.Azienda Trasporti per l'Area Metropolitana S.p.A. was fined by the Garante €10,000 for failing to provide adequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€10,000
26 Mar 2019А.Р. ЕООДThe CPDP imposed a 10,000 BGN fine on А.Р. ЕООД for processing personal data without consent. The case also involved registering an employment contract for an imprisoned individual, which breached Article 6 GDPR.BGCPDPGDPR€5,113
10 Jun 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages were sent despite the recipient’s request not to receive such communications.ESAEPDePrivacy€10,000
12 Mar 2015Comune di BasicòComune di Basicò was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of data protection rules and the confidentiality of sensitive data.ITGaranteGDPR€10,000
25 Feb 2016Decatel s.r.l.Decatel s.r.l. was fined €10,000 by the Italian Garante. The case concerned the processing and retention of telephone traffic data without the required safeguards, including biometric recognition and strong authentication.ITGaranteGDPR€10,000
15 Jan 2015Comune di SidernoComune di Siderno was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The conduct breached privacy and data protection rules.ITGaranteGDPR€10,000
06 Jan 2020дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR.BGCPDPGDPR€5,113
17 Jul 2025Federazione Italiana Sport EquestriThe Italian Data Protection Authority imposed a EUR 10,000 fine on Federazione Italiana Sport Equestri for publishing a disciplinary decision involving a minor on its website without anonymizing personal data. The breach concerned data protection rules and the disclosure of information that could identify the minor.ITGaranteGDPR€10,000
05 Sept 2024SOCIETE SPECIALISEE DANS LAFABRICATION ET POSE DE CLOTURES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE SPECIALISEE DANS LAFABRICATION ET POSE DE CLOTURES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
17 May 2023Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15.ITGaranteGDPR€10,000
30 Jan 2025Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks.ITGaranteGDPR€10,000
30 Oct 2024COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35.ESAEPDGDPR€10,000
12 Feb 2018Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing.BGCPDPGDPR€5,113
24 Apr 2025Dante International SAIn April 2025, ANSPDCP completed an investigation into Dante International SA and found violations of GDPR provisions. As a result, a fine of 10,000 EUR was imposed.ROANSPDCPGDPR€10,000
01 Jan 2024EMPRENDEDORES ONLINE, LLCEMPRENDEDORES ONLINE, LLC was fined by the AEPD 10,000 EUR for recording and sharing course participants’ personal data without consent. The authority found a breach of GDPR Articles 5(1)(f) and 6(1), indicating unlawful processing and insufficient legal basis.ESAEPDGDPR€10,000