Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2019EL PERIODICO DE CATALUNYA, S.L.EL PERIODICO DE CATALUNYA, S.L. was fined by the AEPD 10,000 EUR for sending a commercial email after a data deletion request. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€10,000
05 Apr 2018Comune di Magliano SabinaThe Municipality of Magliano Sabina was fined 10,000 EUR by the Garante for unlawfully disclosing personal data to a private educational institution without a valid legal basis. The authority found that this conduct breached the Italian Privacy Code.ITGaranteGDPR€10,000
06 Apr 2017Effepì Credit s.r.l.Effepì Credit s.r.l. was fined by the Garante in the amount of EUR 10,000 for inadequate security measures. The authority cited weak and outdated passwords as a breach of data protection rules.ITGaranteGDPR€10,000
19 Jul 2018Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules.CZUOOUGDPR€386
11 Mar 2021Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data.ITGaranteGDPR€10,000
26 Jun 2026Artmark Holding SRLArtmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements.ROANSPDCPePrivacy€1,908
08 Oct 2019Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure.BGCPDPGDPR€5,113
13 Feb 2025Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing.ITGaranteGDPR€10,000
24 Nov 2016Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules.ITGaranteGDPR€10,000
16 May 2018Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
01 May 2025CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.CURENERGÍA was fined EUR 10,000 by the AEPD for sharing personal data with IBERDROLA without the data subject’s consent. The disclosure led to a contract offer at a higher price than requested.ESAEPDGDPR€10,000
25 Sept 2023UAT Comuna AlbeniANSPDCP imposed a 10,000 RON fine on UAT Comuna Albeni for failing to implement measures previously ordered by the authority. The entity also did not respond to the authority’s requests.ROANSPDCPGDPR€2,013
10 Nov 2016Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined by the Garante for making an unsolicited promotional call to a number listed in the public opposition registry. The conduct breached data protection rules.ITGaranteGDPR€10,000
12 Nov 2014Ruggiero FerdinandoRuggiero Ferdinando was fined EUR 10,000 by the Garante. The sanction concerned failing to provide a complete response to a request for information during a privacy investigation.ITGaranteGDPR€10,000
01 Jan 2023EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.EL ESPAÑOL was fined 10,000 EUR by the AEPD for publishing a private video without the consent of the data subject. The case concerns a breach of data protection rules.ESAEPDGDPR€10,000
24 Nov 2016Unione Comunale del Chianti fiorentinoUnione Comunale del Chianti fiorentino was fined by the Garante 10,000 EUR for publishing on its website the personal data of individuals who were not admitted to a financial benefit. The conduct breached data protection rules.ITGaranteGDPR€10,000
14 Sept 2006Asl FerraraAsl Ferrara was fined by the Garante for processing genetic, health, and sexual life data without the required notification. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
26 Feb 2026Radio Immagine Uno S.r.l.The Garante imposed a €10,000 fine on Radio Immagine Uno S.r.l. for failing to respond to a data subject's request to remove an online article containing personal data. The company did not comply with the right to be forgotten, resulting in a data protection breach.ITGaranteGDPR€10,000
10 Jul 2014Comune di OrbetelloThe Municipality of Orbetello was fined EUR 10,000 by the Italian data protection authority, Garante. The sanction concerned the publication of individuals’ personal health data on the municipality’s official website, in breach of privacy rules.ITGaranteGDPR€10,000
10 Feb 2022Regione ToscanaRegione Toscana was fined by the Garante EUR 10,000 for failing to implement adequate security measures, which resulted in a data breach. The breach was mitigated by the region’s prompt response to reduce the negative effects on affected individuals.ITGaranteGDPR€10,000