Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2021B.B.B.B.B.B. was fined by the AEPD 10,000 EUR for publishing personal data, including DNI/NIF, on a website. The authority found a breach of data minimization principles and GDPR requirements.ESAEPDGDPR€10,000
07 Mar 2024BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15.ITGaranteGDPR€10,000
29 Oct 2019JOKER PREMIUM INVEX, S.L.JOKER PREMIUM INVEX, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited commercial communications. The company used personal data taken from public sources without the individuals’ consent.ESAEPDGDPR€10,000
11 Jan 2024DESPACHO TORRENTE, S.L.P.DESPACHO TORRENTE, S.L.P. was fined by the AEPD 10,000 EUR for improperly disclosing personal data, including sensitive information, in a letter concerning damage at public facilities. The authority found a breach of data protection principles.ESAEPDGDPR€10,000
04 Jul 2024Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles.ITGaranteGDPR€10,000
16 Dec 2009BonassisaLab s.r.l.BonassisaLab s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code.ITGaranteGDPR€10,000
21 Jan 2010Servizi sanitari s.r.l. – Istituto cardiovascolare CamogliServizi sanitari s.r.l. was fined by the Garante 10,000 EUR for violations related to the processing of personal data without the required notification. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
01 Jan 2015ORANGE ESPAGNE, S.A.U.JAZZ TELECOM S.A.U. was fined for sending unsolicited SMS advertising to a non-customer. The authority found that the conduct breached the LSSI rules on marketing communications.ESAEPDePrivacy€10,000
19 Mar 2024LOCAL VERTICALS, S.L.LOCAL VERTICALS, S.L. was fined by the AEPD 10,000 EUR for storing cookies without user consent and for failing to provide a legal notice on its website. The case concerns breaches of data protection rules and website transparency obligations.ESAEPDePrivacy€10,000
15 Jul 2010Comune di VentimigliaComune di Ventimiglia was fined by the Garante for processing employees’ biometric data without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
27 Jan 2021Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty.ITGaranteGDPR€10,000
23 Mar 2021Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules.CZUOOUePrivacy€382
10 Jan 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited commercial SMS messages. The messages were sent despite the complainant being registered on the Robinson List, breaching Articles 21.1 and 21.2 of the LSSI.ESAEPDePrivacy€10,000
01 Jun 2016Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
26 Jul 2018Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data.ITGaranteGDPR€10,000
01 Mar 2025Tensa Art Design S.A.The Romanian data protection authority investigated Tensa Art Design S.A., operator of lensa.ro, in March 2025. It found GDPR violations involving direct marketing without valid consent and improper handling of data subject access and erasure requests. Two fines totaling 15,000 EUR were imposed.ROANSPDCPGDPR€10,000
26 Apr 2018Falotico Luca CarmeloFalotico Luca Carmelo, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
11 Jul 2018BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules.ITGaranteGDPR€10,000
02 Oct 2014San Petronio s.r.l.San Petronio s.r.l. was fined by the Garante for failing to appoint data processing officers and for providing inadequate information about video surveillance. The authority found that these practices breached data protection rules.ITGaranteGDPR€10,000
01 Jul 2020COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD for publishing a resident’s personal data on a community notice board. The conduct breached data protection rules.ESAEPDGDPR€10,000