Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Mar 2015GRAMMATA, S.L.GRAMMATA, S.L. was fined by the AEPD 1,100 EUR for sending unsolicited advertising emails. The authority also found that the company failed to provide a functional opt-out mechanism, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,100
20 Jun 2024Grafiche E.The Garante imposed a fine of EUR 12,000 on Grafiche E. for violations of data protection rules. The case concerned non-compliance with regulatory requirements for the processing of personal data.ITGaranteGDPR€12,000
11 Mar 2020Google, rätten att få sökresultat borttagnaGoogle LLC was fined by IMY for processing sensitive personal data without a valid legal basis and for handling data relating to criminal offenses without authorization. The authority also found that Google did not respond promptly to requests for data removal, in breach of several GDPR provisions.SEIMYGDPR€6,993,000
01 Jan 2020GOOGLE LLCGoogle LLC was fined by the AEPD EUR 5,000,000 for the unauthorized communication of personal data to the “Lumen Project”. The authority found breaches of the right to erasure and the GDPR requirement for lawful processing.ESAEPDGDPR€5,000,000
01 Jan 2013GOOGLE INCGoogle Inc. was fined by the AEPD EUR 130,000 for failing to provide adequate information on privacy and cookie policies on a website. The authority found a breach of the LSSI information requirements toward users.ESAEPDePrivacy€130,000
18 Dec 2013Google Inc.Google Inc. was fined EUR 1 million by the Italian Data Protection Authority, Garante. The authority found that individuals were not adequately informed during data collection by Google cars for the Street View service.ITGaranteGDPR€1,000,000
04 Sept 2025GoogleFrance's CNIL imposed a record 325 million euro fine on Google for cookie consent violations. The authority found that Google did not obtain free and informed consent before placing advertising cookies and used Gmail ad practices that required prior consent.FRCNILePrivacy€325,000,000
04 Sept 2025GoogleThe French data protection authority CNIL fined Google for setting advertising cookies without valid user consent. Google was ordered to bring its practices into compliance within a set deadline, with daily penalties possible for non-compliance.FRCNILGDPR€379,000,000
09 Jan 2014Goldenbridge s.r.l.Goldenbridge s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice when collecting personal data through a website contact form. The authority found this to be a breach of the Italian data protection rules.ITGaranteGDPR€2,400
19 Jul 2018Go Internet S.p.AGo Internet S.p.A was fined by the Garante in the amount of 40,000 EUR for processing and retaining telephone and internet traffic data beyond the permitted period. The authority found this conduct contrary to the Italian Data Protection Code.ITGaranteGDPR€40,000
06 Aug 2025GOHIPOTECA, S.L.GOHIPOTECA, S.L. processed personal data without consent, using an individual's data to apply for a mortgage without authorization. The AEPD imposed a fine of EUR 2,000 for this violation.ESAEPDGDPR€2,000
13 Apr 2023GMC s.a.p.a.GMC s.a.p.a. was fined EUR 15,000 by the Italian supervisory authority, Garante. The case concerned the publication of detailed health data of an individual without consent, in breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€15,000
18 Nov 2015G.M.C. - Giuseppe Marra Communications s.a.p.a.G.M.C. - Giuseppe Marra Communications s.a.p.a. was fined by the Garante in the amount of €4,000 for unlawfully obtaining consent for data processing through a newsletter subscription. The form included marketing purposes beyond the stated intent, which breached Article 23 of the Italian Data Protection Code.ITGaranteGDPR€4,000
08 Jun 2020G.L.P. Instalaciones 86, S.L.G.L.P. Instalaciones 86, S.L. was fined by the AEPD EUR 60,000 for processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€60,000
07 Jul 2022Głównego Geodetę Kraju z siedzibą w Warszawie, przy ul.UODO imposed a PLN 60,000 administrative fine on the Chief Geodesist of Poland. The authority found that the personal data breach was not reported to the supervisory authority without undue delay and that affected individuals were not notified.PLUODOGDPR€12,573
02 Jul 2020Głównego Geodetę Kraju z siedzibą w Warszawie przy ul.UODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland based in Warsaw. The sanction concerned failure to provide access during an inspection to rooms, equipment and tools used for personal data processing, as well as access to personal data and information.PLUODOGDPR€22,351
24 Aug 2020Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records.PLUODOGDPR€22,735
01 Jan 2022GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security.ESAEPDGDPR€550,000
01 Jan 2019GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR.ESAEPDGDPR€25,000
01 Jan 2023GLOVOGLOVO was fined EUR 15,000 by the AEPD for failing to properly handle a data access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€15,000