Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information.GRHDPAGDPR€7,500
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data.GRHDPAGDPR€7,500
02 Apr 2026SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,500 on SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES under a simplified procedure. The case concerns a breach of rules covered by the authority’s decision.FRCNILGDPR€7,500
07 Nov 2014MASTOCADOS S.L.MASTOCADOS S.L. was fined by the AEPD 7,400 EUR for sending unauthorized commercial emails to individuals without a prior contractual relationship. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€7,400
01 Jan 2015JAZZ TELECOM, SAUJAZZ TELECOM, SAU was fined by the AEPD in the amount of 7,400 EUR for sending unsolicited commercial emails to a complainant. The conduct occurred after the cancellation of the complainant’s personal data had been confirmed and breached Article 21.1 of the LSSI.ESAEPDePrivacy€7,400
16 Dec 2025Anonymisé (CNPD decision-05-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. The record lacked or contained incomplete information on data categories and transfers to third countries.LUCNPDGDPR€7,341
11 Jun 2021Anonymisé (CNPD decision-22-fr-2021)The company failed to comply with GDPR requirements on data minimization and transparency. It also did not adequately inform individuals about video surveillance and geolocation systems, breaching Articles 5(1)(c), 5(1)(e), 13, and 32(1) of the GDPR.LUCNPDGDPR€7,200
11 Jul 2018General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met.ITGaranteGDPR€7,200
14 Mar 2017GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€7,100
20 Oct 2022I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk.ITGaranteGDPR€7,000
11 Sept 2025ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE (procédure simplifiée)CNIL imposed an administrative fine of 7,000 EUR on ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€7,000
22 Feb 2023MUNDOVIAJES2010, S.L.MUNDOVIAJES2010, S.L. was fined by the AEPD in the amount of 7,000 EUR for processing personal data without consent. The authority also found a failure to provide the required information about data processing, in breach of GDPR Articles 6(1) and 14.ESAEPDGDPR€7,000
01 Jan 2016CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€7,000
01 Jan 2023INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR.ESAEPDGDPR€7,000
12 May 2022Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures.ITGaranteGDPR€7,000
25 Mar 2021TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data.ITGaranteGDPR€7,000
01 Dec 2017BILUA E-COMMERCE S.L (CARETHY y BIUKY)BILUA E-COMMERCE S.L. was fined by the AEPD EUR 7,000 for sending unsolicited commercial emails. The messages were sent despite the recipient's request to unsubscribe, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€7,000
01 Jan 2012MAIL MARKETING SERVICIOS INFORMATICOS, S.LMAIL MARKETING SERVICIOS INFORMATICOS, S.L was fined by the AEPD in the amount of 7,000 EUR for sending unsolicited commercial emails. The case concerned a breach of Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€7,000
15 Mar 2022CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine.ESAEPDePrivacy€7,000
02 Dec 2021Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data.ITGaranteGDPR€7,000