Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Dec 2023Gestioni Aziendali s.r.l.Gestioni Aziendali s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating a video surveillance system at Hotel della Vittoria without appropriate informational signage. The authority found this to be a breach of GDPR transparency requirements toward monitored individuals.ITGaranteGDPR€5,000
23 Jul 2022GESTIONES AUTO LOW COST S. LThe entity was fined for not having a privacy policy on its website. The breach concerned Article 13 of the GDPR, which requires specific information to be provided to data subjects.ESAEPDGDPR€1,000
06 Sept 2024GESTIÓN DE VENTAS IBERIA S.L.GESTIÓN DE VENTAS IBERIA S.L. was fined 4,000 EUR by the AEPD for failing to provide access as required under Article 58.1 of the GDPR. The case concerns non-compliance with a supervisory authority request.ESAEPDGDPR€4,000
06 Feb 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe AEPD fined GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADA EUR 2,000 for sending unsolicited commercial communications without the recipient's consent. The authority noted that the messages were sent despite the recipient's opposition.ESAEPDePrivacy€2,000
07 Feb 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR.ESAEPDGDPR€4,000
08 Jan 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity sent unsolicited commercial emails to an individual registered on the Robinson List. This breached Article 21 of the LSSI and led to a fine imposed by the AEPD.ESAEPDePrivacy€2,000
15 Nov 2022GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity was fined for sending unsolicited commercial emails despite the recipient's explicit objection. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
01 Jan 2019GESTIÓN DE COBROS, YO COBRO SLThe company was fined EUR 60,000 by the AEPD for unlawfully processing personal data. The breach involved sending debt collection emails to an institutional email address without consent, in violation of data protection rules.ESAEPDGDPR€60,000
01 Jan 2013GESTION CONFIDENCIAL DESTRUPACK S LGESTION CONFIDENCIAL DESTRUPACK S L was fined by the AEPD 1,800 EUR for sending unsolicited commercial emails despite a prior request to unsubscribe. The authority found a breach of Article 21 of Spain’s LSSI.ESAEPDePrivacy€1,800
20 Dec 2019GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f).ESAEPDGDPR€15,000
27 Sept 2010GESTEVISION TELECINCO, S.A.GESTEVISION TELECINCO, S.A. was fined by the AEPD 50,000 EUR for sending mass promotional SMS messages. The authority found that recipients were not given a simple and free way to object to the processing of their data for marketing purposes, in breach of Article 21.2 of the LSSI.ESAEPDePrivacy€50,000
01 Jan 2022GESTERPOOL, S.L.U.The AEPD imposed a 15,000 EUR fine on GESTERPOOL, S.L.U. for unauthorized use of personal data in a commercial call and for contract processing without consent. The case concerns breaches of GDPR rules, including Articles 28 and 58(1).ESAEPDGDPR€15,000
01 Jan 2024GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14.ESAEPDGDPR€220,000
14 Jun 2024GESCONSULT, S.A. S.G.I.I.C.GESCONSULT, S.A. S.G.I.I.C. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case involved recording a meeting and sharing the recording without proper consent.ESAEPDGDPR€5,000
17 Mar 2021GERCO FIT, S.L.GERCO FIT, S.L. was fined by the AEPD in the amount of 2,000 EUR for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
16 Jul 2025Georgescu CălinThe operator Georgescu Călin was fined by ANSPDCP in the amount of EUR 4,000 for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€4,000
24 Feb 2017Geoanalysis S.A.Geoanalysis S.A. was fined EUR 10,000 by the HDPA for improper installation and operation of a video surveillance system. The authority found data protection breaches, including failure to notify the authority and inadequate employee information.GRHDPAGDPR€10,000
19 Jan 2024GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill.ESAEPDGDPR€20,000
08 May 2024Genpact România SRLThe ANSPDCP imposed a fine of EUR 3,000 on Genpact România SRL. The sanction concerned sending a file containing recruitment data to an unauthorized employee email address. The incident indicates a failure to control access to personal data and maintain confidentiality.ROANSPDCPGDPR€3,000
04 Feb 2026GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances.ROANSPDCPGDPR€10,000