Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023B.B.B.The entity used a video from a training session containing the complainant’s personal statements without consent. The material was used for marketing purposes to attract new clients, which constituted a breach of data protection rules.ESAEPDGDPR€10,000
01 Jan 2023VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€10,000
09 Apr 2024ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR.ESAEPDGDPR€10,000
05 Mar 2015Comune di CapaccioComune di Capaccio was fined for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The authority found this to be a breach of privacy and data protection rules.ITGaranteGDPR€10,000
09 Jun 2022Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5.ITGaranteGDPR€10,000
16 Jun 2023BORSA MEDIC, S.L.BORSA MEDIC, S.L. was fined 10,000 EUR by the AEPD for failing to comply with a data deletion request and for sending unsolicited advertising emails after the recipient objected. The case concerns breaches of data protection and electronic commerce rules.ESAEPDePrivacy€10,000
08 Jan 2015CHRYSOS ODIGOS ENTYPH & HLEKTRONIKI PLHROFORISI A.E.The company was fined by the HDPA EUR 10,000 for processing personal data without consent. The authority also found that it failed to respond to data subjects' requests for access and objection.GRHDPAGDPR€10,000
11 Feb 2021Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing.ITGaranteGDPR€10,000
26 Nov 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited advertising emails. The messages were sent despite the recipient's unsubscribe request and inclusion on the Robinson list, breaching the LSSI.ESAEPDePrivacy€10,000
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR.ITGaranteGDPR€10,000
19 Mar 2015Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data.ITGaranteGDPR€10,000
01 Jan 2024ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1).ESAEPDGDPR€10,000
01 Jan 2020CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure.ESAEPDGDPR€10,000
03 Mar 2025BEKO ROMÂNIA SAIn February 2025, ANSPDCP completed an investigation at BEKO ROMÂNIA SA and found violations of GDPR provisions. As a result, the controller was fined EUR 10,000.ROANSPDCPGDPR€10,000
28 Mar 2023SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a fine of EUR 10,000 on SOCIETE DE MARKETING and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
11 Jul 2019Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent.ATDSBGDPR€10,000
29 May 2019Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights.ITGaranteGDPR€10,000
01 Apr 2025BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal€10,000
19 Feb 2015Comune di CampotostoComune di Campotosto was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and personal data protection rules.ITGaranteGDPR€10,000
05 Mar 2015Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri "Cesare Musatti"The Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri “Cesare Musatti” was fined by the Italian data protection authority, Garante, in the amount of €10,000. The violation involved unlawfully publishing personal data on its website that revealed students’ health status.ITGaranteGDPR€10,000