Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Sept 2020Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures.BEAPDGDPR€2,000
28 Jul 2020Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
15 Mar 2021Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached.BEAPDGDPR€2,000
14 May 2020Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements.BEAPDGDPR€50,000
14 May 2020Geanonimiseerd (APD 24/2020)The decision concerns an insurance company that failed to provide sufficient transparency in its privacy policy. It involved the use of health data without explicit consent for purposes beyond hospitalization insurance.BEAPDGDPR€50,000
17 Dec 2024Geanonimiseerd (APD 166/2024)The hospital was fined by the APD for failing to carry out a data protection impact assessment and for lacking effective information security policies. These deficiencies contributed to a ransomware incident affecting up to 300,000 individuals.BEAPDGDPR€50,000
23 Aug 2022Geanonimiseerd (APD 129/2022)The Litigation Chamber imposed a fine for insufficient technical and organizational measures to protect data security. This led to unauthorized access to personal documents.BEAPDGDPR€2,500
23 Aug 2024Geanonimiseerd (APD 107/2024)The APD Litigation Chamber imposed a EUR 5,000 fine for responding to a data subject access request after more than 14 months. The authority found a breach of GDPR Articles 12 and 15, which require timely handling of access rights.BEAPDGDPR€5,000
11 May 2026Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights.BEAPDGDPR€5,000
17 Sept 2019Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000.BEAPDGDPR€10,000
28 May 2019Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
29 Oct 2020Gaypa s.r.l.Gaypa s.r.l. was fined EUR 20,000 by the Garante for continuing to use a personalized email account of a former employee after the employment ended. The authority found this conduct inconsistent with GDPR principles of lawfulness and purpose limitation.ITGaranteGDPR€20,000
28 Nov 2022GAVANOVA DE IMMOBLES, S.L.GAVANOVA DE IMMOBLES, S.L. was fined by the AEPD 2,000 EUR for failing to provide an adequate privacy policy on its website. The authority also found that personal data was shared with a cleaning company without the data subjects’ consent.ESAEPDGDPR€2,000
19 May 2025GATIGOS, S.L.GATIGOS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The authority found a breach of Article 58(1) GDPR.ESAEPDGDPR€6,000
20 Mar 2012GAS NATURAL S.U.R. SDG S.A.GAS NATURAL S.U.R. SDG S.A. was fined EUR 1,800 by the AEPD for continuing to send commercial emails to a complainant after they had requested that such communications stop. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,800
01 Jan 2024GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers.ESAEPDGDPR€25,000
03 Dec 2021GARLEX SOLUTIONS, S.L.GARLEX SOLUTIONS, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. The case concerned an unsolicited contract offer for electricity supply.ESAEPDGDPR€15,000
19 Mar 2026GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis.ISPersónuverndGDPR€17,425
02 Dec 2019GARANTIZA AUTOMOCIÓN, S.L.The company was fined by the AEPD in the amount of EUR 3,000 for failing to provide information or obtain consent for the use of cookies on its website. The breach concerned LSSI requirements on transparency and user consent.ESAEPDePrivacy€3,000
18 Dec 2024GAOLANIA SERVICIOS, S.L.GAOLANIA SERVICIOS, S.L. was fined EUR 30,000 by the AEPD for breaching the GDPR data accuracy principle under Article 5(1)(d). The authority found a lack of diligence in handling data errors.ESAEPDGDPR€30,000