Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Apr 2014Gambero Rosso Holding s.p.a.Gambero Rosso Holding s.p.a. was fined by the Italian data protection authority, Garante, for sending promotional emails without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,000
08 May 2014Galleria Voci s.r.l.Galleria Voci s.r.l. was fined EUR 2,400 by the Garante for failing to provide simplified information about the use of a video surveillance system. The authority found this to be a breach of privacy and data protection rules.ITGaranteGDPR€2,400
11 Nov 2011Galineio Melathro Private ClinicThe clinic unlawfully disclosed sensitive personal data without the required authorization from the HDPA. The breach involved special-category personal data and resulted in a 2,000 EUR fine.GRHDPAGDPR€2,000
11 Nov 2011Galineio Melathro Private ClinicThe clinic disclosed sensitive personal data without informing the data subject in advance. This breached the individual's right to object to the processing.GRHDPAGDPR€1,000
01 Jan 2013GALIBROKER GESTION TURISTICA, S.L.GALIBROKER GESTION TURISTICA, S.L. was fined by the AEPD 6,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€6,000
10 Oct 2023GALENICUM HEALTH, S.L.U.GALENICUM HEALTH, S.L.U. was fined EUR 500 by the AEPD for failing to display informational signage about its video surveillance system. The authority found a breach of Article 5(1)(c) GDPR in relation to transparency and proper notice.ESAEPDGDPR€500
23 Aug 2023GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined by the AEPD 5,000 EUR for sending commercial emails to a complainant after they had opted out. The authority treated this as a breach of data protection rules.ESAEPDePrivacy€5,000
04 Apr 2024GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications.ESAEPDePrivacy€10,000
19 Sept 2024GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.GACM Seguros was fined 8,000 EUR by the AEPD for improperly sharing personal data related to an insurance claim with another insured party. The authority found a breach of data protection rules.ESAEPDGDPR€8,000
29 Sept 2020GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€2,500
14 Mar 2017GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€7,100
22 Jun 2023Futuro Molise S.r.l.Futuro Molise S.r.l. was fined EUR 2,000 by the Garante for publishing an article that contained personal data without demonstrating a public interest basis. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
09 Feb 2011Futurgroup s.r.l.Futurgroup s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 9,000. The case concerned the failure to provide timely information to the data subject as required by the data protection code.ITGaranteGDPR€9,000
05 Jul 2021FUTURE VINLINE SLFUTURE VINLINE SL was fined by the AEPD EUR 10,000 for not having an adequate privacy policy on its website. The authority found that the company failed to provide clear and complete information about data processing under Article 13 GDPR.ESAEPDGDPR€10,000
24 Jul 2014Future srlFuture srl was fined EUR 36,000 by the Garante for making unsolicited promotional phone calls without proper consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€36,000
18 Apr 2018Futur3 s.r.l.Futur3 s.r.l. was fined EUR 50,000 by the Garante for requiring users to give mandatory consents for marketing and profiling purposes that were not directly related to the requested Wi‑Fi service. The authority found this to be a breach of data protection rules.ITGaranteGDPR€50,000
17 Jun 2024FÚTBOL CLUB BARCELONAFútbol Club Barcelona was fined by the AEPD for processing biometric data without explicit consent during a mandatory member census update. The authority found breaches of GDPR Articles 9 and 35, relating to special-category data processing and data protection impact assessment requirements.ESAEPDGDPR€6,000,000
17 Jan 2023Fusiona Soluciones Energéticas, S.A.Fusiona Soluciones Energéticas, S.A. was fined by the AEPD for unlawfully processing personal data. The company included an individual's data in a credit information system without a lawful basis.ESAEPDGDPR€50,000
05 Jun 2020FURNISHYOURSPACE SL.FURNISHYOURSPACE SL. was fined by the AEPD EUR 3,000 for failing to provide information or obtain consent regarding data storage and retrieval devices on its websites. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
10 Nov 2016Funworld s.r.l.Funworld s.r.l. was fined €2,400 by the Garante for failing to respond to a request for information concerning the unlawful processing of personal data through a video surveillance system. The case concerned a failure to cooperate with the supervisory authority.ITGaranteGDPR€2,400