Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jan 2023KENAI MEDIA, S.L.KENAI MEDIA, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case concerned the publication of a video featuring the complainant without proper consent.ESAEPDGDPR€10,000
23 Jun 2025Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data.ITGaranteGDPR€10,000
03 May 2018Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
20 Nov 2025SOCIETE EXERCANT DES ACTIVITES DE SOCIETES DE HOLDING ET DEVELOPPANT DES SOLUTIONS EN RESSOURCES HUMAINES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 under a simplified procedure. The case concerns a breach of rules covered by the authority's decision.FRCNILGDPR€10,000
17 Jul 2025Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR.ITGaranteGDPR€10,000
16 May 2018Ierardi TeresaIerardi Teresa, a general practitioner, was fined by the Garante for failing to adopt minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
13 Sept 2007Comune di MoncalieriComune di Moncalieri was fined by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the notification obligation under Article 37 of the Italian Data Protection Code.ITGaranteGDPR€10,000
18 Jul 2023Cat s.r.l.The Garante imposed a EUR 10,000 fine on Cat s.r.l. for operating a video surveillance system near waste bins in breach of the principles of lawfulness, fairness, and transparency. The case concerned the data of residents and non-residents of the Comune di Modica.ITGaranteGDPR€10,000
29 Nov 2019BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules.ESAEPDePrivacy€10,000
14 Jan 2021Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
12 Nov 2014Associazione sportiva dilettantistica Sport Fashion (A.S.D. Sport Fashion)The sports association was fined by the Garante 10,000 EUR for processing clients' biometric data without the required information and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€10,000
17 Dec 2020Comune di LuinoComune di Luino was fined EUR 10,000 by the Garante for unlawfully disclosing personal data online. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
14 Sept 2006Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
01 Oct 2015Comune di Loiri Porto San PaoloThe Municipality of Comune di Loiri Porto San Paolo was fined by the Garante 10,000 EUR for publishing personal data on its website that revealed health status. The case involved unlawful disclosure of sensitive data in breach of data protection rules.ITGaranteGDPR€10,000
29 Jan 2026Istituto tecnico industriale statale “Stanislao Cannizzaro” di CataniaIstituto tecnico industriale statale “Stanislao Cannizzaro” di Catania was fined by the Garante €10,000 for breaches of data protection principles. The authority found that personal data were processed in a manner that was not lawful, fair, or transparent.ITGaranteGDPR€10,000
19 May 2021TNT EXPRESS WORLDWIDE SPAIN, S.L.TNT Express Worldwide Spain, S.L. was fined by the AEPD €10,000 for incorrectly linking a personal delivery service to a corporate account. This resulted in the unauthorized sharing of personal data with the complainant’s employer.ESAEPDGDPR€10,000
11 Sept 2025ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD for disclosing personal data, including a handwritten signature, in a news broadcast without necessity. The authority found that the disclosure breached data protection principles because it was not proportionate to the purpose of the publication.ESAEPDGDPR€10,000
26 Mar 2010Lenzi automobili s.p.a.Lenzi automobili s.p.a. was fined by the Garante for using a biometric system to verify employee attendance without the required authorization. This constituted a breach of data protection rules.ITGaranteGDPR€10,000
01 Jan 2025ASESORAMOS TU FORMACIÓN CON CALIDAD S.L.ASESORAMOS TU FORMACIÓN CON CALIDAD S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case also involved the improper inclusion of individuals in credit information systems.ESAEPDGDPR€10,000
23 Jan 2024CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.CAJA RURAL DE BAENA was fined by the AEPD 10,000 EUR for breaching data protection principles. The case involved failures in confidentiality and integrity of personal data, which led to unauthorized access by third parties.ESAEPDGDPR€10,000