Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Sept 2022FONTANORTE, S.L.FONTANORTE, S.L. was fined 2,000 EUR by the AEPD for breaching Article 32 GDPR. The company improperly disposed of documents containing personal data in public waste containers, making them accessible to third parties.ESAEPDGDPR€2,000
07 Nov 2023FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information.SEIMYGDPR€42,845
20 Oct 2022Fondazione Teatro Regio di TorinoFondazione Teatro Regio di Torino was fined EUR 5,000 by the Garante for publishing an individual's personal data on its website. The authority found a breach of the GDPR principles of lawful, fair, and transparent processing.ITGaranteGDPR€5,000
21 Apr 2021Fondazione Policlinico Tor Vergata di RomaFondazione Policlinico Tor Vergata di Roma was fined by the Garante 15,000 EUR for breaches of data processing principles. The case concerned compliance with lawfulness, fairness, transparency, and security measures.ITGaranteGDPR€15,000
04 Feb 2016Fondazione IRCCS Cà Granda, Ospedale Maggiore PoliclinicoFondazione IRCCS Cà Granda, Ospedale Maggiore Policlinico was fined by the Garante €10,000 for unlawful processing of personal data. The breach involved the incorrect delivery of documents containing health information of third parties.ITGaranteGDPR€10,000
11 Feb 2021Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da PietrelcinaThe foundation was fined by the Garante 5,000 EUR for processing personal data in breach of the principles of lawfulness, fairness, transparency, integrity, and confidentiality. The case concerned in particular the handling of health data.ITGaranteGDPR€5,000
28 Apr 2026Fondation YThe APD Litigation Chamber fined Fondation Y EUR 1,000 for failing to respond to a data erasure request. The authority also found negligent cooperation with the data protection authority, constituting a breach of Article 31 GDPR.BEAPDGDPR€1,000
08 Jul 2015FNAC Italia s.r.l.FNAC Italia s.r.l. was fined €2,400 by the Garante. The authority found that the company did not provide data subjects with adequate information about the purpose of processing under its video surveillance system.ITGaranteGDPR€2,400
06 Jun 2021FLY FUT, S.L.FLY FUT, S.L. was fined by the AEPD in the amount of 3,000 EUR for recording a minor during football matches without prior consent. The case concerns a breach of data protection rules and the requirement to obtain consent before processing a child’s image.ESAEPDGDPR€3,000
02 Mar 2023Flowers R di Malalan MitjaMalalan Mitja was fined by the Garante in the amount of 5,000 EUR for sending unsolicited promotional emails. The messages were sent to randomly generated email addresses, which constituted a breach of GDPR requirements.ITGaranteGDPR€5,000
22 Jul 2021Flowbird s.r.l.Flowbird s.r.l. was fined EUR 30,000 by the Garante for processing personal data through parking meters in Rome without a legal basis. The authority also found that the company failed to maintain a record of processing activities.ITGaranteGDPR€30,000
03 Feb 2022FLORAQUEEN FLOWERING THE WORLD S.L.FLORAQUEEN FLOWERING THE WORLD S.L. was fined 3,000 EUR by the AEPD for failing to provide requested information. The case concerned the duty to cooperate with the Spanish data protection authority under GDPR Article 58(1).ESAEPDGDPR€3,000
20 Feb 2021FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements.ESAEPDGDPR€3,000
01 Jan 2024FLEXICAR IBÉRICA, S.L.FLEXICAR IBÉRICA, S.L. was fined €50,000 by the AEPD for a personal data breach. The incident occurred when information belonging to other clients was mistakenly shared via WhatsApp.ESAEPDGDPR€50,000
01 Jan 2013FLAYBOX S.L.FLAYBOX S.L. was fined by the AEPD in the amount of EUR 3,100 for sending unsolicited promotional emails despite the recipient's request to unsubscribe. The authority found a breach of Articles 21.1 and 21.2 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€3,100
26 Feb 2026Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals.ITGaranteGDPR€15,000
05 Mar 2020Fjölbrautaskólinn í BreiðholtiFjölbrautaskólinn í Breiðholti was fined by Persónuvernd after a teacher accidentally sent sensitive personal data about students to unauthorized recipients. The authority found that the school had not implemented adequate technical and organizational measures to protect data security.ISPersónuverndGDPR€9,139
03 Nov 2025Fiziskas personaA fine of EUR 250 was imposed by DVI. The decision has entered into force.LVDVIGDPR€250
03 Apr 2024Fiziska personaA fine of EUR 150 was imposed by the DVI. The decision is final and has entered into force.LVDVIGDPR€150
06 Aug 2024Fiziska personaA monetary fine of EUR 100 was imposed. The decision is final and has entered into force.LVDVIGDPR€100